Browse State-of-the-Art › Network Intrusion Detection
Network Intrusion Detection
67 papers with code · 6 benchmarks · 14 datasets archive 2025-07-28
Network intrusion detection is the task of monitoring network traffic to and from all devices on a network in order to detect computer attacks.
Description from the archive archive 2025-07-28.
Benchmarks archive 2025-07-28
6 leaderboard tables shown for this task, 6 with rows (a “benchmark” on this site is a table with at least one row, as on /sota), ordered by row count. “Best model” is the first row in the archive's own order at snapshot; nothing is re-ranked here and metric direction is not recorded in the archive. PwC's Trend sparklines are not in the archive, so that column is omitted.
| Dataset | Best model (first row in archive order) | Paper | Code | Syntology | Compare |
|---|---|---|---|---|---|
| CICIDS2017 (5 rows) | OC-SVM / RF | A Novel Multi-Stage Approach for Hierarchical Intrusion Detection | code | — | Compare |
| UNSW-NB15 (2 rows) | Edge-Detect-FRNN | Edge-Detect: Edge-centric Network Intrusion Detection using Deep... | code | — | Compare |
| KDD (1 row) | DNN-3 | Evaluating Shallow and Deep Neural Networks for Network Intrusion... | code | — | Compare |
| NB15-Backdoor (1 row) | DevNet | Deep Anomaly Detection with Deviation Networks | code | — | Compare |
| SIDD-Image (1 row) | Segmented-FL | Intrusion Detection with Segmented Federated Learning for... | code | — | Compare |
| ToN_IoT (1 row) | PPO optimized TabTransformer | A Robust PPO-optimized Tabular Transformer Framework for Intrusion... | code | — | Compare |
Syntology column: samples harvested from the paper's repositories and executed on synthesized fixtures; “ran” is not a correctness claim and does not order the table. A dash means no Syntology record for that paper, not a recorded non-run. Read from the graph 2026-09-24.
Libraries
Not in the archive: the export carries no per-task library table, so there is nothing to show at snapshot 2025-07-28.
Datasets archive 2025-07-28
14 datasets whose archive record lists this task, ordered by the archive's paper count.
Subtasks archive 2025-07-28
No subtask under this task in the archive's task tree.
Parent tasks archive 2025-07-28
Most implemented papers archive 2025-07-28
30 shown of 67 papers with code (261 tagged with this task in all), ordered by repositories listed in the archive, not by stars (the archive holds no stars, so PwC's “Social” and “Latest” sorts cannot be reproduced). Papers without a page here are shown as plain text.
-
19 Nov 2019 6 repositories listedInstead of representation learning, our method fulfills an end-to-end learning of anomaly scores by a neural deviation learning, in which we leverage a few (e.
-
8 Oct 2018 5 repositories listedIn this paper, DNNs have been utilized to predict the attacks on Network Intrusion Detection System (N-IDS).
-
30 Mar 2021 3 repositories listed Syntology ran 1 of 1 samples · 0 unverified · 1 pointer-only (licence)This paper presents a new Network Intrusion Detection System (NIDS) based on Graph Neural Networks (GNNs).
-
10 Feb 2020 3 repositories listed Syntology ran 5 of 14 samples · 9 unverifiedIn this paper, we propose a deep joint representation learning framework for anomaly detection through a dual autoencoder (AnomalyDAE), which captures the complex interactions between network structure and node…
-
13 Jun 2018 3 repositories listed Syntology ran 5 of 5 samples · 0 unverified · 5 pointer-only (licence)However, existing unsupervised representation learning methods mainly focus on preserving the data regularity information and learning the representations independently of subsequent outlier detection methods, which can…
-
25 Feb 2018 3 repositories listed Syntology ran 0 of 3 samples · 3 unverifiedIn this paper, we present Kitsune: a plug and play NIDS which can learn to detect attacks on the local network, without supervision, and in an efficient online manner.
-
17 Oct 2023 2 repositories listedPrevious research on behavior-based attack detection for networks of IoT devices has resulted in machine learning models whose ability to adapt to unseen data is limited and often not demonstrated.
-
Synthesis of a Machine Learning Model for Detecting Computer Attacks Based on the CICIDS2017 Dataset1 Jan 2020 2 repositories listedThe conclusion was made that it is possible to use machine learning methods to detect computer attacks taking into account these limitations.
-
9 Jun 2018 2 repositories listedThis manuscript aims to pinpoint research gaps and shortcomings of current datasets, their impact on building Network Intrusion Detection Systems (NIDS) and the growing number of sophisticated threats.
-
23 May 2025 1 repository listedIn this paper, we propose a robust and reinforcement-learning-enhanced network intrusion detection system (NIDS) designed for class-imbalanced and few-shot attack scenarios in Industrial Internet of Things (IIoT)…
-
CAGN-GAT Fusion: A Hybrid Contrastive Attentive Graph Neural Network for Network Intrusion Detection2 Mar 2025 1 repository listedCybersecurity threats are growing, making network intrusion detection essential.
-
16 Feb 2025 1 repository listedIn this work, we investigate the potential impact of QML on cybersecurity applications of traditional ML.
-
14 Jan 2025 1 repository listedNew research focuses on creating artificial intelligence (AI) solutions for network intrusion detection systems (NIDS), drawing its inspiration from the ever-growing number of intrusions on networked systems, increasing…
-
20 Dec 2024 1 repository listedOur approach features a strategic sample selection algorithm to select representative new samples and a strategic forgetting mechanism to drop outdated samples.
-
11 Dec 2024 1 repository listed Syntology ran 1 of 1 samples · 0 unverifiedOutlier detection (OD), also known as anomaly detection, is a critical machine learning (ML) task with applications in fraud detection, network intrusion detection, clickstream analysis, recommendation systems, and…
-
29 Oct 2024 1 repository listedIntrusion detection system (IDS) is a piece of hardware or software that looks for malicious activity or policy violations in a network.
-
28 Oct 2024 1 repository listedThe rapid growth of Internet of Things (IoT) devices has increased the risk of network intrusions, which need effective security solutions for devices with low computational capability.
-
21 Oct 2024 1 repository listedOur framework encompasses the loading of input datasets, training of individual models and ensemble methods, and the generation of evaluation metrics.
-
18 Oct 2024 1 repository listedThis approach enhances the performance of intrusion detection by effectively representing normal network data and accurately identifying anomalies in the decentralized strategy.
-
14 Oct 2024 1 repository listedExplainability and evaluation of AI models are crucial parts of the security of modern intrusion detection systems (IDS) in the network security field, yet they are lacking.
-
6 Oct 2024 1 repository listed Syntology ran 12 of 13 samples · 1 unverifiedData valuation is a class of techniques for quantitatively assessing the value of data for applications like pricing in data marketplaces.
-
27 Sep 2024 1 repository listedThis demonstrates the effectiveness of EnCNN in real-time network intrusion detection, offering a robust solution for identifying and mitigating security threats, and enhancing overall network resilience.
-
27 Aug 2024 1 repository listedThis paper introduces "XG-NID," a novel framework that, to the best of our knowledge, is the first to fuse flow-level and packet-level data within a heterogeneous graph structure, offering a comprehensive analysis of…
-
25 Jun 2024 1 repository listedThe escalating sophistication of cyberattacks has encouraged the integration of machine learning techniques in intrusion detection systems, but the rise of adversarial examples presents a significant challenge.
-
7 Jun 2024 1 repository listedFPGAs have distinct advantages as a technology for deploying deep neural networks (DNNs) at the edge.
-
8 May 2024 1 repository listed Syntology ran 3 of 3 samples · 0 unverifiedOverall, our survey provides a comprehensive overview of the current state-of-the-art in LLM4Security and identifies several promising directions for future research.
-
18 Mar 2024 1 repository listedMachine Learning (ML) algorithms have become increasingly popular for supporting Network Intrusion Detection Systems (NIDS).
-
3 Mar 2024 1 repository listedTo the best of our knowledge, it is the first GNN-based self-supervised method for the multiclass classification of network flows in NIDS.
-
15 Feb 2024 1 repository listedThe results show nearly perfect classification performance when the models are trained and tested on the same dataset.
-
13 Jan 2024 1 repository listedThe CNN-BiLSTM neural network is synthesized to assess the applicability of deep learning methods for intrusion detection.
Syntology lines on 7 of the papers shown; no Syntology record for the others (a paper without an arXiv id cannot be joined to the graph, and absence from the graph layer is not a recorded non-run). “Ran” means the sample executed on a synthesized fixture, not that the paper's result was reproduced. Read from the graph 2026-09-24.
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections