<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.4 20241031//EN" "JATS-journalpublishing1-4.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="research-article" dtd-version="1.4" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">ojapps</journal-id>
      <journal-title-group>
        <journal-title>Open Journal of Applied Sciences</journal-title>
      </journal-title-group>
      <issn pub-type="epub">2165-3925</issn>
      <issn pub-type="ppub">2165-3917</issn>
      <publisher>
        <publisher-name>Scientific Research Publishing</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.4236/ojapps.2026.169191</article-id>
      <article-id pub-id-type="publisher-id">ojapps-154018</article-id>
      <article-categories>
        <subj-group>
          <subject>Article</subject>
        </subj-group>
        <subj-group>
          <subject>Biomedical</subject>
          <subject>Life Sciences</subject>
          <subject>Chemistry</subject>
          <subject>Materials Science</subject>
          <subject>Computer Science</subject>
          <subject>Communications</subject>
          <subject>Engineering</subject>
          <subject>Physics</subject>
          <subject>Mathematics</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>Applying Machine Learning for Real-Time Threat Detection in Adaptive Cybersecurity Systems</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name name-style="western">
            <surname>Wandwi</surname>
            <given-names>Godfrey</given-names>
          </name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <name name-style="western">
            <surname>Habimana</surname>
            <given-names>Theodore</given-names>
          </name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
      </contrib-group>
      <aff id="aff1"><label>1</label> Department of Digital Technologies and Information Science, Dar es Salaam Tumaini University, Dar es Salaam, Tanzania </aff>
      <author-notes>
        <fn fn-type="conflict" id="fn-conflict">
          <p>The authors declare no conflicts of interest regarding the publication of this paper.</p>
        </fn>
      </author-notes>
      <pub-date pub-type="epub">
        <day>07</day>
        <month>09</month>
        <year>2026</year>
      </pub-date>
      <pub-date pub-type="collection">
        <month>09</month>
        <year>2026</year>
      </pub-date>
      <volume>16</volume>
      <issue>09</issue>
      <fpage>3469</fpage>
      <lpage>3488</lpage>
      <history>
        <date date-type="received">
          <day>09</day>
          <month>07</month>
          <year>2026</year>
        </date>
        <date date-type="accepted">
          <day>18</day>
          <month>09</month>
          <year>2026</year>
        </date>
        <date date-type="published">
          <day>21</day>
          <month>09</month>
          <year>2026</year>
        </date>
      </history>
      <permissions>
        <copyright-statement>© 2026 by the authors and Scientific Research Publishing Inc.</copyright-statement>
        <copyright-year>2026</copyright-year>
        <license license-type="open-access">
          <license-p> This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license ( <ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by/4.0/">https://creativecommons.org/licenses/by/4.0/</ext-link> ). </license-p>
        </license>
      </permissions>
      <self-uri content-type="doi" xlink:href="https://doi.org/10.4236/ojapps.2026.169191">https://doi.org/10.4236/ojapps.2026.169191</self-uri>
      <abstract>
        <p>The dynamic landscape of cybersecurity threats necessitates intelligent and responsive defense mechanisms. As cyberattacks become increasingly sophisticated, real-time detection within adaptive systems becomes crucial. This study proposes a machine learning-driven framework for real-time threat detection, specifically tailored for adaptive cybersecurity environments. The architecture leverages supervised learning algorithms integrated with dynamic feature selection to process and classify evolving network behaviors effectively. Emphasis is placed on minimizing detection latency and improving classification precision across diverse attack vectors. Performance evaluation is conducted using benchmark datasets, including UNSW-NB15, NSL-KDD, and KDD Cup’99, under varying traffic conditions and attack intensities. Experimental findings demonstrate that the applied machine learning framework consistently achieves high detection accuracy and reduced false-positive rates, affirming its reliability for real-time deployment. The framework’s ability to adaptively respond to novel threats while maintaining computational efficiency positions it as a practical solution for next-generation cybersecurity systems.</p>
      </abstract>
      <kwd-group kwd-group-type="author-generated" xml:lang="en">
        <kwd>Real-Time Detection</kwd>
        <kwd>Machine Learning</kwd>
        <kwd>Adaptive Cybersecurity</kwd>
        <kwd>Threat Detection</kwd>
        <kwd>Network Intrusion</kwd>
        <kwd>Classification Accuracy</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec1">
      <title>1. Introduction</title>
      <p>The widespread integration of digital systems into daily operations including government services, financial transactions, and private communication has elevated the importance of cybersecurity across all domains. As digital environments evolve, traditional methods such as static firewall rules or signature-based Intrusion Detection Systems (IDS) increasingly fall short in mitigating advanced and adaptive cyber threats. This is due to the sophisticated nature of modern attacks, which often exploit unknown system vulnerabilities or encrypted channels to evade conventional security controls. Consequently, there is a pressing need for responsive, intelligent, and adaptive mechanisms capable of identifying malicious activity in real time [<xref ref-type="bibr" rid="B1">1</xref>].</p>
