Adaptive Network Intrusion Detection Using Reinforcement Learning with Proximal Policy Optimization
Akshaya Suresh, Arun Cyril Jose · ACM Transactions on Privacy and Security · 2025
In an increasingly digital and interconnected world, the need for robust network intrusion detection systems is crucial to ensure cybersecurity. This article presents a novel approach to network intrusion detection that integrates both traditional machine learning methods and advanced reinforcement learning techniques to enhance detection capabilities and accuracy. The proposed system uses Proximal Policy Optimization, a reinforcement learning algorithm, to dynamically adjust ensemble weights, thereby optimizing the contributions of base learners, such as Random Forest and CatBoost. Additionally, a Multi-layer Perceptron-based meta-learner is employed to refine the predictions, leading to an overall improvement in detection performance. The model was evaluated on five diverse datasets, including NSL-KDD, CICIDS, TON IoT, DDoS, and UNSW-NB15, achieving an average accuracy of 97.16%, and an average precision, recall, and F1-score of 97% across all datasets. The proposed work is compared with the existing state-of-the-art detection methods demonstrating its better performance in detecting both known and novel attack types. Furthermore, the integration of reinforcement learning allowed for dynamic and context-sensitive decision-making, enabling the system to handle complex attack patterns that traditional models struggle with. The training and validation results across all datasets showed rapid convergence and minimal overfitting, further supporting the model’s robustness.