These findings demonstrate that stacking ensemble learning is a practical and computationally efficient alternative to complex deep learning architectures for SDN intrusion detection, with strong potential for scalable and real-time cybersecurity deployment in modern network environments.
Abstract
Software-Defined Networking (SDN) has become a key enabler of next-generation communication infrastructures because of its centralized control, programmability, and global network visibility. However, the centralized architecture also introduces significant security vulnerabilities, making SDN environments highly susceptible to attacks such as DoS, DDoS, probing, brute-force, and botnet activities. Although deep learning-based intrusion detection systems have achieved high detection accuracy, many existing approaches suffer from high computational complexity, long training time, and limited suitability for real-time deployment. This study addresses this gap by developing a lightweight stacking ensemble intrusion detection framework for SDN using the InSDN dataset. The proposed framework employs XGBoost, LightGBM, CatBoost, Random Forest, and Extra Trees as base learners, with Logistic Regression serving as the meta-learner. Experiments were conducted using 48-feature, 6-feature, and 4-feature configurations derived from previous feature-reduction studies. The results demonstrate consistently high detection performance, achieving accuracies above 99% across all feature subsets, with only marginal degradation under reduced feature dimensions. The framework showed excellent detection capability for major attack categories while maintaining reliable performance for most minority classes. These findings demonstrate that stacking ensemble learning is a practical and computationally efficient alternative to complex deep learning architectures for SDN intrusion detection, with strong potential for scalable and real-time cybersecurity deployment in modern network environments.
A lightweight, explainable IDS that combines a 1D-CNN for spatial feature analysis with SHAP for model interpretation, yielding streamlined models that preserve over 93% F1-score and reduce computational overhead by more than 38%, facilitating millisecond-level inference on edge hardware.
Miracle Udurume, Vladimir V. Shakhov, Insoo Koo· Scientific Reports· 0 citations
Software-Defined Networking (SDN) provides a programmable and centrally managed network architecture, but its centralized control plane introduces significant vulnerability to Distributed Denial of Service (DDoS) attacks. These attacks can overwhelm controller resources and disrupt network availability, making efficient and reliable detection mechanisms essential. This study proposes an optimization-driven ensemble learning framework for DDoS detection in SDN environments by integrating a Gradient Boosting Classifier (GBC) with Particle Swarm Optimization (PSO). PSO is employed to automatically tune key hyperparameters of the ensemble model, improving classification stability and enhancing detection performance while maintaining lightweight inference suitable for real-time deployment in SDN monitoring systems. The proposed framework is evaluated using an SDN-specific dataset generated in a realistic Mininet-based environment with OpenFlow-enabled switches and a Ryu controller. Experimental results under stratified 5-fold cross-validation show near-perfect detection performance, achieving accuracy and F1-score values 0.9999, with consistently high precision and recall. To further assess generalization capability, the model is validated on the CICDDoS2019 benchmark dataset, where it achieves more than 99% accuracy across all evaluation metrics. The results demonstrate strong robustness across heterogeneous traffic distributions while maintaining stable performance. Overall, the findings indicate that PSO-enhanced ensemble learning provides an effective and computationally efficient approach for improving DDoS detection in SDN environments, offering a practical balance between accuracy, robustness, and deployment feasibility.
I. A. Mahar, Libing Wu, G. A. Rahu et al.· Peer-to-Peer Networking and...· 0 citations
This work proposed a modular weight-based framework that evaluates cross-layer Machine Learning (ML) IDS across multiple dimensions, namely, detection effectiveness and generalizability, data quality, and attack coverage and practical deployability, and applied this framework to the state-of-the-art cross-layer ML IDS identified through the PRISMA framework.
Dimitrios Tasiopoulos, A. Xenakis, A. Lekidis et al.· Electronics· 0 citations
An intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies is presented.
S. Singh, Alok Kumar· International Journal of Com...· 0 citations
: Machine learning-based intrusion detection for Internet of Things (IoT) networks remains difficult because modern traffic is highly imbalanced and attack behaviors are heterogeneous. Evaluation pipelines can also overestimate performance when preprocessing is performed before train-test separation. We propose a family-aware hierarchical intrusion detection framework for attack-family prediction. The proposed approach first separates normal and attack traffic, then routes attack samples into empirically defined majority and minority attack-family branches, and finally performs branch-specific family classification. Within each cross-validation fold, training-label counts define the majority/minority routing branches, while scaling, weighting, model fitting, stage diagnostics, and metric computation remain fold-local. The final implementation uses XGBoost as the base learner in the hierarchical stages and compares it with flat LightGBM, XGBoost, Random Forest, Extra Trees, and stacking baselines under matched folds and metrics. On the CICIoT2023 30% stratified development split, the proposed approach achieved a Macro-F1 of 0.8380 and Weighted-F1 of 0.9940, performing close to the best flat Random Forest baseline while improving weak rare-family F1 scores for BruteForce and Web. On Edge-IIoTset, where the full processed dataset is used, the proposed approach achieved a Macro-F1 of 0.9456 and Weighted-F1 of 0.9494, outperforming all individual flat baselines and approaching the flat stacking ensemble. The hierarchy had lower inference time than the evaluated flat baselines under the workstation protocol.
Motab F. Alenezi, F. Alotaibi, B. Alturki et al.· Computer Modeling in Enginee...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.