Home / Current Issue / Paper 1716588
A Comparative Evaluation of Optimized Machine Learning Classifiers for Network Intrusion Detection: Random Forest, K-Nearest Neighbors, and Support Vector Machine Approaches
Subject area: Science,Engineering and Technology · Area of research: Artificial Intelligence, Cyber-security, ML
DOI: https://doi.org/10.64388/IREV9I10-1716588
Abstract
The proliferation of sophisticated cyber threats necessitates intelligent intrusion detection systems (IDS) capable of accurately distinguishing between normal and anomalous network traffic. This study presents a comparative evaluation of three optimized machine learning classifiers, Random Forest (RF), K-Nearest Neighbors (KNN), and Support Vector Machine (SVM), for binary network intrusion detection. The methodology integrates Recursive Feature Elimination (RFE) for dimensionality reduction, selecting 10 discriminative features, and Bayesian hyperparameter optimization using the Optuna framework. Models were trained and evaluated on the KDD Cup 1999 dataset with a 70/30 stratified split. Results demonstrate that RF achieved the highest performance (accuracy: 99.62%, F1-score: 99.59%), followed by KNN (accuracy: 98.25%, F1-score: 98.11%) and SVM (accuracy: 95.82%, F1-score: 95.46%). Ten-fold stratified cross-validation confirmed the robustness of these findings (RF: 99.64% ± 0.12%, KNN: 98.41% ± 0.16%, SVM: 96.10% ± 0.30%). McNemar’s test established that all pairwise performance differences are statistically significant (p < 0.001). Computational cost analysis revealed that RF offers the best accuracy-efficiency balance, with training in 0.098s and prediction in 0.0025s. A Streamlit-based web application was developed for real-time inference. The findings underscore the efficacy of combining automated feature selection with Bayesian optimization for high-performance IDS.
Keywords
Intrusion Detection System, Machine Learning, Recursive Feature Elimination, Bayesian Optimization, Network Security.
References
[1] I. H. Sarker, A. S. M. Kayes, and P. Watters, "Effectiveness analysis of machine learning classification models for predicting cybersecurity attacks," J. Big Data, vol. 11, p. 45, 2024.
[2] Z. Ahmad, A. S. Khan, C. W. Shiang, J. Abdullah, and F. Ahmad, "Network intrusion detection system: A systematic study of machine learning and deep learning approaches," Trans. Emerg. Telecommun. Technol., vol. 34, no. 1, p. e4150, 2023.
[3] A. Khraisat and A. Alazab, "A critical review of intrusion detection systems in the Internet of Things: Techniques, deployment strategy, validation strategy, attacks, public datasets, and challenges," Cybersecurity, vol. 6, no. 1, pp. 1– 28, 2023.
[4] A. Geron, Hands-On Machine Learning with Scikit-Learn, Keras, and TensorFlow, 3rd ed. Sebastopol, CA: O'Reilly Media, 2023.
[5] A. Thakkar and R. Lohiya, "Role of feature selection in optimizing machine learning-based intrusion detection systems: A comprehensive review," Arch. Comput. Methods Eng., vol. 31, no. 2, pp. 1027–1058, 2024.
[6] B. Bischl et al., "Hyperparameter optimization: Foundations, algorithms, best practices, and open challenges," Wiley Interdiscip. Rev. Data Min. Knowl. Discov., vol. 13, no. 2, p. e1484, 2023.
[7] K. A. Dhanya and S. Mathew, "A comparative study of ensemble classifiers for intrusion detection," J. Inf. Secur. Appl., vol. 76, p. 103539, 2024.
[8] E. E. Abdallah and A. F. Otoom, "A comparative evaluation of supervised machine learning classifiers for network intrusion detection," Int. J. Inf. Secur., vol. 23, no. 1, pp. 537–552, 2024.
