Patent
US 12,651,159 B2Patent
Atlas literature
Patent
US 12,651,159 B2Patent drawings and their descriptions. Click a drawing to enlarge it.
FIG. 1 illustrates an example of the architecture of a CGAN network, as known in the state of the art.
FIG. 2.
FIGS. 3-6 schematically illustrate each of the different steps of
FIG. 4). 50 Step 3 is performed by means of a component called “Combined Module”, which is in charge of training neural networks G and D through the …
FIG. 5 graphically shows this step being run. 65 It must be taken into consideration that the generator G can produce synthetic data of different classes, …
FIG. 6) statistical data, for example, the mean and standard deviation, among others, for each column (characteristic) of the dataset of real data X and for …
FIG. 7 schematically illustrates an alternative implemen- tation of step 4 of
Claims define the patent's legal scope. Independent claims stand alone; dependent claims (nested) narrow them. Click a claim to expand its dependents.
A computer-implemented method for accelerating con-vergence in the training of generative adversarial networks (GAN) to generate synthetic network traffic, wherein the method comprises: receiving, in a generator of a GAN, identifiers of at least one class of network traffic; generating, by the generator, using a random vector, synthetic network traffic elements of the at least one class of network traffic associated with each of the identifiers received and generating a dataset of syn-thetic network traffic; training a discriminator of the GAN based on a dataset of real network traffic, the dataset of synthetic network B₂ traffic, and a first ratio of elements of dataset of real network traffic to elements of the dataset of synthetic network traffic, wherein the first ratio is such that the elements of the dataset of synthetic network traffic represent a smaller percentage of a total number of elements than that of the elements of the dataset of real network traffic, wherein each element of the dataset of real network traffic is associated by a class of traffic to which a respective element belongs and each element of the dataset of synthetic network traffic is provided to the discriminator identified as synthetic traffic, and wherein the training process for the discriminator com-prises adjusting internal parameters of the discrimi-nator; training the generator by generating new synthetic net-work traffic based on the dataset of real network traffic, the dataset of synthetic network traffic, and a second ratio of the elements of the dataset of real network traffic to the elements of the dataset of synthetic net-work traffic, the second ratio being different than the first ratio, wherein, during the training of the generator, each element of the dataset of synthetic network traffic is provided to the discriminator, wherein a total set of elements provided to the dis-criminator when the generator is training is greater, by a predetermined ratio, than the total set of ele-ments provided to the discriminator when the dis-criminator is training, wherein during the training process for the generator, the discriminator does not modify the internal parameters of the discriminator, and wherein the training process for the generator com-prises adjusting internal parameters of the generator, the adjusting being performed based on a probability of the discriminator classifying an element of the dataset of synthetic network traffic as real traffic; and comparing statistical distributions of the dataset of real network traffic and of the dataset of synthetic network traffic, wherein the comparing comprises: generating statistical data of the dataset of real network traffic for each set of elements of the same class of traffic; repeating the generating of the dataset of synthetic net-work traffic having a first size using the internal param-eters of the generator, wherein a difference between the first size and a size of the dataset of real network traffic is within a threshold; generating statistical data of the dataset of synthetic network traffic for each set of elements of a same class of traffic; comparing the statistical data of the dataset of real net-work traffic with the statistical data of the dataset of synthetic network traffic for each class of network traffic; based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic being less than a predetermined threshold for each class of traffic, con-cluding GAN training; and based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic not being less than the threshold for each class of traffic, continuing GAN training.
The method according to claim 1, wherein the prede-termined threshold is specific for each class of traffic.
The method according to claim 1, wherein the prede-termined threshold is the same for all classes of traffic.
The method according to claim 1, which further com-prises performing a detection of a divergence of the GAN based on a first difference between the statistical data of the dataset of real network traffic and the statistical data of the dataset of synthetic network traffic being greater than a previous difference for at least one class of traffic, wherein when the first difference is greater than the previous difference, restarting the training of the GAN based on revised internal parameters of the generator and revised internal parameters of the discriminator.
The method according to claim 1, wherein statistical data comprises the mean or standard deviation of at least one characteristic parameter of network traffic elements.
The method according to claim 1, wherein a percentage of elements of the dataset of synthetic network traffic out of the total number of elements is between 1% and 20%.
The method according to claim 1, wherein the prede-termined ratio is in the range of 10-100.
The method according to claim 1, wherein the random vector has a uniform distribution with a support of [−1, 1]d.
The method according to claim 1, wherein the random vector has a multivariate normal distribution.
The method according to claim 1, wherein network traffic comprises network traffic of at least one of the following types: web, video, and traffic coming from a cloud storage service.
A non-transitory computer readable medium storing instructions, that when executed, cause at least one proces-sor to: receive, in a generator of a GAN, identifiers of at least one class of network traffic; generate, by the generator, using a random vector, syn-thetic network traffic elements of the at least one class of network traffic associated with each of the identifiers received and generating a dataset of synthetic network traffic; train a discriminator of the GAN based on a dataset of real network traffic, the dataset of synthetic network traffic, and a first ratio of elements of dataset of real network traffic to elements of the dataset of synthetic network traffic, wherein the first ratio is such that the elements of the dataset of synthetic network traffic represent a smaller percentage of a total number of elements than that of the elements of the dataset of real network traffic, B₂ wherein each element of the dataset of real network traffic is associated by a class of traffic to which a respective element belongs and each element of the dataset of synthetic network traffic is provided to the discriminator identified as synthetic traffic, and wherein the training process for the discriminator com-prises adjusting internal parameters of the discrimi-nator; train the generator by generating new synthetic network traffic based on the dataset of real network traffic, the dataset of synthetic network traffic, and a second ratio of the elements of the dataset of real network traffic to the elements of the dataset of synthetic network traffic, the second ratio being different than the first ratio, wherein, during the training of the generator, each element of the dataset of synthetic network traffic is provided to the discriminator, wherein a total set of elements provided to the dis-criminator when the generator is training is greater, by a predetermined ratio, than the total set of ele-ments provided to the discriminator when the dis-criminator is training, wherein during the training process for the generator, the discriminator does not modify the internal parameters of the discriminator, and wherein the training process for the generator com-prises adjusting internal parameters of the generator, the adjusting being performed based on a probability of the discriminator classifying an element of the dataset of synthetic network traffic as real traffic; and compare statistical distributions of the dataset of real network traffic and of the dataset of synthetic network traffic, wherein the comparing comprises: generate statistical data of the dataset of real network traffic for each set of elements of the same class of traffic; repeat the generating of the dataset of synthetic network traffic having a first size using the internal parameters of the generator, wherein a difference between the first size and a size of the dataset of real network traffic is within a threshold; generate statistical data of the dataset of synthetic network traffic for each set of elements of a same class of traffic; compare the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic for each class of network traffic; based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic being less than a predetermined threshold for each class of traffic, con-clude GAN training; and based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic not being less than the threshold for each class of traffic, continue GAN training. ∗ ∗ ∗ ∗ ∗
Patents and literature cited by this patent (applicant and examiner references).
Cited patents · 4
Patent
Atlas literature
Patent
US 12,651,159 B2Patent drawings and their descriptions. Click a drawing to enlarge it.
FIG. 1 illustrates an example of the architecture of a CGAN network, as known in the state of the art.
FIG. 2.
FIGS. 3-6 schematically illustrate each of the different steps of
FIG. 4). 50 Step 3 is performed by means of a component called “Combined Module”, which is in charge of training neural networks G and D through the …
FIG. 5 graphically shows this step being run. 65 It must be taken into consideration that the generator G can produce synthetic data of different classes, …
FIG. 6) statistical data, for example, the mean and standard deviation, among others, for each column (characteristic) of the dataset of real data X and for …
FIG. 7 schematically illustrates an alternative implemen- tation of step 4 of
Claims define the patent's legal scope. Independent claims stand alone; dependent claims (nested) narrow them. Click a claim to expand its dependents.
