{"url":"/task/intrusion-detection","name":"Intrusion Detection","slug":"intrusion-detection","description_markdown":"**Intrusion Detection** is the process of dynamically monitoring events occurring in a computer system or network, analyzing them for signs of possible incidents and often interdicting the unauthorized access. This is typically accomplished by automatically collecting information from a variety of systems and network sources, and then analyzing the information for possible security problems.\r\n\r\n\r\n<span class=\"description-source\">Source: [Machine Learning Techniques for Intrusion Detection ](https://arxiv.org/abs/1312.2177)</span>","categories":[{"name":"Miscellaneous","url":"/area/miscellaneous"},{"name":"Natural Language Processing","url":"/area/natural-language-processing"}],"source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","slug_source":"archive_url"},"counts":{"papers_tagged":800,"papers_with_code":151,"benchmarks":6,"benchmark_tables_in_archive":6,"benchmark_tables_shown":6,"benchmark_tables_withheld_as_spam":0,"benchmark_definition":"a leaderboard table with at least one row; benchmark_tables_shown also counts the zero-row tables; benchmark_tables_in_archive adds the tables withheld as spam","datasets":9,"subtasks":1,"parent_tasks":0},"benchmarks":[{"leaderboard":"/sota/intrusion-detection-on-cicids2017","slug":"intrusion-detection-on-cicids2017","dataset":"CICIDS2017","dataset_url":"/dataset/cicids2017","rows_in_archive":2,"metrics":["Accuracy (%)","F1 Score (Macro Avg)","Precision (Macro Avg)","Recall (Macro Avg)"],"first_row_in_archive_order":{"model":"K-Nearest Neighbors","paper_title":"Implementing Lightweight Intrusion Detection System on Resource Constrained Devices","paper_url":"/paper/implementing-lightweight-intrusion-detection","paper_date":"2024-10-28","arxiv_id":null,"code_links":[{"title":"rylandtikes/Lightweight-IDS","url":"https://github.com/rylandtikes/Lightweight-IDS"}],"syntology":null}},{"leaderboard":"/sota/intrusion-detection-on","slug":"intrusion-detection-on","dataset":"^(#$!@#$)(()))******","dataset_url":null,"rows_in_archive":1,"metrics":["0..5sec"],"first_row_in_archive_order":{"model":"aaaaaaaaa","paper_title":"A Novel SDN Dataset for Intrusion Detection in IoT Networks","paper_url":"/paper/a-noval-sdn-dataset-for-intrusion-detection","paper_date":"2020-06-16","arxiv_id":null,"code_links":[{"title":"AlperKaan35/SDN-Dataset","url":"https://github.com/AlperKaan35/SDN-Dataset"}],"syntology":null}},{"leaderboard":"/sota/intrusion-detection-on-20newsgroups","slug":"intrusion-detection-on-20newsgroups","dataset":"20NewsGroups","dataset_url":"/dataset/20newsgroups","rows_in_archive":1,"metrics":["Actions Top-1 (S2)"],"first_row_in_archive_order":{"model":"intrusion detection","paper_title":"A Neural Network Architecture Combining Gated Recurrent Unit (GRU) and Support Vector Machine (SVM) for Intrusion Detection in Network Traffic Data","paper_url":"/paper/a-neural-network-architecture-combining-gated","paper_date":"2017-09-10","arxiv_id":"1709.03082","code_links":[{"title":"AFAgarap/cnn-svm","url":"https://github.com/AFAgarap/cnn-svm"},{"title":"AFAgarap/malware-classification","url":"https://github.com/AFAgarap/malware-classification"},{"title":"AFAgarap/gru-svm","url":"https://github.com/AFAgarap/gru-svm"},{"title":"AFAgarap/wisconsin-breast-cancer","url":"https://github.com/AFAgarap/wisconsin-breast-cancer"},{"title":"da-moon/classifiers-monorepo","url":"https://github.com/da-moon/classifiers-monorepo"}],"syntology":null}},{"leaderboard":"/sota/intrusion-detection-on-cic-ddos","slug":"intrusion-detection-on-cic-ddos","dataset":"CIC-DDoS","dataset_url":"/dataset/cic","rows_in_archive":1,"metrics":["AUC"],"first_row_in_archive_order":{"model":"MSTREAM-PCA","paper_title":"MSTREAM: Fast Anomaly Detection in Multi-Aspect