A hybrid ensemble framework with particle swarm optimization for network anomaly detection
摘要
The increasing complexity of cyber threats necessitates the development of a robust and adaptive Intrusion Detection System (IDS) capable of safeguarding network infrastructures. Traditional IDS approaches often struggle to detect sophisticated attacks due to their reliance on predefined patterns. We propose an adaptive particle swarm optimization (PSO)-optimized ensemble learning framework tailored to address these challenges in modern IDS applications. Our approach leverages the NSL-KDD and CICIDS datasets to ensure the IDS is trained and evaluated on data reflecting current network behaviours and threat landscapes. We evaluate multiple machine learning models, including Decision Trees (DT), Artificial Neural Networks (ANN), K-Nearest Neighbors (KNN), Random Forests (RF), and an ensemble of these models for both binary and multi-class classification tasks. By incorporating adaptive mechanisms within the PSO algorithm, our framework dynamically adjusts hyperparameters during optimization, enhancing model robustness and convergence speed. The proposed framework is also benchmarked against state-of-the-art IDS approaches, including ASRL and PSOGSA. Empirical evaluations demonstrate that the ensemble model achieves superior detection accuracy and reduced false positive rates, thereby advancing the efficacy of intrusion detection methodologies.