Comparative Evaluation of Machine Learning Algorithms for Intrusion Detection Systems

Authors

  • Reza Nismara UNIVERSITAS DIAN NUSWANTORO
  • Rama Aria Megantara Universitas Dian Nuswantoro

DOI:

10.33395/sinkron.v10i3.16227

Keywords:

CIC-IDS2017, Evaluation Bias, Intrusion Detection Systems, Machine Learning, Random Split, Temporal Evaluation

Abstract

Performance estimates of intrusion detection models may vary depending on how the training and testing data are separated. Although random split is commonly used in IDS experiments, network traffic often follows time-dependent patterns that differ from one day to another. This study compares random split, single temporal split, and rolling temporal split to examine whether random evaluation produces overly optimistic performance estimates. The CIC-IDS2017 dataset was used because it contains network traffic collected across several days and includes benign as well as malicious activities. The evaluation involved five classical learning models: Decision Tree, Random Forest, Logistic Regression, K-Nearest Neighbors, and Linear Support Vector Machine. The dataset was prepared by combining daily traffic files, removing irrelevant and invalid features, converting labels into binary classes, and applying consistent preprocessing for all models. Performance was measured using accuracy, precision, recall, F1-score, ROC-AUC, PR-AUC, training time, and prediction time. The results show that random split produced very high scores, with several models reaching F1-scores close to 1.0. In contrast, temporal evaluation caused a clear performance decrease, with single temporal F1-scores ranging from approximately 0.60 to 0.71, while rolling temporal validation showed that model performance varied across different chronological testing periods. These findings indicate that random split may overestimate IDS model performance because similar traffic patterns can appear in both training and testing data. Therefore, time-aware evaluation provides a more realistic strategy for assessing IDS model generalization.

GS Cited Analysis

Downloads

Download data is not yet available.

References

Alzahrani, A. O., & Alenazi, M. J. F. (2021). future internet Designing a Network Intrusion Detection System Based on Machine Learning for Software Defined Networks. https://doi.org/10.3390/fi

Arcos-Argudo, M., Bojorque, R., & Torres, A. (2025). A Deterministic Comparison of Classical Machine Learning and Hybrid Deep Representation Models for Intrusion Detection on NSL-KDD and CICIDS2017. Algorithms, 18(12). https://doi.org/10.3390/a18120749

Bakro, M., Kumar, R. R., Alabrah, A. A., Ashraf, Z., Bisoy, S. K., Parveen, N., Khawatmi, S., & Abdelsalam, A. (2023). Efficient Intrusion Detection System in the Cloud Using Fusion Feature Selection Approaches and an Ensemble Classifier. Electronics (Switzerland), 12(11). https://doi.org/10.3390/electronics12112427

Chen, Z., Yu, W., & Zhou, L. (2021). ADASYN-Random Forest Based Intrusion Detection Model. Proceedings of the 2021 4th International Conference on Signal Processing and Machine Learning, 152–159. https://doi.org/10.1145/3483207.3483232

Chua, T.-H., & Salam, I. (2022). Evaluation of Machine Learning Algorithms in Network-Based Intrusion Detection System. http://arxiv.org/abs/2203.05232

Maseer, Z. K., Yusof, R., Bahaman, N., Mostafa, S. A., & Foozy, C. F. M. (2021). Benchmarking of Machine Learning for Anomaly Based Intrusion Detection Systems in the CICIDS2017 Dataset. IEEE Access, 9, 22351–22370. https://doi.org/10.1109/ACCESS.2021.3056614

Mhawi, D. N., Aldallal, A., & Hassan, S. (2022). Advanced Feature-Selection-Based Hybrid Ensemble Learning Algorithms for Network Intrusion Detection Systems. Symmetry, 14(7). https://doi.org/10.3390/sym14071461

Mondragon, J. C., Branco, P., Jourdan, G. V., Gutierrez-Rodriguez, A. E., & Biswal, R. R. (2025). Advanced IDS: a comparative study of datasets and machine learning algorithms for network flow-based intrusion detection systems. Applied Intelligence, 55(7). https://doi.org/10.1007/s10489-025-06422-4

Oluwakemi, O. O., Abdullahi, M. U., & Anyachebelu, K. T. (2023). Comparative Evaluation of Machine Learning Algorithms for Intrusion Detection. Asian Journal of Research in Computer Science, 16(4), 8–22. https://doi.org/10.9734/ajrcos/2023/v16i4366

Rodríguez, M., Alesanco, Á., Mehavilla, L., & García, J. (2022). Evaluation of Machine Learning Techniques for Traffic Flow-Based Intrusion Detection. Sensors, 22(23). https://doi.org/10.3390/s22239326

Samantaray, M., Barik, R. C., & Biswal, A. K. (2024). A comparative assessment of machine learning algorithms in the IoT-based network intrusion detection systems. Decision Analytics Journal, 11. https://doi.org/10.1016/j.dajour.2024.100478

Singh, A., Prakash, J., Kumar, G., Jain, P. K., & Ambati, L. S. (2024). Intrusion Detection System: A Comparative Study of Machine Learning-Based IDS. Journal of Database Management, 35(1). https://doi.org/10.4018/JDM.338276

Thockchom, N., Singh, M. M., & Nandi, U. (2023). A novel ensemble learning-based model for network intrusion detection. Complex and Intelligent Systems, 9(5), 5693–5714. https://doi.org/10.1007/s40747-023-01013-7

Tripathy, S. S., & Behera, B. (2023). PERFORMANCE EVALUATION OF MACHINE LEARNING ALGORITHMS FOR INTRUSION DETECTION SYSTEM. https://doi.org/10.17605/OSF.IO/WX6CS

Udurume, M., Shakhov, V., & Koo, I. (2024). Comparative Analysis of Deep Convolutional Neural Network—Bidirectional Long Short-Term Memory and Machine Learning Methods in Intrusion Detection Systems. Applied Sciences (Switzerland), 14(16). https://doi.org/10.3390/app14166967

Downloads


Crossmark Updates

How to Cite

Nismara, R., & Rama Aria Megantara. (2026). Comparative Evaluation of Machine Learning Algorithms for Intrusion Detection Systems. Sinkron : Jurnal Dan Penelitian Teknik Informatika, 10(3), 2712-1720. https://doi.org/10.33395/sinkron.v10i3.16227