# Read Data Sample

In [1]:
import pandas as pd
import numpy as np
import os
import time
from collections import namedtuple
pd.set_option("display.max_rows",35)
%matplotlib inline

In [2]:

class preprocess:
    
    paths = {}

    def get_files(folder_path):
        paths = {}
        for path, subdirs, files in os.walk(folder_path):
            for name in files:
                if name.endswith("csv"):
                    key = name.split("_")[0]

                    if paths.get(key) is None:
                        paths[key] = {}

                    if name.endswith("_x.csv"):
                        x = os.path.join(path, name)
                        paths[key]['x'] = x
                    elif name.endswith("_y.csv"):
                        y = os.path.join(path, name)
                        paths[key]['y'] = y
        preprocess.paths = paths
        return paths

    def get_data(paths):
        for key, value in paths.items():
            x = pd.read_csv(value['x'])
            y = pd.read_csv(value['y'])
            #print(x.shape)
            #print(x.values.shape)
            #print(y.sum())
            yield key, x.values, y.values
        
        
    
    
train_paths = preprocess.get_files("dataset/Kyoto2016/2014/01")
test_paths = preprocess.get_files("dataset/Kyoto2016/2015/01")

print(train_paths)
print("----------------------------------------------------------------------------------------")
#test_paths = test_paths.popitem()
#test_paths = {test_paths[0]: test_paths[1]}
print(test_paths)


{'20140122': {'y': 'dataset/Kyoto2016/2014/01/20140122_y.csv', 'x': 'dataset/Kyoto2016/2014/01/20140122_x.csv'}}
----------------------------------------------------------------------------------------
{'20150125': {'x': 'dataset/Kyoto2016/2015/01/20150125_x.csv', 'y': 'dataset/Kyoto2016/2015/01/20150125_y.csv'}, '20150101': {'y': 'dataset/Kyoto2016/2015/01/20150101_y.csv', 'x': 'dataset/Kyoto2016/2015/01/20150101_x.csv'}, '20150117': {'y': 'dataset/Kyoto2016/2015/01/20150117_y.csv', 'x': 'dataset/Kyoto2016/2015/01/20150117_x.csv'}, '20150105': {'y': 'dataset/Kyoto2016/2015/01/20150105_y.csv', 'x': 'dataset/Kyoto2016/2015/01/20150105_x.csv'}, '20150116': {'x': 'dataset/Kyoto2016/2015/01/20150116_x.csv', 'y': 'dataset/Kyoto2016/2015/01/20150116_y.csv'}, '20150131': {'x': 'dataset/Kyoto2016/2015/01/20150131_x.csv', 'y': 'dataset/Kyoto2016/2015/01/20150131_y.csv'}, '20150113': {'y': 'dataset/Kyoto2016/2015/01/20150113_y.csv', 'x': 'dataset/Kyoto2016/2015/01/20150113_x.csv'}, '20150118': {

In [3]:
import tensorflow as tf
from tensorflow.contrib.legacy_seq2seq.python.ops.seq2seq import basic_rnn_seq2seq
from tensorflow.contrib.rnn import RNNCell, LSTMCell, MultiRNNCell
from sklearn import model_selection as ms
from sklearn import metrics as me

In [4]:
class network(object):
    
    input_dim = 42
    classes = 2
    hidden_encoder_dim = 42
    hidden_layers = 1
    latent_dim = 40

    hidden_decoder_dim = 42
    lam = 0.01
    
    def __init__(self, classes, hidden_layers, num_of_features):
        self.classes = classes
        self.hidden_layers = hidden_layers
        self.latent_dim = num_of_features
            
    def build_layers(self):
        tf.reset_default_graph()
        #learning_rate = tf.Variable(initial_value=0.001)

        input_dim = self.input_dim
        classes = self.classes
        hidden_encoder_dim = self.hidden_encoder_dim
        hidden_layers = self.hidden_layers
        latent_dim = self.latent_dim
        hidden_decoder_dim = self.hidden_decoder_dim
        lam = self.lam
        
        with tf.variable_scope("Input"):
            self.x_input = tf.placeholder("float", shape=[None, 1, input_dim])
            self.y_input_ = tf.placeholder("float", shape=[None, 1, classes])
            self.keep_prob = tf.placeholder("float")
            self.lr = tf.placeholder("float")
            self.x_list = tf.unstack(self.x_input, axis= 1)
            self.y_list_ = tf.unstack(self.y_input_, axis = 1)
            self.y_ = self.y_list_[0]
            
