Evaluating the Impact of Data Exfiltration Volume on Intrusion Detection Models
Cristiano L. M. Borges, Rodrigo Sanches Miani · 2025
The main goal of this paper is to detect data exfiltration via DNS, exploring various training and testing scenarios to understand the capabilities and limitations of these techniques in dynamic environments. We extend a previous study and examine multiple machine learning-based intrusion detection models trained with different file sizes and types. A secondary goal is to use XAI techniques to better interpret the results and improve model transparency. Our experiments demonstrated that models trained with diverse datasets perform better under various conditions, highlighting the importance of training data selection and diversity.