A PyTorch-based implementation of neuromorphic cybersecurity systems using spiking neural networks (SNNs) for Network Intrusion Detection Systems (NIDS). This project implements a hierarchical SNN architecture with Growing When Required (GWR) mechanisms for lifelong learning of cyber threats, enabling networks to dynamically adapt to new attack patterns while preserving knowledge of existing threats.
# Clone the repository
git clone https://github.com/zesun33/neuromorphic-cybersecurity-for-lifelong-learning.git
cd neuromorphic-cybersecurity
# Install dependencies
pip install torch torchvision numpy matplotlib seaborn plotly pandas scikit-learn tqdm wandb
# The modified BindsNET framework is included in the bindsnet/ directory# Network intrusion detection with UNSW-NB15 (Primary focus)
cd notebooks
python current/network_test_nids_v23.py --trial_name nids_experiment --n_epochs 10 --gpu
# MNIST digit classification with GWR (for comparison)
python current/mnist_gwr_v7.py --trial_name mnist_experiment --n_epochs 5 --gpuExpected Results: NIDS should achieve ~85.3% overall accuracy across 9 attack types with robust adaptation to new threats. MNIST should achieve ~95% accuracy with network growth from 10 to ~20 neurons.
- Static SNN Layer: Efficient initial threat detection and filtering
- Dynamic SNN Layer: Adaptive classification of specific attack types
- Bio-plausible Learning: Mimics biological adaptation mechanisms
- Energy Efficiency: High operational sparsity for low-power deployment
- Threat Adaptation: Learn new attack patterns without forgetting existing ones
- GWR Structural Plasticity: Dynamic network growth based on threat complexity
- Adaptive STDP: Novel learning rule for continuous threat learning
- Catastrophic Forgetting Mitigation: Preserve knowledge of known threats
- UNSW-NB15: Primary cybersecurity benchmark (23 features, 9 attack types)
- MNIST: Handwritten digit classification for comparison (28Γ28 images, 10 classes)
- Iris: Classic flower classification (4 features, 3 classes)
- Custom Threat Datasets: Easy integration for new attack patterns
- WandB Integration: Comprehensive experiment tracking and visualization
- Real-time Plots: Network dynamics, weight evolution, and performance metrics
- Statistical Analysis: Precision, recall, F1-score, and growth statistics
This framework is designed for researchers working on:
- Neuromorphic Cybersecurity: Applying brain-inspired computing to cyber threat detection
- Lifelong Learning: Continuous adaptation to evolving cyber threats
- Spiking Neural Networks: Energy-efficient neural computation for edge security
- Network Intrusion Detection: Real-time threat classification and adaptation
- Bio-plausible Learning: Mimicking biological adaptation mechanisms in artificial systems
- New Model Classes:
DiehlAndCook2015GWR,DiehlAndCook2015ReInit,DiehlAndCook2015AdaptiveLR - Adaptive STDP: Modified spike-timing-dependent plasticity with firing factor integration
- Dynamic Topology: Support for runtime network structure changes
- BMU Selection: Best Matching Unit identification for weight initialization
- Firing Factor Management: Exponential decay-based neuron activity tracking
- Threshold Adaptation: Dynamic spike thresholds based on network size and performance
- Installation Guide - Detailed setup instructions including GPU configuration
- Quick Start Tutorial - Your first experiment walkthrough
- Architecture Overview - System design and component interactions
- BindsNET Modifications - Technical changes and additions
- Algorithm Reference - Mathematical formulations and pseudocode
- Parameter Reference - Complete parameter documentation
- Metrics Guide - Performance metrics interpretation
- MNIST Experiments - Digit classification experiments
- NIDS Experiments - Network intrusion detection
- Custom Datasets - Integrating your own data
- Results Interpretation - Understanding network behavior
- Troubleshooting Guide - Common issues and solutions
βββ notebooks/ # Experiment scripts and data
β βββ current/ # Latest experiment implementations
β β βββ mnist_gwr_v7.py # MNIST with GWR
β β βββ network_test_nids_v23.py # NIDS experiments
β β βββ CustomDataloader.py # Continual learning data loaders
β βββ data/ # Datasets and preprocessed files
β βββ utils/ # Utility scripts and helpers
β βββ archive/ # Historical versions
βββ bindsnet/ # Modified BindsNET framework
β βββ models/ # GWR model implementations
β βββ learning/ # Adaptive learning rules