A computer-implemented method for accelerating con-vergence in the training of generative adversarial networks (GAN) to generate synthetic network traffic, wherein the method comprises: receiving, in a generator of a GAN, identifiers of at least one class of network traffic; generating, by the generator, using a random vector, synthetic network traffic elements of the at least one class of network traffic associated with each of the identifiers received and generating a dataset of syn-thetic network traffic; training a discriminator of the GAN based on a dataset of real network traffic, the dataset of synthetic network B₂ traffic, and a first ratio of elements of dataset of real network traffic to elements of the dataset of synthetic network traffic, wherein the first ratio is such that the elements of the dataset of synthetic network traffic represent a smaller percentage of a total number of elements than that of the elements of the dataset of real network traffic, wherein each element of the dataset of real network traffic is associated by a class of traffic to which a respective element belongs and each element of the dataset of synthetic network traffic is provided to the discriminator identified as synthetic traffic, and wherein the training process for the discriminator com-prises adjusting internal parameters of the discrimi-nator; training the generator by generating new synthetic net-work traffic based on the dataset of real network traffic, the dataset of synthetic network traffic, and a second ratio of the elements of the dataset of real network traffic to the elements of the dataset of synthetic net-work traffic, the second ratio being different than the first ratio, wherein, during the training of the generator, each element of the dataset of synthetic network traffic is provided to the discriminator, wherein a total set of elements provided to the dis-criminator when the generator is training is greater, by a predetermined ratio, than the total set of ele-ments provided to the discriminator when the dis-criminator is training, wherein during the training process for the generator, the discriminator does not modify the internal parameters of the discriminator, and wherein the training process for the generator com-prises adjusting internal parameters of the generator, the adjusting being performed based on a probability of the discriminator classifying an element of the dataset of synthetic network traffic as real traffic; and comparing statistical distributions of the dataset of real network traffic and of the dataset of synthetic network traffic, wherein the comparing comprises: generating statistical data of the dataset of real network traffic for each set of elements of the same class of traffic; repeating the generating of the dataset of synthetic net-work traffic having a first size using the internal param-eters of the generator, wherein a difference between the first size and a size of the dataset of real network traffic is within a threshold; generating statistical data of the dataset of synthetic network traffic for each set of elements of a same class of traffic; comparing the statistical data of the dataset of real net-work traffic with the statistical data of the dataset of synthetic network traffic for each class of network traffic; based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic being less than a predetermined threshold for each class of traffic, con-cluding GAN training; and based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic not being less than the threshold for each class of traffic, continuing GAN training.
The method according to claim 1, wherein the prede-termined threshold is specific for each class of traffic.
The method according to claim 1, wherein the prede-termined threshold is the same for all classes of traffic.
The method according to claim 1, which further com-prises performing a detection of a divergence of the GAN based on a first difference between the statistical data of the dataset of real network traffic and the statistical data of the dataset of synthetic network traffic being greater than a previous difference for at least one class of traffic, wherein when the first difference is greater than the previous difference, restarting the training of the GAN based on revised internal parameters of the generator and revised internal parameters of the discriminator.
The method according to claim 1, wherein statistical data comprises the mean or standard deviation of at least one characteristic parameter of network traffic elements.
The method according to claim 1, wherein a percentage of elements of the dataset of synthetic network traffic out of the total number of elements is between 1% and 20%.
The method according to claim 1, wherein the prede-termined ratio is in the range of 10-100.
The method according to claim 1, wherein the random vector has a uniform distribution with a support of [−1, 1]d.
The method according to claim 1, wherein the random vector has a multivariate normal distribution.
The method according to claim 1, wherein network traffic comprises network traffic of at least one of the following types: web, video, and traffic coming from a cloud storage service.
A non-transitory computer readable medium storing instructions, that when executed, cause at least one proces-sor to: receive, in a generator of a GAN, identifiers of at least one class of network traffic; generate, by the generator, using a random vector, syn-thetic network traffic elements of the at least one class of network traffic associated with each of the identifiers received and generating a dataset of synthetic network traffic; train a discriminator of the GAN based on a dataset of real network traffic, the dataset of synthetic network traffic, and a first ratio of elements of dataset of real network traffic to elements of the dataset of synthetic network traffic, wherein the first ratio is such that the elements of the dataset of synthetic network traffic represent a smaller percentage of a total number of elements than that of the elements of the dataset of real network traffic, B₂ wherein each element of the dataset of real network traffic is associated by a class of traffic to which a respective element belongs and each element of the dataset of synthetic network traffic is provided to the discriminator identified as synthetic traffic, and wherein the training process for the discriminator com-prises adjusting internal parameters of the discrimi-nator; train the generator by generating new synthetic network traffic based on the dataset of real network traffic, the dataset of synthetic network traffic, and a second ratio of the elements of the dataset of real network traffic to the elements of the dataset of synthetic network traffic, the second ratio being different than the first ratio, wherein, during the training of the generator, each element of the dataset of synthetic network traffic is provided to the discriminator, wherein a total set of elements provided to the dis-criminator when the generator is training is greater, by a predetermined ratio, than the total set of ele-ments provided to the discriminator when the dis-criminator is training, wherein during the training process for the generator, the discriminator does not modify the internal parameters of the discriminator, and wherein the training process for the generator com-prises adjusting internal parameters of the generator, the adjusting being performed based on a probability of the discriminator classifying an element of the dataset of synthetic network traffic as real traffic; and compare statistical distributions of the dataset of real network traffic and of the dataset of synthetic network traffic, wherein the comparing comprises: generate statistical data of the dataset of real network traffic for each set of elements of the same class of traffic; repeat the generating of the dataset of synthetic network traffic having a first size using the internal parameters of the generator, wherein a difference between the first size and a size of the dataset of real network traffic is within a threshold; generate statistical data of the dataset of synthetic network traffic for each set of elements of a same class of traffic; compare the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic for each class of network traffic; based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic being less than a predetermined threshold for each class of traffic, con-clude GAN training; and based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic not being less than the threshold for each class of traffic, continue GAN training. ∗ ∗ ∗ ∗ ∗
Patents and literature cited by this patent (applicant and examiner references).
Cited patents · 4
Patent
Atlas literature
Patent
US 12,651,159 B2Patent drawings and their descriptions. Click a drawing to enlarge it.
FIG. 1 illustrates an example of the architecture of a CGAN network, as known in the state of the art.
FIG. 2.
FIGS. 3-6 schematically illustrate each of the different steps of
FIG. 4). 50 Step 3 is performed by means of a component called “Combined Module”, which is in charge of training neural networks G and D through the …
FIG. 5 graphically shows this step being run. 65 It must be taken into consideration that the generator G can produce synthetic data of different classes, …
FIG. 6) statistical data, for example, the mean and standard deviation, among others, for each column (characteristic) of the dataset of real data X and for …
FIG. 7 schematically illustrates an alternative implemen- tation of step 4 of
Claims define the patent's legal scope. Independent claims stand alone; dependent claims (nested) narrow them. Click a claim to expand its dependents.
A computer-implemented method for accelerating con-vergence in the training of generative adversarial networks (GAN) to generate synthetic network traffic, wherein the method comprises: receiving, in a generator of a GAN, identifiers of at least one class of network traffic; generating, by the generator, using a random vector, synthetic network traffic elements of the at least one class of network traffic associated with each of the identifiers received and generating a dataset of syn-thetic network traffic; training a discriminator of the GAN based on a dataset of real network traffic, the dataset of synthetic network B₂ traffic, and a first ratio of elements of dataset of real network traffic to elements of the dataset of synthetic network traffic, wherein the first ratio is such that the elements of the dataset of synthetic network traffic represent a smaller percentage of a total number of elements than that of the elements of the dataset of real network traffic, wherein each element of the dataset of real network traffic is associated by a class of traffic to which a respective element belongs and each element of the dataset of synthetic network traffic is provided to the discriminator identified as synthetic traffic, and wherein the training process for the discriminator com-prises adjusting internal parameters of the discrimi-nator; training the generator by generating new synthetic net-work traffic based on the dataset of real network traffic, the dataset of synthetic network traffic, and a second ratio of the elements of the dataset of real network traffic to the elements of the dataset of synthetic net-work traffic, the second ratio being different than the first ratio, wherein, during the training of the generator, each element of the dataset of synthetic network traffic is provided to the discriminator, wherein a total set of elements provided to the dis-criminator when the generator is training is greater, by a predetermined ratio, than the total set of ele-ments provided to the discriminator when the dis-criminator is training, wherein during the training process for