In [1]:
import sys
sys.path.append("C:/Users/user/meepc")
import numpy as np
import pandas as pd
from models import Hankel,Corrhankel,Pipeline
from sklearn.preprocessing import StandardScaler
from sklearn.metrics import accuracy_score,precision_score,recall_score,f1_score,roc_auc_score

C:\Users\user\AppData\Local\Packages\PythonSoftwareFoundation.Python.3.9_qbz5n2kfra8p0\LocalCache\local-packages\Python39\site-packages\numpy\.libs\libopenblas.EL2C6PLE4ZYW3ECEVIV3OXXGRN2NRFM2.gfortran-win_amd64.dll
C:\Users\user\AppData\Local\Packages\PythonSoftwareFoundation.Python.3.9_qbz5n2kfra8p0\LocalCache\local-packages\Python39\site-packages\numpy\.libs\libopenblas.WCDJNK7YVMPZQ2ME2ZZHJJRJ3JIKNDB7.gfortran-win_amd64.dll


In [2]:
def calculate_fpr(y_actual, y_prediction):
    fp = 0
    tn = 0
    
    for i in range(len(y_actual)):
        if y_actual[i] == 0 and y_prediction[i] == 1:
            fp += 1
        elif y_actual[i] == 0 and y_prediction[i] == 0:
            tn += 1
    fpr= fp/(fp+tn)
    return fpr

In [3]:
df1 = pd.read_csv('~/data/ctown/dataset03.csv')
df2 = pd.read_csv('~/data/ctown/dataset04.csv')

train_normal = pd.concat((df1,df2[df2['ATT_FLAG']==0]),axis=0,ignore_index=True)
train_attack = df2[df2['ATT_FLAG']==1]

In [4]:
sensors = [col for col in train_normal.columns if col not in ['DATETIME','ATT_FLAG']]

In [5]:
scaler = StandardScaler()
X_normal = pd.DataFrame(index=train_normal.index, columns=sensors, data=scaler.fit_transform(train_normal[sensors]))
X_attack = train_attack[sensors].reset_index().drop(columns=['index'])

In [6]:
hankel = Hankel()
corrhankel = Corrhankel()
lag = 60
stride = 0.5

In [7]:
corr_normal,nolag_normal = corrhankel.fit(X_normal.to_numpy(),lag,stride)

In [8]:
corr_attack,nolag_attack = corrhankel.fit(X_attack.to_numpy(),lag,stride)

In [9]:
df_test = pd.read_csv('~/data/ctown/test_dataset.csv')

# Epasad with 1 cluster and no threshold tuning (training attack included in test data)

In [10]:
test_combined = pd.concat((df_test,train_attack),axis=0)
X_test = pd.DataFrame(index=test_combined.index, columns=sensors, data=scaler.fit_transform(test_combined[sensors]))
corr_test,nolag_test = corrhankel.fit(X_test.to_numpy(),lag,stride)
Y_test = test_combined.loc[:,'ATT_FLAG']

In [11]:
labels = hankel.fit(np.array(Y_test),lag,stride)
y_actual = np.any(labels>0,axis=0).astype(int)

In [12]:
sensor_models = []
sensor_predicted = []
accuracy = []
precision = []
recall = []
fscore = []
fpr = []
for i,sens in enumerate(sensors):
    train_normal = X_normal.loc[:,sens].values
    train_attack = X_attack.loc[:,sens].values
    model = Pipeline()
    model.fit(train_normal,train_attack,lag,stride,optimal_k=1,tune=False,kscore_init='inertia',corr_normal=corr_normal[:,i].reshape(nolag_normal,len(X_normal.columns)).T)
    test = X_test.loc[:,sens].values
    y_predicted = model.predict(test,corr_test[:,i].reshape(nolag_test,len(X_test.columns)).T)
    sensor_predicted.append(y_predicted)
    accuracy.append(accuracy_score(y_actual,y_predicted))
    precision.append(precision_score(y_actual,y_predicted))
    recall.append(recall_score(y_actual,y_predicted))
    fscore.append(f1_score(y_actual,y_predicted))
    fpr.append(calculate_fpr(y_actual,y_predicted))
    sensor_models.append(model)    

In [13]:
sensor_predicted = np.asarray(sensor_predicted)
y_predicted = np.any(sensor_predicted,axis=0).astype(int)
y_predicted

array([1, 0, 1, 1, 0, 1, 0, 1, 1, 0, 1, 1, 1, 1, 0, 0, 0, 1, 0, 0, 1, 1,
       1, 0, 1, 0, 1, 0, 1, 1, 1, 1, 0, 0, 0, 0, 0, 0, 0, 1, 1, 1, 1, 1,
       1, 1, 0, 0, 0, 1, 1, 1, 1, 1, 1, 0, 0, 0, 0, 0, 0, 1, 1, 1, 1, 1,
       0, 0, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 0, 1, 1, 1, 1, 1, 1])

In [14]:
print("Accuracy ",accuracy_score(y_actual,y_predicted))
print("Precision ",precision_score(y_actual,y_predicted))
print("Recall ",recall_score(y_actual,y_predicted))
print("F1-score ",f1_score(y_actual,y_predicted))
print("False Positive Rate ",calculate_fpr(y_actual,y_predicted))

Accuracy  0.7647058823529411
Precision  0.7407407407407407
Recall  0.8695652173913043
F1-score  0.7999999999999999
False Positive Rate  0.358974358974359


In [15]:
print("Accuracy -  Mean: {} Median : {} Min : {} Max : {}".format(np.asarray(accuracy).mean(), np.median(np.asarray(accuracy)),np.asarray(accuracy).min(), np.asarray(accuracy).max()))
print("precision - Mean: {} Median : {} Min : {} Max : {}".format(np.asarray(precision).mean(), np.median(np.asarray(precision)),np.asarray(precision).min(), np.asarray(precision).max()))
print("recall -    Mean: {} Median : {} Min : {} Max : {}".format(np.asarray(recall).mean(), np.median(np.asarray(recall)),np.asarray(recall).min(), np.asarray(recall).max()))
print("f1 -        Mean: {} Median : {} Min : {} Max : {}".format(np.asarray(fscore).mean(), np.median(np.asarray(fscore)),np.asarray(fscore).min(), np.asarray(fscore).max()))
print("fpr -        Mean: {} Median : {} Min : {} Max : {}".format(np.asarray(fpr).mean(), np.median(np.asarray(fpr)),np.asarray(fpr).min(), np.asarray(fpr).max()))

Accuracy -  Mean: 0.4987688098495213 Median : 0.5058823529411764 Min : 0.4588235294117647 Max : 0.6
precision - Mean: 0.6158757301370161 Median : 0.8333333333333334 Min : 0.0 Max : 1.0
recall -    Mean: 0.0839231547017189 Median : 0.08695652173913043 Min : 0.0 Max : 0.32608695652173914
f1 -        Mean: 0.14260352866148635 Median : 0.16 Min : 0.0 Max : 0.46875000000000006
fpr -        Mean: 0.011926058437686344 Median : 0.0 Min : 0.0 Max : 0.10256410256410256


# Multiple clusters + No threshold tuning (training attack mixed in test data)

In [16]:
cluster_accuracy_1 = []
cluster_precision_1 = []
cluster_recall_1 = []
cluster_fscore_1 = []
cluster_fpr_1 = []
for k in range(2,8):
    sensor_models = []
    sensor_predicted = []
    accuracy = []
    precision = []
    recall = []
    fscore = []
    fpr = []
    for i,sens in enumerate(sensors):
        train_normal = X_normal.loc[:,sens].values
        train_attack = X_attack.loc[:,sens].values
        model = Pipeline()
        model.fit(train_normal,train_attack,lag,stride,optimal_k = k,tune=False,kscore_init='inertia',corr_normal=corr_normal[:,i].reshape(nolag_normal,len(X_normal.columns)).T)
        test = X_test.loc[:,sens].values
        y_predicted = model.predict(test,corr_test=corr_test[:,i].reshape(nolag_test,len(X_test.columns)).T)
        sensor_predicted.append(y_predicted)
        accuracy.append(accuracy_score(y_actual,y_predicted))
        precision.append(precision_score(y_actual,y_predicted))
        recall.append(recall_score(y_actual,y_predicted))
        fscore.append(f1_score(y_actual,y_predicted))
        fpr.append(calculate_fpr(y_actual,y_predicted))
        sensor_models.append(model)  
    sensor_predicted = np.asarray(sensor_predicted)
    y_predicted = np.any(sensor_predicted,axis=0).astype(int) 
    cluster_accuracy_1.append(accuracy_score(y_actual, y_predicted))
    cluster_precision_1.append(precision_score(y_actual,y_predicted))
    cluster_recall_1.append(recall_score(y_actual,y_predicted))
    cluster_fscore_1.append(f1_score(y_actual,y_predicted))
    cluster_fpr_1.append(calculate_fpr(y_actual,y_predicted))
    print('------Number of Clusters: ',k,'-----------') 
    print("Accuracy ",cluster_accuracy_1[-1])
    print("Precision ",cluster_precision_1[-1])
    print("Recall ",cluster_recall_1[-1])
    print("F1-score ",cluster_fscore_1[-1])
    print("False Positive Rate ",cluster_fpr_1[-1],"/n") 

