Multi-class network intrusion detection: Machine and deep learning benchmark with live stream deployment
| dc.authorid | 0000-0003-0261-4404 | |
| dc.contributor.author | Danışmaz, Betül | |
| dc.contributor.author | Bıyık, Mustafa Emre | |
| dc.contributor.author | Gözüaçık, Necip | |
| dc.date.accessioned | 2026-08-21T10:19:43Z | |
| dc.date.available | 2026-08-21T10:19:43Z | |
| dc.date.issued | 2026 | |
| dc.department | Fakülteler, Mühendislik ve Doğa Bilimleri Fakültesi, Yazılım Mühendisliği Bölümü | |
| dc.description.abstract | The rapid rise of advanced cyber threats is exposing the limitations of traditional, signature-based network intrusion detection systems. While machine learning and deep learning models offer proactive defense mechanisms, current research is often compromised due to temporal data leakage, impractical threat classifications, and significant discrepancies between offline evaluation and online deployment. This study presents a comparative evaluation of traditional machine learning and deep learning architectures integrated into a fully functional real-time inference pipeline. Additionally, we propose an operationally motivated three-class classification encompassing Benign, Volumetric, and Semantic traffic to contextualize incident response. When the trained XGBoost, Random Forest, Decision Tree, LSTM, and BiLSTM models were evaluated and compared under the same constraints, the BiLSTM model achieved the highest Macro F1 score at 97.72%. However, XGBoost closely followed with a Macro F1 of 95.87%, while achieving 15.5 times faster inference. To translate these findings into practice, a Kafka-based live system architecture was designed that integrates real-time stream inference, zero-downtime model switching, and automated threat response capabilities. | |
| dc.description.abstract | Gelişmiş siber tehditlerin hızla artması, geleneksel, imza tabanlı ağ saldırı tespit sistemlerinin sınırlarını ortaya koymaktadır. Makine öğrenimi ve derin öğrenme modelleri proaktif savunma mekanizmaları sunarken, mevcut araştırmalar genellikle zamansal veri sızıntıları, pratik olmayan tehdit sınıflandırmaları ve çevrimdışı değerlendirme ile çevrimiçi dağıtım arasındaki önemli farklar nedeniyle tehlikeye girmektedir. Bu çalışma, tamamen işlevsel bir gerçek zamanlı çıkarım hattına entegre edilmiş geleneksel makine öğrenimi ve derin öğrenme mimarilerinin karşılaştırmalı değerlendirmesini sunmaktadır. Ayrıca, olaylara müdahaleyi anlamlandırmak için Zararsız, Hacimsel ve Semantik trafiğini kapsayan, operasyonel olarak motive edilmiş üç sınıflı bir sınıflandırma önerilmiştir. Eğitilen XGBoost, Rastgele Orman, Karar Ağacı, LSTM, BiLSTM modelleri aynı kısıtlamalar altında değerlendirilerek karşılaştırıldığında BiLSTM ağı, %97,72 ile en yüksek Makro F1 puanını elde etmiştir. Ancak, XGBoost algoritması %95,87 ile 15,5 kat daha hızlı çıkarım sergilemiştir. Bu bulguları pratiğe aktarmak için, gerçek zamanlı akış çıkarımı, sıfır kesintili model değişimi ve otomatik tehdit yanıtı özelliklerini bir arada barındıran Kafka tabanlı bir canlı sistem mimarisi tasarlanmıştır. | |
| dc.identifier.citation | Danışmaz, B., Bıyık, M. E., & Gözüaçık, N. (2026). Multi-class network intrusion detection: Machine and deep learning benchmark with live stream deployment. 34th Signal Processing and Communications Applications Conference (SIU), IEEE. https://doi.org/10.1109/SIU71813.2026.11636987 | |
| dc.identifier.doi | 10.1109/SIU71813.2026.11636987 | |
| dc.identifier.issn | 2165-0608 | |
| dc.identifier.uri | https://doi.org/10.1109/SIU71813.2026.11636987 | |
| dc.identifier.uri | https://hdl.handle.net/20.500.13055/1587 | |
| dc.indekslendigikaynak | Web of Science | |
| dc.institutionauthor | Danışmaz, Betül | |
| dc.institutionauthor | Bıyık, Mustafa Emre | |
| dc.institutionauthor | Gözüaçık, Necip | |
| dc.institutionauthorid | 0000-0003-0261-4404 | |
| dc.language.iso | tr | |
| dc.publisher | IEEE | |
| dc.relation.ispartof | 34th Signal Processing and Communications Applications Conference (SIU) | |
| dc.relation.publicationcategory | Konferans Öğesi - Uluslararası - Kurum Öğretim Elemanı | |
| dc.rights | info:eu-repo/semantics/openAccess | |
| dc.subject | Network Intrusion Detection | |
| dc.subject | Machine Learning | |
| dc.subject | Deep Learning | |
| dc.subject | Real-Time Deployment | |
| dc.subject | Multi-Class Attack | |
| dc.subject | CICIDS2017 | |
| dc.subject | Ağ Saldırı Tespiti | |
| dc.subject | Makine Öğrenimi | |
| dc.subject | Derin Öğrenme | |
| dc.subject | Gerçek Zamanlı Dağıtım | |
| dc.subject | Çok Sınıflı Saldırı | |
| dc.title | Multi-class network intrusion detection: Machine and deep learning benchmark with live stream deployment | |
| dc.title.alternative | Çok sınıflı ağ saldırı tespiti: Canlı akış dağıtımı ile makine ve derin öğrenme karşılaştırması | |
| dc.type | Conference Object | |
| dspace.entity.type | Publication |