the generator, the discriminator does not modify the internal parameters of the discriminator, and wherein the training process for the generator com-prises adjusting internal parameters of the generator, the adjusting being performed based on a probability of the discriminator classifying an element of the dataset of synthetic network traffic as real traffic; and comparing statistical distributions of the dataset of real network traffic and of the dataset of synthetic network traffic, wherein the comparing comprises: generating statistical data of the dataset of real network traffic for each set of elements of the same class of traffic; repeating the generating of the dataset of synthetic net-work traffic having a first size using the internal param-eters of the generator, wherein a difference between the first size and a size of the dataset of real network traffic is within a threshold; generating statistical data of the dataset of synthetic network traffic for each set of elements of a same class of traffic; comparing the statistical data of the dataset of real net-work traffic with the statistical data of the dataset of synthetic network traffic for each class of network traffic; based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic being less than a predetermined threshold for each class of traffic, con-cluding GAN training; and based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic not being less than the threshold for each class of traffic, continuing GAN training.
The method according to claim 1, wherein the prede-termined threshold is specific for each class of traffic.
The method according to claim 1, wherein the prede-termined threshold is the same for all classes of traffic.
The method according to claim 1, which further com-prises performing a detection of a divergence of the GAN based on a first difference between the statistical data of the dataset of real network traffic and the statistical data of the dataset of synthetic network traffic being greater than a previous difference for at least one class of traffic, wherein when the first difference is greater than the previous difference, restarting the training of the GAN based on revised internal parameters of the generator and revised internal parameters of the discriminator.
The method according to claim 1, wherein statistical data comprises the mean or standard deviation of at least one characteristic parameter of network traffic elements.
The method according to claim 1, wherein a percentage of elements of the dataset of synthetic network traffic out of the total number of elements is between 1% and 20%.
The method according to claim 1, wherein the prede-termined ratio is in the range of 10-100.
The method according to claim 1, wherein the random vector has a uniform distribution with a support of [−1, 1]d.
The method according to claim 1, wherein the random vector has a multivariate normal distribution.
The method according to claim 1, wherein network traffic comprises network traffic of at least one of the following types: web, video, and traffic coming from a cloud storage service.
A non-transitory computer readable medium storing instructions, that when executed, cause at least one proces-sor to: receive, in a generator of a GAN, identifiers of at least one class of network traffic; generate, by the generator, using a random vector, syn-thetic network traffic elements of the at least one class of network traffic associated with each of the identifiers received and generating a dataset of synthetic network traffic; train a discriminator of the GAN based on a dataset of real network traffic, the dataset of synthetic network traffic, and a first ratio of elements of dataset of real network traffic to elements of the dataset of synthetic network traffic, wherein the first ratio is such that the elements of the dataset of synthetic network traffic represent a smaller percentage of a total number of elements than that of the elements of the dataset of real network traffic, B₂ wherein each element of the dataset of real network traffic is associated by a class of traffic to which a respective element belongs and each element of the dataset of synthetic network traffic is provided to the discriminator identified as synthetic traffic, and wherein the training process for the discriminator com-prises adjusting internal parameters of the discrimi-nator; train the generator by generating new synthetic network traffic based on the dataset of real network traffic, the dataset of synthetic network traffic, and a second ratio of the elements of the dataset of real network traffic to the elements of the dataset of synthetic network traffic, the second ratio being different than the first ratio, wherein, during the training of the generator, each element of the dataset of synthetic network traffic is provided to the discriminator, wherein a total set of elements provided to the dis-criminator when the generator is training is greater, by a predetermined ratio, than the total set of ele-ments provided to the discriminator when the dis-criminator is training, wherein during the training process for the generator, the discriminator does not modify the internal parameters of the discriminator, and wherein the training process for the generator com-prises adjusting internal parameters of the generator, the adjusting being performed based on a probability of the discriminator classifying an element of the dataset of synthetic network traffic as real traffic; and compare statistical distributions of the dataset of real network traffic and of the dataset of synthetic network traffic, wherein the comparing comprises: generate statistical data of the dataset of real network traffic for each set of elements of the same class of traffic; repeat the generating of the dataset of synthetic network traffic having a first size using the internal parameters of the generator, wherein a difference between the first size and a size of the dataset of real network traffic is within a threshold; generate statistical data of the dataset of synthetic network traffic for each set of elements of a same class of traffic; compare the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic for each class of network traffic; based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic being less than a predetermined threshold for each class of traffic, con-clude GAN training; and based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic not being less than the threshold for each class of traffic, continue GAN training. ∗ ∗ ∗ ∗ ∗
Patents and literature cited by this patent (applicant and examiner references).
