In [1]:
# import libraries
import pandas as pd
from sklearn import metrics
import numpy as np
from IPython.display import display, HTML 
import tensorflow as tf
from tensorflow.keras.models import Sequential
from tensorflow.keras.layers import Dense, Activation
import keras 

Using TensorFlow backend.


In [40]:
df = pd.read_csv("C:/Users/Ruben/Datasets/BATADAL/BATADAL_dataset04.csv")

df.columns = [
    'DATETIME','L_T1','L_T2','L_T3','L_T4','L_T5','L_T6','L_T7','F_PU1','S_PU1','F_PU2','S_PU2','F_PU3',
    'S_PU3','F_PU4','S_PU4','F_PU5','S_PU5','F_PU6','S_PU6','F_PU7','S_PU7','F_PU8','S_PU8','F_PU9','S_PU9',
    'F_PU10','S_PU10','F_PU11','S_PU11','F_V2','S_V2','P_J280','P_J269','P_J300','P_J256','P_J289','P_J415',
    'P_J302','P_J306','P_J307','P_J317','P_J14','P_J422','OUTCOME'
]

# 'DATETIME' is irrelevant for the thesis
# The other dropped columns contain either only 0s, only 1s or only 2s and are therefore irrelevant

df = df.drop(['DATETIME', 'S_PU1', 'F_PU3', 'S_PU3', 'F_PU5', 'S_PU5', 'F_PU9', 'S_PU9'], axis = 1)

# The dataset labels attacks by '-999' and labels normal data as 1
# To keep the same structure in all datasets, the '-999' values are changed to '-1' and normal values to '1'

df['OUTCOME'].replace(to_replace = [-999], value = '-1', inplace = True)
df['OUTCOME'].replace(to_replace = [1], value = '1', inplace = True)

# data types need to be numeric to be encoded to z-scores --> convert column object data types to numerics

cols = df.columns[df.columns != 'OUTCOME']
df[cols] = df[cols].apply(pd.to_numeric, errors='coerce')

# Encoding the feature vectors to z-scores
cols = list(df.columns[df.columns != 'OUTCOME'])
for col in cols:
    df[col] = ((df[col] - df[col].mean())/df[col].std(ddof=0))

In [42]:
normal_mask = df['OUTCOME'] == '1'
attack_mask = df['OUTCOME'] == '-1'

df.drop('OUTCOME',axis=1,inplace=True)

df_normal = df[normal_mask]
df_attack = df[attack_mask]

print(f"Normal count: {len(df_normal)}")
print(f"Attack count: {len(df_attack)}")

Normal count: 219
Attack count: 3958


In [43]:
# This is the numeric feature vector, as it goes to the neural net
x_normal = df_normal.values
x_attack = df_attack.values

In [44]:
from sklearn.model_selection import train_test_split

x_normal_train, x_normal_test = train_test_split(
    x_normal, test_size=0.25, random_state=42)

In [45]:
print(f"Normal train count: {len(x_normal_train)}")
print(f"Normal test count: {len(x_normal_test)}")

Normal train count: 164
Normal test count: 55


In [50]:
# Create neural network architecture
model = Sequential()
model.add(Dense(150, input_dim=x_normal.shape[1], activation='relu'))
model.add(Dense(75, activation='relu'))
model.add(Dense(25, activation='relu'))
model.add(Dense(15, activation='relu'))
model.add(Dense(25, activation='relu'))
model.add(Dense(75, activation='relu'))
model.add(Dense(150, activation='relu'))
model.add(Dense(x_normal.shape[1])) # Multiple output neurons
model.compile(loss='mean_squared_error', optimizer='adam')
model.fit(x_normal_train,x_normal_train,verbose=1,epochs=100)

Epoch 1/100
Epoch 2/100
Epoch 3/100
Epoch 4/100
Epoch 5/100
Epoch 6/100
Epoch 7/100
Epoch 8/100
Epoch 9/100
Epoch 10/100
Epoch 11/100
Epoch 12/100
Epoch 13/100
Epoch 14/100
Epoch 15/100
Epoch 16/100
Epoch 17/100
Epoch 18/100
Epoch 19/100
Epoch 20/100
Epoch 21/100
Epoch 22/100
Epoch 23/100
Epoch 24/100
Epoch 25/100
Epoch 26/100
Epoch 27/100
Epoch 28/100
Epoch 29/100
Epoch 30/100
Epoch 31/100
Epoch 32/100
Epoch 33/100
Epoch 34/100
Epoch 35/100
Epoch 36/100
Epoch 37/100
Epoch 38/100
Epoch 39/100
Epoch 40/100
Epoch 41/100
Epoch 42/100
Epoch 43/100
Epoch 44/100
Epoch 45/100
Epoch 46/100
Epoch 47/100
Epoch 48/100
Epoch 49/100
Epoch 50/100
Epoch 51/100
Epoch 52/100
Epoch 53/100
Epoch 54/100
Epoch 55/100
Epoch 56/100
Epoch 57/100
Epoch 58/100
Epoch 59/100
Epoch 60/100
Epoch 61/100
Epoch 62/100
Epoch 63/100
Epoch 64/100
Epoch 65/100
Epoch 66/100
Epoch 67/100
Epoch 68/100
Epoch 69/100
Epoch 70/100
Epoch 71/100
Epoch 72/100
Epoch 73/100
Epoch 74/100
Epoch 75/100
Epoch 76/100
Epoch 77/100
Epoch 78

<tensorflow.python.keras.callbacks.History at 0x2746d544908>

In [49]:
pred = model.predict(x_normal_test)
score1 = np.sqrt(metrics.mean_squared_error(pred,x_normal_test))
pred = model.predict(x_normal)
score2 = np.sqrt(metrics.mean_squared_error(pred,x_normal))
pred = model.predict(x_attack)
score3 = np.sqrt(metrics.mean_squared_error(pred,x_attack))
print(f"Out of Sample Score (RMSE): {score1}")
print(f"Insample Normal Score (RMSE): {score2}")
print(f"Attack Underway Score (RMSE): {score3}")

