Skip to content
Review Open access

A Systematic Review of Machine Learning Techniques in Intrusion Detection Systems

2026 · Journal of Cyber Security · Vol 8, pp. 319-356 · 1 citation · 80 references

TL;DR

ML is a significant addition to intrusion detection, especially for anomaly detection and zero-day attack detection, however, the actual implementation is still limited due to the lack of detailed assessment systems and strict robustness testing.

Abstract

: Background: The evolution of modern networked systems in complexity, volume, and diversity has markedly increased the cyber-attack area. Conventional signature-based intrusion detection systems (IDS) will no longer be adequate for identifying advanced threats. A data-driven, adaptive approach that can identify malicious network activity is provided by machine learning (ML) techniques. This review aims to study, compare, and analyze ML-based approaches in IDS and improve the security defense mechanism. Methods: This systematic review followed the PRISMA 2020 guidelines. ML-based IDS peer-reviewed papers were identified from five scientific databases. Abstracts, full texts, and titles were filtered using predetermined inclusion and exclusion criteria, resulting in a sample of 53 primary studies. Data extraction included the algorithms used, the data used, and the metrics used to evaluate. Findings: The data show that most supervised ML techniques, such as decision trees, support vector machines, ensemble models, and deep learning systems (e.g., convolutional and recurrent neural networks), are predominant. In the majority of studies, high detection accuracy was obtained in controlled experimental settings. Conclusions: ML is a significant addition to intrusion detection, especially for anomaly detection and zero-day attack detection. However, the actual implementation is still limited due to the lack of detailed assessment systems and strict robustness testing. Future studies can focus on reproducibility, the use of diverse datasets, adversarial robustness, and the development of explainable ML methods.

Read PDF

Similar papers

#artificial intelligence Review Open access Sep 2026

A Systematic Literature Review on Machine Learning for Intrusion Detection Systems

The use of Artificial Intelligence (AI) and Machine Learning (ML) in cybersecurity, especially for creating Intrusion Detection Systems (IDSs), has become increasingly important. These systems are essential for detecting malicious behaviour, identifying network issues, and stopping cyberattacks in real time. Despite extensive research on various ML and Deep Learning (DL) models for IDS, the current literature remains incomplete. It has many different datasets, methods, and evaluation standards. As cyber threats become more advanced, it is crucial to conduct a thorough analysis of ML techniques for intrusion detection. The goal of this Systematic Literature Review (SLR) is to provide a full picture of the most recent academic articles on ML-based IDS. The study addresses important research questions about the most widely used algorithms, the types of attacks and network environments covered, the methodological problems that remain unsolved, and the new trends that should shape future research. Following the PRISMA framework, we conducted a systematic review of peer-reviewed articles published between January 2022 and May 2025. We searched IEEE Xplore, ACM Digital Library, and SpringerLink, yielding 22,558 initial records. After carefully applying strict inclusion criteria, 125 papers were selected for the final analysis. We created a standardised data extraction form (i.e., using MS Excel) to gather bibliographic details, research emphasis, methodological strategies, datasets, evaluation criteria, and recognised constraints. We employed thematic analysis to develop a clear taxonomy. We identified five main research themes in our analysis: (1) ensemble and hybrid learning pipelines focused on performance optimisation (30 papers), (2) context-specific IDS designs for Internet of Things (IoT), cloud, and Software-Defined Networking (SDN) environments (34 papers), (3) data-centric engineering that deals with class imbalance and feature selection (20 papers), (4) deep neural architectures for representation learning (31 papers), and (5) trustworthiness concerns like adversarial robustness, zero-day detection, and Explainable AI (XAI) (10 papers). Convolutional Neural Networks (CNNs), Long Short-Term Memory (LSTM), and Random Forests are the most commonly used algorithms, often combined. Nonetheless, significant deficiencies remain: about 2% of papers incorporate XAI, only 4% focus on adversarial robustness, and none validate their models in real-world production settings. Denial-of-Service (DoS) and Distributed DoS (DDoS) attacks are the most common types in the literature, whereas Web attacks, ransomware, and advanced persistent threats remain poorly studied. The number of publications grows at an average of 30.2% annually, but the field still relies on legacy benchmark datasets rather than operational validation.