Streams","paper_url":"/paper/mstream-fast-streaming-multi-aspect-group","paper_date":"2020-09-17","arxiv_id":"2009.08451","code_links":[{"title":"Stream-AD/MStream","url":"https://github.com/Stream-AD/MStream"}],"syntology":null}},{"leaderboard":"/sota/intrusion-detection-on-cic-dos","slug":"intrusion-detection-on-cic-dos","dataset":"CIC-DoS","dataset_url":"/dataset/cic","rows_in_archive":1,"metrics":["AUC"],"first_row_in_archive_order":{"model":"MSTREAM-IB","paper_title":"MSTREAM: Fast Anomaly Detection in Multi-Aspect Streams","paper_url":"/paper/mstream-fast-streaming-multi-aspect-group","paper_date":"2020-09-17","arxiv_id":"2009.08451","code_links":[{"title":"Stream-AD/MStream","url":"https://github.com/Stream-AD/MStream"}],"syntology":null}},{"leaderboard":"/sota/intrusion-detection-on-unsw-nb15","slug":"intrusion-detection-on-unsw-nb15","dataset":"UNSW-NB15","dataset_url":"/dataset/unsw-nb15","rows_in_archive":1,"metrics":["AUC"],"first_row_in_archive_order":{"model":"MSTREAM-AE","paper_title":"MSTREAM: Fast Anomaly Detection in Multi-Aspect Streams","paper_url":"/paper/mstream-fast-streaming-multi-aspect-group","paper_date":"2020-09-17","arxiv_id":"2009.08451","code_links":[{"title":"Stream-AD/MStream","url":"https://github.com/Stream-AD/MStream"}],"syntology":null}}],"datasets":[{"url":"/dataset/unsw-nb15","name":"UNSW-NB15","full_name":"UNSQ-NB15","num_papers_in_archive":156},{"url":"/dataset/20newsgroups","name":"20NewsGroups","full_name":"","num_papers_in_archive":20},{"url":"/dataset/cicids2017","name":"CICIDS2017","full_name":"Intrusion Detection Evaluation Dataset (CIC-IDS2017)","num_papers_in_archive":18},{"url":"/dataset/edge-iiotset","name":"EDGE-IIOTSET","full_name":"A NEW COMPREHENSIVE REALISTIC CYBER SECURITY DATASET OF IOT AND IIOT APPLICATIONS: CENTRALIZED AND FEDERATED LEARNING","num_papers_in_archive":4},{"url":"/dataset/kitsune-network-attack-dataset","name":"Kitsune Network Attack Dataset","full_name":"","num_papers_in_archive":4},{"url":"/dataset/iot-network-intrusion-dataset","name":"IoT Network Intrusion Dataset","full_name":"","num_papers_in_archive":3},{"url":"/dataset/cic","name":"CIC","full_name":"Catalonia Independence Corpus","num_papers_in_archive":2},{"url":"/dataset/arinc-429-voltage-data","name":"ARINC 429 Voltage Data","full_name":"","num_papers_in_archive":1},{"url":"/dataset/iot-environment-dataset","name":"IoT ENVIRONMENT DATASET","full_name":"","num_papers_in_archive":1}],"subtasks":[{"url":"/task/network-intrusion-detection","name":"Network Intrusion Detection"}],"parent_tasks":[],"papers":{"order":"repositories listed in the archive (desc), then date (desc); the archive holds no stars","population":"papers tagged with this task that list at least one repository in the archive","shown":30,"of":151,"tagged_in_all":800,"items":[{"url":"/paper/evaluating-shallow-and-deep-neural-networks","title":"Evaluating Shallow and Deep Neural Networks for Network Intrusion Detection Systems in Cyber Security","date":"2018-10-08","arxiv_id":null,"repositories_listed":5,"syntology":null},{"url":"/paper/a-neural-network-architecture-combining-gated","title":"A Neural Network Architecture Combining Gated Recurrent Unit (GRU) and Support Vector Machine (SVM) for Intrusion Detection in Network Traffic Data","date":"2017-09-10","arxiv_id":"1709.03082","repositories_listed":5,"syntology":null},{"url":"/paper/e-graphsage-a-graph-neural-network-based","title":"E-GraphSAGE: A Graph Neural Network based Intrusion Detection System for IoT","date":"2021-03-30","arxiv_id":"2103.16329","repositories_listed":3,"syntology":{"n":1,"n_ran":1,"n_unverified":0,"n_pointer_only":1}},{"url":"/paper/anomalydae-dual-autoencoder-for-anomaly","title":"AnomalyDAE: Dual autoencoder for anomaly detection on attributed