------Number of Clusters:  2 -----------
Accuracy  0.788235294117647
Precision  0.7916666666666666
Recall  0.8260869565217391
F1-score  0.8085106382978724
False Positive Rate  0.2564102564102564 /n
------Number of Clusters:  3 -----------
Accuracy  0.7647058823529411
Precision  0.782608695652174
Recall  0.782608695652174
F1-score  0.782608695652174
False Positive Rate  0.2564102564102564 /n
------Number of Clusters:  4 -----------
Accuracy  0.788235294117647
Precision  0.8043478260869565
Recall  0.8043478260869565
F1-score  0.8043478260869565
False Positive Rate  0.23076923076923078 /n
------Number of Clusters:  5 -----------
Accuracy  0.7294117647058823
Precision  0.7017543859649122
Recall  0.8695652173913043
F1-score  0.7766990291262136
False Positive Rate  0.4358974358974359 /n
------Number of Clusters:  6 -----------
Accuracy  0.6470588235294118
Precision  0.625
Recall  0.8695652173913043
F1-score  0.7272727272727273
False Positive Rate  0.6153846153846154 /n
------Number of Cluste

In [17]:
print("Accuracy Scores: ",cluster_accuracy_1)
print("Precision Scores: ",cluster_precision_1)
print("Recall Scores: ",cluster_recall_1)
print("F1 Scores: ",cluster_fscore_1)
print("False Positive Rates: ",cluster_fpr_1)

Accuracy Scores:  [0.788235294117647, 0.7647058823529411, 0.788235294117647, 0.7294117647058823, 0.6470588235294118, 0.6823529411764706]
Precision Scores:  [0.7916666666666666, 0.782608695652174, 0.8043478260869565, 0.7017543859649122, 0.625, 0.6461538461538462]
Recall Scores:  [0.8260869565217391, 0.782608695652174, 0.8043478260869565, 0.8695652173913043, 0.8695652173913043, 0.9130434782608695]
F1 Scores:  [0.8085106382978724, 0.782608695652174, 0.8043478260869565, 0.7766990291262136, 0.7272727272727273, 0.7567567567567568]
False Positive Rates:  [0.2564102564102564, 0.2564102564102564, 0.23076923076923078, 0.4358974358974359, 0.6153846153846154, 0.5897435897435898]


# Multiple clusters + No threshold tuning (No concat of training and test data)

In [18]:
X_test = pd.DataFrame(index=df_test.index, columns=sensors, data=scaler.fit_transform(df_test[sensors]))
Y_test = df_test.loc[:,'ATT_FLAG']
corr_test,nolag_test = corrhankel.fit(X_test.to_numpy(),lag,stride)

In [19]:
labels = hankel.fit(np.array(Y_test),lag,stride)
y_actual = np.any(labels>0,axis=0).astype(int)