      <p>Modern threat actors utilize advanced tactics such as polymorphic malware, zero-day exploits, and anonymization tools like Tor to infiltrate systems undetected. Despite widespread adoption of encryption protocols like HTTPS, attackers have continued to bypass security through phishing attacks, Distributed Denial-of-Service (DDoS), and man-in-the-middle exploits, often targeting sensitive communications on social media platforms, email servers, and financial systems. These dynamic attack vectors pose a unique challenge to static IDS models, which cannot rapidly adapt to changing patterns of behavior within network environments.</p>
      <p>Machine Learning (ML) has emerged as a powerful solution in addressing the shortcomings of conventional IDS. While prior works have applied ensemble learning and feature selection independently, our novel contribution lies in the tight integration of realtime adaptive correlation-based feature selection with a heterogeneous boosting ensemble. Unlike static models that require offline retraining, our system adaptively updates the feature subset based on streaming data characteristics, and re-weights weak learners dynamically based on their per-class performance. This dual adaptation (both at the feature and model level) enables faster reaction to new threat vectors and lower latency compared to traditional ensemble methods. We argue that this specific integration is particularly advantageous for operational IDS deployments, because it balances detection performance, computational cost, and adaptability in a way that prior work (which often uses fixed features or homogeneous learners) does not. ML algorithms offer the ability to learn from vast datasets and generalize patterns associated with both known and unknown threats. However, no single ML model has proven entirely effective across all forms of cyberattacks. Studies have revealed persistent challenges in misclassification and false alarm rates, even in systems that use sophisticated techniques like support vector machines, clustering, or probabilistic models [<xref ref-type="bibr" rid="B2">2</xref>].</p>
      <p>Ensemble learning techniques have been introduced to overcome these limitations, especially through hybrid or adaptive models that combine multiple weak learners into a stronger classifier. Research by [<xref ref-type="bibr" rid="B3">3</xref>] demonstrated the superiority of ensemble models in classifying complex cyber intrusion scenarios. Their work distinguishes between homogeneous ensembles where similar learners are boosted and heterogeneous ensembles that combine diverse learners to improve prediction accuracy and reduce false positives. Nevertheless, most ensemble models still struggle to detect novel attack vectors, indicating a need for more responsive and context-aware systems.</p>
      <p>In this paper, we present a machine learning-based framework tailored for real-time threat detection in adaptive cybersecurity systems. Unlike traditional models, our framework integrates dynamic learning algorithms with temporal data analysis to process network traffic in real time. Feature selection is optimized through a correlation-based approach to reduce redundancy and improve model precision. The core system adapts continuously to environmental changes, thereby enhancing its ability to detect both known and emerging cyber threats with minimal latency.</p>
      <p>The remainder of this paper is structured as follows: The next section presents a review of relevant literature on machine learning applications in cybersecurity. This is followed by an overview of ensemble techniques and adaptive learning. Subsequently, the proposed framework is detailed, including its real-time processing pipeline and feature selection mechanism. Experimental results using benchmark datasets such as UNSW-NB15, NSL-KDD, and KDD Cup’99 are presented to validate the system’s performance. The final section concludes the study and outlines directions for future research.</p>
    </sec>
    <sec id="sec2">
      <title>2. Related Work</title>
      <p>The rapid evolution of cyber threats has driven extensive research into real-time threat detection methodologies, leveraging machine learning (ML) techniques within adaptive cybersecurity systems. The application of ML for anomaly and intrusion detection has been a dominant theme, with numerous studies focusing on improving classification accuracy, reducing false positives, and enabling timely responses to emergent attacks [<xref ref-type="bibr" rid="B2">2</xref>][<xref ref-type="bibr" rid="B4">4</xref>]-[<xref ref-type="bibr" rid="B7">7</xref>]. These foundational works underscore the challenges inherent in static detection frameworks and highlight the necessity of adaptive models capable of learning from streaming data in real time.</p>
      <p>In an effort to enhance detection capabilities, [<xref ref-type="bibr" rid="B8">8</xref>] explored hybrid ensemble methods, combining various feature selection techniques with adaptive boosting (Adaboost) algorithms. Their study demonstrated that a wrapper-based feature selection paired with Adaboost using decision trees as weak learners yielded notable improvements in classification efficiency. Similarly, [<xref ref-type="bibr" rid="B9">9</xref>] advanced this approach by integrating correlation-based and information gain methods for feature selection, subsequently employing Adaboost.M1 with Naïve Bayes weak learners. Their hybrid framework achieved commendable detection rates while maintaining a low false-positive rate, underscoring the importance of strategic feature engineering alongside ensemble learning.</p>