Out of Sample Score (RMSE): 0.5264941886771264
Insample Normal Score (RMSE): 0.42163648432558243
Attack Underway Score (RMSE): 0.5460020593959424


In [41]:
with pd.option_context('display.max_rows', 10, 'display.max_columns', None):
    display(df)

Unnamed: 0,L_T1,L_T2,L_T3,L_T4,L_T5,L_T6,L_T7,F_PU1,F_PU2,S_PU2,F_PU4,S_PU4,F_PU6,S_PU6,F_PU7,S_PU7,F_PU8,S_PU8,F_PU10,S_PU10,F_PU11,S_PU11,F_V2,S_V2,P_J280,P_J269,P_J300,P_J256,P_J289,P_J415,P_J302,P_J306,P_J307,P_J317,P_J14,P_J422,OUTCOME
0,-0.221124,1.327657,-1.489124,0.998033,0.151721,0.741081,1.272798,-0.705623,0.575307,0.606764,-0.851806,-0.852913,-0.145194,-0.145847,0.492284,0.450998,0.829600,0.826798,0.402494,0.485591,-0.087728,-0.087864,-1.557071,-1.631203,-0.134706,0.703293,0.180093,-1.109739,0.163175,0.422972,-0.612301,0.824104,-0.612983,0.704231,1.179237,0.071841,-1
1,-0.039228,0.844757,-1.474446,1.144866,0.736189,0.403126,1.439856,-1.118676,0.475250,0.606764,1.161397,1.172452,-0.145194,-0.145847,0.413687,0.450998,0.960905,0.826798,-2.050802,-2.059345,-0.087728,-0.087864,-1.557071,-1.631203,-0.134706,1.096933,-1.221813,0.982480,-1.212720,0.290987,1.111116,1.213368,1.125392,-1.467869,1.796704,-1.230930,-1
2,0.332832,0.253036,-0.799237,1.199928,1.524541,-1.230321,-0.123326,-1.072672,0.486157,0.606764,1.085593,1.172452,-0.145194,-0.145847,0.330783,0.450998,0.931089,0.826798,-2.050802,-2.059345,-0.087728,-0.087864,-1.557071,-1.631203,-0.134706,1.054377,-1.421050,1.166567,-1.413447,0.586633,1.119606,1.315176,1.133841,-1.691650,1.759743,-1.451169,-1
3,0.754500,-0.168651,-0.050635,0.887909,1.103181,-2.187859,-1.101807,-1.246898,0.444190,0.606764,1.103222,1.172452,-0.145194,-0.145847,-2.190776,-2.217303,-1.208210,-1.209485,0.633286,0.485591,-0.087728,-0.087864,-1.557071,-1.631203,-0.134706,1.219280,-0.276342,1.483999,-0.245579,-1.836604,1.491032,-1.019412,1.476025,0.759288,2.029341,-0.398500,-1
4,1.134828,-0.413501,0.771359,-0.653829,0.491528,0.121498,0.163058,-1.353587,0.418346,0.606764,1.086769,1.172452,-0.145194,-0.145847,-2.190776,-2.217303,-1.208210,-1.209485,0.643963,0.485591,-0.087728,-0.087864,-1.557071,-1.631203,-0.134706,1.318576,-0.395884,1.499339,-0.369665,-1.837924,1.639602,-1.021408,1.623882,0.800137,2.194579,-0.525418,-1
...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...,...
4172,-0.047496,-0.624345,-0.520346,-0.947493,1.456580,-2.413162,-1.352393,1.883299,-1.645156,-1.648087,-0.851806,-0.852913,-0.145194,-0.145847,0.517047,0.450998,0.756780,0.826798,0.471485,0.485591,-0.087728,-0.087864,0.300335,0.613044,1.365743,-1.899692,-0.124197,-1.106199,-0.143390,0.194639,-1.299969,0.719302,-1.297350,-0.352514,-0.875362,-0.174528,-1
4173,-0.386484,-0.495118,-1.151520,-1.167741,1.279880,-1.962556,-1.614912,1.789335,-1.645156,-1.648087,-0.851806,-0.852913,-0.145194,-0.145847,0.542887,0.450998,-1.208210,-1.209485,0.616038,0.485591,-0.087728,-0.087864,0.401452,0.613044,1.365743,-1.802169,-0.019144,-1.274945,-0.041202,0.104889,0.175122,-1.358770,0.168547,-0.201550,-0.807963,-0.058809,-1
4174,-0.659328,-0.359090,-1.841408,-1.956964,-0.065755,-1.286647,-1.734239,1.944964,-1.645156,-1.648087,1.313004,1.172452,-0.145194,-0.145847,0.538042,0.450998,-1.208210,-1.209485,0.612753,0.485591,-0.087728,-0.087864,0.285968,0.613044,1.365743,-1.965299,-0.359659,0.734671,-0.340468,0.020419,-0.024386,-1.487527,-0.030004,-0.345410,-0.918846,-0.249185,-1
4175,-0.981780,-0.522324,-1.283626,-2.801249,-1.438575,-1.511950,-2.307008,1.877427,-1.645156,-1.648087,1.262468,1.172452,5.285289,6.856493,-0.203245,0.450998,-1.208210,-1.209485,0.611931,0.485591,-0.087728,-0.087864,0.546497,0.613044,1.365743,-1.892600,-0.729153,0.796033,-0.727325,2.767018,0.041409,-1.542423,0.035475,-0.285024,-1.071039,-0.510486,-1
