{"url":"/task/network-intrusion-detection","name":"Network Intrusion Detection","slug":"network-intrusion-detection","description_markdown":"**Network intrusion detection** is the task of monitoring network traffic to and from all devices on a network in order to detect computer attacks.","categories":[{"name":"Miscellaneous","url":"/area/miscellaneous"},{"name":"Natural Language Processing","url":"/area/natural-language-processing"}],"source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","slug_source":"archive_url"},"counts":{"papers_tagged":261,"papers_with_code":67,"benchmarks":6,"benchmark_tables_in_archive":6,"benchmark_tables_shown":6,"benchmark_tables_withheld_as_spam":0,"benchmark_definition":"a leaderboard table with at least one row; benchmark_tables_shown also counts the zero-row tables; benchmark_tables_in_archive adds the tables withheld as spam","datasets":14,"subtasks":0,"parent_tasks":1},"benchmarks":[{"leaderboard":"/sota/network-intrusion-detection-on-cicids2017","slug":"network-intrusion-detection-on-cicids2017","dataset":"CICIDS2017","dataset_url":"/dataset/cicids2017","rows_in_archive":5,"metrics":["Avg F1","Precision","Recall"],"first_row_in_archive_order":{"model":"OC-SVM / RF","paper_title":"A Novel Multi-Stage Approach for Hierarchical Intrusion Detection","paper_url":"/paper/a-novel-multi-stage-approach-for-hierarchical","paper_date":"2023-03-21","arxiv_id":null,"code_links":[{"title":"mverkerk/multi-stage-hierarchical-ids","url":"https://gitlab.ilabt.imec.be/mverkerk/multi-stage-hierarchical-ids"}],"syntology":null}},{"leaderboard":"/sota/network-intrusion-detection-on-unsw-nb15","slug":"network-intrusion-detection-on-unsw-nb15","dataset":"UNSW-NB15","dataset_url":"/dataset/unsw-nb15","rows_in_archive":2,"metrics":["Accuracy","Precision","Recall"],"first_row_in_archive_order":{"model":"Edge-Detect-FRNN","paper_title":"Edge-Detect: Edge-centric Network Intrusion Detection using Deep Neural Network","paper_url":"/paper/edge-detect-edge-centric-network-intrusion","paper_date":"2021-02-03","arxiv_id":"2102.01873","code_links":[{"title":"racsa-lab/EDD","url":"https://github.com/racsa-lab/EDD"}],"syntology":null}},{"leaderboard":"/sota/network-intrusion-detection-on-kdd","slug":"network-intrusion-detection-on-kdd","dataset":"KDD","dataset_url":null,"rows_in_archive":1,"metrics":["Accuracy"],"first_row_in_archive_order":{"model":"DNN-3","paper_title":"Evaluating Shallow and Deep Neural Networks for Network Intrusion Detection Systems in Cyber Security","paper_url":"/paper/evaluating-shallow-and-deep-neural-networks","paper_date":"2018-10-08","arxiv_id":null,"code_links":[{"title":"rahulvigneswaran/Intrusion-Detection-Systems","url":"https://github.com/rahulvigneswaran/Intrusion-Detection-Systems"},{"title":"jackaduma/NLP4CyberSecurity","url":"https://github.com/jackaduma/NLP4CyberSecurity"},{"title":"Wphackedhelp/PHP-backdoors","url":"https://github.com/Wphackedhelp/PHP-backdoors"},{"title":"Wphackedhelp/Wordpress-scanner","url":"https://github.com/Wphackedhelp/Wordpress-scanner"},{"title":"larsonreever/awesome-malware-analysis","url":"https://github.com/larsonreever/awesome-malware-analysis"}],"syntology":null}},{"leaderboard":"/sota/network-intrusion-detection-on-nb15-backdoor","slug":"network-intrusion-detection-on-nb15-backdoor","dataset":"NB15-Backdoor","dataset_url":null,"rows_in_archive":1,"metrics":["AUC","Average Precision"],"first_row_in_archive_order":{"model":"DevNet","paper_title":"Deep Anomaly Detection with Deviation Networks","paper_url":"/paper/deep-anomaly-detection-with-deviation","paper_date":"2019-11-19","arxiv_id":"1911.08623","code_links":[{"title":"xuhongzuo/DeepOD","url":"https://github.com/xuhongzuo/DeepOD"},{"title":"GuansongPang/deviation-network","url":"https://github.com/GuansongPang/deviation-network"},{"title":"Ryosaeba8/Anomaly_detection","url":"https://github.com/Ryosaeba8/Anomaly_detection"},{"title":"robeespi/Deep-Semi-supervised-intrusion-detection-on-Hadoop-distributed-file-system-log","url":"https://github.com/robeespi/Deep-Semi-supervised-intrusion-detection-on-Hadoop-distributed-file-system-log"},{"title":"robeespi/Deep-Semi-supervised-intrusion-detection-on-unstructured-Hadoop-distributed-file-system-logs","url":"https://github.com/robeespi/Deep-Semi-supervised-intrusion-detection-on-unstructured-Hadoop-distributed-file-system-logs"},{"title":"robeespi/Weakly-Supervised-Malware-Detection","url":"https://github.com/robeespi/Weakly-Supervised-Malware-Detection"}],"syntology":null}},{"leaderboard":"/sota/network-intrusion-detection-on-sidd-a-large","slug":"network-intrusion-detection-on-sidd-a-large","dataset":"SIDD-Image","dataset_url":"/dataset/sidd-network","rows_in_archive":1,"metrics":["F1 