Adaptive hybrid ensemble-based DDoS detection using reinforcement learning-guided optimization and deep learning

(1) Maha Ismail Raheem Mail (College of Engineering, University of Information Technology and Communications, Al-Mansour, 3071, Baghdad, Iraq)
(2) * Shouket Abdulrahman Ahmed Mail (Department of Medical Instrumentation Techniques Engineering, Technical Engineering College, Al-Kitab University, Altun Kupri, Kirkuk, 36001, Iraq)
(3) Enas Faek Aziz Mail (Department of Cybersecurity Engineering Technologies, Technical Engineering College for Computer and Artificial Intelligence/Kirkuk, Northern Technical University, 36001, Kirkuk, Iraq)
(4) Saad Ali Assi Mail (Software Department, College of Computer Science and Information Technology, University of Kirkuk, Kirkuk, Iraq)
(5) Sinan Qahtan Salih Mail (Technical College of Engineering, Al-Bayan University, Baghdad 10011, Iraq)
(6) Ahmed Dheyaa Radhi Mail (College of Pharmacy, University of Al-Ameed, Karbala PO Box 198, Iraq)
(7) Hilal Adnan Fadhil Mail (Department of Electrical and Computer Engineering, Sohar University, Sohar, Oman)
(8) Taha Almulaisi Mail (Renewable Energy Research Unit, Polytechnic College Hawija, Northern Technical University, Hawija, 36007, Iraq)
*corresponding author

Abstract


Distributed Denial-of-Service (DDoS) attacks remain among the most disruptive network threats, and detectors that generalize across attack families with low false-alarm rates are still an open problem. Propose an adaptive hybrid ensemble that unifies two gradient-boosting learners (Random Forest and Gradient Boosting) with three deep neural base learners (DNN, CNN-1D, and LSTM) under a weighted soft-voting rule whose weights are produced by a Reinforcement Learning (RL) policy. The RL agent treats the ensemble-weight simplex as its action space, observes a state vector built from validation-set diagnostic statistics, and is trained by REINFORCE-with-baseline to maximize a reward equal to validation F1 minus a small calibration penalty. The framework is formalized as a Markov decision process with one stochastic step per training episode, which decouples ensemble-weight learning from the (non-differentiable) outer F1 objective. On a 10,000-sample, 25-feature, five-class benchmark with 7% label noise, the proposed system reaches weighted F1 = 0.846, accuracy = 84.7%, MCC = 0.781, AUC = 0.952, and ECE = 0.039. Friedman and Nemenyi post-hoc tests over 50 CV folds confirm the RL-guided ensemble is significantly better than every individual base learner and uniform voting at α = 0.05 (Cohen's d = 0.96). An ablation isolates the RL policy and gradient boosting as the main drivers; a label-noise robustness study shows graceful degradation up to 20%; a head-to-head comparison against the Bonobo Optimizer (BO), GA, PSO, GWO, and WOA shows the best F1/wallclock trade-off.

Keywords


DDoS detection; reinforcement learning; policy gradient; adaptive ensemble; deep learning; network intrusion detection

   

DOI

https://doi.org/10.26555/ijain.v12i3.2109
      

Article metrics

Abstract views : 253 | PDF views : 41

   

Cite

   

Full Text

Download

References


[1] Q. Zhou, X. Mao, and Y. Chen, “A DDoS attack detection method combining federated learning and hybrid deep learning in software-defined networking,” Comput. J., vol. 68, no. 10, pp. 1463–1475, Oct. 2025, doi: 10.1093/comjnl/bxaf049.

[2] R. Abdulhammed, H. Musafer, A. Alessa, M. Faezipour, and A. Abuzneid, “Features Dimensionality Reduction Approaches for Machine Learning Based Network Intrusion Detection,” Electronics, vol. 8, no. 3, p. 322, Mar. 2019, doi: 10.3390/electronics8030322.

[3] F. Z. Errounda and Y. Liu, “Adaptive differential privacy in vertical federated learning for mobility forecasting,” Futur. Gener. Comput. Syst., vol. 149, no. December, pp. 531–546, Dec. 2023, doi: 10.1016/J.FUTURE.2023.07.033.