Cited patents · 4
Patent
Atlas literature
Patent
US 12,651,159 B2Patent drawings and their descriptions. Click a drawing to enlarge it.
FIG. 1 illustrates an example of the architecture of a CGAN network, as known in the state of the art.
FIG. 2.
FIGS. 3-6 schematically illustrate each of the different steps of
FIG. 4). 50 Step 3 is performed by means of a component called “Combined Module”, which is in charge of training neural networks G and D through the …
FIG. 5 graphically shows this step being run. 65 It must be taken into consideration that the generator G can produce synthetic data of different classes, …
FIG. 6) statistical data, for example, the mean and standard deviation, among others, for each column (characteristic) of the dataset of real data X and for …
FIG. 7 schematically illustrates an alternative implemen- tation of step 4 of
Claims define the patent's legal scope. Independent claims stand alone; dependent claims (nested) narrow them. Click a claim to expand its dependents.
A computer-implemented method for accelerating con-vergence in the training of generative adversarial networks (GAN) to generate synthetic network traffic, wherein the method comprises: receiving, in a generator of a GAN, identifiers of at least one class of network traffic; generating, by the generator, using a random vector, synthetic network traffic elements of the at least one class of network traffic associated with each of the identifiers received and generating a dataset of syn-thetic network traffic; training a discriminator of the GAN based on a dataset of real network traffic, the dataset of synthetic network B₂ traffic, and a first ratio of elements of dataset of real network traffic to elements of the dataset of synthetic network traffic, wherein the first ratio is such that the elements of the dataset of synthetic network traffic represent a smaller percentage of a total number of elements than that of the elements of the dataset of real network traffic, wherein each element of the dataset of real network traffic is associated by a class of traffic to which a respective element belongs and each element of the dataset of synthetic network traffic is provided to the discriminator identified as synthetic traffic, and wherein the training process for the discriminator com-prises adjusting internal parameters of the discrimi-nator; training the generator by generating new synthetic net-work traffic based on the dataset of real network traffic, the dataset of synthetic network traffic, and a second ratio of the elements of the dataset of real network traffic to the elements of the dataset of synthetic net-work traffic, the second ratio being different than the first ratio, wherein, during the training of the generator, each element of the dataset of synthetic network traffic is provided to the discriminator, wherein a total set of elements provided to the dis-criminator when the generator is training is greater, by a predetermined ratio, than the total set of ele-ments provided to the discriminator when the dis-criminator is training, wherein during the training process for the generator, the discriminator does not modify the internal parameters of the discriminator, and wherein the training process for the generator com-prises adjusting internal parameters of the generator, the adjusting being performed based on a probability of the discriminator classifying an element of the dataset of synthetic network traffic as real traffic; and comparing statistical distributions of the dataset of real network traffic and of the dataset of synthetic network traffic, wherein the comparing comprises: generating statistical data of the dataset of real network traffic for each set of elements of the same class of traffic; repeating the generating of the dataset of synthetic net-work traffic having a first size using the internal param-eters of the generator, wherein a difference between the first size and a size of the dataset of real network traffic is within a threshold; generating statistical data of the dataset of synthetic network traffic for each set of elements of a same class of traffic; comparing the statistical data of the dataset of real net-work traffic with the statistical data of the dataset of synthetic network traffic for each class of network traffic; based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic being less than a predetermined threshold for each class of traffic, con-cluding GAN training; and based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic not being less than the threshold for each class of traffic, continuing GAN training.
