Geri Dön

Nöromorfik hesaplama ve memristor tabanlı ağ saldırı tespit sistemleri: Siber güvenlikte yeni yaklaşımlar

Neuromorphic computing and memristor-based network attack detection systems: New approaches in cyber security

  1. Tez No: 978070
  2. Yazar: YUSUF ETKA KÖYLÜ
  3. Danışmanlar: PROF. DR. İLHAN KOCAARSLAN
  4. Tez Türü: Yüksek Lisans
  5. Konular: Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol, Computer Engineering and Computer Science and Control
  6. Anahtar Kelimeler: Belirtilmemiş.
  7. Yıl: 2025
  8. Dil: Türkçe
  9. Üniversite: İstanbul Teknik Üniversitesi
  10. Enstitü: Lisansüstü Eğitim Enstitüsü
  11. Ana Bilim Dalı: Mekatronik Mühendisliği Ana Bilim Dalı
  12. Bilim Dalı: Belirtilmemiş.
  13. Sayfa Sayısı: Belirtilmemiş.

Özet

Güncel siber tehditler, giderek artan trafik hacimleri ve karmaşık saldırı vektörleri nedeniyle geleneksel imza-tabanlı çözümlerin sınırlarını zorlamaktadır. Gecikme ve enerji kısıtları altında çalışan uç/bulut-kenarı sistemlerde, hem bilinen hem de“zero-day”niteliğindeki bilinmeyen saldırıların yakalanması için daha verimli, adaptif ve düşük maliyetli yaklaşımlara ihtiyaç vardır. Bu tez, nöromorfik hesaplama ilkelerini (olay-tabanlı işleme, sivri uç/spike tabanlı temsil) ve memristif donanım olanaklarını, saldırı tespit sistemlerine (IDS) uyarlayan bir çatı önermektedir. Çalışmada spiking autoencoder (SAE) ve spiking varyasyonel autoencoder (SVAE) mimarileri üzerine kurulu, unsupervised/yarı-gözetimsiz anomali tespiti yaklaşımı geliştirilmiş; model öğrenimi ile donanıma eşleme süreci“train-then-constrain”çizgisinde ele alınmıştır. Özellikle Intel Loihi/IBM TrueNorth sınıfı nöromorfik işlemcilerle ve memristör çapraz-çubuk matrisleriyle uyumlu düşük bitli nicemleme, ağırlık ayrıklaştırma ve çekirdek/sinaps yerleşimi stratejileri, çalışma kapsamının ayrılmaz parçasıdır. Veri tarafında, geniş kabul görmüş NSL-KDD ve CICIDS2017 veri setleri esas alınmış; öz nitelik temizleme, kodlama ve dengeleme adımları sistematik bir iş akışı şeklinde uygulanmıştır. Kodlama cephesinde hibrit bir strateji izlenmiş; ikili (binary), hız-tabanlı (rate) ve ateşleme-zamanı (time-to-spike, TTS) kodlama yöntemleri, nöromorfik sinir katmanlarına uygun spike akışları üretmek üzere kalibre edilmiştir. Rate kodlamada hedef ortalama spike oranı p̄, zaman penceresi T ve özellik boyutu D göz önüne alınarak beklenen spike sayısı T×D×p̄ düzeyinde kontrol edilmiştir; T'nin artırılmasının beklenen olay sayısını doğrusal büyüttüğü analizlerle gösterilmiştir. Bu sayede hem bilgi kaybı sınırlandırılmış hem de olay-tabanlı donanım tarafında enerji-gecikme dengesi optimize edilmiştir. Model mimarisinde SAE ve SVAE'nin tercih edilmesinin temel gerekçesi, etiket bağımlılığını azaltarak“normal davranışın spiking temsillerini”öğrenebilme yeteneğidir. SAE, yeniden yapım hatasını (binary çapraz entropi) minimize ederken; SVAE, olasılıksal gizil değişkenler üzerinden β-ağırlıklı ELBO optimizasyonu ile düzenli bir gizil alan öğrenir. Bu olasılıksal çerçeve, özellikle zero-day koşullarında gözlenen dağılım kaymalarına karşı daha esnek karar yüzeyleri sağlar. Her iki mimari de LIF nöronları ve vekil-türev yaklaşımlarıyla eğitilmiş; eğitimden sonra ağırlıklar simetrik int8 düzeyine nicemlenerek çekirdekler/sinapslar üstünde ayrıklaştırılmıştır. Eğitim-doğrulama-test ayrımlarında veri sızmasını önlemek ve adil kıyaslama yapmak amacıyla katı ilkelere bağlı kalınmıştır: karar eşiği τ, yalnızca doğrulama kümesindeki yeniden yapım ya da ELBO skor dağılımının üst yüzdeliklerine (%97–%99.9) göre seçilmiş ve test aşamasında dondurulmuştur. Dengesiz sınıf koşullarını doğru yansıtmak için ROC-AUC ile birlikte PR-AUC, saldırı sınıfı odaklı Precision/Recall/F1 ve Balanced Accuracy birlikte raporlanmıştır. Uygulama senaryosuna göre“dengeli politika”(BA maksimizasyonu) ya da“saldırı odaklı politika”(Recall/F1 