electronics-logo

Journal Browser

Journal Browser

Advanced Technologies in Intrusion Detection System

A special issue of Electronics (ISSN 2079-9292). This special issue belongs to the section "Computer Science & Engineering".

Deadline for manuscript submissions: 15 August 2026 | Viewed by 883

Editors


E-Mail Website
Guest Editor
Computing Center, Institute of High Energy Physics, Chinese Academy of Sciences, Beijing 100049, China
Interests: computing; network and cybersecurity; intrusion detection

E-Mail Website
Guest Editor
Computing Center, Institute of High Energy Physics, Chinese Academy of Sciences, Beijing 100049, China
Interests: cybersecurity; intrusion detection; anomaly detection

Special Issue Information

Dear Colleagues,

In the contemporary digital landscape, Intrusion Detection Systems (IDSs) constitute a critical component of modern cybersecurity architectures, whose core function lies in monitoring network traffic and system activities to identify potential breaches and malicious behaviors.

Though there has been significant advancement in this area, traditional IDS approaches are often insufficient to cope with sophisticated attack techniques. The primary reasons that have been identified in the literature are (a) high false positive rates; (b) poor detection efficacy for unknown or dynamically changing threats; (c) difficulties in maintaining scalability and real-time performance; (d) inability to identify traffic patterns in encrypted communications; (e) limited interpretability of ML/AI-driven IDS; (f) insufficient robustness against evasion techniques.

The objective of this Special Issue is to explore advanced technologies for advancing IDS, with a focus on improving detection accuracy, reducing false-positive rates, and expanding the capacity to identify a broad spectrum of cyber threats. Emerging advanced technologies such as artificial intelligence (AI), deep learning, distributed architectures, blockchain technology are reshaping the conceptualization and practical implementation of information security. These approaches offer not only enhanced accuracy and robustness but also scalability, adaptability, and resilience across diverse, resource-limited environments.

We invite high-quality, original research papers and review articles addressing topics including, but not limited to, the following:

  • ML and AI-enhanced intrusion detection;
  • Distributed and collaborative intrusion detection;
  • Privacy-preserving intrusion detection;
  • Deep learning architectures for anomaly detection;
  • Creation and use of benchmark datasets for intrusion detection;
  • Real-time and scalable intrusion detection;
  • Blockchain for intrusion detection;
  • Intrusion detection in industrial control systems, IoT and cloud environments;
  • Intrusion detection in resource-constrained environments.

Prof. Dr. Fazhi Qi
Dr. Jiarong Wang
Guest Editors

Manuscript Submission Information

Manuscripts should be submitted online at www.mdpi.com by registering and logging in to this website. Once you are registered, click here to go to the submission form. Manuscripts can be submitted until the deadline. All submissions that pass pre-check are peer-reviewed. Accepted papers will be published continuously in the journal (as soon as accepted) and will be listed together on the special issue website. Research articles, review articles as well as short communications are invited. For planned papers, a title and short abstract (about 250 words) can be sent to the Editorial Office for assessment.

Submitted manuscripts should not have been published previously, nor be under consideration for publication elsewhere (except conference proceedings papers). All manuscripts are thoroughly refereed through a single-anonymized peer-review process. A guide for authors and other relevant information for submission of manuscripts is available on the Instructions for Authors page. Electronics is an international peer-reviewed open access semimonthly journal published by MDPI.

Please visit the Instructions for Authors page before submitting a manuscript. The Article Processing Charge (APC) for publication in this open access journal is 2400 CHF (Swiss Francs). Submitted papers should be well formatted and use good English. Authors may use MDPI's English editing service prior to publication or during author revisions.

Keywords

  • intrusion detection systems
  • cybersecurity
  • data security
  • machine learning
  • artificial intelligence
  • anomaly detection
  • industrial control systems
  • IoT
  • cloud environments
  • blockchain

Benefits of Publishing in a Special Issue

  • Ease of navigation: Grouping papers by topic helps scholars navigate broad scope journals more efficiently.
  • Greater discoverability: Special Issues support the reach and impact of scientific research. Articles in Special Issues are more discoverable and cited more frequently.
  • Expansion of research network: Special Issues facilitate connections among authors, fostering scientific collaborations.
  • External promotion: Articles in Special Issues are often promoted through the journal's social media, increasing their visibility.
  • Reprint: MDPI Books provides the opportunity to republish successful Special Issues in book format, both online and in print.

Further information on MDPI's Special Issue policies can be found here.

Published Papers (1 paper)

Order results
Result details
Select all
Export citation of selected articles as:

Research

33 pages, 3199 KB  
Article
From Detection to Triage: Explainable Suspicious Flow Prioritization for Multiclass Intrusion Detection Using CSE-CIC-IDS2018
by Marija Gombar
Electronics 2026, 15(12), 2739; https://doi.org/10.3390/electronics15122739 - 22 Jun 2026
Viewed by 379
Abstract
Intrusion detection systems (IDSs) are commonly evaluated through aggregate classification metrics, although operational workflows require detected flows to be interpreted, prioritized, and transformed into actionable evidence. This study proposes a detection-to-triage framework for multiclass intrusion detection using a CSE-CIC-IDS2018-derived experimental subset containing 213,463 [...] Read more.
Intrusion detection systems (IDSs) are commonly evaluated through aggregate classification metrics, although operational workflows require detected flows to be interpreted, prioritized, and transformed into actionable evidence. This study proposes a detection-to-triage framework for multiclass intrusion detection using a CSE-CIC-IDS2018-derived experimental subset containing 213,463 records across one benign class and fourteen attack classes. The framework combines supervised multiclass classification, SHAP-style post hoc explanation, class-specific false positive analysis, and a Suspicious Flow Priority Score (SFPS) for analyst-oriented suspicious flow ranking. The practical role of SFPS is to reorder suspicious flows by combining model confidence, explanation strength, predefined attack severity, and validation-based false positive control, thereby producing a transparent triage list rather than a probability-only alert queue. Three detection backbones were evaluated under a shared preprocessing protocol: Random Forest, XGBoost, and a lightweight multilayer perceptron baseline. To assess stability, experiments were repeated across five random seeds. XGBoost achieved the strongest mean performance across most aggregate indicators, with an accuracy of 0.9494 ± 0.0011, a macro F1-score of 0.8366 ± 0.0193, a weighted F1-score of 0.9494 ± 0.0011, and a Matthews Correlation Coefficient of 0.9429 ± 0.0012. Random Forest produced closely comparable results, while the lightweight MLP remained lower on aggregate and macro-level indicators. False positive analysis showed that the alert burden was concentrated in selected classes and differed across models, confirming that aggregate performance alone is insufficient for assessing IDS usefulness. SHAP-style analysis identified stable flow-level contributors to XGBoost discrimination, while SFPS substantially changed the post-detection ordering of suspicious flows compared with probability-only ranking. The study does not claim universal state-of-the-art superiority, causal explanation, or deployment validation; instead, it demonstrates how multiclass IDS outputs can be extended into explainable, false positive-aware, and triage-oriented rankings for analyst review. Full article
(This article belongs to the Special Issue Advanced Technologies in Intrusion Detection System)
Show Figures

Figure 1

Back to TopTop