Network Intrusion Detection System Based on Multiple Datasets: Machine Learning Approaches

André Henrique Araújo, David Rodrigues, Patrícia Leite, Joaquim José Gonçalves · 2025

Network Intrusion Detection Systems (NIDS) detect network attacks before they reach host systems. Initially rule-based, NIDS have evolved to leverage machine learning (ML) and deep learning (DL) techniques. This study evaluates classical ML methods for classifying network attacks across three datasets: HIKARI-2021, UNR-IDD, and CIC-UNSW-NB15. Recursive feature elimination with a Random Forest classifier was employed for feature selection, reducing training and hyperparameter search times. We further implemented a stacking ensemble of tree-based boosting classifiers-XGBoost, LightGBM, and Cat-Boost-for classification. The stacking ensemble achieved the best results, with F1 scores of 93.7% for CIC-UNSW-NB15, 78.1 % for HIKARI-2021, and 95.6% for UNR-IDD. This study highlights the trade-offs between feature selection, model complexity, and dataset size, offering insights into optimizing NIDS performance. The results provide a foundation for future research, particularly on the underexplored UNR-IDD and CIC-UNSW-NB15 datasets.

Read the paper · More papers on PaperTik