maksimizasyonu) benimsenmiş; eşik kalibrasyonu buna göre yapılmıştır. Bu prosedür, sabit yanlış-alarm (FPR) ya da sabit geri çağırma (Recall) rejimlerinde operasyonel kararlılığı artırmıştır. Deneysel çalışma iki eksende yürütülmüştür: (i) Algısal performans: SAE/SVAE'nin CNN, RNN/LSTM ve Transformer tabanlı çizgilerle karşılaştırılması; (ii) Donanım verimliliği: CPU/GPU'ya kıyasla Nöromorfik sınıfı ve memristör prototiplerinin enerji, gecikme, bellek ayak izi ve akson yoğunluğu metrikleri. NSL-KDD'de özet metrikler, SVAE'nin düşük FPR ve yüksek Recall bölgelerinde daha kararlı kaldığını; bu dengenin F1 ve PR-AUC üstünlüğüne yansıdığını göstermektedir. Zero-day alt senaryolarında SVAE, tüm geri çağırma aralığında SAE'ye göre daha yüksek duyarlılık üretmekte; PR-AUC bakımından da belirgin bir üstünlük sergilemektedir. Sayısal bulgular, önerilen yöntemin hem bilinen hem de bilinmeyen tehditlerde etkili olduğunu ortaya koymaktadır.“Tespit edilen anomaliler oranı”başlığında özetlenen sonuçlara göre imza-tabanlı bilinen saldırılarda başarı %95,30; zero-day saldırılarda ise %89,00 seviyesine ulaşmıştır. Ayrıca saldırı türü bazında (ör. DDoS, MITM, phishing) oranlar yüksek düzeydedir ve zero-day alt kümesi için de rekabetçi değerler raporlanmıştır. Metodolojik olarak farkların tesadüfi olup olmadığını sınamak üzere McNemar ve işaret testleri ile bootstrap güven aralıkları kullanılmış; eşik seçimi ise doğrulama üzerinde belirlenip testte sabitlenerek tekrarlanabilirlik güçlendirilmiştir. Donanım verimliliği karşılaştırmaları, nöromorfik/memristif platformların enerji ve gecikme açısından klasik CPU tabanlı çalışmaya kıyasla kayda değer üstünlük sunduğunu göstermektedir. Örneğin TrueNorth sınıfı bir yerleşimde tahmini kestirim başına enerji ~0.012 J ve gecikme ~3.8 ms seviyesindeyken, CPU tabanlı karşılaştırmada bu değerler sırasıyla ~0.250 J ve ~22 ms düzeyindedir; bellek ayak izi ve çekirdek ataması da donanıma elverişli ölçekte tutulabilmiştir. Memristör prototiplemesinde sinaptik iletkenlikler ayrık ağırlıklara eşlenmiş; yaz-okuma sürünmesi ve gürültü etkileri yinelemeli kalibrasyonla dengelenmiştir. Bu bulgular, uç cihazlarda enerji-gecikme kısıtları altında gerçek zamanlı IDS dağıtımını mümkün kılmaktadır. Çalışmanın özgün katkıları üç başlıkta toplanabilir: (i) Nöromorfik donanımla uyumlu hibrit veri kodlama ve spike bütçesi yönetimi (p̄, T, D parametrelerinin birlikte kalibrasyonu) sayesinde hem bilgi bütünlüğü hem de enerji-gecikme dengesi korunmuştur. (ii) SAE/SVAE'nin donanıma eşlenmesini kolaylaştıran ayrık ağırlıklar, int8 nicemleme ve çekirdek/sinaps yerleşimi prosedürleri açıkça tanımlanmış; memristif çapraz-çubuklara aktarımda sürünme/gürültü telafisi pratik bir akışa bağlanmıştır. (iii) Adil değerlendirme ve eşiğe duyarlı raporlama ilkeleri (τ'nin doğrulama-temelli seçilmesi; ROC-AUC ve PR-AUC'nin birlikte verilmesi; BA/F1 odaklı politika seçimi), IDS literatüründeki dengesiz veri ve operasyonel maliyet sorunlarını pratikte gözetmiştir. Sınırlılıklar ve gelecek çalışmalar açısından, daha geniş ölçekli trafiğin (ör. CICIDS2017 tam akışları), canlı ağ telemetrisi ve farklı saldırı türleriyle (ör. tedarik zinciri, çok-aşamalı APT) sınanması; ayrıca federatif/kenar dağıtımla model güncellemelerinin gecikme-gizlilik dengesinde yönetilmesi planlanmaktadır. Donanım tarafında, çok çekirdekli nöromorfik dizilerde akson yönlendirme maliyetleri ve bellek dar boğazları için akıllı yerleşim/bağlaç stratejileri; memristörlerde dayanıklılık-kararlılık (endurance/retention)-hassasiyet (conductance precision) üçgeninin uygulamaya özel optimizasyonu da önemli bir araştırma vektörüdür. Sonuç olarak, tezde sunulan çatı; zero-day tespitinde rekabetçi doğruluk, düşük gecikme ve yüksek enerji verimliliğini birlikte sağlayarak, gerçek zamanlı ve kaynak kısıtlı ortamlarda uygulanabilir bir IDS çözümü ortaya koymaktadır.

Özet (Çeviri)

The increasing diversity and sophistication of cyber threats, particularly under high-volume and continuously streaming network traffic, strain the sensitivity and scalability of traditional signature-based intrusion detection systems (IDS). Solutions dependent on signature updates often lag in capturing new variants or previously unseen“zero-day”attacks; moreover, real-time operation on resource-constrained edge devices (gateways, IoT nodes, cyber-physical systems) becomes challenging due to power and latency budgets. In this context, event-centric and sparsity-promoting neuromorphic paradigms offer compelling advantages through low power consumption, inherent parallelism, and natural timing. This thesis proposes an anomaly-detection framework built on spiking neural networks (SNN) using the autoencoder family—spiking autoencoder (SAE) and its variational extension (SVAE)—and shapes the model–hardware co-design under a“train-then-constrain”principle. The objective is to validate an IDS that sustains high sensitivity to both known and unknown (zero-day) threats while meeting real-time constraints on energy, latency, and memory footprint, and to demonstrate reproducible deployment steps on neuromorphic and memristive hardware. The central challenge is to construct an edge-deployable IDS with limited dependence on labeled attack exemplars—one that remains robust to distributional shifts (concept drift) and zero-day scenarios. The thesis addresses four questions: (i) To what extent can autoencoder-based spiking representations maintain the normal/attack separation under label scarcity? (ii) What practical gains in the energy–latency trade-off arise from event-based encoding (rate and time-to-spike) and explicit spike-budget management? (iii) How should weight quantization, core/synapse placement, and routing constraints be handled for neuromorphic and memristive mappings? (iv) What constitutes a fair evaluation protocol—especially with PR-AUC, ROC-AUC, Balanced Accuracy (BA), F1 jointly reported—together with a principled thresholding strategy? The framework comprises two principal components: (1) a data–feature pipeline and spike generation layer; (2) the spiking AE/SVAE model with thresholding and decision logic. The first component processes raw flow records via missing/outlier handling, categorical conversion (binary/one-hot or compact numerical embeddings), normalization, and when necessary, discretization (quantile- or arithmetic-interval-based). It then produces spike trains suited to neuromorphic layers. A hybrid encoding strategy is adopted: rate coding establishes a target mean spiking probability pˉ\bar{p}pˉ per feature channel within a time window TTT, controlling the expected total spike count at roughly T×D×pˉT \times D \times \bar{p}T×D×pˉ (with DDD the effective feature dimension). This constrains unnecessary event generation—benefiting energy and latency—without excessive information loss. Complementarily, where temporal discriminability is critical, time-to-spike (TTS) encoding maps low values to earlier spikes and high values to later spikes, enhancing separability of anomalous temporal signatures. The second component is the spiking autoencoder family. SAE reconstructs input spike sequences and minimizes reconstruction loss (binary cross-entropy/Poisson likelihood). SVAE builds a probabilistic latent representation; within a β-VAE formulation, it optimizes the ELBO to learn a regularized, disentangled latent space. The probabilistic nature of SVAE yields more flexible decision boundaries under distribution shifts and is therefore advantageous in zero-day conditions. Both models use leaky integrate-and-fire (LIF) neurons trained with surrogate gradients to enable backpropagation through spiking non-linearities. After training, parameters are quantized to symmetric int8, and weight discretization plus clustering prepares the network for core/synapse placement on neuromorphic substrates, easing translation to Intel Loihi/IBM TrueNorth-class processors and to memristive crossbar arrays. To avoid leakage and ensure fair comparisons, the work uses strictly disjoint train/validation/test splits. The decision threshold τ\tauτ is chosen exclusively on the validation set by scanning upper percentiles (e.g., 97–99.9%) of reconstruction scores (SAE) or negative ELBO-like anomaly scores (SVAE), in alignment with the operational policy (e.g., low false alarm vs. high