Score"],"first_row_in_archive_order":{"model":"Segmented-FL","paper_title":"Intrusion Detection with Segmented Federated Learning for Large-Scale Multiple LANs","paper_url":"/paper/intrusion-detection-with-segmented-federated","paper_date":"2020-09-28","arxiv_id":null,"code_links":[{"title":"yuweisunn/segmented-FL","url":"https://github.com/yuweisunn/segmented-FL"}],"syntology":null}},{"leaderboard":"/sota/network-intrusion-detection-on-ton-iot","slug":"network-intrusion-detection-on-ton-iot","dataset":"ToN_IoT","dataset_url":"/dataset/ton-iot","rows_in_archive":1,"metrics":["Average Class Accuracy"],"first_row_in_archive_order":{"model":"PPO optimized TabTransformer","paper_title":"A Robust PPO-optimized Tabular Transformer Framework for Intrusion Detection in Industrial IoT Systems","paper_url":"/paper/a-robust-ppo-optimized-tabular-transformer","paper_date":"2025-05-23","arxiv_id":"2505.18234","code_links":[{"title":"RussellTNY/PPO-optimized-Tab-Transformer-for-NIDS-on-TON_IoT","url":"https://github.com/RussellTNY/PPO-optimized-Tab-Transformer-for-NIDS-on-TON_IoT"}],"syntology":null}}],"datasets":[{"url":"/dataset/unsw-nb15","name":"UNSW-NB15","full_name":"UNSQ-NB15","num_papers_in_archive":156},{"url":"/dataset/cicids2017","name":"CICIDS2017","full_name":"Intrusion Detection Evaluation Dataset (CIC-IDS2017)","num_papers_in_archive":18},{"url":"/dataset/ton-iot","name":"ToN_IoT","full_name":"","num_papers_in_archive":8},{"url":"/dataset/edge-iiotset","name":"EDGE-IIOTSET","full_name":"A NEW COMPREHENSIVE REALISTIC CYBER SECURITY DATASET OF IOT AND IIOT APPLICATIONS: CENTRALIZED AND FEDERATED LEARNING","num_papers_in_archive":4},{"url":"/dataset/kitsune-network-attack-dataset","name":"Kitsune Network Attack Dataset","full_name":"","num_papers_in_archive":4},{"url":"/dataset/iot-network-intrusion-dataset","name":"IoT Network Intrusion Dataset","full_name":"","num_papers_in_archive":3},{"url":"/dataset/sidd-network","name":"SIDD-Image","full_name":"Segmented Intrusion Detection Dataset","num_papers_in_archive":3},{"url":"/dataset/cic-iot-dataset-2022","name":"CIC IoT Dataset 2022","full_name":"","num_papers_in_archive":2},{"url":"/dataset/iot-benign-and-attack-traces","name":"IoT Benign and Attack Traces","full_name":"IoT Benign and Attack Traces -  Data Collected for ACM SOSR 2019","num_papers_in_archive":2},{"url":"/dataset/iot-environment-dataset","name":"IoT ENVIRONMENT DATASET","full_name":"","num_papers_in_archive":1},{"url":"/dataset/uq-netflow-nids-v1","name":"UQ NetFlow NIDS v1","full_name":"Machine Learning-Based NIDS Datasets","num_papers_in_archive":1},{"url":"/dataset/uq-nids-datasets","name":"UQ NIDS Datasets","full_name":"Machine Learning-Based NIDS Datasets","num_papers_in_archive":1},{"url":"/dataset/uq-nids-datasets-flowmeter-format","name":"UQ NIDS Datasets (FlowMeter Format)","full_name":"Machine Learning-Based NIDS Datasets","num_papers_in_archive":1},{"url":"/dataset/web-ids23-dataset","name":"WEB-IDS23 Dataset","full_name":"","num_papers_in_archive":1}],"subtasks":[],"parent_tasks":[{"url":"/task/intrusion-detection","name":"Intrusion Detection"}],"papers":{"order":"repositories listed in the archive (desc), then date (desc); the archive holds no stars","population":"papers tagged with this task that list at least one repository in the archive","shown":30,"of":67,"tagged_in_all":261,"items":[{"url":"/paper/deep-anomaly-detection-with-deviation","title":"Deep Anomaly Detection with Deviation Networks","date":"2019-11-19","arxiv_id":"1911.08623","repositories_listed":6,"syntology":null},{"url":"/paper/evaluating-shallow-and-deep-neural-networks","title":"Evaluating