Enhancing the Artificial Rabbit Optimizer Using Fuzzy Rule Interpolation
Abstract
1. Introduction
- First, we introduce a fuzzy rule interpolation mechanism to compute the energy factor of ARO dynamically, resulting in an intelligent and adaptive optimization algorithm.
- Second, we design a multi-objective fitness function that jointly optimizes two critical aspects: maximizing classification accuracy and minimizing the number of selected features.
- Third, we apply enhanced ARO to the classification task in intrusion detection, addressing both feature selection and model optimization.
- Fourth, we provide comprehensive experimental validation demonstrating that FRI-ARO achieves improved classification performance over baseline methods.
2. Related Work
2.1. Fuzzy System in Intrusion Detection Systems
2.2. Artificial Rabbit Optimizer in Intrusion Detection
2.3. Hybrid Approaches Combining Metaheuristics Algorithms
2.4. Discussion and Motivation for Modifying the ARO Algorithm
- Premature convergence: The issues related to the limited diversity in population could lead to suffering from local optima in large-scale datasets.
- Exploration-exploitation imbalance: Although the shift between phases is controlled via an energy-shrink factor, adjusting this balance remains challenging in dynamic environments.
- Performance variability: In several benchmark and engineering tasks, ARO often ranked second or lower when compared to its hybridized versions (e.g., GBO-ARO, ABC-ARO, or AO-ARO).
- Integration of FRI into ARO: The proposed method introduces a novel hybrid approach (FRI-ARO) by incorporating an FRI inference engine into the ARO algorithm. This integration dynamically adjusts the energy factor A, which controls the balance between exploration and exploitation phases. Contrary to traditional ARO variants that rely on linearly decaying strategies, this fuzzy adaptation enables the algorithm to respond more intelligently to population diversity and iteration progress.
- A Multi-objective Fitness Function: In this work, we design a multi-objective fitness function that maximizes classification accuracy and minimizes the number of selected features.
- Comprehensive Analysis of Large-Scale Intrusion Detection System Datasets: The proposed FRI-ARO method was evaluated on eight intrusion detection datasets. These datasets cover a wide range of intrusions, including Denial of Service (DoS), phishing attacks, and various IoT attack scenarios.
- Use of Simple Classifier for Evaluation: The decision tree algorithm was used to assess the performance of the selected subset features within a 5-fold cross-validation.
3. The Proposed Hybrid FRI-ARO Strategy
3.1. Main Steps of the Original ARO Algorithm
- Initialize the population of solutions randomly within the defined search bounds.
- Evaluate the fitness of each solution using the target benchmark function.
- Determine the best solution found so far.
- For each iteration:
- (a)
- (b)
- If , perform exploration:
- Select a random solution and move in its direction, modified by a random step length L and noise.
- (c)
- If , perform exploitation:
- Modify the current solution using directional vectors and Gaussian noise to simulate hiding behavior.
- (d)
- Apply boundary control to ensure the new solution remains within the search space.
- (e)
- Evaluate the new fitness and update the solution if improved.
- Record the best fitness found at each iteration.
- Define the input parameters: The first step involves selecting and setting up the relevant input variables that influence the dynamic behavior of the energy factor. In this work, the inputs are chosen as the optimization stage and the solution variability, which together reflect the progress of the optimization process and the variability within the population.Design membership functions and fuzzy rule base: Each input and output variable had linguistic values such as Low, Mid, and High. Additionally, a concise set of fuzzy rules is constructed to describe how combinations of input conditions affect the output energy factor. FRI is particularly effective here, as it can operate reliably even when the rule base is sparse.Apply the FRI inference mechanism: Once the inputs and rules are defined, the FRI engine is used to interpolate the fuzzy rules and infer an appropriate output value for A. This enables the system to handle missing or incomplete rule coverage while still producing valid reasoning outcomes.Integrate the output with ARO: The defuzzified result from the FRI (the computed energy factor A) is fed directly into the ARO algorithm at each iteration. This allows ARO to dynamically adjust its behavior based on real-time feedback, improving its ability to balance global exploration and local exploitation.
