Application of Machine Unlearning Techniques to Enhance the Performance and Adaptability of DDoS Attack Detection Models

K. Muthamil Sudar, P. Nagaraj, P. Vaissnave · 2025

Traditional detection models may be accurate at first, but they quickly lose effectiveness as patterns of attacks change. They therefore require frequent and resource-intensive retraining. To achieve this, the authors have adopted several machine unlearning techniques, such as incremental unlearning, selective forgetting, recurrent unlearning, and adversarial unlearning, which allow a model to forget outdated information dynamically and learn from the new relevant traffic patterns. They assessed the performance of the models in terms of accuracy, precision, recall, F1-score, AUC-ROC, Matthews correlation coefficient (MCC), and adaptability measures such as the unlearning rate and time taken for retraining. The results show that detection accuracy was better in the models using machine unlearning, from 95.6% to 97.2%, with fewer false positives and negatives. A notable improvement in AUC-ROC scores was observed, from 0.89 to 0.94, and a 35% reduction in retraining time, which indicates the model's efficiency in adapting to changing threats. Moreover, the adversarial unlearning integration improved the model's robustness against evasive attack tactics by 30%. The hybrid approach, combining machine unlearning with ensemble methods, further elevated performance metrics to an AUC-ROC of 0.96 and balanced precision and recall rates over 95%. This chapter highlights the potential of machine unlearning in creating more robust, efficient, and adaptive DDoS detection systems, which have tremendous implications for real-time cybersecurity defense in dynamic network environments.

Read the paper · More papers on PaperTik