In [20]:
cluster_accuracy_2 = []
cluster_precision_2 = []
cluster_recall_2 = []
cluster_fscore_2 = []
cluster_fpr_2 = []
for k in range(2,8):
    sensor_models = []
    sensor_predicted = []
    accuracy = []
    precision = []
    recall = []
    fscore = []
    fpr = []
    for sens in sensors:
        train_normal = X_normal.loc[:,sens].values
        train_attack = X_attack.loc[:,sens].values
        model = Pipeline()
        model.fit(train_normal,train_attack,lag,stride,optimal_k=1,tune=False,kscore_init='inertia',corr_normal=corr_normal[:,i].reshape(nolag_normal,len(X_normal.columns)).T,corr_attack=corr_attack[:,i].reshape(nolag_attack,len(X_attack.columns)).T)
        test = X_test.loc[:,sens].values
        y_predicted = model.predict(test,corr_test[:,i].reshape(nolag_test,len(X_test.columns)).T)
        sensor_predicted.append(y_predicted)
        accuracy.append(accuracy_score(y_actual,y_predicted))
        precision.append(precision_score(y_actual,y_predicted))
        recall.append(recall_score(y_actual,y_predicted))
        fscore.append(f1_score(y_actual,y_predicted))
        fpr.append(calculate_fpr(y_actual,y_predicted))
        sensor_models.append(model)    
    sensor_predicted = np.asarray(sensor_predicted)
    y_predicted = np.any(sensor_predicted,axis=0).astype(int)
    cluster_accuracy_2.append(accuracy_score(y_actual, y_predicted))
    cluster_precision_2.append(precision_score(y_actual,y_predicted))
    cluster_recall_2.append(recall_score(y_actual,y_predicted))
    cluster_fscore_2.append(f1_score(y_actual,y_predicted))
    cluster_fpr_2.append(calculate_fpr(y_actual,y_predicted))
    print('------Number of Clusters: ',k,'-----------') 
    print("Accuracy ",cluster_accuracy_2[-1])
    print("Precision ",cluster_precision_2[-1])
    print("Recall ",cluster_recall_2[-1])
    print("F1-score ",cluster_fscore_2[-1])
    print("False Positive Rate ",cluster_fpr_2[-1],"/n") 

------Number of Clusters:  2 -----------
Accuracy  0.6911764705882353
Precision  0.6
Recall  0.8275862068965517
F1-score  0.6956521739130435
False Positive Rate  0.41025641025641024 /n
------Number of Clusters:  3 -----------
Accuracy  0.7058823529411765
Precision  0.6153846153846154
Recall  0.8275862068965517
F1-score  0.7058823529411765
False Positive Rate  0.38461538461538464 /n
------Number of Clusters:  4 -----------
Accuracy  0.6764705882352942
Precision  0.5897435897435898
Recall  0.7931034482758621
F1-score  0.676470588235294
False Positive Rate  0.41025641025641024 /n
------Number of Clusters:  5 -----------
Accuracy  0.6764705882352942
Precision  0.5897435897435898
Recall  0.7931034482758621
F1-score  0.676470588235294
False Positive Rate  0.41025641025641024 /n
------Number of Clusters:  6 -----------
Accuracy  0.6911764705882353
Precision  0.6
Recall  0.8275862068965517
F1-score  0.6956521739130435
False Positive Rate  0.41025641025641024 /n
------Number of Clusters:  7 ---

In [21]:
print("Accuracy Scores: ",cluster_accuracy_2)
print("Precision Scores: ",cluster_precision_2)
print("Recall Scores: ",cluster_recall_2)
print("F1 Scores: ",cluster_fscore_2)
print("False Positive Rates: ",cluster_fpr_2)

Accuracy Scores:  [0.6911764705882353, 0.7058823529411765, 0.6764705882352942, 0.6764705882352942, 0.6911764705882353, 0.7058823529411765]
Precision Scores:  [0.6, 0.6153846153846154, 0.5897435897435898, 0.5897435897435898, 0.6, 0.6153846153846154]
Recall Scores:  [0.8275862068965517, 0.8275862068965517, 0.7931034482758621, 0.7931034482758621, 0.8275862068965517, 0.8275862068965517]
F1 Scores:  [0.6956521739130435, 0.7058823529411765, 0.676470588235294, 0.676470588235294, 0.6956521739130435, 0.7058823529411765]
False Positive Rates:  [0.41025641025641024, 0.38461538461538464, 0.41025641025641024, 0.41025641025641024, 0.41025641025641024, 0.38461538461538464]


