Skip to content
Open access

Explainable Machine Learning for DDoS Attack Detection with Physical Network Validation

Aug 2026 · Journal of Computer Science Application and Engineering (JOSAPEN) · 0 citations · 26 references

TL;DR

This study evaluates two explainable ML classifiers, XGBoost and Random Forest, for DDoS detection and examines whether their near-perfect offline accuracy translates into reliable physical-network operation, indicating that offline benchmarks alone are insufficient for validating IDS readiness.

Abstract

Distributed Denial-of-Service (DDoS) attacks remain one of the most disruptive threats to network infrastructure, yet many machine learning (ML)-based detection studies report only offline benchmark performance without verifying whether that performance holds under real network conditions. This study evaluates two explainable ML classifiers, XGBoost and Random Forest, for DDoS detection and examines whether their near-perfect offline accuracy translates into reliable physical-network operation. The study combines offline benchmarking on the CIC-DDoS2019 dataset (293,485 flows) with physical-network validation using a working Intrusion Detection System (IDS) prototype under a controlled SYN-flood attack. Session-disjoint stratified sampling prevented flow-level leakage across attack sessions, while SHapley Additive exPlanations (SHAP) interpreted global and local feature importance. Offline, both classifiers achieved near-perfect performance (accuracy 99.99% for XGBoost, 99.98% for Random Forest; F1 = 0.9999; ROC-AUC up to 1.0000), with no statistically significant difference between them (McNemar's exact test, p = 0.2188), though XGBoost achieved approximately 3.69 times higher inference throughput (1,819,816 flows/s). SHAP identified Min Packet Length, Fwd Packet Length Min, Inbound, Protocol, and Init_Win_bytes_forward as the most influential features. In physical deployment, however, the IDS prototype flagged 6.26% of captured flows (6,935 of 110,762) as ATTACK during the SYN-flood test, and a separate 397-flow ambient-benign subset yielded a 6.80% false positive rate (95% Wilson CI: 4.72–9.71%), with short-duration SSDP/UPnP-style UDP control traffic accounting for 70% of observed false positives. This gap shows that near-perfect offline accuracy does not guarantee low false positives in real deployment, indicating that offline benchmarks alone are insufficient for validating IDS readiness.

Read PDF

Similar papers

Open access Aug 2026

Intelligent DDOS Attack Detection and Mitigation Using Machine Learning Techniques

An intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies is presented.

S. Singh, Alok Kumar · 0 citations
#software testing Open access Sep 2026

Intelligent DDoS Attack Detection in Software-Defined Networks Using Explainable Machine Learning

An explainable machine learning-based framework for accurate, transparent, and reliable DDoS attack detection in an SDN environment that combines reliable DDoS detection with transparent, analyst-oriented decision support for SDN security monitoring is developed.

J. Malik, N. Naz, Muhammad Saleem et al. · 0 citations
Open access Aug 2026

Mitigation of DDoS Attacks in the Data Plane of Software-Defined Networking Using ML Techniques

Distributed Denial-of-Service (DDoS) attacks remain one of the most significant cyber threats faced by Software-Defined Networking (SDN) architectures, essentially because of the salient decoupling of the control and data planes. This study examines the implications of DDoS attacks on the SDN data plane and evaluates t...

Kamal Singh, Brijesh Kumar · 0 citations

Real-time detection of cryptographic key misuse in software-defined networks using incremental learning

An incremental learning based framework to detect anomalous traffic patterns which may indicate any key misuse in Software-Defined Networks in dynamic and real-time environments in modern SDN environments is proposed.

Gineeth Rajeshkhanna, Tamilarasi Kathirvel Murugan, Logeswari Govindaraj et al. · 0 citations
#machine learning Preprint Sep 2026

Unmasking Shortcut Learning in IoT Intrusion Detection: A Forensic, Multi-Paradigm Evaluation of Feature Dependence and Data Leakage

Machine learning-based Network Intrusion Detection Systems often report near-perfect performance on IoT benchmarks. However, whether these models learn generalizable attack behavior or exploit spurious dataset shortcuts- such as static testbed IP/MAC addresses and chronological recording artifacts-remains an important...

Uday Shankar Roy, Mahbuba Jahan Minu · 0 citations
Open access Sep 2026

Real-Traffic Enrichment for Improved Minority Web Attack Detection in Network Intrusion Detection

This study enriches CICIDS2017 with authentic SQL Injection, Cross-Site Scripting (XSS), and Web Brute Force (WBF) traffic captured from a controlled DVWA/XAMPP environment, processed with CICFlowMeter to match the original feature space.

Zeyneb Berkat, Amina Fatima Zahra Yahiaoui, Mahfoud Aliouat et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.