      <p>Recent studies have emphasized the importance of real-time machine learning defenses in operational environments. For instance, [<xref ref-type="bibr" rid="B10">10</xref>] provide a performance overview of ML-based defense strategies against Advanced Persistent Threats (APTs) in industrial control systems, highlighting real-time constraints, adaptive threat identification, and feature engineering in ICS settings. Similarly, [<xref ref-type="bibr" rid="B11">11</xref>] developed a real-world anomaly detection framework using heterogeneous ML models (Random Forest, Decision Tree, Gaussian Naive Bayes) specifically designed for heterogeneous network environments; their work underscores the challenge of reducing false positives while ensuring continuous monitoring in real time. These works reinforce the gap that our study fills by combining adaptive feature selection with a heterogeneous boosting ensemble, tailored specifically for real-time, resource-conscious deployment.</p>
      <p>Further innovations in ensemble learning were introduced by [<xref ref-type="bibr" rid="B2">2</xref>], who proposed a novel multi-expert system combining support vector machines (SVM), k-nearest neighbors (k-NN), and particle swarm optimization (PSO) within a weighted majority voting scheme. This heterogeneous ensemble approach outperformed traditional classifiers, validating the premise that diversity among learners enhances robustness against a wider variety of intrusion patterns. Likewise, [<xref ref-type="bibr" rid="B12">12</xref>] applied meta-classifiers and found that bagging combined with REPTree weak learners significantly improved predictive performance, particularly in complex multi-class classification scenarios.</p>
      <p>The significance of feature reduction in optimizing model performance is further illustrated by [<xref ref-type="bibr" rid="B13">13</xref>], who utilized information gain (IG) and gain ratio (GR) for dimensionality reduction before applying Adaboost with random tree learners. Their results confirmed that effective feature selection is integral to boosting the accuracy and reliability of intrusion detection systems, especially when handling large-scale, high-dimensional data.</p>
      <p>Several studies have explored the enhancement of Adaboost through integration with other machine learning paradigms. For example, [<xref ref-type="bibr" rid="B14">14</xref>] combined Adaboost with SVM to leverage the strengths of both boosting and margin-based classification, while [<xref ref-type="bibr" rid="B15">15</xref>] developed a Neuro-Fuzzy system integrated with boosting to capture nonlinear and uncertain data patterns. [<xref ref-type="bibr" rid="B16">16</xref>] proposed a novel weighted voting framework within Adaboost to improve classifier decision-making. Despite these advances, [<xref ref-type="bibr" rid="B17">17</xref>] noted persistent challenges in adapting Adaboost effectively to multi-class intrusion detection problems, which remain critical given the diversity of cyberattack vectors.</p>
      <p>Addressing the challenge of evasive and anonymized network traffic, recent research has targeted the detection of Tor traffic, a known obstacle in network monitoring due to its anonymizing overlay routing. [<xref ref-type="bibr" rid="B18">18</xref>] applied artificial neural networks (ANN) and SVM classifiers on the UNB-CIC Tor Network Traffic dataset, coupled with correlation-based feature selection (CFS), achieving classification accuracies up to 99.8%. This high performance highlights the effectiveness of hybrid ML and feature selection methods in uncovering obscured traffic behaviors. Similarly, Ghafir, Svoboda, and [<xref ref-type="bibr" rid="B19">19</xref>] validated a methodology capable of automatically detecting Tor connections within live campus traffic, further emphasizing the feasibility of real-time adaptive detection.</p>
      <p>Other applications of hybrid feature selection and classification techniques have targeted phishing detection, where [<xref ref-type="bibr" rid="B20">20</xref>] combined Mbox2xml feature extraction tools with Bayesian network classifiers, selecting a concise subset of eight features to achieve 94% accuracy. [<xref ref-type="bibr" rid="B21">21</xref>] contributed by developing a multi-label associative classification (MCAC) model using Chi-square feature selection, which uniquely identified a novel “Suspicious” category outside of the original training data. These findings demonstrate the value of multi-label and adaptive classification strategies in real-world cybersecurity contexts.</p>
      <p>Collectively, these studies illustrate the trajectory toward machine learning models that are not only accurate but also adaptive and capable of real-time response in dynamic cybersecurity environments. The current research builds upon these foundations by designing a framework specifically optimized for real-time threat detection in adaptive systems, emphasizing continuous learning and efficient feature selection to confront emerging cyber threats effectively.</p>
    </sec>
    <sec id="sec3">
      <title>3. Ensemble Learning</title>
      <p>In the domain of adaptive cybersecurity systems designed for real-time threat detection, ensemble learning techniques have become integral to improving model accuracy and robustness. Ensemble learning is a paradigm that constructs a set of classifiers, typically called weak learners, which individually perform only slightly better than random guessing, and then combines them to form a single, stronger predictive model [<xref ref-type="bibr" rid="B22">22</xref>]. This synergy among multiple learners helps overcome the limitations of individual models and allows the system to adapt dynamically to diverse and evolving cyber threats.</p>
      <p>Among ensemble methods, Boosting holds a prominent place due to its sequential training mechanism, which focuses on samples that previous learners misclassified. The core principle of Boosting is to re-weight the training samples based on their classification errors such that subsequent weak learners pay more attention to the difficult-to-classify instances [<xref ref-type="bibr" rid="B23">23</xref>]. Through this iterative process, Boosting converts a collection of weak classifiers into a highly accurate strong classifier, making it especially effective in real-time environments where rapid adaptation to new threats is crucial.</p>
