Intrusion Detection System (IDS) Classifications Using Hyperparameter Tuning for Machine Learning and Deep Learning
Tan May May, Zanariah Zainudin, Norliana Muslim, Nurul Syafidah Jamil, Nur Amalina Mat Jan, Noraini Ibrahim, Nor 'Afifah Binti Sabri · 2024
With the rapid advancement of technology, new security vulnerabilities are emerging. Intrusion Detection Systems (IDS) are responsible for protecting corporate networks by detecting potential threats and anomalies. High false alarm rates that burden administrators with unnecessary alerts have caused the focus of IDS research to shift to exploring Machine Learning (ML) and Deep Learning (DL) algorithms to improve intrusion detection. Therefore, this paper focuses on improving ML and DL-based IDS models to improve the performances in terms of accuracy, precision, recall, and F1 score, and ultimately better detect threats and anomalies in the networks using hyperparameter tuning. Hyperparameter tuning is crucial for optimizing model performance in ML and DL. It can lead to more robust models that have higher accuracy. This paper aims that select the best hyperparameter tuning to increase performance for the ML and DL models. The CIC-IDS2017 dataset is investigated for the task of network intrusion detection. The performance of three machine learning models is evaluated: Random Forest (RF), Deep Neural Network (DNN), and Deep Autoencoder (DAE). The pre-processing phase included data cleaning and feature selection using Pearson correlation. Subsequently, the dataset is subjected to model training and testing, followed by hyperparameter tuning facilitated by grid search, allowing fine-tuning of key features to optimize model performance. The results show a significant improvement and balanced performance compared to previous researchers' models, which achieved an average performance of 99.5% across all models, proving that the hyperparameters applied to the models proposed by the research are effective in discriminating normal and attacked traffic.