Shallow and Deep Neural Networks for Network Intrusion Detection Systems in Cyber Security","date":"2018-10-08","arxiv_id":null,"repositories_listed":5,"syntology":null},{"url":"/paper/e-graphsage-a-graph-neural-network-based","title":"E-GraphSAGE: A Graph Neural Network based Intrusion Detection System for IoT","date":"2021-03-30","arxiv_id":"2103.16329","repositories_listed":3,"syntology":{"n":1,"n_ran":1,"n_unverified":0,"n_pointer_only":1}},{"url":"/paper/anomalydae-dual-autoencoder-for-anomaly","title":"AnomalyDAE: Dual autoencoder for anomaly detection on attributed networks","date":"2020-02-10","arxiv_id":"2002.03665","repositories_listed":3,"syntology":{"n":14,"n_ran":5,"n_unverified":9,"n_pointer_only":0}},{"url":"/paper/learning-representations-of-ultrahigh","title":"Learning Representations of Ultrahigh-dimensional Data for Random Distance-based Outlier Detection","date":"2018-06-13","arxiv_id":"1806.04808","repositories_listed":3,"syntology":{"n":5,"n_ran":5,"n_unverified":0,"n_pointer_only":5}},{"url":"/paper/kitsune-an-ensemble-of-autoencoders-for","title":"Kitsune: An Ensemble of Autoencoders for Online Network Intrusion Detection","date":"2018-02-25","arxiv_id":"1802.09089","repositories_listed":3,"syntology":{"n":3,"n_ran":0,"n_unverified":3,"n_pointer_only":0}},{"url":"/paper/iotgem-generalizable-models-for-behaviour","title":"IoTGeM: Generalizable Models for Behaviour-Based IoT Attack Detection","date":"2023-10-17","arxiv_id":"2401.01343","repositories_listed":2,"syntology":null},{"url":"/paper/synthesis-of-a-machine-learning-model-for","title":"Synthesis of a Machine Learning Model for Detecting Computer Attacks Based on the CICIDS2017 Dataset","date":"2020-01-01","arxiv_id":null,"repositories_listed":2,"syntology":null},{"url":"/paper/a-taxonomy-and-survey-of-intrusion-detection","title":"A Taxonomy of Network Threats and the Effect of Current Datasets on Intrusion Detection Systems","date":"2018-06-09","arxiv_id":"1806.03517","repositories_listed":2,"syntology":null},{"url":"/paper/a-robust-ppo-optimized-tabular-transformer","title":"A Robust PPO-optimized Tabular Transformer Framework for Intrusion Detection in Industrial IoT Systems","date":"2025-05-23","arxiv_id":"2505.18234","repositories_listed":1,"syntology":null},{"url":"/paper/cagn-gat-fusion-a-hybrid-contrastive","title":"CAGN-GAT Fusion: A Hybrid Contrastive Attentive Graph Neural Network for Network Intrusion Detection","date":"2025-03-02","arxiv_id":"2503.00961","repositories_listed":1,"syntology":null},{"url":"/paper/evaluating-the-potential-of-quantum-machine","title":"Evaluating the Potential of Quantum Machine Learning in Cybersecurity: A Case-Study on PCA-based Intrusion Detection Systems","date":"2025-02-16","arxiv_id":"2502.11173","repositories_listed":1,"syntology":null},{"url":"/paper/a-comparative-analysis-of-dnn-based-white-box","title":"A Comparative Analysis of DNN-based White-Box Explainable AI Methods in Network Security","date":"2025-01-14","arxiv_id":"2501.07801","repositories_listed":1,"syntology":null},{"url":"/paper/continual-learning-with-strategic-selection","title":"Continual Learning with Strategic Selection and Forgetting for Network Intrusion Detection","date":"2024-12-20","arxiv_id":"2412.16264","repositories_listed":1,"syntology":null},{"url":"/paper/pyod-2-a-python-library-for-outlier-detection","title":"PyOD 2: A Python Library for Outlier Detection with LLM-powered Model Selection","date":"2024-12-11","arxiv_id":"2412.12154","repositories_listed":1,"syntology":{"n":1,"n_ran":1,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/scgnet-stacked-convolution-with-gated","title":"SCGNet-Stacked Convolution with Gated Recurrent Unit Network for Cyber Network Intrusion Detection and Intrusion Type Classification","date":"2024-10-29","arxiv_id":"2410.21873","repositories_listed":1,"syntology":null},{"url":"/paper/implementing-lightweight-intrusion-detection","title":"Implementing Lightweight Intrusion Detection System on Resource Constrained Devices","date":"2024-10-28","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/a-comprehensive-comparative-study-of","title":"A