      <p>A well-recognized variant, Adaboost.M1, extends the classical Adaboost algorithm to handle multiclass classification problems, a necessary feature when detecting multiple threat categories simultaneously [<xref ref-type="bibr" rid="B24">24</xref>]. The algorithm begins with an initial uniform distribution over all training samples:</p>
      <disp-formula id="FD1">
        <mml:math display="inline">
          <mml:mrow>
            <mml:msub>
              <mml:mi>D</mml:mi>
              <mml:mn>1</mml:mn>
            </mml:msub>
            <mml:mrow>
              <mml:mo>(</mml:mo>
              <mml:mi>i</mml:mi>
              <mml:mo>)</mml:mo>
            </mml:mrow>
            <mml:mo>=</mml:mo>
            <mml:mfrac>
              <mml:mn>1</mml:mn>
              <mml:mi>m</mml:mi>
            </mml:mfrac>
            <mml:mo>,</mml:mo>
            <mml:mo>∀</mml:mo>
            <mml:mi>i</mml:mi>
            <mml:mo>=</mml:mo>
            <mml:mn>1</mml:mn>
            <mml:mo>,</mml:mo>
            <mml:mn>2</mml:mn>
            <mml:mo>,</mml:mo>
            <mml:mo>⋯</mml:mo>
            <mml:mo>,</mml:mo>
            <mml:mi>m</mml:mi>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>where m is the total number of training examples. At each iteration <italic>t</italic> = 1, 2, ..., T, the weak learner is trained using the distribution <italic>D</italic><italic><sub>t</sub></italic> producing a hypothesis ht: X → Y where <italic>Y</italic> = {1, 2, ..., <italic>k</italic>} represents the multiclass labels.</p>
      <p>The weighted error <italic>ε</italic><italic><sub>t</sub></italic> of the weak learner on the current distribution is calculated as:</p>
      <disp-formula id="FD2">
        <mml:math display="inline">
          <mml:mrow>
            <mml:msub>
              <mml:mi>ε</mml:mi>
              <mml:mi>t</mml:mi>
            </mml:msub>
            <mml:mo>=</mml:mo>
            <mml:mstyle displaystyle="true">
              <mml:munder>
                <mml:mo>∑</mml:mo>
                <mml:mrow>
                  <mml:mi>i</mml:mi>
                  <mml:mo>:</mml:mo>
                  <mml:msub>
                    <mml:mi>h</mml:mi>
                    <mml:mi>t</mml:mi>
                  </mml:msub>
                  <mml:mrow>
                    <mml:mo>(</mml:mo>
                    <mml:mrow>
                      <mml:msub>
                        <mml:mi>x</mml:mi>
                        <mml:mi>i</mml:mi>
                      </mml:msub>
                    </mml:mrow>
                    <mml:mo>)</mml:mo>
                  </mml:mrow>
                  <mml:mo>≠</mml:mo>
                  <mml:msub>
                    <mml:mi>y</mml:mi>
                    <mml:mi>i</mml:mi>
                  </mml:msub>
                </mml:mrow>
              </mml:munder>
              <mml:mrow>
                <mml:msub>
                  <mml:mi>D</mml:mi>
                  <mml:mi>t</mml:mi>
                </mml:msub>
                <mml:mrow>
                  <mml:mo>(</mml:mo>
                  <mml:mi>i</mml:mi>
                  <mml:mo>)</mml:mo>
                </mml:mrow>
              </mml:mrow>
            </mml:mstyle>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>If <italic>ε</italic><italic><sub>t</sub></italic> &gt; 1/2, the learner is discarded, and the boosting process halts early. Otherwise, the learner’s weight <italic>β</italic><italic><sub>t</sub></italic> is computed by:</p>
      <disp-formula id="FD3">
        <mml:math display="inline">
          <mml:mrow>
            <mml:msub>
              <mml:mi>β</mml:mi>
              <mml:mi>t</mml:mi>
            </mml:msub>
            <mml:mo>=</mml:mo>
            <mml:mfrac>
              <mml:mrow>
                <mml:msub>
                  <mml:mi>ε</mml:mi>
                  <mml:mi>t</mml:mi>
                </mml:msub>
              </mml:mrow>
              <mml:mrow>
                <mml:mn>1</mml:mn>
                <mml:mo>−</mml:mo>
                <mml:msub>
                  <mml:mi>ε</mml:mi>
                  <mml:mi>t</mml:mi>
                </mml:msub>
              </mml:mrow>
            </mml:mfrac>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>The distribution <italic>D</italic><italic><sub>t</sub></italic> is updated for the next iteration by increasing weights on misclassified samples:</p>
      <disp-formula id="FD4">
        <mml:math display="inline">
          <mml:mrow>
            <mml:msub>
              <mml:mi>D</mml:mi>
              <mml:mrow>
                <mml:mi>t</mml:mi>
                <mml:mo>+</mml:mo>
                <mml:mn>1</mml:mn>
              </mml:mrow>
            </mml:msub>
            <mml:mrow>
              <mml:mo>(</mml:mo>
              <mml:mi>i</mml:mi>
              <mml:mo>)</mml:mo>
            </mml:mrow>
            <mml:mo>=</mml:mo>
            <mml:mfrac>
              <mml:mrow>
                <mml:msub>
                  <mml:mi>D</mml:mi>
                  <mml:mi>t</mml:mi>
                </mml:msub>
                <mml:mrow>
                  <mml:mo>(</mml:mo>
                  <mml:mi>i</mml:mi>
                  <mml:mo>)</mml:mo>
                </mml:mrow>
              </mml:mrow>
              <mml:mrow>
                <mml:msub>
                  <mml:mi>Z</mml:mi>
                  <mml:mi>t</mml:mi>
                </mml:msub>
              </mml:mrow>
            </mml:mfrac>
            <mml:mo>×</mml:mo>
            <mml:mrow>
              <mml:mo>{</mml:mo>
              <mml:mtable columnalign="left">
                <mml:mtr>
                  <mml:mtd>
                    <mml:msub>
                      <mml:mi>β</mml:mi>
                      <mml:mi>t</mml:mi>
                    </mml:msub>