β βββ network/ # Network topology management
βββ docs/ # Comprehensive documentation
β βββ USAGE/ # Dataset-specific guides
β βββ REFERENCE/ # Technical references
β βββ GUIDES/ # Analysis and troubleshooting
β βββ *.md # Core documentation files
βββ Images/ # Generated plots and figures
- Overall Accuracy: 85.3% across 9 attack types
- Lifelong Learning: Robust adaptation to new threats while preserving existing knowledge
- Operational Sparsity: High sparsity confirmed via Intel Lava framework
- Energy Efficiency: Optimized for low-power neuromorphic hardware deployment
- False Positive Rate: <10% for normal traffic classification
- Base Accuracy: ~95% on standard MNIST
- Continual Learning: Maintains >90% on old classes while learning new ones
- Network Growth: Typically grows from 10 to 15-25 neurons
- Training Time: ~5-10 minutes on GPU for 10 epochs
- Accuracy: >95% on 3-class flower classification
- Network Efficiency: Minimal growth needed (10-12 neurons)
- Training Speed: <1 minute for complete training
- Python: 3.8+
- PyTorch: 1.9+
- CUDA: Optional but recommended for GPU acceleration
- Memory: 8GB+ RAM recommended for larger experiments
- Storage: 2GB+ for datasets and experiment logs
torch>=1.9.0
torchvision>=0.10.0
numpy>=1.21.0
matplotlib>=3.3.0
seaborn>=0.11.0
plotly>=5.0.0
pandas>=1.3.0
scikit-learn>=1.0.0
tqdm>=4.60.0
wandb>=0.12.0
# Grid search over key parameters
python current/mnist_gwr_v7.py --spike_threshold 0.05 --firing_threshold_grow 0.1
python current/mnist_gwr_v7.py --spike_threshold 0.07 --firing_threshold_grow 0.2
python current/mnist_gwr_v7.py --spike_threshold 0.09 --firing_threshold_grow 0.3# Example: Wine quality dataset
from notebooks.current.CustomDataloader import IncrementalClassDataset
from your_dataset_loader import WineQualityDataset
# Create continual learning setup
dataset = WineQualityDataset('path/to/wine_data.csv')
continual_dataset = IncrementalClassDataset(dataset.data, dataset.targets)import wandb
# Initialize experiment tracking
wandb.init(
project='Continual_Learning_SNN',
name='custom_experiment',
config={
'dataset': 'custom',
'spike_threshold': 0.07,
'n_epochs': 10
}
)If you use this code in your research, please cite our paper:
@article{mia2025neuromorphic,
title={Neuromorphic Cybersecurity with Semi-supervised Lifelong Learning},
author={Mia, Md Zesun Ahmed and Bal, Malyaban and Lu, Sen and Nishibuchi, George M and Chelian, Suhas and Vasan, Srini and Sengupta, Abhronil},
journal={arXiv preprint arXiv:2508.04610},
year={2025},
url={https://arxiv.org/abs/2508.04610}
}Paper: Neuromorphic Cybersecurity with Semi-supervised Lifelong Learning
Conference: Accepted at ACM International Conference on Neuromorphic Systems (ICONS) 2025
We welcome contributions! Please see our Contributing Guidelines for details on:
- Code style and standards
- Testing requirements
- Documentation updates
- Issue reporting
# Clone for development
git clone https://github.com/zesun33/neuromorphic-cybersecurity-for-lifelong-learning.git
cd neuromorphic-cybersecurity
# Install in development mode
pip install -e .
# Run tests
python -m pytest tests/This project is licensed under the MIT License - see the LICENSE file for details.
- BindsNET Team: For the foundational spiking neural network framework
- PyTorch Community: For the excellent deep learning platform
- Intel Lava Framework: For neuromorphic hardware simulation capabilities
- Research Community: For neuromorphic computing and cybersecurity research contributions
- Dataset Providers: UNSW-NB15, MNIST, and Iris dataset maintainers
- ICONS 2025 Conference: For accepting our work and providing valuable feedback
- Primary Contact: Md Zesun Ahmed Mia
- Website: https://zesun33.github.io/
- Issues: Please use GitHub Issues for bug reports and feature requests
- Discussions: Join our community discussions for questions and ideas
- Documentation: Visit our comprehensive docs for detailed guides
- BindsNET - Original spiking neural network framework
- Intel Lava - Neuromorphic computing framework
- Continual Learning Papers - Comprehensive paper collection
- Avalanche - Continual learning library
- Neuromorphic Computing - Related neuromorphic projects
Ready to explore neuromorphic cybersecurity with lifelong learning?
π Start here: Quick Start Guide
π Learn more: Full Documentation
π¬ Research: Results Interpretation Guide
π Paper: Neuromorphic Cybersecurity with Semi-supervised Lifelong Learning
Last updated: January 2025