DDOSNAS: Efficient Neural Architecture Search With Weight Sharing for Ddos Attack Detection

Emmanuel Owusu, Iddrisu Danlard, Griffith Selorm Klogo, Kwame Osei Boateng, Emmanuel Kofi Akowuah · Concurrency and Computation Practice and Experience · 2025

ABSTRACT DDoS attacks continue to be one of the most prominent cybersecurity threats of this era as they overload network systems and paralyze vital services. Even though Deep Neural Networks have showcased strong detection capabilities, their detection and response efficiency is hindered due to high computational requirements, time‐consuming processes, and limited resources prevalent in IoT, edge devices, and other time‐sensitive environments. This study introduces DDoSNAS, a Transformer‐controlled, multi‐objective Neural Architecture Search (NAS) framework explicitly designed for DDoS attack detection. By integrating a hierarchical macro–micro Transformer controller with one‐shot weight sharing and Pareto‐based evolutionary search, DDoSNAS optimizes accuracy, latency, and FLOPs, producing high‐performing and lightweight architectures. The search space is tailored for 1D network flow analysis and guided by an ensemble feature selection method, ensuring domain‐specific relevance. On the CICIDS2017 dataset, DDoSNAS achieves 99.98% accuracy, 99.97% precision, and 100% recall with only 94 k FLOPs and 0.8 ms latency, outperforming state‐of‐the‐art intrusion detection models in both predictive performance and efficiency. This work represents the first application of a Transformer‐based NAS controller to cybersecurity, demonstrating that cutting‐edge neural architecture search can yield models capable of real‐time, on‐device DDoS defense without sacrificing accuracy. The results establish DDoSNAS as a new benchmark for efficient, high‐accuracy cyber threat detection and a blueprint for applying advanced NAS techniques to other security‐critical domains.

Read the paper · More papers on PaperTik