It is argued that attack-held-out and LOO should be standard protocols for network-traffic IDS benchmarks on SWaT, and the full preprocessing, evaluation, and ensemble pipeline is released.
Abstract
Intrusion detection systems (IDSs) for industrial control networks are commonly evaluated using random stratified splits, placing rows from every recorded attack in both training and test sets. Although convenient, this practice measures a model’s ability to recognise repetitions of patterns it has already seen rather than its ability to detect novel attacks. We revisit supervised and unsupervised machine-learning IDSs on the Secure Water Treatment (SWaT) dataset’s network-traffic modality, extending a prior conference study, and quantify the effect of more rigorous evaluation protocols. We evaluate five model families (XGBoost, a convolutional–MLP hybrid, a bidirectional LSTM classifier, an unsupervised LSTM-Autoencoder, and a temporal convolutional network) under three protocols: stratified random, attack-held-out, and leave-one-attack-out (LOO). Under LOO on a 30-file subsample, every supervised classifier scores below random on the majority of held-out attacks; the unsupervised LSTM-Autoencoder retains the best solo mean of 0.550 with a strongly bimodal per-attack distribution spanning 0.046 to 0.894. A sign-adjusted oracle-bound ensemble flips members whose per-attack AUROC inverts achieves a mean LOO AUROC of 0.844; adding the TCN as a fourth ensemble member does not improve the result, providing evidence that what is needed is an additional detection mode rather than another supervised classifier. We additionally report recall at a 5% false-positive-rate budget, paired Wilcoxon significance tests, and bootstrap confidence intervals. The full preprocessing, evaluation, and ensemble pipeline is released, and we argue that attack-held-out and LOO should be standard protocols for network-traffic IDS benchmarks on SWaT.
The SHAP analysis identifies the transformed network attributes that contribute most strongly to attack predictions and illustrates how individual records can be explained, which adds an interpretability layer to conventional network-traffic classification and can support analystoriented investigation of suspicious eve...
D. P., H. S.· International Journal of Sci...· 0 citations
The findings support the adoption of hybrid IDS architectures as a balanced and practical solution that enhances detection capability, adaptability, and reliability in evolving cyber threat landscapes.
Bang-Chen Yu· Technologique: A Global Jour...· 0 citations
The rapid expansion of networked infrastructure, cloud computing, and IoT environments has significantly increased the attack surface, while traditional signature-based Network Intrusion Detection Systems (NIDS) remain limited in detecting zero-day attacks, polymorphic threats, and malicious activities within encrypted...
Y. Alnattaf, Hanaa Fathi Mahmoud· Neutrosophic Optimization an...· 1 citation
Network intrusion detection systems (NIDS) play a critical role in protecting modern communication networks against increasingly sophisticated cyber attacks. In this paper, we propose a Transformer-based network intrusion detection system (t-NIDS) that integrates a Transformer encoder with contrastive learning to learn...
A hybrid IDS framework built on a stacking ensemble of four heterogeneous base classifiers, namely random forest, extreme gradient boosting, light gradient-boosting machine, and a shallow multi-layer perceptron (MLP), coupled with a PyTorch-based neural network meta-classifier, establishing that pairing meta-learning w...
Zobayer Alam, Arnab Bishakh Sarker, Jariatun Islam et al.· International Journal of Adv...· 0 citations
This paper presents a data-driven analysis of network attack detection and reduction using machine learning, deep learning, and an Autonomous Defense Agent (ADA) for real-time threat detection and response, and provides an ADA design to validate real benchmark datasets.
Marwah Yaseen· Al-Noor Journal of Engineeri...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.