# Multiple clusters + Threshold tuning (No concat of training and test data)

In [22]:
cluster_accuracy_3 = []
cluster_precision_3 = []
cluster_recall_3 = []
cluster_fscore_3 = []
cluster_fpr_3 = []
for k in range(2,10):
    sensor_models = []
    sensor_predicted = []
    accuracy = []
    precision = []
    recall = []
    fscore = []
    fpr = []
    for sens in sensors:
        train_normal = X_normal.loc[:,sens].values
        train_attack = X_attack.loc[:,sens].values
        model = Pipeline()
        model.fit(train_normal,train_attack,lag,stride,optimal_k = k,tune=True,kscore_init='inertia',corr_normal=corr_normal[:,i].reshape(nolag_normal,len(X_normal.columns)).T,corr_attack=corr_attack[:,i].reshape(nolag_attack,len(X_attack.columns)).T)
        test = X_test.loc[:,sens].values
        y_predicted = model.predict(test,corr_test=corr_test[:,i].reshape(nolag_test,len(X_test.columns)).T)
        sensor_predicted.append(y_predicted)
        accuracy.append(accuracy_score(y_actual,y_predicted))
        precision.append(precision_score(y_actual,y_predicted))
        recall.append(recall_score(y_actual,y_predicted))
        fscore.append(f1_score(y_actual,y_predicted))
        fpr.append(calculate_fpr(y_actual,y_predicted))
        sensor_models.append(model)    
    sensor_predicted = np.asarray(sensor_predicted)
    y_predicted = np.any(sensor_predicted,axis=0).astype(int)
    cluster_accuracy_3.append(accuracy_score(y_actual, y_predicted))
    cluster_precision_3.append(precision_score(y_actual,y_predicted))
    cluster_recall_3.append(recall_score(y_actual,y_predicted))
    cluster_fscore_3.append(f1_score(y_actual,y_predicted))
    cluster_fpr_3.append(calculate_fpr(y_actual,y_predicted))
    print('------Number of Clusters: ',k,'-----------') 
    print("Accuracy ",cluster_accuracy_3[-1])
    print("Precision ",cluster_precision_3[-1])
    print("Recall ",cluster_recall_3[-1])
    print("F1-score ",cluster_fscore_3[-1])
    print("False Positive Rate ",cluster_fpr_3[-1],"/n") 

------Number of Clusters:  2 -----------
Accuracy  0.4264705882352941
Precision  0.4264705882352941
Recall  1.0
F1-score  0.5979381443298969
False Positive Rate  1.0 /n
------Number of Clusters:  3 -----------
Accuracy  0.4411764705882353
Precision  0.43283582089552236
Recall  1.0
F1-score  0.6041666666666666
False Positive Rate  0.9743589743589743 /n
------Number of Clusters:  4 -----------
Accuracy  0.45588235294117646
Precision  0.4393939393939394
Recall  1.0
F1-score  0.6105263157894737
False Positive Rate  0.9487179487179487 /n
------Number of Clusters:  5 -----------
Accuracy  0.5
Precision  0.4603174603174603
Recall  1.0
F1-score  0.6304347826086957
False Positive Rate  0.8717948717948718 /n
------Number of Clusters:  6 -----------
Accuracy  0.4852941176470588
Precision  0.45161290322580644
Recall  0.9655172413793104
F1-score  0.6153846153846154
False Positive Rate  0.8717948717948718 /n
------Number of Clusters:  7 -----------
Accuracy  0.5441176470588235
Precision  0.483333333

In [23]:
print("Accuracy Scores: ",cluster_accuracy_3)
print("Precision Scores: ",cluster_precision_3)
print("Recall Scores: ",cluster_recall_3)
print("F1 Scores: ",cluster_fscore_3)
print("False Positive Rates: ",cluster_fpr_3)

Accuracy Scores:  [0.4264705882352941, 0.4411764705882353, 0.45588235294117646, 0.5, 0.4852941176470588, 0.5441176470588235, 0.5, 0.5441176470588235]
Precision Scores:  [0.4264705882352941, 0.43283582089552236, 0.4393939393939394, 0.4603174603174603, 0.45161290322580644, 0.48333333333333334, 0.45901639344262296, 0.48333333333333334]
Recall Scores:  [1.0, 1.0, 1.0, 1.0, 0.9655172413793104, 1.0, 0.9655172413793104, 1.0]
F1 Scores:  [0.5979381443298969, 0.6041666666666666, 0.6105263157894737, 0.6304347826086957, 0.6153846153846154, 0.6516853932584269, 0.6222222222222222, 0.6516853932584269]
False Positive Rates:  [1.0, 0.9743589743589743, 0.9487179487179487, 0.8717948717948718, 0.8717948717948718, 0.7948717948717948, 0.8461538461538461, 0.7948717948717948]