                    <mml:mo>,</mml:mo>
                    <mml:mtext>if</mml:mtext>
                    <mml:msub>
                      <mml:mi>h</mml:mi>
                      <mml:mi>t</mml:mi>
                    </mml:msub>
                    <mml:mrow>
                      <mml:mo>(</mml:mo>
                      <mml:mrow>
                        <mml:msub>
                          <mml:mi>x</mml:mi>
                          <mml:mi>i</mml:mi>
                        </mml:msub>
                      </mml:mrow>
                      <mml:mo>)</mml:mo>
                    </mml:mrow>
                    <mml:mo>=</mml:mo>
                    <mml:msub>
                      <mml:mi>y</mml:mi>
                      <mml:mi>i</mml:mi>
                    </mml:msub>
                  </mml:mtd>
                </mml:mtr>
                <mml:mtr>
                  <mml:mtd>
                    <mml:mn>1</mml:mn>
                    <mml:mo>,</mml:mo>
                    <mml:mtext>otherwise</mml:mtext>
                  </mml:mtd>
                </mml:mtr>
              </mml:mtable>
            </mml:mrow>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>where <italic>Z</italic><italic><sub>t</sub></italic> is a normalization factor ensuring that <italic>D</italic><italic><sub>t</sub></italic><sub>+1</sub> sums to one.</p>
      <p>After completing <italic>T</italic> iterations, the final strong classifier <italic>h</italic><italic><sub>fin</sub></italic> is constructed by a weighted majority vote of the weak learners, with weights logarithmically scaled according to their accuracy:</p>
      <disp-formula id="FD5">
        <mml:math display="inline">
          <mml:mrow>
            <mml:msub>
              <mml:mi>h</mml:mi>
              <mml:mrow>
                <mml:mi>f</mml:mi>
                <mml:mi>i</mml:mi>
                <mml:mi>n</mml:mi>
              </mml:mrow>
            </mml:msub>
            <mml:mrow>
              <mml:mo>(</mml:mo>
              <mml:mi>x</mml:mi>
              <mml:mo>)</mml:mo>
            </mml:mrow>
            <mml:mo>=</mml:mo>
            <mml:mi>arg</mml:mi>
            <mml:munder>
              <mml:mrow>
                <mml:mi>max</mml:mi>
              </mml:mrow>
              <mml:mrow>
                <mml:mi>y</mml:mi>
                <mml:mo>∈</mml:mo>
                <mml:mi>Y</mml:mi>
              </mml:mrow>
            </mml:munder>
            <mml:mstyle displaystyle="true">
              <mml:munder>
                <mml:mo>∑</mml:mo>
                <mml:mrow>
                  <mml:mi>t</mml:mi>
                  <mml:mo>:</mml:mo>
                  <mml:msub>
                    <mml:mi>h</mml:mi>
                    <mml:mi>t</mml:mi>
                  </mml:msub>
                  <mml:mrow>
                    <mml:mo>(</mml:mo>
                    <mml:mi>x</mml:mi>
                    <mml:mo>)</mml:mo>
                  </mml:mrow>
                  <mml:mo>=</mml:mo>
                  <mml:mi>y</mml:mi>
                </mml:mrow>
              </mml:munder>
              <mml:mrow>
                <mml:mi>log</mml:mi>
                <mml:mrow>
                  <mml:mo>(</mml:mo>
                  <mml:mrow>
                    <mml:mfrac>
                      <mml:mn>1</mml:mn>
                      <mml:mrow>
                        <mml:msub>
                          <mml:mi>β</mml:mi>
                          <mml:mi>t</mml:mi>
                        </mml:msub>
                      </mml:mrow>
                    </mml:mfrac>
                  </mml:mrow>
                  <mml:mo>)</mml:mo>
                </mml:mrow>
              </mml:mrow>
            </mml:mstyle>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>This procedure ensures that more accurate weak learners have a greater influence on the final decision, a critical property for adaptive cybersecurity where correct identification of subtle attack vectors is paramount.</p>
      <p>In the context of real-time cybersecurity threat detection, the advantage of Adaboost.M1 lies in its continuous focus on the most challenging examples, enabling the adaptive system to rapidly learn from new, emerging threats that often manifest as rare or obfuscated events in network traffic [<xref ref-type="bibr" rid="B22">22</xref>][<xref ref-type="bibr" rid="B24">24</xref>]. This iterative re-weighting mechanism contrasts with static classifiers, which may fail to generalize well to novel attack patterns, making Boosting particularly suited for the dynamic cybersecurity landscape.</p>
      <p>Furthermore, empirical research supports the superior performance of Boosting ensembles in cybersecurity applications. [<xref ref-type="bibr" rid="B18">18</xref>] demonstrated that Adaboost integrated with decision tree weak learners achieved high detection accuracy for zero-day attacks in streaming network data. Similarly, [<xref ref-type="bibr" rid="B25">25</xref>] illustrated how adaptive ensemble methods based on Boosting effectively identified new malware variants with minimal latency, affirming the method’s practical efficacy for real-time threat mitigation.</p>
      <p>While other ensemble techniques such as Bagging and Stacking have been applied in cybersecurity, their suitability for adaptive, real-time environments is comparatively limited. Bagging reduces variance by training multiple independent models on bootstrapped datasets, but it lacks the focused adaptation to misclassified samples that Boosting provides [<xref ref-type="bibr" rid="B26">26</xref>]. Stacking, involving a meta-learner to combine base classifiers, adds complexity and latency which can hinder timely threat response in fast-paced networks [<xref ref-type="bibr" rid="B27">27</xref>]. Thus, Boosting remains the ensemble learning technique of choice for systems requiring both accuracy and swift adaptation.</p>
