Next Article in Journal
FireXplainNet: Optimizing Convolution Block Architecture for Enhanced Wildfire Detection and Interpretability
Next Article in Special Issue
HotCFuzz: Enhancing Vulnerability Detection through Fuzzing and Hotspot Code Coverage Analysis
Previous Article in Journal
Dual-Frequency, Dual-Mode Reconfigurable Digital Atmospheric Radar Receiver Design
Previous Article in Special Issue
Learn-IDS: Bridging Gaps between Datasets and Learning-Based Network Intrusion Detection
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Sampling-Based Machine Learning Models for Intrusion Detection in Imbalanced Dataset

1
College of Computer Science and Technology, Huaqiao University, Xiamen 361021, China
2
College of Engineering, Science and Environment, The University of Newcastle, Callaghan, NSW 2308, Australia
3
School of Engineering and Technology, Central Queensland University, Rockhampton, QLD 4701, Australia
4
Lincoln Institute of Higher Education, Sydney, NSW 2000, Australia
*
Author to whom correspondence should be addressed.
These authors contributed equally to this work.
Electronics 2024, 13(10), 1878; https://doi.org/10.3390/electronics13101878
Submission received: 8 March 2024 / Revised: 26 April 2024 / Accepted: 1 May 2024 / Published: 11 May 2024
(This article belongs to the Special Issue Machine Learning for Cybersecurity: Threat Detection and Mitigation)

Abstract

Cybersecurity is one of the important considerations when adopting IoT devices in smart applications. Even though a huge volume of data is available, data related to attacks are generally in a significantly smaller proportion. Although machine learning models have been successfully applied for detecting security attacks on smart applications, their performance is affected by the problem of such data imbalance. In this case, the prediction model is preferable to the majority class, while the performance for predicting the minority class is poor. To address such problems, we apply two oversampling techniques and two undersampling techniques to balance the data in different categories. To verify their performance, five machine learning models, namely the decision tree, multi-layer perception, random forest, XGBoost, and CatBoost, are used in the experiments based on the grid search with 10-fold cross-validation for parameter tuning. The results show that both the oversampling and undersampling techniques can improve the performance of the prediction models used. Based on the results, the XGBoost model based on the SMOTE has the best performance in terms of accuracy at 75%, weighted average precision at 82%, weighted average recall at 75%, weighted average F1 score at 78%, and Matthews correlation coefficient at 72%. This indicates that this oversampling technique is effective for multi-attack prediction under a data imbalance scenario.
Keywords: cybersecurity; oversampling technique; undersampling technique; multi-class classification; machine learning cybersecurity; oversampling technique; undersampling technique; multi-class classification; machine learning

Share and Cite

MDPI and ACS Style

Fan, Z.; Sohail, S.; Sabrina, F.; Gu, X. Sampling-Based Machine Learning Models for Intrusion Detection in Imbalanced Dataset. Electronics 2024, 13, 1878. https://doi.org/10.3390/electronics13101878

AMA Style

Fan Z, Sohail S, Sabrina F, Gu X. Sampling-Based Machine Learning Models for Intrusion Detection in Imbalanced Dataset. Electronics. 2024; 13(10):1878. https://doi.org/10.3390/electronics13101878

Chicago/Turabian Style

Fan, Zongwen, Shaleeza Sohail, Fariza Sabrina, and Xin Gu. 2024. "Sampling-Based Machine Learning Models for Intrusion Detection in Imbalanced Dataset" Electronics 13, no. 10: 1878. https://doi.org/10.3390/electronics13101878

APA Style

Fan, Z., Sohail, S., Sabrina, F., & Gu, X. (2024). Sampling-Based Machine Learning Models for Intrusion Detection in Imbalanced Dataset. Electronics, 13(10), 1878. https://doi.org/10.3390/electronics13101878

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop