Network intrusion detection using artificial intelligence

Abstract

i newlineABSTRACT newlineThe rapid growth of digital infrastructure, driven by internet-connected devices, cloud services, and online systems, has significantly increased the attack surface for malicious actors. This surge in network activity has led to a corresponding rise in cyberattacks such as denial-of-service (DoS), ransomware, and advanced persistent threats (APT), making network security a major concern. Traditional Intrusion Detection Systems (IDS) often fail to detect novel or rare attack types and struggle with challenges such as class imbalance in training datasets, redundant features, and limited adaptability to evolving threats. These limitations highlight the need for intelligent and adaptive solutions capable of handling dynamic and imbalanced network environments. newlineThis research focuses on Network Intrusion Detection Systems (NIDS) and proposes reinforcement learning (RL) based frameworks designed to improve detection performance, particularly for underrepresented attack classes. A detailed analysis and pre-processing of three benchmark datasets (i.e. NSL-KDD, UNSW-NB15, and AWID) were performed to ensure data quality and compatibility with AI models. Techniques such as feature encoding, outlier removal, and distribution normalization were applied to enhance training reliability. To improve computational efficiency without compromising detection accuracy, feature selection was carried out using various methods, including correlation-based filtering, information gain, and Recursive Feature Elimination (RFE). RFE achieved the best results on the NSL-KDD dataset, reducing the feature set by 40% while maintaining high performance with 99.12% accuracy and a 99.2% F1-score. newlineTwo novel RL-based frameworks were proposed to address the challenge of class imbalance. The first, Dual Replay Memory Reinforcement Learning (DRM-RL), introduces a dual-memory structure that stores experiences separately for majority and minority attack classes. This design improves learning for rare attack types such as Remote to Local (R2L) and

Description

Keywords

Citation

item.page.endorsement

item.page.review

item.page.supplemented

item.page.referenced