Comparison of Machine Learning Techniques For Intrusion Detection System
Bibliographic record
Abstract
The rapid growth in the ubiquity and sophistication of Information Communication Technology (ICT) and the emergence of new networking paradigms such as Cloud Computing (CC), and Internet of Things (IoT) have made vital changes in the globe. Computer network security is one of the most critical issue as attackers are also evolving dynamically. There should be a mechanism that fill the security vulnerability. One of the promising technique to ensure computer network security is the use of hybrid machine learning (ML) techniques which automate the process of intrusion detection in computer networks. In this research, six hybrid ML models were developed based on the Knowledge Discovery in Database (KDD) process model. The dataset used in this study has been taken from University of New Brunswick Institute (Canada Institute of Cyber Security). After selecting the dataset, preprocessing techniques such as filling missing records, reduce dimension, selecting the most relevant features, and finally normalize the dataset input using features scaling are performed. The hybrid ML models for intrusion detection systems (IDS) are implemented using Python programming language. In this work, a total of 274208 dataset records are used for the ML models evaluation. Out of this, 191945 datasets are used for training and a separate 82263 records are used as a testing set. The decision tree (DT) and neural network (NN) algorithms as supervised and K-means algorithm as unsupervised algorithms are applied in both without feature selection and with feature selection. The principal component analysis and decision tree (PCA-DT) model showed the best results in all performance parameters. The model has a prediction accuracy of 99.89% and the lowest false positive rate of 0.027%. Results confirm the effectiveness of our proposed methods.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.003 | 0.007 |
| Meta-epidemiology (narrow) | 0.001 | 0.000 |
| Meta-epidemiology (broad) | 0.001 | 0.001 |
| Bibliometrics | 0.005 | 0.003 |
| Science and technology studies | 0.001 | 0.000 |
| Scholarly communication | 0.001 | 0.002 |
| Open science | 0.001 | 0.001 |
| Research integrity | 0.001 | 0.001 |
| Insufficient payload (model declined to judge) | 0.001 | 0.001 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".