Anomaly-Based Intrusion Detection Systems by using Machine Learning based Stacking Ensemble Model
P. R. Buvaneswari, G K Madhura, Heba Abdul-Jaleel Al-Asady, K. Alagarraja, Mukesh Soni · 2025
In recent years, network intrusion refers to unauthorized access to systems or networks by external attackers or insiders aimed at stealing information or deploy malicious software. Traditional approaches for anomaly-based intrusion detection systems have faced several challenges which include high computational overhead and limited capability in detecting zero-day attacks due to reliance on predefined attack signatures or handcrafted features. To address these limitations, this research proposes a Machine Learning-based Stacking Ensemble Model (ML-SEM) for anomaly-based intrusion detection, effectively reducing computational overhead and enhancing detection of previously unseen attacks. Initially, data is collected from University of Nevada, Reno Intrusion Detection Dataset (UNR-IDD) which consists of network traffic data and various types of attacks. Then, the collected data is preprocessed by using standard scaler normalization which ensures that all features have a mean of zero and a standard deviation of one. After that, the features are selected using Principal Component Analysis (PCA) which reduces dimensionality and enhances model efficiency by eliminating redundant and less significant features. Finally, anomaly-based intrusion detection is done by using proposed ML-SEM. The proposed ML-SEM achieved better results in terms of accuracy (98.6%), precision (95.5%) and recall (98.3%) when compared with existing Random Forest (RF).