3.2. Fuzzy Inputs for Dynamic Energy Control in FRI-ARO
3.3. Fuzzy Sets and Fuzzy Rule Generations
- Accuracy is the average classification accuracy obtained using the selected subset of features.
- quantifies the proportion of features selected, serving as a measure of dimensionality.
- and are weights such that , used to balance the trade-off between accuracy and reduction. In our case, we use and , giving higher importance to accuracy.
| Algorithm 1 FRI-ARO Algorithm |
|
4. Experiments and Results
4.1. Evaluation on Binary Classification Intrusion Datasets
4.2. Evaluation on Multiclass Intrusion Datasets
4.3. Performance Metrics: Accuracy, Time, and Dimensionality Reduction
4.4. Comparison with State-of-the-Art Methods
5. Conclusions
Funding
Institutional Review Board Statement
Data Availability Statement
Conflicts of Interest
References
- Almseidin, M.; Alzubi, M.; Al-Sawwa, J.; Alkasassbeh, M.; Alfraheed, M. A threefold approach for enhancing fuzzy interpolative reasoning: Case study on phishing attack detection using sparse rule bases. Computers 2024, 13, 291. [Google Scholar] [CrossRef] [Scilit]
- Al-Sawwa, J.; Almseidin, M.; Alkasassbeh, M.; Alemerien, K.; Younisse, R. Spark-based multi-verse optimizer as wrapper features selection algorithm for phishing attack challenge. Clust. Comput. 2024, 27, 5799–5814. [Google Scholar] [CrossRef] [Scilit]
- Wang, L.; Cao, Q.; Zhang, Z.; Mirjalili, S.; Zhao, W. Artificial rabbits optimization: A new bio-inspired meta-heuristic algorithm for solving engineering optimization problems. Eng. Appl. Artif. Intell. 2022, 114, 105082. [Google Scholar] [CrossRef] [Scilit]
- Anka, F.; Agaoglu, N.; Nematzadeh, S.; Torkamanian-afshar, M.; Gharehchopogh, F.S. Advances in artificial rabbits optimization: A comprehensive review. Arch. Comput. Methods Eng. 2024, 32, 2113–2148. [Google Scholar] [CrossRef] [Scilit]
- Qiu, X.; Shi, L.; Fan, P. A cooperative intrusion detection system for internet of things using fuzzy logic and ensemble of convolutional neural networks. Sci. Rep. 2025, 15, 15934. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Heidari, A.; Khalilzadeh, M.; Pamucar, D. An efficient intelligent intrusion detection system using fuzzy logic based on the Particle Swarm Optimization algorithm: A case study. Int. J.-Knowl.-Based Intell. Eng. Syst. 2025, 29, 3–14. [Google Scholar]
- Sharma, J.; Kumar, K.; Jain, P.; Alfilh, R.H.; Alkattan, H. Enhancing Intrusion Detection Systems with Adaptive Neuro-Fuzzy Inference Systems. Mesopotamian J. Cybersecur. 2025, 5, 1–10. [Google Scholar] [CrossRef] [Scilit]
- Subramani, S.; Selvi, M. Intrusion detection system and fuzzy ant colony optimization based secured routing in wireless sensor networks. Soft Comput. 2024, 28, 10345–10367. [Google Scholar] [CrossRef] [Scilit]
- Almseidin, M.; Al-Sawwa, J.; Alkasassbeh, M.; Alzubi, M.; Alrfou, K. DT-ARO: Decision tree-based artificial rabbits optimization to mitigate IoT botnet exploitation. J. Netw. Syst. Manag. 2024, 32, 14. [Google Scholar] [CrossRef] [Scilit]
- Patni, S.; Lee, D.J. Artificial Rabbits Optimizer with Deep Learning Model for Blockchain-Assisted Secure Smart Healthcare System. Comput. Intell. Neurosci. 2024, 14. [Google Scholar] [CrossRef] [Scilit]