      <p>Ensemble learning, and particularly Boosting with the Adaboost.M1 algorithm, offers a robust and flexible framework for real-time threat detection in adaptive cybersecurity systems. By iteratively refining learner focus towards misclassified threats and combining multiple weak learners into a strong classifier, these methods provide critical advantages for detecting and responding to the diverse and rapidly changing spectrum of cyberattacks.</p>
    </sec>
    <sec id="sec4">
      <title>4. Correlation-Based Feature Selection</title>
      <p>In the context of adaptive cybersecurity systems that rely on machine learning for real-time threat detection, the selection of informative and non-redundant features plays a pivotal role in enhancing detection accuracy while optimizing computational efficiency. Correlation-Based Feature Selection (CFS) is a widely adopted technique that evaluates the merit of feature subsets based on the strength of their correlations with the target variable (i.e., the threat class) and the degree of inter-correlation among themselves. The central premise behind CFS is that a valuable feature subset contains features that are highly predictive of the threat classes but exhibit minimal redundancy, thereby ensuring that only the most relevant information is utilized by the learning algorithm [<xref ref-type="bibr" rid="B28">28</xref>].</p>
      <p>Cybersecurity datasets, particularly those comprising network traffic logs and system event attributes, often contain numerous features with complex interrelationships. Many features may be correlated with each other due to underlying network protocols or attack patterns, resulting in redundancy that can degrade model performance or inflate computational overhead [<xref ref-type="bibr" rid="B29">29</xref>]. By applying CFS, the system prioritizes subsets of features that maximize the individual predictive ability while simultaneously minimizing redundancy, thus enabling more efficient real-time detection in dynamic environments.</p>
      <p>The quantitative evaluation of feature subsets in CFS is formalized by a heuristic merit function <italic>M</italic><italic><sub>erits</sub></italic>, which measures the correlation between the subset and the threat class as:</p>
      <disp-formula id="FD6">
        <mml:math display="inline">
          <mml:mrow>
            <mml:msub>
              <mml:mi>M</mml:mi>
              <mml:mrow>
                <mml:mi>e</mml:mi>
                <mml:mi>r</mml:mi>
                <mml:mi>i</mml:mi>
                <mml:mi>t</mml:mi>
                <mml:mi>s</mml:mi>
              </mml:mrow>
            </mml:msub>
            <mml:mo>=</mml:mo>
            <mml:mfrac>
              <mml:mrow>
                <mml:mi>k</mml:mi>
                <mml:msub>
                  <mml:mover accent="true">
                    <mml:mi>r</mml:mi>
                    <mml:mo>¯</mml:mo>
                  </mml:mover>
                  <mml:mrow>
                    <mml:mi>c</mml:mi>
                    <mml:mi>f</mml:mi>
                  </mml:mrow>
                </mml:msub>
              </mml:mrow>
              <mml:mrow>
                <mml:msqrt>
                  <mml:mrow>
                    <mml:mi>k</mml:mi>
                    <mml:mo>+</mml:mo>
                    <mml:mi>k</mml:mi>
                    <mml:mrow>
                      <mml:mo>(</mml:mo>
                      <mml:mrow>
                        <mml:mi>k</mml:mi>
                        <mml:mo>−</mml:mo>
                        <mml:mn>1</mml:mn>
                      </mml:mrow>
                      <mml:mo>)</mml:mo>
                    </mml:mrow>
                    <mml:msub>
                      <mml:mover accent="true">
                        <mml:mi>r</mml:mi>
                        <mml:mo>¯</mml:mo>
                      </mml:mover>
                      <mml:mrow>
                        <mml:mi>f</mml:mi>
                        <mml:mi>f</mml:mi>
                      </mml:mrow>
                    </mml:msub>
                  </mml:mrow>
                </mml:msqrt>
              </mml:mrow>
            </mml:mfrac>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>where:</p>
      <p><italic>k</italic> denotes the number of features in the subset,<inline-formula><mml:math display="inline"><mml:mrow><mml:msub><mml:mover accent="true"><mml:mi> r </mml:mi><mml:mo> ¯ </mml:mo></mml:mover><mml:mrow><mml:mi> c </mml:mi><mml:mi> f </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> is the average correlation between the features and the class label,<inline-formula><mml:math display="inline"><mml:mrow><mml:msub><mml:mover accent="true"><mml:mi> r </mml:mi><mml:mo> ¯ </mml:mo></mml:mover><mml:mrow><mml:mi> f </mml:mi><mml:mi> f </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> is the average inter-correlation among the features themselves.</p>
      <p>The numerator rewards feature subsets with strong individual correlations to the threat class, whereas the denominator penalizes subsets with high internal redundancy. The objective is thus to maximize M<sub>erits</sub>, selecting feature groups that provide maximum predictive value with minimum overlap [<xref ref-type="bibr" rid="B28">28</xref>].</p>
      <p>In practice, the calculation of the correlation coefficients <inline-formula><mml:math display="inline"><mml:mrow><mml:msub><mml:mover accent="true"><mml:mi> r </mml:mi><mml:mo> ¯ </mml:mo></mml:mover><mml:mrow><mml:mi> c </mml:mi><mml:mi> f </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> and <inline-formula><mml:math display="inline"><mml:mrow><mml:msub><mml:mover accent="true"><mml:mi> r </mml:mi><mml:mo> ¯ </mml:mo></mml:mover><mml:mrow><mml:mi> f </mml:mi><mml:mi> f </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> employs measures derived from information theory, such as Symmetrical Uncertainty (SU). SU quantifies the degree of association between two discrete variables, balancing mutual information against the entropy of each variable. It is defined as:</p>
