Comparative Evaluation of Machine Learning Algorithms for Intrusion Detection Systems
DOI:
10.33395/sinkron.v10i3.16227Keywords:
CIC-IDS2017, Evaluation Bias, Intrusion Detection Systems, Machine Learning, Random Split, Temporal EvaluationAbstract
Performance estimates of intrusion detection models may vary depending on how the training and testing data are separated. Although random split is commonly used in IDS experiments, network traffic often follows time-dependent patterns that differ from one day to another. This study compares random split, single temporal split, and rolling temporal split to examine whether random evaluation produces overly optimistic performance estimates. The CIC-IDS2017 dataset was used because it contains network traffic collected across several days and includes benign as well as malicious activities. The evaluation involved five classical learning models: Decision Tree, Random Forest, Logistic Regression, K-Nearest Neighbors, and Linear Support Vector Machine. The dataset was prepared by combining daily traffic files, removing irrelevant and invalid features, converting labels into binary classes, and applying consistent preprocessing for all models. Performance was measured using accuracy, precision, recall, F1-score, ROC-AUC, PR-AUC, training time, and prediction time. The results show that random split produced very high scores, with several models reaching F1-scores close to 1.0. In contrast, temporal evaluation caused a clear performance decrease, with single temporal F1-scores ranging from approximately 0.60 to 0.71, while rolling temporal validation showed that model performance varied across different chronological testing periods. These findings indicate that random split may overestimate IDS model performance because similar traffic patterns can appear in both training and testing data. Therefore, time-aware evaluation provides a more realistic strategy for assessing IDS model generalization.
Downloads
References
Alzahrani, A. O., & Alenazi, M. J. F. (2021). future internet Designing a Network Intrusion Detection System Based on Machine Learning for Software Defined Networks. https://doi.org/10.3390/fi
Arcos-Argudo, M., Bojorque, R., & Torres, A. (2025). A Deterministic Comparison of Classical Machine Learning and Hybrid Deep Representation Models for Intrusion Detection on NSL-KDD and CICIDS2017. Algorithms, 18(12). https://doi.org/10.3390/a18120749
Bakro, M., Kumar, R. R., Alabrah, A. A., Ashraf, Z., Bisoy, S. K., Parveen, N., Khawatmi, S., & Abdelsalam, A. (2023). Efficient Intrusion Detection System in the Cloud Using Fusion Feature Selection Approaches and an Ensemble Classifier. Electronics (Switzerland), 12(11). https://doi.org/10.3390/electronics12112427
Chen, Z., Yu, W., & Zhou, L. (2021). ADASYN-Random Forest Based Intrusion Detection Model. Proceedings of the 2021 4th International Conference on Signal Processing and Machine Learning, 152–159. https://doi.org/10.1145/3483207.3483232
Chua, T.-H., & Salam, I. (2022). Evaluation of Machine Learning Algorithms in Network-Based Intrusion Detection System. http://arxiv.org/abs/2203.05232
Maseer, Z. K., Yusof, R., Bahaman, N., Mostafa, S. A., & Foozy, C. F. M. (2021). Benchmarking of Machine Learning for Anomaly Based Intrusion Detection Systems in the CICIDS2017 Dataset. IEEE Access, 9, 22351–22370. https://doi.org/10.1109/ACCESS.2021.3056614
Mhawi, D. N., Aldallal, A., & Hassan, S. (2022). Advanced Feature-Selection-Based Hybrid Ensemble Learning Algorithms for Network Intrusion Detection Systems. Symmetry, 14(7). https://doi.org/10.3390/sym14071461
Mondragon, J. C., Branco, P., Jourdan, G. V., Gutierrez-Rodriguez, A. E., & Biswal, R. R. (2025). Advanced IDS: a comparative study of datasets and machine learning algorithms for network flow-based intrusion detection systems. Applied Intelligence, 55(7). https://doi.org/10.1007/s10489-025-06422-4
Oluwakemi, O. O., Abdullahi, M. U., & Anyachebelu, K. T. (2023). Comparative Evaluation of Machine Learning Algorithms for Intrusion Detection. Asian Journal of Research in Computer Science, 16(4), 8–22. https://doi.org/10.9734/ajrcos/2023/v16i4366
Rodríguez, M., Alesanco, Á., Mehavilla, L., & García, J. (2022). Evaluation of Machine Learning Techniques for Traffic Flow-Based Intrusion Detection. Sensors, 22(23). https://doi.org/10.3390/s22239326
Samantaray, M., Barik, R. C., & Biswal, A. K. (2024). A comparative assessment of machine learning algorithms in the IoT-based network intrusion detection systems. Decision Analytics Journal, 11. https://doi.org/10.1016/j.dajour.2024.100478
Singh, A., Prakash, J., Kumar, G., Jain, P. K., & Ambati, L. S. (2024). Intrusion Detection System: A Comparative Study of Machine Learning-Based IDS. Journal of Database Management, 35(1). https://doi.org/10.4018/JDM.338276
Thockchom, N., Singh, M. M., & Nandi, U. (2023). A novel ensemble learning-based model for network intrusion detection. Complex and Intelligent Systems, 9(5), 5693–5714. https://doi.org/10.1007/s40747-023-01013-7
Tripathy, S. S., & Behera, B. (2023). PERFORMANCE EVALUATION OF MACHINE LEARNING ALGORITHMS FOR INTRUSION DETECTION SYSTEM. https://doi.org/10.17605/OSF.IO/WX6CS
Udurume, M., Shakhov, V., & Koo, I. (2024). Comparative Analysis of Deep Convolutional Neural Network—Bidirectional Long Short-Term Memory and Machine Learning Methods in Intrusion Detection Systems. Applied Sciences (Switzerland), 14(16). https://doi.org/10.3390/app14166967
Downloads
How to Cite
Issue
Section
License
Copyright (c) 2026 Reza Nismara, Rama Aria Megantara

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.






















Moraref
PKP Index
Indonesia OneSearch
OCLC Worldcat
Index Copernicus
Scilit