networks","date":"2020-02-10","arxiv_id":"2002.03665","repositories_listed":3,"syntology":{"n":14,"n_ran":5,"n_unverified":9,"n_pointer_only":0}},{"url":"/paper/kitsune-an-ensemble-of-autoencoders-for","title":"Kitsune: An Ensemble of Autoencoders for Online Network Intrusion Detection","date":"2018-02-25","arxiv_id":"1802.09089","repositories_listed":3,"syntology":{"n":3,"n_ran":0,"n_unverified":3,"n_pointer_only":0}},{"url":"/paper/iotgem-generalizable-models-for-behaviour","title":"IoTGeM: Generalizable Models for Behaviour-Based IoT Attack Detection","date":"2023-10-17","arxiv_id":"2401.01343","repositories_listed":2,"syntology":null},{"url":"/paper/tod-tensor-based-outlier-detection","title":"TOD: GPU-accelerated Outlier Detection via Tensor Operations","date":"2021-10-26","arxiv_id":"2110.14007","repositories_listed":2,"syntology":{"n":10,"n_ran":0,"n_unverified":10,"n_pointer_only":0}},{"url":"/paper/convolutional-neural-network-based-intrusion","title":"Convolutional Neural Network-based Intrusion Detection System for AVTP Streams in Automotive Ethernet-based Networks","date":"2021-02-06","arxiv_id":"2102.03546","repositories_listed":2,"syntology":null},{"url":"/paper/safeml-safety-monitoring-of-machine-learning","title":"SafeML: Safety Monitoring of Machine Learning Classifiers through Statistical Difference Measure","date":"2020-05-27","arxiv_id":"2005.13166","repositories_listed":2,"syntology":null},{"url":"/paper/cyber-attack-detection-thanks-to-machine","title":"Cyber Attack Detection thanks to Machine Learning Algorithms","date":"2020-01-17","arxiv_id":"2001.06309","repositories_listed":2,"syntology":null},{"url":"/paper/deep-reinforcement-one-shot-learning-for","title":"Deep Reinforcement One-Shot Learning for Artificially Intelligent Classification Systems","date":"2018-08-04","arxiv_id":"1808.01527","repositories_listed":2,"syntology":null},{"url":"/paper/a-taxonomy-and-survey-of-intrusion-detection","title":"A Taxonomy of Network Threats and the Effect of Current Datasets on Intrusion Detection Systems","date":"2018-06-09","arxiv_id":"1806.03517","repositories_listed":2,"syntology":null},{"url":"/paper/expose-a-character-level-convolutional-neural","title":"eXpose: A Character-Level Convolutional Neural Network with Embeddings For Detecting Malicious URLs, File Paths and Registry Keys","date":"2017-02-27","arxiv_id":"1702.08568","repositories_listed":2,"syntology":null},{"url":"/paper/a-robust-ppo-optimized-tabular-transformer","title":"A Robust PPO-optimized Tabular Transformer Framework for Intrusion Detection in Industrial IoT Systems","date":"2025-05-23","arxiv_id":"2505.18234","repositories_listed":1,"syntology":null},{"url":"/paper/adaptive-pruning-of-deep-neural-networks-for","title":"Adaptive Pruning of Deep Neural Networks for Resource-Aware Embedded Intrusion Detection on the Edge","date":"2025-05-20","arxiv_id":"2505.14592","repositories_listed":1,"syntology":null},{"url":"/paper/seccan-an-extended-can-controller-with","title":"SecCAN: An Extended CAN Controller with Embedded Intrusion Detection","date":"2025-05-20","arxiv_id":"2505.14924","repositories_listed":1,"syntology":null},{"url":"/paper/self-supervised-transformer-based-contrastive","title":"Self-Supervised Transformer-based Contrastive Learning for Intrusion Detection Systems","date":"2025-05-12","arxiv_id":"2505.08816","repositories_listed":1,"syntology":null},{"url":"/paper/cyber-security-data-science-machine-learning","title":"Cyber Security Data Science: Machine Learning Methods and their Performance on Imbalanced Datasets","date":"2025-05-07","arxiv_id":"2505.04204","repositories_listed":1,"syntology":null},{"url":"/paper/simplified-and-secure-mcp-gateways-for","title":"Simplified and Secure MCP Gateways for Enterprise AI Integration","date":"2025-04-28","arxiv_id":"2504.19997","repositories_listed":1,"syntology":null},{"url":"/paper/co-defend-continuous-decentralized-federated","title":"CO-DEFEND: