Mobile ad hoc networks (MANETs) are highly vulnerable to denial-of-service (DoS) attacks because their decentralized operation, rapidly changing topology, and constrained node resources limit the use of heavyweight security mechanisms. This paper presents an Adaptive Clustering and Random-Forest-based Intrusion Detection System (ACRF-IDS), a lightweight intrusion detection framework that combines mobility-aware adaptive clustering with supervised learning to detect network-layer DoS behaviors. Cluster heads are elected using a multi-metric utility (residual energy, link stability, and mobility) to stabilize observations under node movement. Within fixed monitoring windows, cluster heads aggregate routing-, forwarding-, and energy-related features and classify nodes using a Random Forest model; a temporal voting scheme further suppresses transient mobility-induced alarms. Using ns-2.35 simulations with Ad hoc On-Demand Distance Vector (AODV) and both flooding and blackhole DoS scenarios, ACRF-IDS is compared with (i) a static clustering-based threshold IDS, (ii) a non-clustered Support Vector Machine (SVM)-based IDS, and (iii) AIFAODV, which specializes in flooding. Across the evaluated network sizes (4–50 nodes), the proposed method achieves a higher detection rate and F1-score while maintaining a lower false positive rate than the baseline techniques. We additionally quantify network-level impact using PDR, throughput, and routing overhead, showing that ACRF-IDS improves availability under DoS while adding bounded overhead. Future work will extend the evaluation to more diverse attack behaviors and validate the approach in real-world MANET testbeds.
Hwanseok Yang (Thu,) studied this question.