- Shahba, L.; Heidary-Sharifabad, A.; Mollahoseini Ardakani, M. Detection of fake web pages and phishing attacks with rabbit optimization algorithm. J. Supercomput. 2025, 81, 313. [Google Scholar] [CrossRef] [Scilit]
- Hamdipour, A.; Basiri, A.; Zaare, M.; Mirjalili, S. Artificial rabbits optimization algorithm with automatically DBSCAN clustering algorithm to similarity agent update for features selection problems. J. Supercomput. 2025, 81, 150. [Google Scholar] [CrossRef] [Scilit]
- Mahesh, D.; Tallapally, S.K. Advanced SDN-based network security: An ensemble optimized deep learning-based framework for mitigating DDoS attacks with intrusion detection. Clust. Comput. 2025, 28, 1–27. [Google Scholar] [CrossRef] [Scilit]
- de Campos Souza, P.V.; Sayyadzadeh, I. GWO-FNN: Fuzzy Neural Network Optimized via Grey Wolf Optimization. Mathematics 2025, 13, 1156. [Google Scholar] [CrossRef] [Scilit]
- Logeswari, G.; Roselind, J.D.; Tamilarasi, K.; Nivethitha, V. A Comprehensive Approach to Intrusion Detection in IoT Environments Using Hybrid Feature Selection and Multi-Stage Classification Techniques. IEEE Access 2025, 13, 24970–24987. [Google Scholar] [CrossRef] [Scilit]
- Madhuridevi, L.; Sree Rathna Lakshmi, N. Metaheuristic assisted hybrid deep classifiers for intrusion detection: A bigdata perspective. Wirel. Netw. 2025, 31, 1205–1225. [Google Scholar] [CrossRef] [Scilit]
- Zhang, F.; Huang, L.; Shi, K.; Zhai, S.; Lan, Y.; Li, Q. Intrusion detection based on hybrid metaheuristic feature selection. Comput. J. 2025, 68, 13–22. [Google Scholar] [CrossRef] [Scilit]
- Maazalahi, M.; Hosseini, S. Machine learning and metaheuristic optimization algorithms for feature selection and botnet attack detection. Knowl. Inf. Syst. 2025, 67, 3549–3597. [Google Scholar] [CrossRef] [Scilit]
- Neto, E.C.P.; Dadkhah, S.; Ferreira, R.; Zohourian, A.; Lu, R.; Ghorbani, A.A. CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment. Sensors 2023, 23, 5941. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Moustafa, N.; Slay, J. UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In 2015 Military Communications and Information Systems Conference (MilCIS), Canberra, ACT, Australia, 10–12 November 2015; IEEE: Piscataway, NJ, USA, 2015; pp. 1–6. [Google Scholar]
- Almseidin, M.; Al-Sawwa, J.; Alkasassbeh, M. Generating a benchmark cyber multi-step attacks dataset for intrusion detection. J. Intell. Fuzzy Syst. 2022, 43, 3679–3694. [Google Scholar] [CrossRef] [Scilit]
- Sharafaldin, I.; Lashkari, A.H.; Ghorbani, A.A. Toward generating a new intrusion detection dataset and intrusion traffic characterization. ICISSp 2018, 1, 108–116. [Google Scholar]
- Tavallaee, M.; Bagheri, E.; Lu, W.; Ghorbani, A.A. A detailed analysis of the KDD CUP 99 data set. In 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications, Ottawa, ON, Canada, 8–10 July 2009; IEEE: Piscataway, NJ, USA, 2009; pp. 1–6. [Google Scholar]
