Comprehensive Analysis of MLP and Ensemble Learning Approaches for Intrusion Detection using CICIDS2017 Dataset
Md Salim Raza, Humaira Arif, Sai Mounika Errapotu, Virgilio González · 2024
This paper presents a comprehensive evaluation of the Multi-Layer Perceptron (MLP) and ensemble learning classifiers, including Random Forest, GBM (Gradient Boosting Machine) and XGBoost, for intrusion detection using the CICIDS2017 dataset. The study analyzes the workflow towards improving accuracy in anomaly based intrusion detection, and assesses the performance of these models across various metrics such as accuracy, precision, recall, and F1 score, with a detailed consideration of receiver operating characteristic (ROC) and learning curves. The training process includes data balancing using Synthetic Minority Over-sampling Technique (SMOTE), feature selection, and hyperparameter tuning through grid search. The results reveal that Random Forest outperforms other classifiers, achieving the highest accuracy, area under the curve (AUC), demonstrating strong learning curve convergence even with smaller data samples. Interestingly, when retrained on reduced data samples, Random Forest maintained its superior accuracy without signs of overfitting, outperforming the other classifiers. These findings highlight Random Forest’s effectiveness in distinguishing between attack and benign traffic, making it the preferred choice for intrusion detection in this study.