CORTEXA
← Browse
crossrefApplied Sciences2025-07-30Cited by 3

The Choice of Training Data and the Generalizability of Machine Learning Models for Network Intrusion Detection Systems

Marcin Iwanowski, Dominik Olszewski, Waldemar Graniszewski, Jacek Krupski, Franciszek Pelc

Network Intrusion Detection Systems (NIDS) driven by Machine Learning (ML) algorithms are usually trained using publicly available datasets consisting of labeled traffic samples, where labels refer to traffic classes, usually one benign and multiple harmful. This paper studies the generalizability of models trained on such datasets. This issue is crucial given the application of such a model to actual internet traffic because high-performance measures obtained on datasets do not necessarily imply similar efficiency on the real traffic. We propose a procedure consisting of cross-validation using various sets sharing some standard traffic classes combined with the t-SNE visualization. We apply it to investigate four well-known and widely used datasets: UNSW-NB15, CIC-CSE-IDS2018, BoT-IoT, and ToN-IoT. Our investigation reveals that the high accuracy of a model obtained on one set used for training is reproducible on others only to a limited extent. Moreover, benign traffic classes’ generalizability differs from harmful traffic. Given its application in the actual network environment, it implies that one needs to select the data used to train the ML model carefully to determine to what extent the classes present in the dataset used for training are similar to those in the real target traffic environment. On the other hand, merging datasets may result in more exhaustive data collection, consisting of a more diverse spectrum of training samples.

View free PDFSource page

Related papers

crossrefApplied Sciences2025-09-30Cited by 3

Robustness of Machine Learning and Deep Learning Models for Power Quality Disturbance Classification: A Cross-Platform Analysis

José Carlos Palomares-Salas, Sergio Aguado-González, José María Sierra-Fernández

Accurate and robust power quality disturbance (PQD) classification is critical for modern electrical grids, particularly in noisy environments. This study presents a comprehensive comparative evaluation of machine learning (ML) and deep learning (DL) models for automatic PQD iden…

View free PDFSource page
crossrefApplied Sciences2026-02-28

Comparative Analysis of Machine Learning and Deep Learning Models for Atrial Fibrillation Detection from Long-Term ECG

Lerina Aversano, Ilaria Mancino, Agostino Marengo, Chiara Verdone

Atrial fibrillation is the most prevalent sustained cardiac arrhythmia and a major risk factor for stroke, heart failure, and premature mortality. Automatic detection remains challenging due to the variability of electrocardiogram (ECG) morphology, noise, and the paroxysmal natur…

View free PDFSource page
crossrefApplied Sciences2026-03-17

A Study on Machine Learning-Based Cost Estimation Models for AI Training Data Construction

Yoon-Seok Ko, Bong Gyou Lee

This study proposes an explainable machine learning framework for estimating the total project cost (TPC) of AI training-data construction, where cost information is difficult to structure due to heterogeneous workflows and quality requirements. Using 386 public AI training-data…

View free PDFSource page
crossrefApplied Sciences2026-06-19

Impact of Network Topology on Machine Learning-Based DDoS and Anomaly Detection in Software-Defined Networks

Łukasz Bakuła, Andrzej Jasinski

The development of Software-Defined Networks (SDNs) introduces new challenges in network security, particularly in detecting Distributed Denial of Service (DDoS) attacks and network anomalies. Due to the centralized architecture of SDN, traditional detection methods are often ins…

View free PDFSource page
crossrefApplied Sciences2026-07-18

Rigorous Evaluation of Machine Learning Intrusion Detection for Water Treatment Systems on SWaT Network Traffic

Sebastian Mesca, Emil Pricop, Grigore Stamatescu

Intrusion detection systems (IDSs) for industrial control networks are commonly evaluated using random stratified splits, placing rows from every recorded attack in both training and test sets. Although convenient, this practice measures a model’s ability to recognise repetitions…

View free PDFSource page
crossrefApplied Sciences2025-09-15Cited by 10

Malicious URL Detection with Advanced Machine Learning and Optimization-Supported Deep Learning Models

Fuat Türk, Mahmut Kılıçaslan

This study presents a comprehensive comparative analysis of machine learning, deep learning, and optimization-based hybrid methods for malicious URL detection on the Malicious Phish dataset. For feature selection and model hyperparameter tuning, the Genetic Algorithm (GA), Partic…

View free PDFSource page