- Mamun, M.S.I.; Rathore, M.A.; Lashkari, A.H.; Stakhanova, N.; Ghorbani, A.A. Detecting malicious urls using lexical analysis. In Network and System Security: 10th International Conference, NSS 2016, Taipei, Taiwan, 28–30 September 2016, Proceedings 10; Springer: Cham, Switzerland, 2016; pp. 467–482. [Google Scholar]
- Tan, C.L.; Chiew, K.L.; Yong, K.S.C. A new hybrid ensemble feature selection framework for machine learning-based phishing detection system. Inf. Sci. 2019, 484, 153–166. [Google Scholar] [CrossRef] [Scilit]
- Moustafa, N. A new distributed architecture for evaluating AI-based security systems at the edge: Network TON_IoT datasets. Sustain. Cities Soc. 2021, 72, 102994. [Google Scholar]
- Dong, R.H.; Li, X.Y.; Zhang, Q.Y.; Yuan, H. Network intrusion detection model based on multivariate correlation analysis–long short-time memory network. IET Inf. Secur. 2020, 14, 166–174. [Google Scholar]
- Yin, C.; Zhu, Y.; Fei, J.; He, X. A deep learning approach for intrusion detection using recurrent neural networks. IEEE Access 2017, 5, 21954–21961. [Google Scholar] [CrossRef] [Scilit]
- Kasongo, S.M.; Sun, Y. A deep learning method with wrapper based feature extraction for wireless intrusion detection system. Comput. Secur. 2020, 92, 101752. [Google Scholar] [CrossRef] [Scilit]
- Mebawondu, J.O.; Alowolodu, O.D.; Mebawondu, J.O.; Adetunmbi, A.O. Network intrusion detection system using supervised learning paradigm. Sci. Afr. 2020, 9, e00497. [Google Scholar] [CrossRef] [Scilit]
- Sajid, M.; Malik, K.R.; Almogren, A.; Malik, T.S.; Khan, A.H.; Tanveer, J.; Rehman, A.U. Enhancing intrusion detection: A hybrid machine and deep learning approach. J. Cloud Comput. 2024, 13, 123. [Google Scholar] [CrossRef] [Scilit]
- Sharma, B.; Sharma, L.; Lal, C.; Roy, S. Anomaly based network intrusion detection for IoT attacks using deep learning technique. Comput. Electr. Eng. 2023, 107, 108626. [Google Scholar] [CrossRef] [Scilit]
- Kasongo, S.M. A deep learning technique for intrusion detection system using a Recurrent Neural Networks based framework. Comput. Commun. 2023, 199, 113–125. [Google Scholar] [CrossRef] [Scilit]
- Jamal, M.H.; Naz, N.; Khattak, M.A.K.; Saeed, F.; Altamimi, S.N.; Qasem, S.N. A Comparison of Re-Sampling Techniques for Detection of Multi-Step Attacks on Deep Learning Models. IEEE Access 2023, 11, 127446–127457. [Google Scholar] [CrossRef] [Scilit]
- Ibrahim, M.; Elhafiz, R. Modeling an intrusion detection using recurrent neural networks. J. Eng. Res. 2023, 11, 100013. [Google Scholar] [CrossRef] [Scilit]
- Lilhore, U.K.; Manoharan, P.; Simaiya, S.; Alroobaea, R.; Alsafyani, M.; Baqasah, A.M.; Dalal, S.; Sharma, A.; Raahemifar, K. HIDM: Hybrid intrusion detection model for industry 4.0 Networks using an optimized CNN-LSTM with transfer learning. Sensors 2023, 23, 7856. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Alazab, M.; Khurma, R.A.; Awajan, A.; Camacho, D. A new intrusion detection system based on Moth–Flame Optimizer algorithm. Expert Syst. Appl. 2022, 210, 118439. [Google Scholar] [CrossRef] [Scilit]









| Author(s) | Year | Method | Dataset(s) | Limitation(s) |
|---|---|---|---|---|
| Qiu et al. [5] | 2025 | Fuzzy system + CNN ensemble | IoT attack datasets | High computational complexity and dependence on deep learning models |