            #GO = tf.fill((tf.shape(self.x)[0], 1), 0.5)
            
            #y_with_GO = tf.stack([self.y_, GO])
            
        with tf.variable_scope("lstm"):
            multi_cell = MultiRNNCell([LSTMCell(input_dim) for i in range(hidden_layers)] )
            
            self.y, states = basic_rnn_seq2seq(self.x_list, self.y_list_, multi_cell)
            #self.y = tf.slice(self.y, [0, 0], [-1,2])
            
            #self.out = tf.squeeze(self.y)
            
            #self.y = tf.layers.dense(self.y[0], classes, activation = None)
            
            self.y = tf.slice(self.y[0], [0, 0], [-1,2])
            
        with tf.variable_scope("Loss"):
            
            self.regularized_loss = tf.losses.mean_squared_error(self.y_, self.y)
            correct_prediction = tf.equal(tf.argmax(self.y_, 1), tf.argmax(self.y, 1))
            self.tf_accuracy = tf.reduce_mean(tf.cast(correct_prediction, tf.float32), name = "Accuracy")

        with tf.variable_scope("Optimizer"):
            learning_rate=self.lr
            optimizer = tf.train.AdamOptimizer(learning_rate)
            gradients, variables = zip(*optimizer.compute_gradients(self.regularized_loss))
            gradients = [
                None if gradient is None else tf.clip_by_value(gradient, -1, 1)
                for gradient in gradients]
            self.train_op = optimizer.apply_gradients(zip(gradients, variables))
            #self.train_op = optimizer.minimize(self.regularized_loss)
            
        # add op for merging summary
        #self.summary_op = tf.summary.merge_all()
        self.pred = tf.argmax(self.y, axis = 1)
        self.actual = tf.argmax(self.y_, axis = 1)

        # add Saver ops
        self.saver = tf.train.Saver()
        

batch_iterations = 200

x_train, x_valid, y_train, y_valid, = ms.train_test_split(preprocess.x_train, 
                                                                          preprocess.y_train, 
                                                                          test_size=0.1)
batch_indices = np.array_split(np.arange(x_train.shape[0]), 
                                           batch_iterations)
                                                                          
for i in batch_indices:
    print(x_train[i,np.newaxis,:])
    print(y_train[i,np.newaxis,:])

In [5]:
import collections

class Train:    
    
    result = namedtuple("score", ['key', 'no_of_features','hidden_layers','train_score', 'test_score', 'f1_score', 'time_taken'])

    predictions = {}

    results = []
    best_acc = 0
    best_acc_global = 0

    def train(epochs, net, h,f, lrs):
        batch_iterations = 1000
        train_loss = None
        Train.best_acc = 0
        os.makedirs("dataset/tf_lstm_nsl_kdd-orig/hidden layers_{}_features count_{}".format(h,f),
                    exist_ok = True)
        with tf.Session() as sess:
            #summary_writer_train = tf.summary.FileWriter('./logs/kdd/VAE/training', graph=sess.graph)
            #summary_writer_valid = tf.summary.FileWriter('./logs/kdd/VAE/validation')

            sess.run(tf.global_variables_initializer())
            start_time = time.perf_counter()
            
            
            for c, lr in enumerate(lrs):
                for epoch in range(1, (epochs+1)):
                    for key, x_train, y_train in preprocess.get_data(train_paths):
                        x_train, x_valid, y_train, y_valid, = ms.train_test_split(x_train, 
                                                                                  y_train, 
                                                                                  test_size=0.1)
                        batch_indices = np.array_split(np.arange(x_train.shape[0]), 
                                                   batch_iterations)

                        for i in batch_indices:

                            _, train_loss = sess.run([net.train_op, net.regularized_loss], #net.summary_op
                                                      feed_dict={net.x_input: x_train[i,np.newaxis,:], 
                                                                 net.y_input_: y_train[i,np.newaxis,:], 
                                                                 net.keep_prob:1, net.lr:lr})
                            #summary_writer_train.add_summary(summary_str, epoch)
                            if(train_loss > 1e9):
                                print("Step {} | Training Loss: {:.6f}".format(epoch, train_loss))


                        valid_accuracy,valid_loss = sess.run([net.tf_accuracy, net.regularized_loss], #net.summary_op 
                                                              feed_dict={net.x_input: x_valid[:,np.newaxis,:], 
                                                                         net.y_input_: y_valid[:,np.newaxis,:], 
                                                                         net.keep_prob:1, net.lr:lr})
                        #summary_writer_valid.add_summary(summary_str, epoch)

                        
                        
                    for key, x_test, y_test in preprocess.get_data(test_paths):
                        accuracy, pred_value, actual_value, y_pred = sess.run([net.tf_accuracy, 
                                                                               net.pred, 
                                                                               net.actual, net.y], 
                                                                              feed_dict={net.x_input: x_test[:,np.newaxis,:], 
                                                                                         net.y_input_: y_test[:,np.newaxis,:], 
                                                                                         net.keep_prob:1, net.lr:lr})

                        f1_score = me.f1_score(actual_value, pred_value)
                        recall = me.recall_score(actual_value, pred_value)
                        prec = me.precision_score(actual_value, pred_value)
                        print("Key {} | Training Loss: {:.6f} | Train Accuracy: {:.6f} | Test Accuracy: {:.6f}, f1_score: {}".format(key, train_loss, valid_accuracy, accuracy, f1_score))

                        if accuracy > Train.best_acc_global:
                                    Train.best_acc_global = accuracy
                                    Train.pred_value = pred_value
                                    Train.actual_value = actual_value

                                    Train.best_parameters = "Hidden Layers:{}, Features Count:{}".format(h, f)

                        if accuracy > Train.best_acc:

                            #net.saver.save(sess, "dataset/tf_vae_only_nsl_kdd_hidden layers_{}_features count_{}".format(epochs,h,f))
                            #Train.results.append(Train.result(epochs, f, h,valid_accuracy, accuracy))
                            #curr_pred = pd.DataFrame({"Attack_prob":y_pred[:,-2], "Normal_prob":y_pred[:, -1]})
                            #Train.predictions.update({"{}_{}_{}".format(epochs,f,h):curr_pred})

                            Train.best_acc = accuracy
                            if not (np.isnan(train_loss)):
                                net.saver.save(sess, 
                                           "dataset/tf_lstm_nsl_kdd-orig/hidden layers_{}_features count_{}/model"
                                           .format(h,f), 
                                           global_step = epoch, 
                                           write_meta_graph=False)

                            curr_pred = pd.DataFrame({"Attack_prob":y_pred[:,-2], "Normal_prob":y_pred[:, -1], "Prediction":pred_value})
                            Train.predictions.update({"{}_{}_{}".format(key,f,h):
                                                      (curr_pred, 
                                                       Train.result(key, f, h,valid_accuracy, accuracy, f1_score, time.perf_counter() - start_time))})



            

In [6]:
import itertools

df_results = []
past_scores = []

class Hyperparameters:
#    features_arr = [2, 4, 8, 16, 32, 64, 128, 256]
#    hidden_layers_arr = [2, 4, 6, 10]

    def start_training():

        global df_results
        global past_scores
        
        Train.predictions = {}
        Train.results = []
        
        features_arr = [1] #[4, 8, 16, 32]
        hidden_layers_arr = [1, 3, 5]

        epochs = [1]
        lrs = [1e-2] #[1e-2, 1e-2/2, 1e-2/4]

        for e, h, f in itertools.product(epochs, hidden_layers_arr, features_arr):
            print("Current Layer Attributes - epochs:{} hidden layers:{} features count:{}".format(e,h,f))
            n = network(2,h,f)
            n.build_layers()
            Train.train(e, n, h,f, lrs)
            
        dict1 = {}
        dict2 = []
        for k, (v1, v2) in Train.predictions.items():
            dict1.update({k: v1})
            dict2.append(v2)
            
        Train.predictions = dict1
        Train.results = dict2
        df_results = pd.DataFrame(Train.results)
        temp = df_results.set_index(['no_of_features', 'hidden_layers'])

        if not os.path.isfile('dataset/tf_lstm_nsl_kdd-orig_all.pkl'):
            past_scores = temp
        else:
            past_scores = pd.read_pickle("dataset/tf_lstm_nsl_kdd-orig_all.pkl")

        past_scores.append(temp).to_pickle("dataset/tf_lstm_nsl_kdd-orig_all.pkl")


In [7]:
%%timeit -r 1

Hyperparameters.start_training()

Current Layer Attributes - epochs:1 hidden layers:1 features count:1
Key 20150125 | Training Loss: 0.005088 | Train Accuracy: 0.999638 | Test Accuracy: 0.998543, f1_score: 0.9844141689373297
Key 20150101 | Training Loss: 0.005088 | Train Accuracy: 0.999638 | Test Accuracy: 0.998688, f1_score: 0.993938659231422
Key 20150117 | Training Loss: 0.005088 | Train Accuracy: 0.999638 | Test Accuracy: 0.998827, f1_score: 0.9941801385681295
Key 20150105 | Training Loss: 0.005088 | Train Accuracy: 0.999638 | Test Accuracy: 0.997277, f1_score: 0.994695268416038
Key 20150116 | Training Loss: 0.005088 | Train Accuracy: 0.999638 | Test Accuracy: 0.994025, f1_score: 0.9600307455803228
Key 20150131 | Training Loss: 0.005088 | Train Accuracy: 0.999638 | Test Accuracy: 0.980737, f1_score: 0.6146138576424993
Key 20150113 | Training Loss: 0.005088 | Train Accuracy: 0.999638 | Test Accuracy: 0.998160, f1_score: 0.9915588171498807
Key 20150118 | Training Loss: 0.005088 | Train Accuracy: 0.999638 | Test Accura

Key 20150118 | Training Loss: 0.000672 | Train Accuracy: 0.999928 | Test Accuracy: 0.989993, f1_score: 0.9175152452367753
Key 20150127 | Training Loss: 0.000672 | Train Accuracy: 0.999928 | Test Accuracy: 0.995301, f1_score: 0.9212414950135148
Key 20150110 | Training Loss: 0.000672 | Train Accuracy: 0.999928 | Test Accuracy: 0.945585, f1_score: 0.7221421043873758
Key 20150102 | Training Loss: 0.000672 | Train Accuracy: 0.999928 | Test Accuracy: 0.981854, f1_score: 0.8130582980724024
Key 20150130 | Training Loss: 0.000672 | Train Accuracy: 0.999928 | Test Accuracy: 0.963812, f1_score: 0.704142758055363
Key 20150122 | Training Loss: 0.000672 | Train Accuracy: 0.999928 | Test Accuracy: 0.991264, f1_score: 0.9146822948797039
Key 20150120 | Training Loss: 0.000672 | Train Accuracy: 0.999928 | Test Accuracy: 0.982186, f1_score: 0.8939983820406512
Key 20150126 | Training Loss: 0.000672 | Train Accuracy: 0.999928 | Test Accuracy: 0.973607, f1_score: 0.8099835245830562
Key 20150109 | Training L

Key 20150120 | Training Loss: 0.000661 | Train Accuracy: 1.000000 | Test Accuracy: 0.999998, f1_score: 0.9999885712979577
Key 20150126 | Training Loss: 0.000661 | Train Accuracy: 1.000000 | Test Accuracy: 1.000000, f1_score: 1.0
Key 20150109 | Training Loss: 0.000661 | Train Accuracy: 1.000000 | Test Accuracy: 0.999996, f1_score: 0.9999810134994019
Key 20150108 | Training Loss: 0.000661 | Train Accuracy: 1.000000 | Test Accuracy: 1.000000, f1_score: 1.0
Key 20150123 | Training Loss: 0.000661 | Train Accuracy: 1.000000 | Test Accuracy: 1.000000, f1_score: 1.0
Key 20150129 | Training Loss: 0.000661 | Train Accuracy: 1.000000 | Test Accuracy: 1.000000, f1_score: 1.0
Key 20150115 | Training Loss: 0.000661 | Train Accuracy: 1.000000 | Test Accuracy: 1.000000, f1_score: 1.0
Key 20150112 | Training Loss: 0.000661 | Train Accuracy: 1.000000 | Test Accuracy: 1.000000, f1_score: 1.0
Key 20150107 | Training Loss: 0.000661 | Train Accuracy: 1.000000 | Test Accuracy: 1.000000, f1_score: 1.0
Key 201