Continuous Decentralized Federated Learning for Secure DoH-Based Threat Detection","date":"2025-04-02","arxiv_id":"2504.01882","repositories_listed":1,"syntology":null},{"url":"/paper/cagn-gat-fusion-a-hybrid-contrastive","title":"CAGN-GAT Fusion: A Hybrid Contrastive Attentive Graph Neural Network for Network Intrusion Detection","date":"2025-03-02","arxiv_id":"2503.00961","repositories_listed":1,"syntology":null},{"url":"/paper/enabling-automl-for-zero-touch-network","title":"Enabling AutoML for Zero-Touch Network Security: Use-Case Driven Analysis","date":"2025-02-28","arxiv_id":"2502.21286","repositories_listed":1,"syntology":null},{"url":"/paper/towards-zero-touch-networks-cross-layer","title":"Towards Zero Touch Networks: Cross-Layer Automated Security Solutions for 6G Wireless Networks","date":"2025-02-28","arxiv_id":"2502.20627","repositories_listed":1,"syntology":null},{"url":"/paper/evaluating-the-potential-of-quantum-machine","title":"Evaluating the Potential of Quantum Machine Learning in Cybersecurity: A Case-Study on PCA-based Intrusion Detection Systems","date":"2025-02-16","arxiv_id":"2502.11173","repositories_listed":1,"syntology":null},{"url":"/paper/gotham-dataset-2025-a-reproducible-large","title":"Gotham Dataset 2025: A Reproducible Large-Scale IoT Network Dataset for Intrusion Detection and Security Research","date":"2025-02-05","arxiv_id":"2502.03134","repositories_listed":1,"syntology":null},{"url":"/paper/secured-communication-schemes-for-uavs-in-5g","title":"Secured Communication Schemes for UAVs in 5G: CRYSTALS-Kyber and IDS","date":"2025-01-31","arxiv_id":"2501.19191","repositories_listed":1,"syntology":null},{"url":"/paper/a-comparative-analysis-of-dnn-based-white-box","title":"A Comparative Analysis of DNN-based White-Box Explainable AI Methods in Network Security","date":"2025-01-14","arxiv_id":"2501.07801","repositories_listed":1,"syntology":null},{"url":"/paper/continual-learning-with-strategic-selection","title":"Continual Learning with Strategic Selection and Forgetting for Network Intrusion Detection","date":"2024-12-20","arxiv_id":"2412.16264","repositories_listed":1,"syntology":null},{"url":"/paper/pyod-2-a-python-library-for-outlier-detection","title":"PyOD 2: A Python Library for Outlier Detection with LLM-powered Model Selection","date":"2024-12-11","arxiv_id":"2412.12154","repositories_listed":1,"syntology":{"n":1,"n_ran":1,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/scgnet-stacked-convolution-with-gated","title":"SCGNet-Stacked Convolution with Gated Recurrent Unit Network for Cyber Network Intrusion Detection and Intrusion Type Classification","date":"2024-10-29","arxiv_id":"2410.21873","repositories_listed":1,"syntology":null}],"syntology_records":5,"syntology_note":"a paper without a record is not a recorded non-run: it may lack an arXiv id or simply be absent from the graph layer"},"description_links":{"kept":0,"unwrapped_to_text":0,"bare_urls_linked":0,"relative_images_dropped":0,"rule":"internal links are kept only when the target slug exists in the catalog"},"syntology":{"read_at":"2026-09-24T18:15:14+00:00","claim":"Per-sample execution status on synthesized fixtures ('ran N of M samples'); not a correctness claim and not a ranking signal.","status_vocabulary":{"ran_honours":"ran, honoured the contract we drafted","ran_violates":"ran, violated the contract we drafted","ran_draft_wrong":"ran; our contract draft was wrong, not the code","ran_fixture":"ran; our fixture could not drive it","ran":"ran on a synthesized input","unverified":"unverified (harvested, no recorded run)"}},"not_shown":{"libraries":"the archive has no per-task library table","trend_sparklines":"the Trend column of the benchmarks table was a rendered image; it is not in the archive","social_and_latest_sorts":"stars and social signals are not in the archive"}}