Ali Ahmed, Ramy Mostafa, Mahmoud H. Qutqut et al. · 0 citations
Review Open access Sep 2026

A Review of Machine Learning Techniques for Network Intrusion Detection Systems

Security researchers rely heavily on Network Intrusion Detection Systems (NIDS) to keep an eye on network traffic and notify administrators of any suspicious activities. The purpose of this paper is to offer a comprehensive overview of intrusion detection systems (IDS), including the following topics: fundamentals, kinds of IDS, methods for detecting intrusions in NIDS, the architecture of IDS, data pre-processing, and examples of ML techniques used in NIDS. This covers several detection methods, including signature-based, anomaly-based, specification-based, and behavior-based approaches, as well as their advantages and disadvantages in recognizing both existing and new cyber threats. The review also covers the architecture of NIDS which consists of network sensors, preprocessors, network traffic analysis, alert generation and security analysis. A variety of ML techniques, including supervised, unsupervised, semi-supervised, ensemble, and deep learning (DL) approaches, are being explored to improve the accuracy and adaptability of intrusion detection systems (IDS). Other applications such as DoS/DDoS attack detection, Malware detection, Botnets, Brute force attacks, Insider compromise, IoT compromise and Critical infrastructure threats are also shown. Despite all the challenges in terms of false positives, scalability, computational complexity, data quality, and novel attack styles, the features that ML can provide for intelligent, adaptive, and accurate intrusion detection systems are appealing.

Madhav Sharma · 0 citations
Review Open access Jul 2026

A Systematic Review of AI-Driven Intrusion Detection and Performance Optimization in Wireless Sensor Networks

The study analyzes the most recent progress in ML and DL methods used to develop IDS that operate in WSNs through analysis of their primary algorithms and algorithmic combinations and concludes that the DL and hybrid approaches are superior to conventional ML algorithms in handling complicated and imbalanced datasets.

Priyanka Sharma, Mohd. Suhaib Kidwai, Piyush Charan · 0 citations
Open access Aug 2026

Enhancing Network Security with a Hybrid Intrusion Detection System Using SVM

A thorough analysis of a modest version of a suggested system that use Support Vector Machines (SVM) to address networking anomaly and misuse detection in the face of insurmountable obstacles, foreseeing an all-encompassing solution to modern network security issues.

Gaurav Kishor Saxena, Shambhu Dayal Sahu · 0 citations
Review Open access Aug 2026

Advancing Intrusion Detection Systems: A Comprehensive Review of Deep Learning and Hyperparameter Optimization Techniques

In the suddenly changing realm of cyber security, Intrusion Detection Systems (IDS) are essential for protecting computer networks from harmful actions.  This survey paper offers an extensive examination of sophisticated approaches and procedures utilised in IDS, emphasising the amalgamation of deep learning (DL) and hyper parameter optimisation.  We examine many categories of cyber-attacks that confront conventional IDS, including phishing, malware, ransom ware, and advanced evasion strategies.  The study explores the intricacies of hyper parameter tuning in DL algorithms, emphasising major methods such grid search (GS), random search (RS), Bayesian optimisation (BO), and genetic algorithms (GA).  This paper examines recent progress in DL applications for IDS, highlighting the efficacy of models such as Convolutional Neural Networks (CNNs), Recurrent Neural Networks (RNNs), and auto encoders in identifying both established and emerging threats.  Case studies and contemporary research illustrate the effects of these tactics on enhancing IDS accuracy, minimising false positives, and responding to novel attack strategies.  This survey highlights the necessity for on-going advancement in IDS to tackle the evolving nature of cyber threats and improve the overall security stance of networked systems.

H. K. · 0 citations
Review Open access Aug 2026

Exploring Optimization and Machine Learning for Effective Intrusion Detection Systems

Intrusion Detection Systems (IDS) are essential elements of contemporary cyber security frameworks, intended to identify unauthorised access and nefarious activity within networks and computer systems.  This survey examines the classification of IDS technologies, methodologies, and approaches, emphasising the benefits and obstacles related to their use.  Numerous optimisation methods in Intrusion Detection Systems (IDS) are examined, emphasising feature selection and machine learning (ML) algorithms that improve detection precision and efficacy.  A comprehensive analysis of recent research investigates progress in IDS, highlighting the utilisation of Genetic Algorithms (GA), Particle Swarm Optimisation (PSO), and ML models like Decision Trees (DT), Support Vector Machines (SVR) and Neural Networks (NN).  Furthermore, the emerging security concerns in Internet of Things (IoT) contexts and the significance of feature optimisation for enhancing IDS performance are discussed.  This review synthesises ideas from current research to offer a thorough overview of IDS technologies and their function in enhancing network security against growing cyber threats.

B. Yelikar, Jawed Sharfuzama Khan, A. Kanade et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.