Real Time Intrusion Detection using XGBoost and Decision Tree Classifier
P. Sindhuja, Vinayak Reddy T, Tarun Raidu M, K. Butchi Raju, Reddy S Sarveswara, Duriseti Venkata Srikanth · 2025
The proposed work builds an intrusion detection system in real-time with the help of machine learning. The proposed work was given raw network traffic data as input and preprocessed the same independently by scaling and normalizing features. The processed data is given to a Decision Tree classifier, which detects potential security threats such as DDoS attacks or port scans. The web interface based on Flask provides the facility of uploading network data in CSV format and view detection output. Classification facility by performance metrics such as precision, accuracy, and recall is offered by the model. Rule-Based intrusion detection often misses new attacks and floods analysts with false alerts. We answer this issue by building a real-time classifier that combines an XGBoost model with a baseline Decision Tree. Raw NSL-KDD traffic (56 590 flows, 78 features after encoding) passes through noise filtering and z-score scaling before training. GridSearchCV fixes learning rate = 0.1, depth = 6, and 200 estimators. On the full test set, the XGBoost model reaches 99.8% accuracy, 99.9% precision, and 99.7% recall. Each prediction needs 4 milli seconds (ms). The Decision Tree scores 96.3 % accuracy and yields feature ranks that aid threat triage. A Flask interface lets operators upload CSV logs, view labelled traffic, and inspect a live confusion matrix. The lightweight design shows that gradient-boosted trees can deliver near-perfect detection in practice, closing the gap between academic models and operational security.