[4] A. Heidari and M. A. Jabraeil Jamali, “Internet of Things intrusion detection systems: a comprehensive review and future directions,” Cluster Comput., vol. 26, no. 6, pp. 3753–3780, Dec. 2023, doi: 10.1007/S10586-022-03776-Z/METRICS.

[5] G. Karatas, O. Demir, and O. K. Sahingoz, “Increasing the Performance of Machine Learning-Based IDSs on an Imbalanced and Up-to-Date Dataset,” IEEE Access, vol. 8, pp. 32150–32162, 2020, doi: 10.1109/ACCESS.2020.2973219.

[6] Z. Ahmad, A. Shahid Khan, C. Wai Shiang, J. Abdullah, and F. Ahmad, “Network intrusion detection system: A systematic study of machine learning and deep learning approaches,” Trans. Emerg. Telecommun. Technol., vol. 32, no. 1, p. e4150, Jan. 2021, doi: 10.1002/ett.4150.

[7] P. Raheem, F. Hamad Hasan, F. A. Mohammed, A. H. Ahmed, R. A. Hasan, and K. Saleh, “Optimization and Simulation of the Perturb and Observe Algorithm for Maximum Power Point Tracking in Photovoltaic Systems,” NTU J. Renew. Energy, vol. 9, no. 1, pp. 73–81, Nov. 2025, doi: 10.56286/02qc5x54.

[8] L. Liu, P. Wang, J. Lin, and L. Liu, “Intrusion Detection of Imbalanced Network Traffic Based on Machine Learning and Deep Learning,” IEEE Access, vol. 9, pp. 7550–7563, 2021, doi: 10.1109/ACCESS.2020.3048198.

[9] M. Macas, C. Wu, and W. Fuertes, “Adversarial examples: A survey of attacks and defenses in deep learning-enabled cybersecurity systems,” Expert Syst. Appl., vol. 238, p. 122223, Mar. 2024, doi: 10.1016/j.eswa.2023.122223.

[10] A. Thakkar and R. Lohiya, “A Review on Challenges and Future Research Directions for Machine Learning-Based Intrusion Detection System,” Arch. Comput. Methods Eng., vol. 30, no. 7, pp. 4245–4269, Sep. 2023, doi: 10.1007/s11831-023-09943-8.

[11] J. Liu, B. Kantarci, and C. Adams, “Machine learning-driven intrusion detection for Contiki-NG-based IoT networks exposed to NSL-KDD dataset,” in Proceedings of the 2nd ACM Workshop on Wireless Security and Machine Learning, New York, NY, USA: ACM, Jul. 2020, pp. 25–30. doi: 10.1145/3395352.3402621.

[12] L. Yang et al., “Multi-Perspective Content Delivery Networks Security Framework Using Optimized Unsupervised Anomaly Detection,” IEEE Trans. Netw. Serv. Manag., vol. 19, no. 1, pp. 686–705, Mar. 2022, doi: 10.1109/TNSM.2021.3100308.

[13] A. Bakhtiarnia, Q. Zhang, and A. Iosifidis, “Efficient High-Resolution Deep Learning: A Survey,” ACM Comput. Surv., vol. 56, no. 7, pp. 1–35, Jul. 2024, doi: 10.1145/3645107.

[14] S. Vadigi, K. Sethi, D. Mohanty, S. P. Das, and P. Bera, “Federated reinforcement learning based intrusion detection system using dynamic attention mechanism,” J. Inf. Secur. Appl., vol. 78, no. November, p. 103608, Nov. 2023, doi: 10.1016/j.jisa.2023.103608.

[15] J. Cao, M. Zhang, W. Liu, L. Wang, and J. Peng, “Deep Learning-Based Security Analysis of Quantum Random Numbers Generated by Imperfect Devices,” IEEE Trans. Inf. Forensics Secur., vol. 19, pp. 7841–7852, 2024, doi: 10.1109/TIFS.2024.3445169.

