ENSEMBLE MACHINE LEARNING: MULTI-CLASS NETWORK ATTACK CLASSIFICATION USING CIC-IDS DATASET WITH HYPER PARAMETER TUNING AND COMPARATIVE ANALYSIS

Authors

  • Sidra Malik Department of Computer Science, UMT
  • Areeba Amer Department of Computer Science, UMT

Abstract

Attacks like Distributed Denial-of-Service (DDoS), Botnets, network scanning etc. remain a big challenge to the modern networked systems. Correct identification of these attacks is key to maintaining network security and to making sure that the incident can be responded to in a timely fashion. Most previous work has used binary classification to identify whether network traffic is malicious or not, but in this research multi-class classification is used. The proposed model is trained on the merged CICIDS 2017 dataset and classifies the network traffic into four classes, i.e., BENIGN, DDoS, Bot, and PortScan, with 184,532 preprocessed records and 78 traffic features. In order to assess classification efficacy, five distinct machine learning algorithms were implemented and evaluated under identical experimental parameters: LR, DT, RF, XGBoost, and LightGBM. The Bot class exhibited substantial underrepresentation within the dataset; consequently, class imbalance was addressed through the application of SMOTE. Additionally, RandomizedSearchCV was employed to fine-tune the hyperparameters of both RF and XGBoost, thereby enhancing their capacity to generalize effectively to previously unseen data. The trial results showed that the tuned XGBoost model exceeded all evaluated classifiers with 99.94% accuracy, precision, recall, and F1-score. To evaluate each model's effectiveness, particularly on minority attack classes, a comprehensive class-wise evaluation and confusion matrix analysis were conducted in addition to overall performance measures. The results show the promise of advanced ensemble learning approaches for network intrusion detection and provide a comprehensive evaluation of five machine learning algorithms, including LightGBM, on the CICIDS 2017 combined dataset.

Downloads

Published

2026-06-24

How to Cite

Sidra Malik, & Areeba Amer. (2026). ENSEMBLE MACHINE LEARNING: MULTI-CLASS NETWORK ATTACK CLASSIFICATION USING CIC-IDS DATASET WITH HYPER PARAMETER TUNING AND COMPARATIVE ANALYSIS. Spectrum of Engineering Sciences, 4(6), 4074–4090. Retrieved from https://thesesjournal.com/index.php/1/article/view/3660