This work proposed a modular weight-based framework that evaluates cross-layer Machine Learning (ML) IDS across multiple dimensions, namely, detection effectiveness and generalizability, data quality, and attack coverage and practical deployability, and applied this framework to the state-of-the-art cross-layer ML IDS identified through the PRISMA framework.
Abstract
Internet of Things networks evolve as a rapidly growing field for security threats, such as Denial-of-Service cross-layer attacks, due to their heterogeneous and resource-constrained environment. Intrusion detection systems (IDSs) serve as a vital defense mechanism in modern cybersecurity. However, the adoption of such a system, especially one that adopts a cross-layer strategy, requires a standardized, multifaceted evaluation framework that accounts for both detection capability and operational overhead. To address these challenges, we proposed a modular weight-based framework that evaluates cross-layer Machine Learning (ML) IDS across multiple dimensions, namely, detection effectiveness and generalizability, data quality, and attack coverage and practical deployability. We then applied this framework to the state-of-the-art cross-layer ML IDSs identified through the PRISMA framework. This proof-of-concept application illustrates how current evaluation practices generate disparate, fragmented results, while also highlighting the limitations inherent in retrospective literature-based scoring.
These findings demonstrate that stacking ensemble learning is a practical and computationally efficient alternative to complex deep learning architectures for SDN intrusion detection, with strong potential for scalable and real-time cybersecurity deployment in modern network environments.
Ubakaghinwa Paul Chigbu, Abdulrashid Abdulrauf, Ishaq Isa et al.· Scientific Journal of Comput...· 0 citations
The rapid expansion of Internet of Things (IoT) technologies has significantly increased the digital attack surface, exposing modern networks to sophisticated cyber threats, particularly zero-day attacks that exploit previously undisclosed vulnerabilities. Conventional intrusion detection systems (IDSs), especially signature-based approaches, rely heavily on predefined attack patterns and large labeled datasets, which limits their effectiveness in identifying emerging and previously unseen attacks. To address this limitation, meta-learning has recently emerged as a promising paradigm for enabling intrusion detection under data-scarce conditions. However, the comparative evaluation of gradient-based and metric-based meta-learning approaches remains relatively underexplored in the domain of intrusion detection. In this study, the potential of meta-learning for zero-day intrusion detection is explored through the evaluation of two representative strategies within a few-shot learning framework: a gradient-based approach based on Model-Agnostic Meta-Learning (MAML), which enables rapid adaptation to new attack types, and a metric-based approach using Prototypical Networks, in which classification is performed within a learned embedding space. For additional comparative analysis, a Siamese network-based Fully Connected Network (FC-Net) is implemented as a baseline model. The framework evaluation is conducted using three diverse and realistic benchmark datasets, including CICIDS2017, CICIoT2023, and an augmented CIC-UNSW-NB15 dataset. Zero-day attack scenarios are simulated under multiclass classification settings to reflect practical deployment environments. Experimental results demonstrate that the MAML-based model consistently achieves superior performance across all datasets, obtaining 96.67% accuracy and 97.54% recall on CICIDS2017, 92.87% accuracy and 92.99% recall on CICIoT2023, and 83.20% accuracy and 83.50% recall on CIC-UNSW-NB15. These findings highlight the effectiveness of gradient-based meta-learning for rapid adaptation to previously unseen attacks and demonstrate its potential for developing intelligent IDSs capable of addressing evolving zero-day threats across heterogeneous network environments.
The findings support federated learning as a viable and communication-efficient direction for privacy-aware intrusion detection in distributed edge-security settings, while also highlighting the need for cautious interpretation, native V2X validation, and future robustness analysis against compromised federated clients.
Network infrastructure faces mounting pressure from increasingly sophisticated cyber attacks targeting systems reliant on digital connectivity. Activities such as Denial of Service, Probe, Remote-to-Local, and User-to-Root represent persistent threats that are challenging to intercept manually owing to high traffic volumes and rapidly evolving intrusion strategies. This work constructs a web-based Intrusion Detection System prototype by training an entropy-based Decision Tree classifier, conceptually grounded in the C4.5 framework, on the NSL-KDD benchmark. Development adheres to the six-phase CRISP-DM process encompassing business understanding, data preparation, model construction, performance evaluation, and system deployment. Preprocessing involves duplicate record elimination, categorical attribute encoding, and consolidation of multi-class attack labels into a binary Normal/Anomaly scheme. Ten-fold cross-validation yields 99.34% accuracy and 99.35% precision for the Decision Tree, representing a substantial margin over Naive Bayes which attains only 66.67% accuracy. A separate Gain Ratio analysis designates src_bytes as the most informative feature with a value of 0.5366, positioning it as the decision tree root node. The prototype is served through a Streamlit web application that accepts CSV dataset uploads, executes batch anomaly classification, presents detection outcomes through interactive visualizations, and produces exportable reports in both CSV and PDF formats. The system offers an interpretable and practically accessible batch-detection tool, continuous real-time monitoring and evaluation on contemporary intrusion benchmarks are identified as priorities for subsequent research.
Daniel Erick Witopo, Hartana Wijaya· bit-Tech· 0 citations
An intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies is presented.
S. Singh, Alok Kumar· International Journal of Com...· 0 citations
Critical safety functions in modern vehicles rely heavily on intra-vehicle networks (IVNs), primarily via the Controller Area Network (CAN) protocol. The inherent vulnerabilities of CAN require robust intrusion detection systems (IDS) to mitigate adversarial threats. However, state-of-the-art IDS, especially AI-based approaches, often lack a comprehensive, well-defined performance analysis method. This work proposes and evaluates a structured pipeline for in-vehicle IDS, analyzing an autoencoder semi-supervised IDS as a practical case study. The method is validated on publicly available datasets, covering multiple attack types, with additional analysis of generalization capabilities. Performance is rigorously assessed using precision, recall, F1-score, and the Matthews Correlation Coefficient (MCC), chosen for its robustness in imbalanced scenarios. Results demonstrated highly efficient identification of DoS attacks (MCC 1.00), though Fuzzy DoS detection showed lower performance (MCC 0.214 in CAN-MIRGU and 0.074 in CAN-MODES). These findings support the viability of the proposed pipeline for IDS analysis focusing on enhancing CAN network security, consistent with recent research trends.
Lucas da Silva Alves, Alexandre dos Santos Roque, E. P. de Freitas· International Conference on...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.