Two-tier Framework with AutoML for Detection and Classification of Multiple Types of Anomalies in Intrusion Attacks

Ting-Yu Chang, Cheng‐Yuan Ku · 2025

Ensuring cybersecurity is paramount for protecting sensitive data and preventing cyberattacks. Consequently, intrusion detection (ID) has emerged as a critical focus in network security research. This paper proposes a two-tier framework incorporating efficient Automatic Machine Learning (AutoML) techniques to address data bias and optimize the combination of dataset attributes for ID and classification of multiple types of anomalies. The first tier of our method selects two models: a primary target model tailored for the overall dataset and a supplementary model chosen for its superior capability of handling balanced distributions. In the second tier, a probability stacking approach integrates insights from the first tier models to enhance the training performance of the final decision-making of the third selected model. Our system effectively mitigates the impacts of data imbalance and improves computational efficiency, enabling broad applications in edge computing. Using the NSL-KDD dataset, the first evaluation experiment compares our proposal against other advanced techniques. The results show that our framework achieves an overall accuracy of 99.73%, presenting a substantial improvement of 0.4-20.6% over many other renowned methods. Furthermore, for another CIC-IDS-2017 dataset, we observe an accuracy improvement of 6.3% and a significant increase of 36% for macro-average recall while comparing our framework to the random-forest-only (RF-only) model.

Read the paper · More papers on PaperTik