capture). The selected single threshold remains frozen during testing. Because of class imbalance, the evaluation jointly reports PR-AUC, ROC-AUC, F1, Recall, Precision, and Balanced Accuracy (BA). Two deployment-oriented regimes are analyzed: a balanced policy (optimizing BA/F1) and an attack-biased policy (high recall under a preset FPR cap). The study focuses on NSL-KDD and CICIDS2017. NSL-KDD is a cleaned successor of KDD'99, reducing redundancy and class imbalance and thus serving as a standardized baseline. CICIDS2017 captures modern protocols and a diverse set of attacks (e.g., DDoS, port scans, brute force, web attacks, botnet activity), reflecting contemporary behaviors. Numerical features are normalized via min–max or robust scaling; categorical fields are converted using one-hot/binary encodings and, where beneficial, frequency-aware embeddings. In high-variance fields, quantile-based discretization is applied to homogenize spike intensities at the LIF input. The hybrid rate/TTS configuration calibrates pˉ\bar{p}pˉ and TTT per flow window according to energy–latency targets informed by scaling analyses (e.g., how TTT linearly increases expected spikes). Experiments proceed along two axes: (1) perceptual performance—comparing SAE/SVAE against non-spiking baselines such as CNNs, RNN/LSTMs, and Transformers; (2) hardware efficiency—contrasting CPU/GPU execution with neuromorphic and memristive prototypes in terms of energy per inference (J/sample), latency (ms), memory footprint (MB), and performance per unit energy. On NSL-KDD, SVAE particularly excels in low-FPR regimes, delivering higher Recall and PR-AUC than SAE and non-spiking baselines. Summarized“detected anomalies”rates yield 95.30% for known (signature-like) attacks and 89.00% for zero-day conditions. In zero-day sub-scenarios, SVAE sustains superior recall across the operating range, producing consistently larger PR-AUC. Statistical significance is assessed via McNemar and sign tests, with bootstrap confidence intervals (95%) reported for key metrics. On CICIDS2017, SVAE maintains its advantage on HTTP anomalies and DDoS traffic in F1 and PR-AUC, while holding the false positive rate within operational bounds under the same aggressive threshold. Neuromorphic and Memristive. Post-training int8 weights are mapped to hardware by considering core budgets and synaptic connectivity limits. Axonal routing costs (fan-out) and buffer usage are critical, particularly in deeper SVAE layers; these are mitigated by intra-layer grouping, sparsification, and topology-aware placement. During spiking inference, short time windows (e.g., T=10T=10T=10–20 ms) reduce latency, while constraining pˉ\bar{p}pˉ limits energy. On a TrueNorth-class configuration, the measured/estimated figures are around ~0.012 J per sample and ~3.8 ms latency, compared with ~0.250 J and ~22 ms on a CPU baseline. Memory footprint and routing tables remain deployable due to clustered discretization before placement. In memristive crossbar prototypes, synaptic conductance levels are mapped to discrete weight levels; drift and read noise are countered via periodic recalibration and a write-expose-read maintenance loop. These results indicate that real-time IDS near the edge (e.g., industrial network gateways) can meet energy–latency constraints with the proposed spiking architectures. Thresholding and Operational Policies. Real systems rarely weigh false alarms (FPR) and misses (FNR) equally. The thesis formalizes two regimes: (i) a fixed-FPR regime—maintain FPR below, say, 1% while maximizing recall; and (ii) a fixed-Recall regime—e.g., preserve ≥95% recall in critical infrastructure while minimizing FPR. The threshold τ\tauτ is selected by percentile scanning on validation scores and then locked for testing. This prevents the common pitfall of“threshold relaxation after the fact”and yields a reliable operating point matched to deployment goals. The resulting calibration guidelines connect threshold shifts to movements along ROC and PR curves, serving as a practical commissioning playbook for system integrators. Across NSL-KDD and CICIDS2017, SVAE demonstrates PR-AUC and Recall advantages over SAE in zero-day scenarios, and maintains an attractive F1 balance across diverse attack types (DDoS, MITM, brute force, scanning, etc.). The high-level summary of detected anomaly rates—95.30% for known and 89.00% for zero-day cases—supports practical viability under stringent