The method according to claim 1, wherein the prede-termined threshold is specific for each class of traffic.
The method according to claim 1, wherein the prede-termined threshold is the same for all classes of traffic.
The method according to claim 1, which further com-prises performing a detection of a divergence of the GAN based on a first difference between the statistical data of the dataset of real network traffic and the statistical data of the dataset of synthetic network traffic being greater than a previous difference for at least one class of traffic, wherein when the first difference is greater than the previous difference, restarting the training of the GAN based on revised internal parameters of the generator and revised internal parameters of the discriminator.
The method according to claim 1, wherein statistical data comprises the mean or standard deviation of at least one characteristic parameter of network traffic elements.
The method according to claim 1, wherein a percentage of elements of the dataset of synthetic network traffic out of the total number of elements is between 1% and 20%.
The method according to claim 1, wherein the prede-termined ratio is in the range of 10-100.
The method according to claim 1, wherein the random vector has a uniform distribution with a support of [−1, 1]d.
The method according to claim 1, wherein the random vector has a multivariate normal distribution.
The method according to claim 1, wherein network traffic comprises network traffic of at least one of the following types: web, video, and traffic coming from a cloud storage service.
A non-transitory computer readable medium storing instructions, that when executed, cause at least one proces-sor to: receive, in a generator of a GAN, identifiers of at least one class of network traffic; generate, by the generator, using a random vector, syn-thetic network traffic elements of the at least one class of network traffic associated with each of the identifiers received and generating a dataset of synthetic network traffic; train a discriminator of the GAN based on a dataset of real network traffic, the dataset of synthetic network traffic, and a first ratio of elements of dataset of real network traffic to elements of the dataset of synthetic network traffic, wherein the first ratio is such that the elements of the dataset of synthetic network traffic represent a smaller percentage of a total number of elements than that of the elements of the dataset of real network traffic, B₂ wherein each element of the dataset of real network traffic is associated by a class of traffic to which a respective element belongs and each element of the dataset of synthetic network traffic is provided to the discriminator identified as synthetic traffic, and wherein the training process for the discriminator com-prises adjusting internal parameters of the discrimi-nator; train the generator by generating new synthetic network traffic based on the dataset of real network traffic, the dataset of synthetic network traffic, and a second ratio of the elements of the dataset of real network traffic to the elements of the dataset of synthetic network traffic, the second ratio being different than the first ratio, wherein, during the training of the generator, each element of the dataset of synthetic network traffic is provided to the discriminator, wherein a total set of elements provided to the dis-criminator when the generator is training is greater, by a predetermined ratio, than the total set of ele-ments provided to the discriminator when the dis-criminator is training, wherein during the training process for the generator, the discriminator does not modify the internal parameters of the discriminator, and wherein the training process for the generator com-prises adjusting internal parameters of the generator, the adjusting being performed based on a probability of the discriminator classifying an element of the dataset of synthetic network traffic as real traffic; and compare statistical distributions of the dataset of real network traffic and of the dataset of synthetic network traffic, wherein the comparing comprises: generate statistical data of the dataset of real network traffic for each set of elements of the same class of traffic; repeat the generating of the dataset of synthetic network traffic having a first size using the internal parameters of the generator, wherein a difference between the first size and a size of the dataset of real network traffic is within a threshold; generate statistical data of the dataset of synthetic network traffic for each set of elements of a same class of traffic; compare the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic for each class of network traffic; based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic being less than a predetermined threshold for each class of traffic, con-clude GAN training; and based on the difference of the statistical data of the dataset of real network traffic with the statistical data of the dataset of synthetic network traffic not being less than the threshold for each class of traffic, continue GAN training. ∗ ∗ ∗ ∗ ∗
Patents and literature cited by this patent (applicant and examiner references).
Cited patents · 4
Cited non-patent literature · 2
Cited non-patent literature · 2
Cited non-patent literature · 2
Cited non-patent literature · 2
