Network Attack Detection Using Machine Learning, Deep Learning, and Autonomous Defense Agents

Authors

DOI:

https://doi.org/10.71229/anc3s258

Keywords:

AI-based cyberattacks , Autonomous Defense , LSTM , XGBoost , CIC-IoT 2023 , UNSW-NB15

Abstract

AI-driven cyberattacks represent major challenges to detect by classic security frameworks, which makes it important to employ intelligent and autonomous mechanisms. In this paper, we present a data-driven analysis of network attack detection and reduction using machine learning, deep learning, and an Autonomous Defense Agent (ADA) for real-time threat detection and response. Experiments are done on two benchmark datasets CIC-IoT 2023 and UNSW-NB15 datasets, representing network intrusion scenarios. We addressed the imbalance in the dataset CIC-IoT 2023 with a 1:41 benign-to-attack skewed ratio by applying the Synthetic Minority Over-sampling Technique (SMOTE) to the training set. For classification progress, we used four classical ML classifiers (Decision Tree, Random Forest, XGBoost, and KNN), and also an LSTM model. Furthermore, we designed an Autonomous Defense Agent (ADA) for real-time intrusion detection. The highest F1 achieved for Random Forest is 99.39% on CIC-IoT 2023 and 88.67% on UNSW-NB15. For XGBoost, the same accuracy was achieved with 12 times faster training speed. This makes it the preferred ADA backbone. LSTM outperforms on structured IoT traffic with F1=98.82%, but on the other hand, fails on heterogeneous traffic with F1=43.29%. This shows how data temporal characteristics affect model selection. The ADA achieves 99.94% precision on CIC-IoT 2023 with sub-1ms average response latency. The results provide a principled model selection criterion that prefers the classical ML methods for heterogeneous traffic and LSTM for temporally structured IoT traffic, and also provides an ADA design to validate real benchmark datasets.

References

[1] I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, “Toward generating a new intrusion detection dataset and intrusion traffic characterization”, in Proc. Int. Conf. Information Systems Security and Privacy (ICISSP), 2018, pp. 108–116. DOI: https://doi.org/10.5220/0006639801080116

[2] M. Al-Hawawreh, M. Moustafa, and A. Sitnikova, “An autonomous intrusion detection system using an ensemble of advanced learners”, Future Generation Computer Systems, vol. 102, pp. 541–552, 2020.

[3] I. S. Thaseen and C. A. Kumar, “Building an efficient intrusion detection system based on feature selection and ensemble classifier”, Computer Networks, vol. 174, 2020, Art. no. 107247. DOI: https://doi.org/10.1016/j.comnet.2020.107247

[4] Y. Gao, “Cyber attacks and defense: AI-driven approaches and techniques”, Academic Journal of Computing & Information Science, vol. 7, no. 7, pp. 41–46, 2024. DOI: https://doi.org/10.25236/AJCIS.2024.070706

[5] Y. Chen, C. Zhang, and Z. Wang, Deep “Q-learning based intrusion detection system”, IEEE Access, vol. 7, pp. 77714–77724, 2019.

[6] T. T. Nguyen and V. J. Reddi, “Deep reinforcement learning for cyber security”, IEEE Security & Privacy Workshops (SPW), 2019, pp. 1–8.

[7] N. Moustafa and J. Slay, “Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study”, Journal of Information Security and Applications, vol. 50, 2020. DOI: https://doi.org/10.1016/j.jisa.2019.102419

[8] A. Alsheikh, S. Lin, D. Niyato, and H. Tan, “Enhancing intrusion detection systems with reinforcement learning: A comprehensive survey”, IEEE Communications Surveys & Tutorials, vol. 23, no. 2, pp. 1–30, 2021.

[9] Y. Mirsky, T. Doitshman, Y. Elovici, and A. Shabtai, “Kitsune: An ensemble of autoencoders for online network intrusion detection”, in Proc. Network and Distributed System Security Symposium (NDSS), 2018. doi: 10.14722/ndss.2018.23204. DOI: https://doi.org/10.14722/ndss.2018.23204

[10] S. Sarker, Y. Abushark, and A. I. Khan, “Study of artificial intelligence in cyber security”, International Journal of Advanced Computer Science and Applications, vol. 11, no. 9, 2020.

[11] A. B. M. Alim Al Islam et al., “The emerging threat of AI-driven cyber attacks: A review”, Journal of Cybersecurity and Privacy, vol. 3, no. 4, pp. 1–20, 2023.

[12] M. Javaid, A. Haleem, R. P. Singh, and R. Suman, “Utilising deep learning techniques for effective zero-day attack detection”, IEEE Access, vol. 8, pp. 177583–177593, 2020.

[13] X. Zhang, J. Liu, and Y. Chen, “Adaptive deception framework with behavioral analysis for cyber defense”, IEEE Transactions on Information Forensics and Security, 2024.

[14] V. Mnih et al., “Human-level control through deep reinforcement learning”, Nature, vol. 518, pp. 529–533, 2015. DOI: https://doi.org/10.1038/nature14236

[15] MITRE Corporation, ATT&CK for Enterprise, MITRE ATT&CK Knowledge Base, 2024. [Online]. Available: https://attack.mitre.org

[16] E. C. P. Neto et al., “CICIoT2023: A real-time dataset and benchmark for large-scale attacks” in IoT environment, Sensors, vol. 23, no. 13, p. 5941, 2023. DOI: https://doi.org/10.3390/s23135941

[17] N. Moustafa and J. Slay, U”NSW-NB15: A comprehensive data set for network intrusion detection systems”, in Proc. Military Communications and Information Systems Conf. (MilCIS), 2015, pp. 1–6. DOI: https://doi.org/10.1109/MilCIS.2015.7348942

[18] T. Chen and C. Guestrin, “XGBoost: A scalable tree boosting system”, in Proc. ACM SIGKDD Int. Conf. Knowledge Discovery and Data Mining, 2016, pp. 785–794. DOI: https://doi.org/10.1145/2939672.2939785

[19] A. Shiravi, H. Shiravi, M. Tavallaee, and A. A. Ghorbani, “Toward developing a systematic approach to generate benchmark datasets for intrusion detection”, Computers & Security, vol. 31, no. 3, 2012. DOI: https://doi.org/10.1016/j.cose.2011.12.012

[20] B. Biggio and F. Roli, “Wild patterns: Ten years after the rise of adversarial machine learning”, Pattern Recognition, vol. 84, pp. 317–331, 2018. DOI: https://doi.org/10.1016/j.patcog.2018.07.023

[21] A. Shabtai et al., “Detecting unknown malicious code by applying classification techniques on OpCode patterns”, Security Informatics, vol. 1, no. 1, 2012. DOI: https://doi.org/10.1186/2190-8532-1-1

fig 3

Downloads

Published

2026-08-24

Issue

Section

Original Articles

How to Cite

Network Attack Detection Using Machine Learning, Deep Learning, and Autonomous Defense Agents. (2026). Al-Noor Journal of Engineering Management and Computer Science, 2(3), 509-517. https://doi.org/10.71229/anc3s258

Similar Articles

11-20 of 69

You may also start an advanced similarity search for this article.