Hybrid Machine Learning Models: Combining Strengths of Supervised and Unsupervised Learning Approaches
Shashwat Agrawal, Gopal Kumar Gupta, Pandi Kirupa Gopalakrishna, Vanitha Sivasankaran Balasubramaniam, Lagan Goel, Siddhey Mahadik · 2024
This research uses NSL-KDD to test hybrid machine learning models for network intrusion detection. The NSL-KDD dataset, a better version of KDD-99, is selected for its data quality and minimized duplication. It contains 147,907 entries with 42 properties for Attacks such as R2L, U2R, DoS, Probe, and normal. The dataset’s improvements fix bugs and improve testing. Data preparation removed duplicates, normalized values to $0-1$, and addressed class imbalance. The research tests supervised learning approaches like Random Forest and SVM. The Random Forest model has 97% accuracy, precision, recall, and F1-scores, whereas the SVM model had $95 \%$. The most accurate model was a hybrid CNN-LSTM model with $\mathbf{9 9 \%}$ accuracy. Random Forest with K-Means clustering and SVM classification were used for unsupervised learning. The Hybrid model using Autoencoders and Clustering outperformed other models with $\mathbf{9 9 . 8 \%}$ accuracy. This research demonstrates how hybrid machine learning techniques may categorize and handle diverse attack types while overcoming model constraints in network intrusion detection.