Comprehensive Comparative Study of Individual ML Models and Ensemble Strategies for Network Intrusion Detection Systems","date":"2024-10-21","arxiv_id":"2410.15597","repositories_listed":1,"syntology":null},{"url":"/paper/fedmse-federated-learning-for-iot-network","title":"FedMSE: Federated learning for IoT network intrusion detection","date":"2024-10-18","arxiv_id":"2410.14121","repositories_listed":1,"syntology":null},{"url":"/paper/xai-based-feature-selection-for-improved","title":"XAI-based Feature Selection for Improved Network Intrusion Detection Systems","date":"2024-10-14","arxiv_id":"2410.10050","repositories_listed":1,"syntology":null},{"url":"/paper/data-distribution-valuation","title":"Data Distribution Valuation","date":"2024-10-06","arxiv_id":"2410.04386","repositories_listed":1,"syntology":{"n":13,"n_ran":12,"n_unverified":1,"n_pointer_only":0}},{"url":"/paper/enhanced-convolution-neural-network-with","title":"Enhanced Convolution Neural Network with Optimized Pooling and Hyperparameter Tuning for Network Intrusion Detection","date":"2024-09-27","arxiv_id":"2409.18642","repositories_listed":1,"syntology":null},{"url":"/paper/xg-nid-dual-modality-network-intrusion","title":"XG-NID: Dual-Modality Network Intrusion Detection using a Heterogeneous Graph Neural Network and Large Language Model","date":"2024-08-27","arxiv_id":"2408.16021","repositories_listed":1,"syntology":null},{"url":"/paper/diffusion-based-adversarial-purification-for-2","title":"Diffusion-based Adversarial Purification for Intrusion Detection","date":"2024-06-25","arxiv_id":"2406.17606","repositories_listed":1,"syntology":null},{"url":"/paper/polylut-add-fpga-based-lut-inference-with","title":"PolyLUT-Add: FPGA-based LUT Inference with Wide Inputs","date":"2024-06-07","arxiv_id":"2406.04910","repositories_listed":1,"syntology":null},{"url":"/paper/large-language-models-for-cyber-security-a","title":"Large Language Models for Cyber Security: A Systematic Literature Review","date":"2024-05-08","arxiv_id":"2405.04760","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/problem-space-structural-adversarial-attacks","title":"Problem space structural adversarial attacks for Network Intrusion Detection Systems based on Graph Neural Networks","date":"2024-03-18","arxiv_id":"2403.11830","repositories_listed":1,"syntology":null},{"url":"/paper/applying-self-supervised-learning-to-network","title":"Applying Self-supervised Learning to Network Intrusion Detection for Network Flows with Graph Neural Network","date":"2024-03-03","arxiv_id":"2403.01501","repositories_listed":1,"syntology":null},{"url":"/paper/on-the-cross-dataset-generalization-of","title":"On the Cross-Dataset Generalization of Machine Learning for Network Intrusion Detection","date":"2024-02-15","arxiv_id":"2402.10974","repositories_listed":1,"syntology":null},{"url":"/paper/deep-learning-applications-for-intrusion","title":"Deep Learning Applications for Intrusion Detection in Network Traffic","date":"2024-01-13","arxiv_id":null,"repositories_listed":1,"syntology":null}],"syntology_records":7,"syntology_note":"a paper without a record is not a recorded non-run: it may lack an arXiv id or simply be absent from the graph layer"},"description_links":{"kept":0,"unwrapped_to_text":0,"bare_urls_linked":0,"relative_images_dropped":0,"rule":"internal links are kept only when the target slug exists in the catalog"},"syntology":{"read_at":"2026-09-24T18:15:14+00:00","claim":"Per-sample execution status on synthesized fixtures ('ran N of M samples'); not a correctness claim and not a ranking signal.","status_vocabulary":{"ran_honours":"ran, honoured the contract we drafted","ran_violates":"ran, violated the contract we drafted","ran_draft_wrong":"ran; our contract draft was wrong, not the code","ran_fixture":"ran; our fixture could not drive it","ran":"ran on a synthesized input","unverified":"unverified (harvested, no recorded run)"}},"not_shown":{"libraries":"the archive has no per-task library table","trend_sparklines":"the Trend column of the benchmarks table was a rendered image; it is not in the archive","social_and_latest_sorts":"stars and social signals are not in the archive"}}