An AutoML-based approach for Network Intrusion Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Gyimah, Nana Kankam, Mwakalonge, Judith, Comert, Gurcan, Siuhi, Saidi, Akinie, Robert, Sulle, Methusela, Ruganuza, Denis, Izison, Benibo, Mukwaya, Arthur
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929603751182336
author Gyimah, Nana Kankam
Mwakalonge, Judith
Comert, Gurcan
Siuhi, Saidi
Akinie, Robert
Sulle, Methusela
Ruganuza, Denis
Izison, Benibo
Mukwaya, Arthur
author_facet Gyimah, Nana Kankam
Mwakalonge, Judith
Comert, Gurcan
Siuhi, Saidi
Akinie, Robert
Sulle, Methusela
Ruganuza, Denis
Izison, Benibo
Mukwaya, Arthur
contents In this paper, we present an automated machine learning (AutoML) approach for network intrusion detection, leveraging a stacked ensemble model developed using the MLJAR AutoML framework. Our methodology combines multiple machine learning algorithms, including LightGBM, CatBoost, and XGBoost, to enhance detection accuracy and robustness. By automating model selection, feature engineering, and hyperparameter tuning, our approach reduces the manual overhead typically associated with traditional machine learning methods. Extensive experimentation on the NSL-KDD dataset demonstrates that the stacked ensemble model outperforms individual models, achieving high accuracy and minimizing false positives. Our findings underscore the benefits of using AutoML for network intrusion detection, as the AutoML-driven stacked ensemble achieved the highest performance with 90\% accuracy and an 89\% F1 score, outperforming individual models like Random Forest (78\% accuracy, 78\% F1 score), XGBoost and CatBoost (both 80\% accuracy, 80\% F1 score), and LightGBM (78\% accuracy, 78\% F1 score), providing a more adaptable and efficient solution for network security applications.
format Preprint
id arxiv_https___arxiv_org_abs_2411_15920
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle An AutoML-based approach for Network Intrusion Detection
Gyimah, Nana Kankam
Mwakalonge, Judith
Comert, Gurcan
Siuhi, Saidi
Akinie, Robert
Sulle, Methusela
Ruganuza, Denis
Izison, Benibo
Mukwaya, Arthur
Machine Learning
In this paper, we present an automated machine learning (AutoML) approach for network intrusion detection, leveraging a stacked ensemble model developed using the MLJAR AutoML framework. Our methodology combines multiple machine learning algorithms, including LightGBM, CatBoost, and XGBoost, to enhance detection accuracy and robustness. By automating model selection, feature engineering, and hyperparameter tuning, our approach reduces the manual overhead typically associated with traditional machine learning methods. Extensive experimentation on the NSL-KDD dataset demonstrates that the stacked ensemble model outperforms individual models, achieving high accuracy and minimizing false positives. Our findings underscore the benefits of using AutoML for network intrusion detection, as the AutoML-driven stacked ensemble achieved the highest performance with 90\% accuracy and an 89\% F1 score, outperforming individual models like Random Forest (78\% accuracy, 78\% F1 score), XGBoost and CatBoost (both 80\% accuracy, 80\% F1 score), and LightGBM (78\% accuracy, 78\% F1 score), providing a more adaptable and efficient solution for network security applications.
title An AutoML-based approach for Network Intrusion Detection
topic Machine Learning
url https://arxiv.org/abs/2411.15920