Multi-Objective Feature Selection for Intrusion Detection Systems: A Comparative Analysis of Bio-Inspired Optimization Algorithms
Bibliographic record
Abstract
The increasing sophistication of cyberattacks makes Intrusion Detection Systems (IDSs) essential, yet the high dimensionality of modern network traffic hinders accuracy and efficiency. We conduct a comparative study of multi-objective feature selection for IDS using four bio-inspired metaheuristics-Grey Wolf Optimizer (GWO), Genetic Algorithm (GA), Particle Swarm Optimization (PSO), and Ant Colony Optimization (ACO)-on the X-IIoTID dataset. GA achieved the highest accuracy (99.60%) with the lowest FPR (0.39%) using 34 features. GWO offered the best accuracy-subset balance, reaching 99.50% accuracy with 22 features (65.08% reduction) within 0.10 percentage points of GA while using ~35% fewer features. PSO delivered competitive performance with 99.58% accuracy, 32 features (49.21% reduction), FPR 0.40%, and FNR 0.44%. ACO was the fastest (total training time 3001 s) and produced the smallest subset (7 features; 88.89% reduction), at an accuracy of 97.65% (FPR 2.30%, FNR 2.40%). These results delineate clear trade-off regions of high accuracy (GA/PSO/GWO), balanced (GWO), and efficiency-oriented (ACO) and underscore that algorithm choice should align with deployment constraints (e.g., edge vs. enterprise vs. cloud). We selected this quartet because it spans distinct search paradigms (hierarchical hunting, evolutionary recombination, social swarming, pheromone-guided foraging) commonly used in IDS feature selection, aiming for a representative, reproducible comparison rather than exhaustiveness; extending to additional bio-inspired and hybrid methods is left for future work.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame distilled prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.
Codex and Gemma teacher scores by category
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.000 | 0.000 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.000 | 0.000 |
| Bibliometrics | 0.001 | 0.005 |
| Science and technology studies | 0.000 | 0.000 |
| Scholarly communication | 0.000 | 0.000 |
| Open science | 0.000 | 0.000 |
| Research integrity | 0.000 | 0.000 |
| Insufficient payload (model declined to judge) | 0.000 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one teacher head, not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".