Jul 2026· International Journal of Creative and Open Research in Engineering and Management· Vol 02, pp. 1-9· 0 citations
TL;DR
Experimental results demonstrate that an ensemble-optimized model achieves improved predictive accuracy, reduced false positives, and enhanced generalization to unseen attack patterns, providing a scalable and adaptive defense against evolving cyber threats in online banking.
Abstract
The rapid expansion of digital infrastructures has increased the magnitude and sophistication of cyber threats, making timely and accurate threat prediction a foundational requirement for modern cyber-security systems. We use multiple algorithms—including Random Forest, Gradient Boosting Machines, and Deep Neural Networks—on benchmark intrusion-detection datasets and real-world enterprise log samples. Experimental results demonstrate that an ensemble-optimized model achieves improved predictive accuracy, reduced false positives, and enhanced generalization to unseen attack patterns. The study highlights important feature engineering techniques, model-optimization strategies, and deployment considerations for practical cyber-security environments. This research focuses on developing a supervised machine learning model to improve the accuracy of cyber threat prediction by leveraging historical and labeled cyber-security data.
Experimental analysis on a benchmark transaction dataset demonstrates that unsupervised models can achieve over 90% recall in detecting abnormal activities, providing a scalable and adaptive defense against evolving cyber threats in online banking.
The rise in frequency and complexity of cyber attacks has led to an increased demand for advanced intrusion detection systems that can effectively identify emerging network threats. This document outlines an AI-based framework for predicting cyber attacks, which incorporates machine learning, deep learning, generative artificial intelligence, and explainable artificial intelligence techniques utilizing the CICIDS2017 dataset. The dataset undergoes preprocessing, including data cleaning, feature transformation, normalization, and principal component analysis, to enhance data quality and computational efficiency. A variety of machine learning and deep learning models are assessed comparatively, while generative AI models are utilized to simulate synthetic attack patterns and improve anomaly representation. Experimental findings indicate that the ensemble Voting Classifier achieves the highest classification accuracy at 99.6%, while the LSTM model reaches 99.3%, underscoring the effectiveness of both ensemble learning and sequential deep learning in cyber attack prediction. The interpretability of the models is enhanced using LIME and SHAP, which provide clear explanations of prediction results. Additionally, a Flask-based deployment framework supports real-time network traffic classification and visualization, offering an interpretable and scalable solution for advanced cybersecurity applications.
Jaswanth Garugu· International Journal For Mu...· 0 citations
A multi-layered intelligent detection system that unites supervised learning, unsupervised anomaly analysis, and ensemble decision strategies to identify network intrusions, malicious software activity, and stealthy advanced persistent threats in near real time is introduced.
Ameen Pasha.A· International Scientific Jou...· 0 citations
The increasing complexity of cyber threats has exposed the limitations of traditional signature-based intrusion detection systems, creating a need for intelligent and adaptive cybersecurity solutions. This study proposes an artificial intelligence-driven cybersecurity framework for enterprise threat detection using the CICIDS2017 benchmark dataset. The framework incorporates data preprocessing, feature engineering, and supervised machine learning to classify network traffic as benign or malicious. Seven machine learning algorithms, including Logistic Regression, Decision Tree, Support Vector Machine, Random Forest, Extra Trees, LightGBM, and XGBoost, were evaluated using accuracy, precision, recall, F1-score, and AUC-ROC. The results indicate that ensemble learning models outperform conventional classifiers, with XGBoost achieving the highest performance, recording 99.42% accuracy, 99.39% precision, 99.31% recall, 99.35% F1-score, and an AUC-ROC of 0.999. LightGBM also demonstrated excellent performance with lower computational time. The findings suggest that the proposed XGBoost-based framework provides an accurate, scalable, and efficient solution for real-time enterprise threat detection and can be effectivel
Sanjida Akter Tisha· The American Journal of Engi...· 0 citations
They originate from the rapid rise of cyber threats such as malware, phishing, ransomware,
denial of service, and unauthorised network intrusion, which have proven to be so difficult to
tackle that traditional security measures can hardly deal with the issue. Signature-based
intrusion detection system techniques in particular, which are commonly adopted by traditional
methods, usually lack the ability to detect novel and evolving attack vectors in addition to high
false positive rate and response time. In this regard, this paper proposes an AI threat detection
framework, employing data science methods to boost cybersecurity performances. The
researchers of this paper have tested the effectiveness of several models using a benchmark
dataset for cyber security, including CICIDS2017 or NSL-KDD and machine learning
techniques such as Random Forest, Support Vector Machine, Logistic Regression and
XGBoost for evaluating performance. Using measures of accuracy, precision, recall and F1-
score, the experiments show that the performance of ensemble learning models is higher than
shallow learning models in this research; XGBoost and Random Forest.
Praveen Kumar Reddy Gouni· International Journal of Soc...· 0 citations
Advanced persistent threats, zero-day exploits, encrypted command-and-control traffic, and botnet campaigns continue to reduce the reliability of conventional intrusion detection systems because static detectors provide limited transparency and weak adaptation under traffic drift. This paper presents an explainable and adaptive machine learning framework that integrates a LightGBM threat detector, SHAP-based decision explanations, density-aware concept drift detection, active incremental updating, and a contextual bandit defense policy. LightGBM is adopted because its leaf-wise gradient boosting structure provides high discrimination for heterogeneous flow features while maintaining low inference latency and native feature-importance support. The framework is evaluated on CIC-IDS2017, UNSW-NB15, and ToN_IoT using stratified train-validation-test splits, leakage prevention, five-run validation, and a 48-hour Kafka-based streaming simulation. The proposed model achieved 99.1% accuracy, 98.7% F1-score, 98.4% recall, and a 0.007 false alarm rate. During streaming evaluation, 14 adaptive model updates reduced mean detection latency from 27.4 s to 11.2 s, while SHAP explanations based on DNS entropy, JA3 rarity, packet interval, and flow-duration evidence reduced analyst triage time by 23%. Comparative results show that the proposed explainable adaptive pipeline improves detection reliability, reduces false alarms, and supports auditable mitigation decisions better than static and black-box IDS baselines.
P. A. Prakash, Salath Joseph A, A. M et al.· 2026 7th International Confe...· 0 citations
With the widespread adoption of cloud computing, securing enterprise networks against cyber threats has become increasingly important. Cloud environments are highly dynamic and constantly changing, making them susceptible to sophisticated cyberattacks that traditional Intrusion Detection Systems (IDS) often fail to detect. This study focuses on Intelligent Intrusion Detection Systems (IIDS) and their critical role in strengthening cloud security. Unlike conventional signature-based IDS that rely on fixed attack patterns, IIDS employ advanced Machine Learning (ML) and Artificial Intelligence (AI) techniques including deep learning, decision trees, and ensemble models to identify both known and emerging threats with greater accuracy. The paper proposes an integrated framework that combines real-time anomaly detection with automated response capabilities for cloud networks. Key architectural elements of IIDS are examined, alongside major deployment challenges such as scalability, false-positive rates, and computational requirements. Additionally, practical case studies and performance evaluations illustrate how IIDS enhance threat detection by improving accuracy, adaptability, and efficiency. Finally, the paper outlines future research directions to further advance IIDS capabilities and address the evolving security needs of modern cloud infrastructures.
R. Velu· 2026 4th International Confe...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.