Related Experiment Videos
Comparative performance evaluation of machine learning classifiers for multi-class intrusion detection on the NSL-KDD
Aman Jyoti1, Maninder Singh2, V K Banga3
1University School of Research, Rayat Bahra University, Mohali, Punjab, India. ishasareen1@gmail.com.
Scientific Reports
|July 13, 2026
Summary
This study introduces a feature-driven Intrusion Detection System (IDS) framework using XGBoost for feature selection and multiple machine learning (ML) classifiers. The approach enhances network security by improving attack detection performance and reducing complexity, particularly for common threats.
Area of Science:
- Cybersecurity
- Machine Learning
- Network Security
Background:
- Intrusion Detection Systems (IDSs) are crucial for network defense.
- High dimensionality and class imbalance in network data hinder conventional Machine Learning (ML) effectiveness.
- Sophisticated cyber threats necessitate advanced detection methods.
Purpose of the Study:
- To propose a feature-driven Intrusion Detection (ID) framework.
- To enhance attack detection performance and reduce computational complexity in IDSs.
- To leverage XGBoost for feature selection and evaluate multiple ML classifiers on the NSL-KDD dataset.
Main Methods:
- Utilized the NSL-KDD dataset with five traffic classes: Benign, Denial of Service (DoS), Probe, Remote-to-Local (R2L), and User-to-Root (U2R).
- Employed XGBoost feature ranking to identify thirteen highly relevant features per attack category, reducing data dimensionality.
- Evaluated selected features using six ML classifiers: LightGBM, Voting Classifier, CatBoost, Multi-Layer Perceptron (MLP), AdaBoost, and Stochastic Gradient Descent (SGD).
Main Results:
- Ensemble models, specifically CatBoost and LightGBM, showed superior performance for majority classes (DoS, Probe).
- All classifiers faced challenges with minority classes (R2L, U2R) due to severe class imbalance.
- Cross-validation confirmed the robustness and stability of selected feature subsets across attack categories.
Conclusions:
- Feature optimization is effective in enhancing ML classification performance for Intrusion Detection.
- The proposed framework is suitable for practical, resource-constrained ID environments.
- Findings offer insights for developing efficient and scalable IDS solutions.
Related Concept Videos
Classification of Systems-I
Linearity is a system property characterized by a direct input-output relationship, combining homogeneity and additivity.
Homogeneity dictates that if an input x(t) is multiplied by a constant c, the output y(t) is multiplied by the same constant. Mathematically, this is expressed as:
Homogeneity dictates that if an input x(t) is multiplied by a constant c, the output y(t) is multiplied by the same constant. Mathematically, this is expressed as:
Classification of Systems-II
Continuous-time systems have continuous input and output signals, with time measured continuously. These systems are generally defined by differential or algebraic equations. For instance, in an RC circuit, the relationship between input and output voltage is expressed through a differential equation derived from Ohm's law and the capacitor relation,