[9] A. Halbouni, T. S. Guntur, D. T. C. Lai, and N. K. Kasabov, "Machine learning and deep learning approaches for intrusion detection: A comparative study," Inf. Sci., vol. 659, p. 120107, 2024.
[10] P. Devan and N. Khare, "An efficient ensemble- based intrusion detection approach using optimized tree-based classifiers for real-time network traffic classification," Neural Comput. Appl., vol. 36, no. 8, pp. 4023–4037, 2024.
[11] N. Moustafa, G. Creech, and J. Slay, "A comparative study of feature selection methods for network intrusion detection," Comput. Electr. Eng., vol. 106, p. 108582, 2023.
[12] R. Panigrahi and S. Borah, "A hybrid feature selection approach for network intrusion detection using mutual information and recursive feature elimination," Expert Syst. Appl., vol. 238, p. 121876, 2024.
[13] A. Singh and D. Kumar, "Evolutionary feature selection for intrusion detection systems: A genetic algorithm approach," Swarm Evol. Comput., vol. 78, p. 101274, 2023.
[14] A. Ogunleye, S. Misra, and R. Damaševičius, "Bayesian hyperparameter optimization for ensemble methods in intrusion detection," Appl. Soft Comput., vol. 152, p. 111234, 2024.
[15] L. Yang, A. Moubayed, and A. Shami, "MTH- IDS: A multitiered hybrid intrusion detection system for Internet of Vehicles," IEEE Internet Things J., vol. 10, no. 1, pp. 616–630, 2023.
[16] M. Tavallaee, E. Bagheri, W. Lu, and A. A. Ghorbani, "A detailed analysis of the KDD CUP 99 data set," in Proc. IEEE Symp. Comput. Intell. Secur. Def. Appl., 2009, pp. 1–6.
How to cite this paper
@article{1716588,
author = {Oyeladun Bukola Makinde, Adedoyin Simeon Adeyemi, Najeem Oladokun Lawal, Adekunle Joseph Adewale, Olufemi Oriola Anifowose; Suzie Musa Isaac},
title = {A Comparative Evaluation of Optimized Machine Learning Classifiers for Network Intrusion Detection: Random Forest, K-Nearest Neighbors, and Support Vector Machine Approaches},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {9},
number = {10},
pages = {4179-4189},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1716588.pdf},
abstract = {The proliferation of sophisticated cyber threats necessitates intelligent intrusion detection systems (IDS) capable of accurately distinguishing between normal and anomalous network traffic. This study presents a comparative evaluation of three optimized machine learning classifiers, Random Forest (RF), K-Nearest Neighbors (KNN), and Support Vector Machine (SVM), for binary network intrusion detection. The methodology integrates Recursive Feature Elimination (RFE) for dimensionality reduction, selecting 10 discriminative features, and Bayesian hyperparameter optimization using the Optuna framework. Models were trained and evaluated on the KDD Cup 1999 dataset with a 70/30 stratified split. Results demonstrate that RF achieved the highest performance (accuracy: 99.62%, F1-score: 99.59%), followed by KNN (accuracy: 98.25%, F1-score: 98.11%) and SVM (accuracy: 95.82%, F1-score: 95.46%). Ten-fold stratified cross-validation confirmed the robustness of these findings (RF: 99.64% ± 0.12%, KNN: 98.41% ± 0.16%, SVM: 96.10% ± 0.30%). McNemar’s test established that all pairwise performance differences are statistically significant (p < 0.001). Computational cost analysis revealed that RF offers the best accuracy-efficiency balance, with training in 0.098s and prediction in 0.0025s. A Streamlit-based web application was developed for real-time inference. The findings underscore the efficacy of combining automated feature selection with Bayesian optimization for high-performance IDS.},
keywords = {Intrusion Detection System, Machine Learning, Recursive Feature Elimination, Bayesian Optimization, Network Security.},
month = {April},
doi = {https://doi.org/10.64388/IREV9I10-1716588}
}