Machine learning network intrusion detection systems (IDS) rely on aggregate flow statistics that discard distributional structure, while established entropy measures require raw packet sequences unavailable in pre-aggregated flow datasets. We propose Multi-Level Distributional Entropy (MDE), an analytical framework that derives interpretable entropy features directly from flow-level summary statistics at three levels: within-flow Gaussian differential entropy, cross-directional Jensen-Shannon divergence (JSD), and Transmission Control Protocol (TCP) flag-pattern Shannon entropy, without raw packet access or training data.
arXiv:2606. 29797v1 Announce Type: cross Abstract: Machine learning network intrusion detection systems (IDS) rely on aggregate flow statistics that discard distributional structure, while established entropy measures require raw packet sequences unavailable in pre-aggregated flow datasets.
By Mohamed Aly Bouke, Md Shohel Sayeed, Swee-Huay Heng, Azizol Abdullah, Mohamed Othman
arXiv:2609.36039v1 Announce Type: cross
Abstract: Machine learning (ML) and deep learning (DL) have dominated Intrusion Detection System (IDS) research in recent years. Unfortunately, many existing s...
By Yufeng Xin, Bryant Goseland, Mohamed Rahouti
arXiv:2607. 15389v1 Announce Type: cross Abstract: This work investigates a generalized Choquet-integral-based feature aggregation framework to improve anomaly detection in high-dimensional network traffic data.
By Abreu Quevedo, Roger Immich, Giancarlo Lucca, Gra\c{c}aliz Dimuro, Bruno L. Dalmazo
arXiv:2606. 09934v1 Announce Type: new Abstract: Feature selection is critical for network intrusion detection systems (NIDS) operating under high-dimensional, highly imbalanced traffic, as found in operational and defense networks.
By Abu Fuad Ahmad, Istiaque Ahmed
The paper proposes a human-centered framework for validating the semantic soundness of machine learning models used in network traffic classification. It extends existing knowledge-generation methods by integrating data, models, explainability tools, visualizations, and expert reasoning to iteratively explore, verify, and refine model behavior and preprocessing steps. The framework is built on literature findings, benchmark analyses, XAI experience, and expert feedback, offering practical guidance for ensuring models learn trustworthy, semantically meaningful patterns rather than spurious correlations.
By Igor Cherepanov, David Sessler, Alex Ulmer, Thorsten May, J\"orn Kohlhammer
Machine learning (ML) has become the dominant approach for network traffic classification, achieving very high predictive performance. However, a model is only valuable if it learns semantically meani...
arXiv:2609.05701v1 Announce Type: cross
Abstract: One of the biggest risks faced by Software Defined Networks (SDN) is the Distributed Denial of Service (DDoS) attack in which a compromised controlle...
By Adeel Ahmad, Ali Akarma, Ahmad Ali, Hammad Muneer, Toqeer Ali Syed
The paper benchmarks static embedding models—Word2Vec, FastText, and Doc2Vec—for detecting anomalous HTTP requests using a single‑class classification framework. It introduces HEDA, a modular pipeline that trains both embeddings and detectors solely on benign traffic in an unsupervised setting. Experiments on synthetic and real datasets show that FastText embeddings consistently yield high detection rates with controlled false positives.
By Amanda Riverol, Gustavo Betarte, Rodrigo Mart\'inez, \'Alvaro Pardo
arXiv:2606. 28439v1 Announce Type: cross Abstract: Deep neural networks (DNNs) are widely applied in Network-based Intrusion Detection System (NIDS) due to their high accuracy.
By Jinhao You, Zan Zhou, Shujie Yang, Yi Sun, Lei Zhang, Changqiao Xu
JEV-IDS is an open experimental general network intrusion detection system that uses the Jev System One Model to detect zero‑day intrusions even when labeled data are scarce. The system processes one flow per request and asks the model two questions: a binary attack probability and a finite‑choice traffic category. In tests on a 300‑flow NSL‑KDD pilot split, JEV-IDS achieved an F1‑score of 0.859, precision of 0.941, recall of 0.790, and a novel‑attack recall of 0.838, while being 4.8 times faster and 3.8 times cheaper than GPT‑5.6 Luna and producing 15 times fewer false alarms than a low‑data Random Forest.
By Paulo Severo, Silvio E. Quincozes, Amanda Dias
arXiv:2608. 15465v1 Announce Type: cross Abstract: Identification of IoT device types from passive traffic is increasingly used for security management in enterprise and ISP networks.
By Shayan Azizi, Norihiro Okui, Masataka Nakahara, Ayumu Kubota, Gustavo Batista, Hassan Habibi Gharakaheili