operational targets. On the hardware side, the low-latency nature of spiking inference shortens“time-to-alert”in flow-based IDS pipelines, potentially limiting lateral movement by adversaries. The energy savings extend battery life on edge nodes and reduce power-thermal budget pressure in data-center-adjacent deployments. The small memory footprint, enabled by quantization and discretization, simplifies cost and maintenance for embedded platforms. Conventional deep models (CNN, LSTM, Transformer) can excel when labels are plentiful, yet they face three hurdles in edge deployments: (i) label dependency, (ii) update overhead, and (iii) energy–latency disadvantages. The proposed SAE/SVAE approach alleviates the label scarcity pain point through unsupervised/semi-supervised learning while delivering energy-efficient, low-latency inference via spiking representations. Persistently high PR-AUC indicates robust discrimination of the positive (attack) class under imbalance; when co-interpreted with ROC-AUC, it reduces reporting bias and better reflects costs in imbalanced detection. SVAE's regularized latent space confers flexibility under distributional shift; in practice this eases detection of out-of-distribution samples through ELBO-style anomaly scores. The thesis advances the state of the art with three concrete contributions: 1. Hybrid spike encoding and explicit spike-budgeting. Joint calibration of pˉ\bar{p}pˉ, TTT, and DDD preserves information while optimizing the energy–latency trade-off in hardware execution; the linear impact of TTT on expected spike counts is empirically characterized, yielding a practical selection guide. 2. Hardware-conscious spiking architectures. SAE/SVAE are tailored for int8 quantization, weight discretization, core/synapse placement, and axonal routing constraints, smoothing translation to Loihi/TrueNorth and to memristive crossbars. For memristors, a feasible calibration loop mitigates drift/noise, enabling stable multi-level conductance mapping. 3. Fair and reproducible evaluation. Thresholds are selected only on validation and frozen for testing; PR-AUC, ROC-AUC, F1, Recall, Precision, BA are jointly reported; fixed-FPR/fixed-Recall regimes are analyzed separately; and statistical significance with confidence intervals is provided. Limitations. (i) NSL-KDD's historical constraints and CICIDS2017's laboratory-like design cannot fully capture the richness of live network telemetry. (ii) Fixed thresholds require periodic re-calibration under drift; in field deployments, cost matrices (false alarm vs. miss) should be revisited and reflected in the operating point. (iii) In memristive mapping, material-level constraints—endurance/retention and conductance step granularity—may limit highly precise weight encoding; stability of multi-level cells can be context-dependent. (iv) In large neuromorphic arrays, axonal routing and packetization overheads can bottleneck very deep SNNs; topology-aware placement and sparsity become increasingly important. (i) Broader data coverage: full CICIDS2017 flows, CICIDS2018/UNSW-NB15, and live telemetry to stress generalization under real traffic dynamics. (ii) Federated/edge learning: local updates at edge nodes with privacy-preserving aggregation (e.g., differentially private federated averaging) to form a distributed learning loop. (iii) Adaptive thresholding and drift management: drift detection and dynamic τ\tauτ update policies, coupled with cost-sensitive decision rules tuned to deployment-specific loss functions. (iv) Hardware innovation: joint optimization of routing/placement for large neuromorphic fabrics, and in-situ calibration for memristors to compensate temperature and noise effects. By combining the spiking autoencoder family (SAE/SVAE) with hybrid spike encodings (rate + TTS), this thesis delivers an IDS approach that achieves high sensitivity and low latency against both known and zero-day attacks. Results on NSL-KDD and CICIDS2017—95.30% for known and 89.00% for zero-day“detected anomalies”rates—demonstrate competitive performance under low-FPR constraints with strong PR-AUC/F1/BA balance. Overall, the thesis offers a practical, scalable path for real-time IDS in resource-constrained environments, uniting the probabilistic latent modeling strengths of SVAE for zero-day detection with the inherent efficiency of spiking computation—thus contributing original advances at both methodological and hardware levels.

