Browse State-of-the-Art › Intrusion Detection
Intrusion Detection
151 papers with code · 6 benchmarks · 9 datasets archive 2025-07-28
Intrusion Detection is the process of dynamically monitoring events occurring in a computer system or network, analyzing them for signs of possible incidents and often interdicting the unauthorized access. This is typically accomplished by automatically collecting information from a variety of systems and network sources, and then analyzing the information for possible security problems.
Description from the archive archive 2025-07-28.
Benchmarks archive 2025-07-28
6 leaderboard tables shown for this task, 6 with rows (a “benchmark” on this site is a table with at least one row, as on /sota), ordered by row count. “Best model” is the first row in the archive's own order at snapshot; nothing is re-ranked here and metric direction is not recorded in the archive. PwC's Trend sparklines are not in the archive, so that column is omitted.
| Dataset | Best model (first row in archive order) | Paper | Code | Syntology | Compare |
|---|---|---|---|---|---|
| CICIDS2017 (2 rows) | K-Nearest Neighbors | Implementing Lightweight Intrusion Detection System on Resource... | code | — | Compare |
| ^(#!@#)(()))****** (1 row) | aaaaaaaaa | A Novel SDN Dataset for Intrusion Detection in IoT Networks | code | — | Compare |
| 20NewsGroups (1 row) | intrusion detection | A Neural Network Architecture Combining Gated Recurrent Unit (GRU)... | code | — | Compare |
| CIC-DDoS (1 row) | MSTREAM-PCA | MSTREAM: Fast Anomaly Detection in Multi-Aspect Streams | code | — | Compare |
| CIC-DoS (1 row) | MSTREAM-IB | MSTREAM: Fast Anomaly Detection in Multi-Aspect Streams | code | — | Compare |
| UNSW-NB15 (1 row) | MSTREAM-AE | MSTREAM: Fast Anomaly Detection in Multi-Aspect Streams | code | — | Compare |
Syntology column: samples harvested from the paper's repositories and executed on synthesized fixtures; “ran” is not a correctness claim and does not order the table. A dash means no Syntology record for that paper, not a recorded non-run. Read from the graph 2026-09-24.
Libraries
Not in the archive: the export carries no per-task library table, so there is nothing to show at snapshot 2025-07-28.
Datasets archive 2025-07-28
9 datasets whose archive record lists this task, ordered by the archive's paper count.
Subtasks archive 2025-07-28
1 subtask in the archive's task tree.
Most implemented papers archive 2025-07-28
30 shown of 151 papers with code (800 tagged with this task in all), ordered by repositories listed in the archive, not by stars (the archive holds no stars, so PwC's “Social” and “Latest” sorts cannot be reproduced). Papers without a page here are shown as plain text.
-
8 Oct 2018 5 repositories listedIn this paper, DNNs have been utilized to predict the attacks on Network Intrusion Detection System (N-IDS).
-
10 Sep 2017 5 repositories listedConventionally, like most neural networks, both of the aforementioned RNN variants employ the Softmax function as its final output layer for its prediction, and the cross-entropy function for computing its loss.
-
30 Mar 2021 3 repositories listed Syntology ran 1 of 1 samples · 0 unverified · 1 pointer-only (licence)This paper presents a new Network Intrusion Detection System (NIDS) based on Graph Neural Networks (GNNs).
-
10 Feb 2020 3 repositories listed Syntology ran 5 of 14 samples · 9 unverifiedIn this paper, we propose a deep joint representation learning framework for anomaly detection through a dual autoencoder (AnomalyDAE), which captures the complex interactions between network structure and node…
-
25 Feb 2018 3 repositories listed Syntology ran 0 of 3 samples · 3 unverifiedIn this paper, we present Kitsune: a plug and play NIDS which can learn to detect attacks on the local network, without supervision, and in an efficient online manner.
-
17 Oct 2023 2 repositories listedPrevious research on behavior-based attack detection for networks of IoT devices has resulted in machine learning models whose ability to adapt to unseen data is limited and often not demonstrated.
-
26 Oct 2021 2 repositories listed Syntology ran 0 of 10 samples · 10 unverifiedOutlier detection (OD) is a key learning task for finding rare and deviant data samples, with many time-critical applications such as fraud detection and intrusion detection.
-
6 Feb 2021 2 repositories listedIn this paper, we present an intrusion detection method for detecting audio-video transport protocol (AVTP) stream injection attacks in automotive Ethernet-based networks.
