PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
March 24, 2026Scientific Reports2 citationsOpen Access

Supervised machine learning intrusion detection review and multi-criteria evaluation

AAAhmad Adel Abu-SharehaMAMosleh M. AbualhajAHAbdelrahman H. Hussein

Key Points

  • The research aims to review components of supervised machine learning intrusion detection systems and evaluate various techniques using a multi-criteria approach.
  • Reviewed components of supervised ML intrusion detection systems, including algorithms and datasets.
  • Evaluated alternative techniques using a multi-criteria decision-making approach.
  • Employed the TOPSIS method to rank algorithms based on distances to ideal alternatives across various evaluator preferences.
  • Used datasets including KDD, NSL-KDD, and CICIDS2017 for experimental evaluation.
  • Tree-based methods like Random Tree, C4.5, and Random Forest ranked highest across multiple evaluators.
  • Naïve Bayes classifiers performed poorly, indicating sensitivity to feature dependencies in high-dimensional data.

Abstract

The intrusion detection system (IDS) that uses a machine learning (ML) algorithm recognizes attack flows from normal ones using supervised, semi-supervised, or unsupervised techniques. Supervised ML (SML) IDS achieved the best detection rate when historical data was available. Therefore, various SML-IDS techniques have been proposed, combining classification algorithms with preprocessing and normalization steps. This research has two aims (1) to review the components of the SML-IDS and (2) to evaluate the alternative techniques using a multi-criteria decision-making approach with reference to positive and negative ideal alternatives. The review focuses on the algorithms, datasets, and metrics used with the SML-IDS. On the other hand, the proposed evaluation framework uses the Technique for Order of Preference by Similarity to Ideal Solution (TOPSIS) and employs various evaluators’ preferences. Initially, the algorithms and the datasets are gathered, and then the evaluation criteria and their types are identified, e.g., cost vs. benefit. The weights for these criteria are initialized next, taking various preferences into account. The alternative algorithms are then evaluated, and their results are conveyed and ranked based on their distances to the ideal alternatives with references to the stored initialized weights. Three datasets are used in the evaluation process: KDD, NSL-KDD, and CICIDS2017. The results indicate that, within the experimental setup and the utilized datasets, tree-based methods (Random Tree, C4.5, and Random Forest) frequently achieved top rankings across multiple evaluator preferences. Naïve Bayes classifiers performed consistently worse across the experiments, likely reflecting their sensitivity to feature dependencies and high-dimensional distributions in the selected datasets.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Abu-Shareha et al. (2026) studied this question.

synapsesocial.com/papers/69c229b2aeb5a845df0d48fehttps://doi.org/10.1038/s41598-026-44773-1
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1A Systematic Analysis and Review on Intrusion Detection Systems Using Machine Learning and Deep Learning Algorithms2024 · 2 citations
  2. 2Evaluating Security enhancement through Machine Learning Approaches for Anomaly Based Intrusion Detection Systems2024 · 3 citations
  3. 3An Enhanced Intrusion Detection System Model Using Machine Learning Algorithm2024
  4. 4Network Intrusion Detection and Classification System: A Supervised Machine Learning Approach2024 · 2 citations
  5. 5Comparing Machine Learning Algorithms for Intrusion Detection Systems2025