CORTEXA
← Browse
openalexFuture Internet2026-07-23Cited by 0

AutoML for Network-Based Intrusion Detection: Evaluation Practice, Dataset Quality, and Deployment Constraints

Abdulla Amin Aburomman, Mamun Bin Ibne Reaz

Machine learning techniques for network-based intrusion detection systems (NIDS) have advanced considerably over the past decade. Still, improvements are inhibited by handcrafted feature pipelines, isolated public benchmark data, and evaluation procedures that do not reflect real-life deployment. AutoML, a branch of ML automating model selection, automated architecture search, and the creation of model pipelines, may help overcome these shortcomings. While numerous NIDS applications employing automated ML techniques have been proposed, and recent surveys have mapped the AutoML framework landscape for network intrusion detection, no existing review critically audits the evaluation practice of this literature: the quality of its benchmark datasets, the reproducibility of its reported results, and the realism of its deployment assumptions. This paper critically reviews 26 research works published between January 2023 and June 2026, collected via a two-phase structured search: a documented keyword search across five databases (Scopus, IEEE Xplore, Web of Science, ACM Digital Library, and Google Scholar), followed by full-text eligibility screening, citation chaining, and expert evaluation. Findings drawn from this collection capture trends observed among the selected studies, rather than reflecting the broader state of the field. Analysis of the corpus reveals that 88% of dataset-verified studies evaluate exclusively or partly on the legacy benchmark family (KDD-derived, CICIDS, UNSW-NB15, CIDDS), 21% evaluate on a single dataset only, and among attribute-verified studies only 32% release source code, 40% report statistical significance testing, and 36% include variance analysis, findings that collectively motivate the four contributions of this study. First, a recommended evaluation framework is proposed, addressing baseline parity, transparent search-space and budget reporting, nested cross-validation for selection-bias control, and stability reporting across multiple random seeds. Second, a dataset quality scoring framework is introduced, assessing five dimensions: overlap rate, duplication rate, label correctness, attack-type representativeness, and coverage of benign, IoT, and IIoT traffic. Third, a cross-domain justification is provided for neural architecture search (NAS) and meta-learning in NIDS, grounded in advances in federated NAS, out-of-distribution robustness, edge-constrained search cost reduction, and few-shot adaptation. Fourth, a structured research roadmap is outlined, targeting real-world validation, standardized benchmarks, curated datasets, resource-aware AutoML, and privacy-preserving federated NAS. In contrast to prior surveys of AutoML for network intrusion detection, which map frameworks and computational paradigms, this review contributes a formalized evaluation checklist, an explicit and partially empirically validated dataset quality scoring scheme, and evidence-based methodological guidance grounded in a transparent, fully enumerated study corpus.

View free PDFSource page

Related papers

crossrefFuture Internet2020-09-30Cited by 101

Comparison of Machine Learning and Deep Learning Models for Network Intrusion Detection Systems

Niraj Thapa, Zhipeng Liu, Dukka B. KC, Balakrishna Gokaraju, Kaushik Roy

The development of robust anomaly-based network detection systems, which are preferred over static signal-based network intrusion, is vital for cybersecurity. The development of a flexible and dynamic security system is required to tackle the new attacks. Current intrusion detect…

View free PDFSource page
crossrefFuture Internet2026-04-27Cited by 1

Enhancing Network Intrusion Detection with Quantum Machine Learning: A Comprehensive Survey of Methods, Metrics, and Applications

Antanios Kaissar, Ali Bou Nassif, Ahmed Bouridane

Quantum computing introduces new computational capabilities that can support advanced cybersecurity solutions when combined with machine learning. In recent years, quantum machine learning (QML) has emerged as a promising approach for enhancing network intrusion detection systems…

View free PDFSource page
crossrefFuture Internet2021-04-28Cited by 260

Designing a Network Intrusion Detection System Based on Machine Learning for Software Defined Networks

Abdulsalam O. Alzahrani, Mohammed J. F. Alenazi

Software-defined Networking (SDN) has recently developed and been put forward as a promising and encouraging solution for future internet architecture. Managed, the centralized and controlled network has become more flexible and visible using SDN. On the other hand, these advanta…

View free PDFSource page
crossrefFuture Internet2026-02-21Cited by 4

Machine Learning-Driven Intrusion Detection for Securing IoT-Based Wireless Sensor Networks

Yirga Yayeh Munaye, Abebaw Demelash Gebeyehu, Li-Chia Tai, Zemenu Alem Abebe, Aeneas Bekele Workneh, Robel Berie Tarekegn, et al.

Wireless sensor networks (WSNs) have become a critical component of modern Internet of Things (IoT) infrastructures; however, their constrained resources and distributed deployment expose them to various cyber threats. In this work, we present a machine learning-driven intrusion…

View free PDFSource page
crossrefFuture Internet2024-06-05Cited by 34

Implementation of Lightweight Machine Learning-Based Intrusion Detection System on IoT Devices of Smart Homes

Abbas Javed, Amna Ehtsham, Muhammad Jawad, Muhammad Naeem Awais, Ayyaz-ul-Haq Qureshi, Hadi Larijani

Smart home devices, also known as IoT devices, provide significant convenience; however, they also present opportunities for attackers to jeopardize homeowners’ security and privacy. Securing these IoT devices is a formidable challenge because of their limited computational resou…

View free PDFSource page
crossrefFuture Internet2023-07-26Cited by 17

Intelligent Caching with Graph Neural Network-Based Deep Reinforcement Learning on SDN-Based ICN

Jiacheng Hou, Tianhao Tao, Haoye Lu, Amiya Nayak

Information-centric networking (ICN) has gained significant attention due to its in-network caching and named-based routing capabilities. Caching plays a crucial role in managing the increasing network traffic and improving the content delivery efficiency. However, caching faces…

View free PDFSource page