A Comparative Analysis of Machine Learning and Deep Reinforcement Learning Approaches for Adaptive Intrusion Detection
Ayşe Okutan Kara, Mustafa Kara, Aytuğ Boyacı · IEEE Access · 2025
Cyber threats are rapidly developing, necessitating more adaptable and intelligent security frameworks for intrusion detection systems (IDS). Conventional Machine Learning (ML) methodologies, although proficient in identifying recognized attack patterns, frequently falter against unexpected threats, such as zero-day assaults, owing to their dependence on labeled datasets. Deep Reinforcement Learning (DRL) addresses this limitation by independently learning and adapting to novel dangers via trial-and-error interactions with the environment. This study rigorously assesses the efficacy of Random Forest (RF), Decision Tree (DT), and Deep Q-Learning (DQL) models utilizing the CIC-IDS2017 dataset, contrasting their capacity to identify both known and new (zero-day) attacks. The experimental findings indicate that DT and RF attain the maximum accuracy in identifying known attacks, whereas DQL displays enhanced generalization ability for unknown threats. Furthermore, comparative evaluation of the DQL model across the CIC-IDS2017, NSL-KDD, and AWID datasets offers important insights into its robustness and generalization capacity under heterogeneous experimental conditions. In this study, we investigate the influence of hyperparameter tuning on the efficacy of deep reinforcement learning, demonstrating that modifications to the learning rate, exploration strategy, and experience replay buffer substantially improve detection accuracy. This study systematically compares classic machine learning techniques with deep reinforcement learning, demonstrating the viability of reinforcement learning-based intrusion detection system models and providing insights into adaptive and autonomous cybersecurity solutions.