| Heidari et al. [6] | 2025 | Fuzzy system + PSO | KDD-99 | Requires parameter tuning and fixed optimization strategy |
| Sharma et al. [7] | 2025 | ANFIS-based IDS | KDD-99 | Sensitive to membership function selection and rule design |
| Subramani and Selvi [8] | 2024 | Fuzzy system + Ant Colony Optimization | NSL-KDD | Performance depends on predefined fuzzy rules |
| Almseidin et al. [1] | 2024 | Fuzzy Rule Interpolation-based IDS | Phishing datasets | Not integrated with metaheuristic optimization algorithms |
| Patni and Lee [10] | 2024 | ARO + Deep Extreme Learning Machine | Cleveland Heart Dataset | Focuses on hyperparameter tuning rather than adaptive search control |
| Almseidin et al. [9] | 2024 | ARO-based wrapper feature selection + DT | N-BaIoT | Uses static parameter settings for exploration and exploitation |
| Input/Output | Linguistic Term | Triangular MF Range |
|---|---|---|
| Optimization Stage | Low | [0, 0.2, 0.3] |
| Mid | [0.4, 0.5, 0.6] | |
| High | [0.7, 0.9, 1] | |
| Solution Variability | Low | [0, 0.3, 0.4] |
| Mid | [0.5, 0.6, 0.8] | |
| High | [0.9, 0.9, 1] | |
| Energy Factor | Low | [0, 0.5, 0.9] |
| Mid | [1.2, 1.4, 1.6] | |
| High | [1.8, 1.9, 2] |
| Optimization Stage | Solution Variability | Output |
|---|---|---|
| Low | High | High |
| Low | Low | Mid |
| Mid | Mid | Mid |
| High | High | Mid |
| High | Low | Low |
| Dataset | # Features | # Instances | Category |
|---|---|---|---|
| CIC IoT 2023 | 46 | 238,687 | IoT-based Attacks |
| ToN IoT | 124 | 21,105 | IoT-based Attacks |
| UNSW-NB15 | 76 | 447,916 | Hybrid/Synthetic Attacks |
| MSCAD | 66 | 131,258 | Hybrid/Synthetic Attacks |
| CIC IDS 2017 | 78 | 225,746 | Traditional IDS Benchmarks |
| NSL-KDD | 38 | 25,139 | Traditional IDS Benchmarks |
| Phishing URL | 79 | 15,368 | Specialized Cyber Attacks |
| Phishing Detection | 48 | 10,000 | Specialized Cyber Attacks |
| Parameter | Value |
|---|---|
| Population size | 30 |
| Maximum number of iterations | 100 |
| Problem dimensionality | Dataset-dependent |
| Search space bounds | Dataset-dependent |
| Number of fuzzy input variables | 2 |
| Number of membership functions | 3 (Low, Mid, High) |
| Dataset | Accuracy (%) | Fitness | Time (s) |
|---|---|---|---|
| MSCAD | 99.73 | 0.0128 | 2168.43 |
| Phishing Detection | 96.00 | 0.0756 | 258,040.31 |
| PhishingURL | 96.98 | 0.0424 | 654,944.71 |
| NSL-KDD | 98.35 | 0.0220 | 655,835.64 |
| CICIDS2017 | 99.04 | 0.0128 | 665,009.41 |
| ToN IoT | 100.00 | 0.0114 | 355,835.21 |
| CIC IoT 2023 | 98.99 | 0.0180 | 12,545.77 |
| UNSW-NB15 | 91.96 | 0.0813 | 9794.09 |
| Dataset | Precision | Recall | F1-Score |
|---|---|---|---|
| MSCAD | 0.9941 | 0.9955 | 0.9948 |
| ToN IoT | 1.0000 | 1.0000 | 1.0000 |
| CIC-IDS-2017 | 0.9797 | 0.9972 | 0.9883 |
| Phishing URL | 0.9696 | 0.9708 | 0.9702 |
| Phishing Detection | 0.9473 | 0.9720 | 0.9595 |
| NSL-KDD | 0.9808 | 0.9852 | 0.9830 |
| Dataset | Selected/Total | Selected Feature Index |
|---|---|---|
| CIC IoT 2023 | 4/46 | [18, 20, 30, 40] |
| CICIDS2017 | 3/78 | [5, 45, 76] |
| NSL-KDD | 3/38 | [2, 23, 34] |