In [8]:
g = df_results.groupby(by=['no_of_features'])
idx = g['test_score'].transform(max) == df_results['test_score']
df_results[idx].sort_values(by = 'test_score', ascending = False)

Unnamed: 0,epoch,no_of_features,hidden_layers,train_score,test_score,f1_score,time_taken
6,20150101,1,3,1.0,1.0,1.0,19.569195


In [9]:
df_results.sort_values(by = 'test_score', ascending = False)

Unnamed: 0,epoch,no_of_features,hidden_layers,train_score,test_score,f1_score,time_taken
6,20150101,1,3,1.0,1.0,1.0,19.569195
5,20150125,1,3,1.0,0.999997,0.999964,12.831741
4,20150124,1,1,0.999964,0.987961,0.812684,149.321016
3,20150129,1,1,0.999964,0.985628,0.540598,103.440948
2,20150127,1,1,0.999964,0.985219,0.746229,51.456299
8,20150131,1,5,0.995514,0.983081,0.0,62.604211
1,20150118,1,1,0.999964,0.972688,0.739992,47.49988
0,20150125,1,1,0.999964,0.970042,0.605247,9.85744
7,20150125,1,5,0.995514,0.95202,0.012861,16.951076


In [10]:
pd.Panel(Train.predictions).to_pickle("dataset/tf_lstm_nsl_kdd_predictions.pkl")
df_results.to_pickle("dataset/tf_lstm_nsl_kdd_scores.pkl")

In [11]:
import numpy as np
import matplotlib.pyplot as plt
import itertools

def plot_confusion_matrix(cm, classes,
                          normalize=False,
                          title='Confusion matrix',
                          cmap=plt.cm.Blues):
    """
    This function prints and plots the confusion matrix.
    Normalization can be applied by setting `normalize=True`.
    """
    np.set_printoptions(precision=4)

    plt.imshow(cm, interpolation='nearest', cmap=cmap)
    plt.title(title)
    plt.colorbar()
    tick_marks = np.arange(len(classes))
    plt.xticks(tick_marks, classes, rotation=45)
    plt.yticks(tick_marks, classes)

    if normalize:
        cm = cm.astype('float') / cm.sum(axis=1)[:, np.newaxis]
        print("Normalized confusion matrix")
    else:
        print('Confusion matrix, without normalization')

    print(cm)

    thresh = cm.max() / 2.
    for i, j in itertools.product(range(cm.shape[0]), range(cm.shape[1])):
        plt.text(j, i, cm[i, j].round(4),
                 horizontalalignment="center",
                 color="white" if cm[i, j] > thresh else "black")

    plt.tight_layout()
    plt.ylabel('True label')
    plt.xlabel('Predicted label')

def plot(actual_value, pred_value):
    from sklearn.metrics import confusion_matrix
    cm_2labels = confusion_matrix(y_pred = pred_value, y_true = actual_value)
    plt.figure(figsize=[6,6])
    plot_confusion_matrix(cm_2labels, preprocess.output_columns_2labels, normalize = False,
                         title = Train.best_parameters)

In [12]:
plot(actual_value = Train.actual_value, pred_value = Train.pred_value)

AttributeError: type object 'preprocess' has no attribute 'output_columns_2labels'

<matplotlib.figure.Figure at 0x7f28a42ae0f0>

In [None]:
#4.5 GB
pd.Series(Train.pred_value).to_csv('LSTM_prediction_values.csv')

In [None]:
past_scores

In [None]:
pgb = past_scores.groupby(by=['no_of_features', 'hidden_layers'])
pgb.mean()

In [None]:
pgb.std()