HydraGuard-ID: A Hybrid Ensemble Framework With Stratified Feature Selection for High-Accuracy DDoS Attack Detection
L Sankar Ganesh, Mohan Kumar P. · IEEE Access · 2026
Distributed Denial-of-Service attacks continue to threaten heterogeneous IoT network infrastructure over the world. In response to these attacks’ complexity, traditional detection methods fail to adapt evolving threats. In this paper, we present HydraGuard-ID, a hybrid ensemble framework that identifies DDoS attacks with high precision by utilizing three core components. First, STRATA-FS, a stratified feature selection algorithm that reduces the feature space by 65.5% while preserving discriminative power across cross-validation folds. Second, HydraBoost constructs an out-of-fold ensemble of six diverse machine learning models with adaptive SMOTE balancing to handle class imbalance without information leakage. Third, Aegis-Elastic, an ElasticNet-based meta-learner that combines base predictions with original features and provides interpretable coefficient analysis. Experimental evaluation on the CIC-DDoS2019 dataset shows HydraGuard-ID achieves 96.87% accuracy, 96.81% weighted F1-score, and a 0.9945 micro-averaged AUC-ROC, outperforming the strongest single model baseline by 2.75%. The framework demonstrates excellent probability calibration (ECE = 0.0082) and efficient inference (2 – 5 ms per sample) suitable for real-time deployment, demonstrating strong and practical performance for explainable DDoS detection in real-world scenarios. The evaluation focuses on BENIGN and three DDoS attack variants (DNS, LDAP, MSSQL) from CIC-DDoS2019, representing realistic experimental setting.