A Comparison of Accuracy: KNN, TabNet, and Wide & Deep Learning for DDoS Attack Detection in Software Defined Network

Ramdan Satra, Imran Afdillah Dahlan, Herdianti Darwis, Purnawansyah Purnawansyah, Syariful Mujaddid, Farniwati Fattah · 2025

This study focuses on comparing the performance of K-Nearest Neighbors (KNN), TabNet, and Wide & deep learning methods in classifying Distributed Denial of Service (DDoS) attacks on Software-Defined Networks (SDN). The use of SDN enables centralized control of network infrastructure, making it vulnerable to DDoS attacks occur due to the centralized nature of SDN architecture. Machine learning models, including KNN, TabNet, and Wide & deep learning, are applied to an SDN-specific DDoS dataset to evaluate their effectiveness in accurately classifying normal and malicious traffic. These models were tested using various data splits (60:40, 70:30, 80:20, and 90:10) to determine the optimal ratio for training and validation. KNN exhibited the highest accuracy, reaching 98% in both 80:20 and 90:10 splits, while wide & deep learning achieved 94.99% accuracy, and TabNet demonstrated a 93.59% accuracy. The results suggest that KNN, despite being a simpler algorithm, outperforms the more complex deep learning models in this specific task. The findings provide valuable insights for researchers and network administrators in selecting effective machine learning algorithms for DDoS detection in SDN environments.

Read the paper · More papers on PaperTik