| MSCAD | 7/66 | [8, 19, 20, 29, 33, 46, 53] |
| Phishing-URL | 13/79 | [2, 13, 20, 26, 29, 41, 44, 49, 60, 61, 63, 67, 70] |
| TON_IoT | 14/123 | [6, 7, 25, 27, 31, 33, 38, 42, 45, 52, 58, 86, 117, 121] |
| UNSW-NB15 | 7/76 | [38, 40, 47, 51, 70, 71, 76] |
| Aspect | Original ARO | FRI-ARO |
|---|---|---|
| Energy Factor (A) Calculation | Fixed formula | Dynamically calculated using a Mamdani FIS based on Iteration Ratio and Diversity |
| Adaptability | Static behavior regardless of population state | Adaptive to optimization stage and diversity level |
| Inputs Considered | Only iteration count (via theta) | Iteration progress and solution diversity |
| System Type | Purely mathematical | Soft computing (Fuzzy system-enhanced) |
| Exploration Exploitation Control | Controlled by A indirectly tied to iterations | Controlled by fuzzy rule base for more intelligent switching engine setup and evaluation |
| Expected Benefit | Fast but rigid convergence | More balanced and context-sensitive search behavior |
| Approach | Dataset | Features Selection | Accuracy | Task Type |
|---|---|---|---|---|
| MCA-LSTM [27] | UNSW-NB15 | Info. Gain | 77.74% | Multiclass |
| RNN [28] | UNSW-NB15 | - | 81.29% | Multiclass |
| FFDNN [29] | UNSW-NB15 | ExtraTrees | 77.16% | Multiclass |
| ANN-MLP [30] | UNSW-NB15 | Gain Ratio | 76.96% | Multiclass |
| LSTM [31] | UNSW-NB15 | XGBoost | 88.60% | Multiclass |
| DNN [32] | UNSW-NB15 | filter-based | 84–91.00% | Multiclass |
| Simple-RNN [33] | UNSW-NB15 | XGBoost | 87.07% | Multiclass |
| CNN+LSTM [34] | MSCAD | - | 87.10% | Multiclass |
| CNN+RNN [34] | MSCAD | - | 85.80% | Multiclass |
| This Work | UNSW-NB15 MSCAD | FRI-ARO | 91.96% 99.73% | Multiclass |
| CNN [31] | CIC-IDS2017 | XGBoost | 95.60% | Binary |
| CNN-LSTM [31] | CIC-IDS2017 | XGBoost | 96.21% | Binary |
| LSTM-RNN [35] | NSL KDD | - | 88.40% | Binary |
| OCNN-LSTM [36] | ToN-IoT | - | 94.40% | Binary |
| LSTM [33] | NSL-KDD | XGBoost | 88.13% | Binary |
| DT [2] | Phishing Detection | PSO | 93.43% | Binary |
| DT [2] | Phishing Detection | FFA | 93.02% | Binary |
| DT [2] | Phishing Detection | MVO | 94.82% | Binary |
| DT [37] | NSL-KDD | MFO | 89.70% | Binary |
| This Work | CIC-IDS2017 NSL-KDD ToN-IoT Phishing Detection | FRI-ARO | 99.90% 98.10% 100.00% 96.00% | Binary |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the author. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Almseidin, M. Enhancing the Artificial Rabbit Optimizer Using Fuzzy Rule Interpolation. Big Data Cogn. Comput. 2026, 10, 57. https://doi.org/10.3390/bdcc10020057
Almseidin M. Enhancing the Artificial Rabbit Optimizer Using Fuzzy Rule Interpolation. Big Data and Cognitive Computing. 2026; 10(2):57. https://doi.org/10.3390/bdcc10020057
Chicago/Turabian StyleAlmseidin, Mohammad. 2026. "Enhancing the Artificial Rabbit Optimizer Using Fuzzy Rule Interpolation" Big Data and Cognitive Computing 10, no. 2: 57. https://doi.org/10.3390/bdcc10020057
APA StyleAlmseidin, M. (2026). Enhancing the Artificial Rabbit Optimizer Using Fuzzy Rule Interpolation. Big Data and Cognitive Computing, 10(2), 57. https://doi.org/10.3390/bdcc10020057

