Comparative Analysis of Deep Learning and Machine Learning Models for DDoS Attack Detection
K. Jayasakthi, S. Uma Maheswari, N. Rajkumar, Vikram Patil, Anuradha Pawar, Jose Anand A. · 2025
This study investigates the performance of deep learning (DL) and machine learning (ML) models for detecting Distributed Denial of Service (DDoS) attacks using the CIC_DDoS_2019 dataset. The DL models, including Convolutional Neural Networks (CNN), Deep Neural Networks (DNN), and Recurrent Neural Networks (RNN), outperformed traditional ML algorithms such as Random Forest, Decision Tree, Logistic Regression, K-Nearest Neighbors, and Naive Bayes in terms of precision, recall, and accuracy. The CNN model achieved the highest performance for 8-class classification with a precision of 91% and a binary classification true positive rate (TPR) of 99.96%. SMOTE oversampling significantly improved the models' performance by addressing class imbalance. Additionally, a 13-class classification task demonstrated the robustness of DL models, despite lower accuracy due to the complexity of the dataset. The analysis underscores the superiority of DL models for intrusion detection, particularly for detecting novel and complex attack patterns, and highlights the critical role of dataset size and balance in optimizing performance.