Skip to content
Open access

Adaptive hybrid ensemble-based DDoS detection using reinforcement learning-guided optimization and deep learning

Aug 2026 · International Journal of Advances in Intelligent Informatics · Vol 12, pp. 650 · 0 citations · 39 references

TL;DR

An adaptive hybrid ensemble that unifies two gradient-boosting learners with three deep neural base learners under a weighted soft-voting rule whose weights are produced by a Reinforcement Learning (RL) policy is proposed.

Abstract

Distributed Denial-of-Service (DDoS) attacks remain among the most disruptive network threats, and detectors that generalize across attack families with low false-alarm rates are still an open problem. Propose an adaptive hybrid ensemble that unifies two gradient-boosting learners (Random Forest and Gradient Boosting) with three deep neural base learners (DNN, CNN-1D, and LSTM) under a weighted soft-voting rule whose weights are produced by a Reinforcement Learning (RL) policy. The RL agent treats the ensemble-weight simplex as its action space, observes a state vector built from validation-set diagnostic statistics, and is trained by REINFORCE-with-baseline to maximize a reward equal to validation F1 minus a small calibration penalty. The framework is formalized as a Markov decision process with one stochastic step per training episode, which decouples ensemble-weight learning from the (non-differentiable) outer F1 objective. On a 10,000-sample, 25-feature, five-class benchmark with 7% label noise, the proposed system reaches weighted F1 = 0.846, accuracy = 84.7%, MCC = 0.781, AUC = 0.952, and ECE = 0.039. Friedman and Nemenyi post-hoc tests over 50 CV folds confirm the RL-guided ensemble is significantly better than every individual base learner and uniform voting at α = 0.05 (Cohen's d = 0.96). An ablation isolates the RL policy and gradient boosting as the main drivers; a label-noise robustness study shows graceful degradation up to 20%; a head-to-head comparison against the Bonobo Optimizer (BO), GA, PSO, GWO, and WOA shows the best F1/wallclock trade-off.

Read PDF

Similar papers

Open access Aug 2026

A hybrid deep reinforcement learning framework for proactive cloud network intrusion detection using spatiotemporal feature learning

ShieldDRLNet is a hybrid deep reinforcement learning framework for proactive cloud-network intrusion detection that employs a convolutional neural network and a long short-term memory encoder to obtain a spatiotemporal traffic representation and uses a Double Deep Q-Network agent for adaptive sequential decision-making...

S. Venkatramulu, Anitha Patil, K. Pradeep et al. · 0 citations
Open access Sep 2026

EWCMD: real-time attack detection using ensemble weighted combination machine learning and deep learning methods

The evolving IoT threat landscape makes Distributed Denial-of-Service (DDoS) attacks a persistent security concern. This paper proposes a five-stage ensemble intrusion detection framework combining machine learning and deep learning. The first four stages train and evaluate seven machine learning classifiers and a co...

Poorya Hassanzadeh, Masoud Kargar, Mozhgan Gholami et al. · 0 citations
Open access Aug 2026

HADS-Net: A Hybrid Attention-Based Deep Security Network for Network Intrusion Detection

The principal contribution of this work is architectural and diagnostic rather than a performance improvement: it documents that combining feature-wise attention with out-of-fold stacked generalization does not, in this setting, outperform a plain multi-layer perceptron, while incurring the highest memory footprint of...

Mahima Khanna, V. Murthy, Siva Ramavarapu et al. · 0 citations
Open access Aug 2026

Network Attack Detection Using Machine Learning, Deep Learning, and Autonomous Defense Agents

This paper presents a data-driven analysis of network attack detection and reduction using machine learning, deep learning, and an Autonomous Defense Agent (ADA) for real-time threat detection and response, and provides an ADA design to validate real benchmark datasets.

Marwah Yaseen · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.