Robust Anomaly Detection in Network Traffic: Evaluating Machine Learning Models on CICIDS2017

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Xu, Zhaoyang, Liu, Yunbo
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866918120364441600
author Xu, Zhaoyang
Liu, Yunbo
author_facet Xu, Zhaoyang
Liu, Yunbo
contents Identifying suitable machine learning paradigms for intrusion detection remains critical for building effective and generalizable security solutions. In this study, we present a controlled comparison of four representative models - Multi-Layer Perceptron (MLP), 1D Convolutional Neural Network (CNN), One-Class Support Vector Machine (OCSVM) and Local Outlier Factor (LOF) - on the CICIDS2017 dataset under two scenarios: detecting known attack types and generalizing to previously unseen threats. Our results show that supervised MLP and CNN achieve near-perfect accuracy on familiar attacks but suffer drastic recall drops on novel attacks. Unsupervised LOF attains moderate overall accuracy and high recall on unknown threats at the cost of elevated false alarms, while boundary-based OCSVM balances precision and recall best, demonstrating robust detection across both scenarios. These findings offer practical guidance for selecting IDS models in dynamic network environments.
format Preprint
id arxiv_https___arxiv_org_abs_2506_19877
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Robust Anomaly Detection in Network Traffic: Evaluating Machine Learning Models on CICIDS2017
Xu, Zhaoyang
Liu, Yunbo
Cryptography and Security
Artificial Intelligence
Machine Learning
Identifying suitable machine learning paradigms for intrusion detection remains critical for building effective and generalizable security solutions. In this study, we present a controlled comparison of four representative models - Multi-Layer Perceptron (MLP), 1D Convolutional Neural Network (CNN), One-Class Support Vector Machine (OCSVM) and Local Outlier Factor (LOF) - on the CICIDS2017 dataset under two scenarios: detecting known attack types and generalizing to previously unseen threats. Our results show that supervised MLP and CNN achieve near-perfect accuracy on familiar attacks but suffer drastic recall drops on novel attacks. Unsupervised LOF attains moderate overall accuracy and high recall on unknown threats at the cost of elevated false alarms, while boundary-based OCSVM balances precision and recall best, demonstrating robust detection across both scenarios. These findings offer practical guidance for selecting IDS models in dynamic network environments.
title Robust Anomaly Detection in Network Traffic: Evaluating Machine Learning Models on CICIDS2017
topic Cryptography and Security
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2506.19877