[16] S. R. Ahmed et al., “Deep Convolutional Neural Network (DCNN) for the Identification of Striping in Images of Blood Cells,” Lect. Notes Networks Syst., vol. 1036 LNNS, pp. 83–89, 2024, doi: 10.1007/978-3-031-62881-8_7/SAVE-RESEARCH.

[17] P. Li, R. Jing, and X. Shi, “Apple Disease Recognition Based on Convolutional Neural Networks With Modified Softmax,” Front. Plant Sci., vol. 13, p. 820146, May 2022, doi: 10.3389/fpls.2022.820146.

[18] T. A. Taha, M. K. Hassan, H. I. Zaynal, and N. I. Abdul Wahab, “Big Data for Smart Grid: A Case Study,” in Big Data Analytics Framework for Smart Grids, CRC Press, 2023, pp. 142–180. doi: 10.1201/9781032665399-8/BIG-DATA-SMART-GRID-TAHA-TAHA-MOHD-KHAIR-HASSAN-HUSSEIN-ZAYNAL-NOOR-IZZRI-ABDUL-WAHAB.

[19] J. Guan, J. Liu, X. Shen, and F. Zhang, “UQ-Guided Hyperparameter Optimization for Iterative Learners,” in Advances in Neural Information Processing Systems 37, San Diego, California, USA: Neural Information Processing Systems Foundation, Inc. (NeurIPS), 2024, pp. 386–415. doi: 10.52202/079017-0013.

[20] E. Bektas and H. Karaca, “GA Based Selective Harmonic Elimination for Multilevel Inverter with Reduced Number of Switches: An Experimental Study,” Elektron. ir Elektrotechnika, vol. 25, no. 3, pp. 10–17, Jun. 2019, doi: 10.5755/j01.eie.25.3.23670.

[21] W. Dai, X. Li, W. Ji, and S. He, “Network Intrusion Detection Method Based on CNN-BiLSTM-Attention Model,” IEEE Access, vol. 12, pp. 53099–53111, 2024, doi: 10.1109/ACCESS.2024.3384528.

[22] M. Zeeshan et al., “Protocol-Based Deep Intrusion Detection for DoS and DDoS Attacks Using UNSW-NB15 and Bot-IoT Data-Sets,” IEEE Access, vol. 10, pp. 2269–2283, 2022, doi: 10.1109/ACCESS.2021.3137201.

[23] A. Thakkar and R. Lohiya, “Attack Classification of Imbalanced Intrusion Data for IoT Network Using Ensemble-Learning-Based Deep Neural Network,” IEEE Internet Things J., vol. 10, no. 13, pp. 11888–11895, Jul. 2023, doi: 10.1109/JIOT.2023.3244810.

[24] Z. Wang, Y. Liu, D. He, and S. Chan, “Intrusion detection methods based on integrated deep learning model,” Comput. Secur., vol. 103, no. April, p. 102177, Apr. 2021, doi: 10.1016/J.COSE.2021.102177.

[25] R. Panigrahi et al., “A Consolidated Decision Tree-Based Intrusion Detection System for Binary and Multiclass Imbalanced Datasets,” Mathematics, vol. 9, no. 7, p. 751, Mar. 2021, doi: 10.3390/math9070751.

[26] S. Rajagopal, P. P. Kundapur, and K. S. Hareesha, “A Stacking Ensemble for Network Intrusion Detection Using Heterogeneous Datasets,” Secur. Commun. Networks, vol. 2020, no. 1, pp. 1–9, Jan. 2020, doi: 10.1155/2020/4586875.

[27] M. Lopez-Martin, B. Carro, and A. Sanchez-Esguevillas, “Application of deep reinforcement learning to intrusion detection for supervised problems,” Expert Syst. Appl., vol. 141, p. 112963, Mar. 2020, doi: 10.1016/j.eswa.2019.112963.

[28] G. Caminero, M. Lopez-Martin, and B. Carro, “Adversarial environment reinforcement learning algorithm for intrusion detection,” Comput. Networks, vol. 159, pp. 96–109, Aug. 2019, doi: 10.1016/j.comnet.2019.05.013.

[29] A. Kanervisto, C. Scheller, and V. Hautamaki, “Action Space Shaping in Deep Reinforcement Learning,” in 2020 IEEE Conference on Games (CoG), IEEE, Aug. 2020, pp. 479–486. doi: 10.1109/CoG47356.2020.9231687.