-
27 May 2020 2 repositories listedEnsuring safety and explainability of machine learning (ML) is a topic of increasing relevance as data-driven applications venture into safety-critical application domains, traditionally committed to high safety…
-
17 Jan 2020 2 repositories listedThe Random Forest Classifier succeeds in detecting more than 95% of the botnets in 8 out of 13 scenarios and more than 55% in the most difficult datasets.
-
4 Aug 2018 2 repositories listedSecond, we develop the first open-source software for practical artificially intelligent one-shot classification systems with limited resources for the benefit of researchers in related fields.
-
9 Jun 2018 2 repositories listedThis manuscript aims to pinpoint research gaps and shortcomings of current datasets, their impact on building Network Intrusion Detection Systems (NIDS) and the growing number of sophisticated threats.
-
27 Feb 2017 2 repositories listedFor years security machine learning research has promised to obviate the need for signature based detection by automatically learning to detect indicators of attack.
-
23 May 2025 1 repository listedIn this paper, we propose a robust and reinforcement-learning-enhanced network intrusion detection system (NIDS) designed for class-imbalanced and few-shot attack scenarios in Industrial Internet of Things (IIoT)…
-
Adaptive Pruning of Deep Neural Networks for Resource-Aware Embedded Intrusion Detection on the Edge20 May 2025 1 repository listedArtificial neural network pruning is a method in which artificial neural network sizes can be reduced while attempting to preserve the predicting capabilities of the network.
-
20 May 2025 1 repository listedHere, initiating IDS requires complete reception of a CAN message from the controller, incurring data movement and software overheads.
-
12 May 2025 1 repository listedUnlike traditional methods reliant on handcrafted statistical features (NetFlow), our approach automatically learns comprehensive packet sequence representations, significantly enhancing performance in anomaly…
-
7 May 2025 1 repository listedTherefore, we recommend testing single classifiers and imbalance learning techniques for each new dataset and application involving imbalanced datasets as is the case in several cyber security applications.
-
28 Apr 2025 1 repository listedThe increased adoption of the Model Context Protocol (MCP) for AI Agents necessitates robust security for Enterprise integrations.
-
2 Apr 2025 1 repository listedThe proposed DFL framework, which is scalable and privacy-preserving, is based on a federation process that allows multiple entities to train online their local models using incoming DoH flows in real time as they are…
-
CAGN-GAT Fusion: A Hybrid Contrastive Attentive Graph Neural Network for Network Intrusion Detection2 Mar 2025 1 repository listedCybersecurity threats are growing, making network intrusion detection essential.
-
28 Feb 2025 1 repository listedIn particular, two critical challenges arise: the need for human expertise in developing AI/ML-based security mechanisms, and the threat of adversarial attacks targeting AI/ML models.
-
28 Feb 2025 1 repository listedThe transition from 5G to 6G mobile networks necessitates network automation to meet the escalating demands for high data rates, ultra-low latency, and integrated technology.
-
16 Feb 2025 1 repository listedIn this work, we investigate the potential impact of QML on cybersecurity applications of traditional ML.
-
5 Feb 2025 1 repository listedIn this paper, a dataset of IoT network traffic is presented.
-
31 Jan 2025 1 repository listedBy incorporating CRYSTALS-Kyber, the framework mitigates vulnerabilities in ECC against quantum attacks, positioning it as a quantum-resistant alternative.
-
14 Jan 2025 1 repository listedNew research focuses on creating artificial intelligence (AI) solutions for network intrusion detection systems (NIDS), drawing its inspiration from the ever-growing number of intrusions on networked systems, increasing…
-
20 Dec 2024 1 repository listedOur approach features a strategic sample selection algorithm to select representative new samples and a strategic forgetting mechanism to drop outdated samples.
-
11 Dec 2024 1 repository listed Syntology ran 1 of 1 samples · 0 unverifiedOutlier detection (OD), also known as anomaly detection, is a critical machine learning (ML) task with applications in fraud detection, network intrusion detection, clickstream analysis, recommendation systems, and…
-
29 Oct 2024 1 repository listedIntrusion detection system (IDS) is a piece of hardware or software that looks for malicious activity or policy violations in a network.
Syntology lines on 5 of the papers shown; no Syntology record for the others (a paper without an arXiv id cannot be joined to the graph, and absence from the graph layer is not a recorded non-run). “Ran” means the sample executed on a synthesized fixture, not that the paper's result was reproduced. Read from the graph 2026-09-24.
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections