<p>The growing complexity and frequency of cyber threats in cloud and IoT environments necessitate the design of advanced, adaptive Intrusion Detection Systems (IDSs) that can transcend the limitations of traditional approaches. Conventional IDS frameworks typically rely on static models that fail to adapt to evolving attack patterns and often lack interpretability, thereby diminishing their practical effectiveness. To confront these challenges, we introduce MF2S-CID, a novel multi-model IDS framework that dynamically selects the most suitable classifier for each attack type in real-time. This dynamic selection mechanism significantly enhances detection accuracy, adaptability, and interpretability compared to fixed classifier or ensemble-based methods. MF2S-CID further addresses the critical issue of class imbalance by incorporating the Stratified Synthetic Minority Oversampling Technique (SSMOTE), which maintains the underlying feature distribution to improve the detection of rare and sophisticated threats. To promote transparency and user trust, the framework integrates a dual-layer explainability approach using Explainable Artificial Intelligence (XAI), offering both global and local interpretive insights into model decisions. Extensive evaluations in six benchmark datasets reveal that MF2S-CID consistently achieves detection accuracies that exceed 99%, while maintaining minimal inference latency and showing strong scalability. Its reliability is further validated by Cohen’s Kappa analysis, confirming robust performance in real-world deployments in both resource-constrained IoT systems and scalable cloud infrastructures. These findings establish MF2S-CID as a novel, robust, interpretable, and efficient solution that effectively addresses the complex challenges posed by modern cybersecurity intrusion detection.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

MF2S-CID: A dynamic multi-model framework for scalable and interpretable intrusion detection

  • Saida Farhat,
  • Ahmed Patel,
  • Ana Luiza Bessa Barros,
  • Alwi M Bamhdi

摘要

The growing complexity and frequency of cyber threats in cloud and IoT environments necessitate the design of advanced, adaptive Intrusion Detection Systems (IDSs) that can transcend the limitations of traditional approaches. Conventional IDS frameworks typically rely on static models that fail to adapt to evolving attack patterns and often lack interpretability, thereby diminishing their practical effectiveness. To confront these challenges, we introduce MF2S-CID, a novel multi-model IDS framework that dynamically selects the most suitable classifier for each attack type in real-time. This dynamic selection mechanism significantly enhances detection accuracy, adaptability, and interpretability compared to fixed classifier or ensemble-based methods. MF2S-CID further addresses the critical issue of class imbalance by incorporating the Stratified Synthetic Minority Oversampling Technique (SSMOTE), which maintains the underlying feature distribution to improve the detection of rare and sophisticated threats. To promote transparency and user trust, the framework integrates a dual-layer explainability approach using Explainable Artificial Intelligence (XAI), offering both global and local interpretive insights into model decisions. Extensive evaluations in six benchmark datasets reveal that MF2S-CID consistently achieves detection accuracies that exceed 99%, while maintaining minimal inference latency and showing strong scalability. Its reliability is further validated by Cohen’s Kappa analysis, confirming robust performance in real-world deployments in both resource-constrained IoT systems and scalable cloud infrastructures. These findings establish MF2S-CID as a novel, robust, interpretable, and efficient solution that effectively addresses the complex challenges posed by modern cybersecurity intrusion detection.