      <disp-formula id="FD7">
        <mml:math display="inline">
          <mml:mrow>
            <mml:mi>S</mml:mi>
            <mml:mi>U</mml:mi>
            <mml:mo>=</mml:mo>
            <mml:mn>2.0</mml:mn>
            <mml:mo>×</mml:mo>
            <mml:mfrac>
              <mml:mrow>
                <mml:mi>H</mml:mi>
                <mml:mrow>
                  <mml:mo>(</mml:mo>
                  <mml:mi>X</mml:mi>
                  <mml:mo>)</mml:mo>
                </mml:mrow>
                <mml:mo>+</mml:mo>
                <mml:mi>H</mml:mi>
                <mml:mrow>
                  <mml:mo>(</mml:mo>
                  <mml:mi>Y</mml:mi>
                  <mml:mo>)</mml:mo>
                </mml:mrow>
                <mml:mo>−</mml:mo>
                <mml:mi>H</mml:mi>
                <mml:mrow>
                  <mml:mo>(</mml:mo>
                  <mml:mrow>
                    <mml:mi>X</mml:mi>
                    <mml:mo>,</mml:mo>
                    <mml:mi>Y</mml:mi>
                  </mml:mrow>
                  <mml:mo>)</mml:mo>
                </mml:mrow>
              </mml:mrow>
              <mml:mrow>
                <mml:mi>H</mml:mi>
                <mml:mrow>
                  <mml:mo>(</mml:mo>
                  <mml:mi>X</mml:mi>
                  <mml:mo>)</mml:mo>
                </mml:mrow>
                <mml:mo>+</mml:mo>
                <mml:mi>H</mml:mi>
                <mml:mrow>
                  <mml:mo>(</mml:mo>
                  <mml:mi>Y</mml:mi>
                  <mml:mo>)</mml:mo>
                </mml:mrow>
              </mml:mrow>
            </mml:mfrac>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>where:</p>
      <p><italic>H</italic>(<italic>X</italic>) and <italic>H</italic>(<italic>Y</italic>) represent the entropy of variables <italic>X</italic> and <italic>Y</italic> respectively,<italic>H</italic>(<italic>X</italic>, <italic>Y</italic>) is the joint entropy of <italic>X</italic> and <italic>Y</italic>.</p>
      <p>Entropy <italic>H</italic>(<italic>X</italic>), measuring the uncertainty or disorder within a variable, is calculated by:</p>
      <disp-formula id="FD8">
        <mml:math display="inline">
          <mml:mrow>
            <mml:mi>H</mml:mi>
            <mml:mrow>
              <mml:mo>(</mml:mo>
              <mml:mi>X</mml:mi>
              <mml:mo>)</mml:mo>
            </mml:mrow>
            <mml:mo>=</mml:mo>
            <mml:mo>−</mml:mo>
            <mml:mstyle displaystyle="true">
              <mml:munder>
                <mml:mo>∑</mml:mo>
                <mml:mrow>
                  <mml:mi>x</mml:mi>
                  <mml:mo>∈</mml:mo>
                  <mml:mi>X</mml:mi>
                </mml:mrow>
              </mml:munder>
              <mml:mrow>
                <mml:mi>p</mml:mi>
                <mml:mrow>
                  <mml:mo>(</mml:mo>
                  <mml:mi>x</mml:mi>
                  <mml:mo>)</mml:mo>
                </mml:mrow>
                <mml:msub>
                  <mml:mrow>
                    <mml:mi>log</mml:mi>
                  </mml:mrow>
                  <mml:mn>2</mml:mn>
                </mml:msub>
                <mml:mi>p</mml:mi>
                <mml:mrow>
                  <mml:mo>(</mml:mo>
                  <mml:mi>x</mml:mi>
                  <mml:mo>)</mml:mo>
                </mml:mrow>
              </mml:mrow>
            </mml:mstyle>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>where <italic>p</italic>(<italic>x</italic>) is the probability of occurrence of the value xxx. Higher SU values indicate stronger dependency, with 1 representing perfect correlation and 0 representing independence [<xref ref-type="bibr" rid="B30">30</xref>].</p>
      <p>In the dynamic cybersecurity context, these information-theoretic measures are invaluable. Network traffic data streams exhibit variability and noise, making correlation-based heuristics more robust compared to purely linear correlation metrics. The CFS approach, by leveraging SU, effectively discerns subtle dependencies between features and emerging attack patterns, which is crucial for detecting sophisticated threats in real time [<xref ref-type="bibr" rid="B31">31</xref>].</p>
      <p>Moreover, the iterative process of CFS enables adaptive feature subset refinement, aligning well with evolving cyber threat landscapes. By periodically reassessing feature correlations, the system can drop obsolete or redundant features and incorporate new indicators of compromise as they arise, facilitating continuous learning and responsiveness [<xref ref-type="bibr" rid="B32">32</xref>]. This adaptivity ensures that computational resources are focused on the most salient features, minimizing latency and preserving throughput during real-time threat monitoring.</p>
      <p>Empirical evaluations reinforce the efficacy of CFS in real-time cybersecurity applications. </p>
      <p>Studies such as by [<xref ref-type="bibr" rid="B33">33</xref>] have shown that applying CFS significantly improves detection accuracy and reduces false positives in intrusion detection systems (IDS) by filtering out noisy or redundant features without compromising relevant information. Similarly, in real-time malware detection frameworks, CFS-based feature optimization has been demonstrated to enhance classification speed and precision, critical for timely incident response [<xref ref-type="bibr" rid="B34">34</xref>].</p>
      <p>Correlation-Based Feature Selection offers a principled and effective method for identifying optimal feature subsets in adaptive machine learning systems for cybersecurity. By balancing predictive relevance against redundancy, CFS enables robust, efficient, and real-time threat detection, supporting the dynamic and fast-paced nature of modern cyber defense operations.</p>
    </sec>
    <sec id="sec5">
      <title>5. Proposed Method</title>
