A Unified Benchmark of Boosting and Tree-Based Models for Flow-Based Network Intrusion Detection

Publications

A Unified Benchmark of Boosting and Tree-Based Models for Flow-Based Network Intrusion Detection

Year : 2025

Publisher : Institute of Electrical and Electronics Engineers Inc.

Source Title : Proceedings - 2025 IEEE 3rd International Symposium on Sustainable Energy, Signal Processing and Cybersecurity, iSSSC 2025

Document Type :

Abstract

Intrusion Detection Systems (IDS) are essential in securing modern networks from advanced cyber threats or intrusions. With increasing network complexity and traffic volume, flow-based intrusion detection has been in the spotlight for scalability and performance. This paper introduces a unified benchmark to evaluate the effectiveness of the boosting and tree-based artificial intelligence models for flow-based network intrusion detection. Six boosting and tree-based machine learning models, such as Decision Tree (DT), eXtreme Gradient Boosting (XGBoost), Light Gradient Boosting Machine (LightGBM), Histogram-Based Gradient Boosting (HistGBM), Categorical Boosting (CatBoost), and Natural Gradient Boosting (NGBoost), are trained and tested on one of the most recent flow-based network intrusion datasets, the HIKARI-2021 dataset. The model development focuses on emulating real-world traffic and feature reduction to mimic realistic deployment conditions. The experimental results demonstrate that ensemble boosting models outperform typical trees in both accuracy and reliability across the board, with some models still displaying more than 98% accuracy after dimensionality reduction. This research offers a holistic guide for choosing proper models to design flow-based IDS and works toward standardizing testing practice in this area.