[30] T. Balasuntharam, H. Davoudi, and M. Ebrahimi, “Preferential Proximal Policy Optimization,” in 2023 International Conference on Machine Learning and Applications (ICMLA), IEEE, Dec. 2023, pp. 293–300. doi: 10.1109/ICMLA58977.2023.00048.

[31] J. Łyskawa, J. Lewandowski, and P. Wawrzyński, “SACn: Soft Actor-Critic with n-step Returns,” in Proceedings of the 18th International Conference on Agents and Artificial Intelligence, SCITEPRESS - Science and Technology Publications, 2026, pp. 2324–2332. doi: 10.5220/0014229900004052.

[32] M. M. Shwaysh et al., “Adaptive Hybrid Information Gain and Autoencoder-Based Feature Selection with Ensemble Recurrent Extreme Learning Machine for Enhanced Network Intrusion Detection Systems,” J. Netw. Syst. Manag., vol. 34, no. 1, p. 1, Jan. 2026, doi: 10.1007/s10922-025-09976-3.

[33] Y. Liu, X. Wang, B. Qu, and F. Zhao, “ATVITSC: A Novel Encrypted Traffic Classification Method Based on Deep Learning,” IEEE Trans. Inf. Forensics Secur., vol. 19, pp. 9374–9389, 2024, doi: 10.1109/TIFS.2024.3433446.

[34] L. Hussain mari and A. F. AL-Allaf, “Analyzing Power Plant Data Using Artificial Intelligence to Enhance Maintenance Strategy,” NTU J. Renew. Energy, vol. 9, no. 1, pp. 30–37, Aug. 2025, doi: 10.56286/fc8qt002.

[35] N. Moustafa, “A new distributed architecture for evaluating AI-based security systems at the edge: Network TON_IoT datasets,” Sustain. Cities Soc., vol. 72, no. September, p. 102994, Sep. 2021, doi: 10.1016/j.scs.2021.102994.

[36] S. A. Hussein, A. I. Saleh, H. E. D. Mostafa, and M. I. Obaya, “RETRACTED: A hybrid security strategy (HS2) for reliable video streaming in fog computing,” J. Inf. Secur. Appl., vol. 51, no. April, p. 102412, Apr. 2020, doi: 10.1016/J.JISA.2019.102412.

[37] P. Henderson, R. Islam, P. Bachman, J. Pineau, D. Precup, and D. Meger, “Deep Reinforcement Learning That Matters,” Proc. AAAI Conf. Artif. Intell., vol. 32, no. 1, pp. 3207–3214, Apr. 2018, doi: 10.1609/aaai.v32i1.11694.

[38] E. ALGUL, F. DOĞAN, A. A. Ahmad, and O. POLAT, “SCADANet: A novel dataset for SCADA cybersecurity and intrusion detection,” Comput. Networks, vol. 278, p. 112087, Apr. 2026, doi: 10.1016/J.COMNET.2026.112087.

[39] A. B. Mohammed, E. Chamseddine, and A. ElAdel, “Enhancing real-time IoT intrusion detection using KAN-based frameworks with SMOTE,” J. Netw. Comput. Appl., vol. 249, no. May, p. 104461, May 2026, doi: 10.1016/j.jnca.2026.104461.

[40] S. A. Abdulkareem et al., “Application of Machine Learning Classifiers for Human Health Care Monitoring System,” in 2024 International Conference on Smart Systems for Electrical, Electronics, Communication and Computer Engineering (ICSSEECC), IEEE, Jun. 2024, pp. 678–683. doi: 10.1109/ICSSEECC61126.2024.10649464.




Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

___________________________________________________________
International Journal of Advances in Intelligent Informatics
ISSN 2442-6571  (print) | 2548-3161 (online)
Organized by UAD and ASCEE Computer Society
Published by Universitas Ahmad Dahlan
W: http://ijain.org
E: info@ijain.org (paper handling issues)
 andri.pranolo.id@ieee.org (publication issues)

View IJAIN Stats

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0