Benzer Tezler

  1. Alucra-Gümüşhane-Bayburt yörelerindeki (Doğu pontid güney zonu) üst jura-alt kretase yaşlı berdiga kireçtaşının sedimantolojik incelemesi

    Sedimentological investigation of the upper jurassiclower cretaceous berdiga limestone in the Alucra-Gümüşhane-Bayburt regions (Eastern pontids, ne Turkey)

    MEHMET ZİYA KIRMACI

    Doktora

    Türkçe

    Türkçe

    1992

    Jeoloji MühendisliğiKaradeniz Teknik Üniversitesi

    Jeoloji Mühendisliği Ana Bilim Dalı

    DOÇ.DR. SALİH YÜKSEL

  2. Diabetes melitusda kornea endotelinin speküler mikroskopla incelenmesi

    Investigating the corneal endothelium in diabetes mellitus by using specular microscopy

    SITKI SAMET ERMİŞ

    Tıpta Uzmanlık

    Türkçe

    Türkçe

    1997

    Göz Hastalıklarıİstanbul Üniversitesi

    Göz Hastalıkları Ana Bilim Dalı

    DOÇ. DR. OSMAN ŞEVKİ ARSLAN

  3. Astroglial hücre kültüründe eritropoietin ve interlökin-1 B'nin NGF ve nitrik oksid üretimi üzerine in vitro etkileri

    In vitro effects of erythropoietin and interleukin-1 beta on production of nitric oxide and NGF in astroglial cell culture

    BAŞAK BİNGÖL

    Tıpta Uzmanlık

    Türkçe

    Türkçe

    2002

    BiyokimyaDokuz Eylül Üniversitesi

    Biyokimya Ana Bilim Dalı

    DOÇ.DR. FİLİZ KURALAY