      <p>This study proposes a comprehensive machine learning framework designed for real-time threat detection in adaptive cybersecurity systems. The framework leverages an ensemble of diverse machine learning algorithms integrated within an adaptive boosting mechanism to enhance detection accuracy and responsiveness to evolving cyber threats. The method consists of four distinct but interconnected phases: data preprocessing, adaptive feature selection, weak learner training, and strong ensemble classification, as illustrated in <xref ref-type="fig" rid="fig1">Figure 1</xref>.</p>
      <fig id="fig1">
        <label>Figure 1</label>
        <graphic xlink:href="https://html.scirp.org/file/2313271-rId38.jpeg?20260921100808" />
      </fig>
      <p><bold>Figure 1.</bold> The workflow of the proposed adaptive machine learning framework for real-time threat detection.</p>
      <p>The initial phase, data preprocessing, prepares raw network and system event data for machine learning application. Given that cybersecurity data streams often include categorical fields such as protocol types, IP addresses, and port numbers, these symbolic attributes are first encoded numerically using label encoding and one-hot encoding techniques to ensure compatibility with machine learning algorithms [<xref ref-type="bibr" rid="B35">35</xref>]. Additionally, noise reduction techniques such as outlier detection and missing value imputation are applied to improve data quality and consistency, which is critical for real-time operational environments [<xref ref-type="bibr" rid="B36">36</xref>].</p>
      <p>The second phase employs an adaptive correlation-based feature selection process. Unlike static feature selection methods, this adaptive mechanism dynamically selects and updates relevant features from the continuous data stream based on their correlation to threat labels and redundancy among features, as measured by Symmetrical Uncertainty [<xref ref-type="bibr" rid="B30">30</xref>]. This step is vital to reduce dimensionality and computational overhead, facilitating faster detection while maintaining high predictive power [<xref ref-type="bibr" rid="B28">28</xref>]. The iterative nature of this process allows the system to adaptively refine feature subsets as new attack vectors emerge, aligning with the evolving cyber threat landscape [<xref ref-type="bibr" rid="B17">17</xref>].</p>
      <p>1) Adaptive Correlation-Based Feature Selection (CFS): Every N = 10,000 flows, we recompute Symmetrical Uncertainty (SU) between each candidate feature and the class label, as well as pairwise SU among features. We then compute the merit score for each feature subset according to</p>
      <disp-formula id="FD9">
        <mml:math display="inline">
          <mml:mrow>
            <mml:mtext>Merit</mml:mtext>
            <mml:mo>=</mml:mo>
            <mml:mfrac>
              <mml:mrow>
                <mml:mi>k</mml:mi>
                <mml:mo>⋅</mml:mo>
                <mml:mover accent="true">
                  <mml:mrow>
                    <mml:msub>
                      <mml:mi>c</mml:mi>
                      <mml:mrow>
                        <mml:mi>f</mml:mi>
                        <mml:mo>,</mml:mo>
                        <mml:mi>c</mml:mi>
                        <mml:mi>l</mml:mi>
                        <mml:mi>a</mml:mi>
                        <mml:mi>s</mml:mi>
                        <mml:mi>s</mml:mi>
                      </mml:mrow>
                    </mml:msub>
                  </mml:mrow>
                  <mml:mo stretchy="true">¯</mml:mo>
                </mml:mover>
              </mml:mrow>
              <mml:mrow>
                <mml:msqrt>
                  <mml:mrow>
                    <mml:mi>k</mml:mi>
                    <mml:mo>+</mml:mo>
                    <mml:mi>k</mml:mi>
                    <mml:mrow>
                      <mml:mo>(</mml:mo>
                      <mml:mrow>
                        <mml:mi>k</mml:mi>
                        <mml:mo>−</mml:mo>
                        <mml:mn>1</mml:mn>
                      </mml:mrow>
                      <mml:mo>)</mml:mo>
                    </mml:mrow>
                    <mml:mo>⋅</mml:mo>
                    <mml:mover accent="true">
                      <mml:mrow>
                        <mml:msub>
                          <mml:mi>c</mml:mi>
                          <mml:mrow>
                            <mml:mi>f</mml:mi>
                            <mml:mo>,</mml:mo>
                            <mml:mi>f</mml:mi>
                          </mml:mrow>
                        </mml:msub>
                      </mml:mrow>
                      <mml:mo stretchy="true">¯</mml:mo>
                    </mml:mover>
                  </mml:mrow>
                </mml:msqrt>
              </mml:mrow>
            </mml:mfrac>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>where <italic>k</italic> is number of features, <inline-formula><mml:math display="inline"><mml:mrow><mml:mi> k </mml:mi><mml:mo> ⋅ </mml:mo><mml:mover accent="true"><mml:mrow><mml:msub><mml:mi> c </mml:mi><mml:mrow><mml:mi> f </mml:mi><mml:mo> , </mml:mo><mml:mi> c </mml:mi><mml:mi> l </mml:mi><mml:mi> a </mml:mi><mml:mi> s </mml:mi><mml:mi> s </mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="true"> ¯ </mml:mo></mml:mover></mml:mrow></mml:math></inline-formula> , class is average feature-class SU and <inline-formula><mml:math display="inline"><mml:mrow><mml:mover accent="true"><mml:mrow><mml:msub><mml:mi> c </mml:mi><mml:mrow><mml:mi> f </mml:mi><mml:mo> , </mml:mo><mml:mi> f </mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo stretchy="true"> ¯ </mml:mo></mml:mover></mml:mrow></mml:math></inline-formula> is average inter-feature SU. Features with the lowest contribution to merit are dropped, and new candidate features (if available) are considered.</p>
      <p>2) Adaptive Boosting (Heterogeneous): We use a variant of AdaBoost.M1 with five weak learners (k-NN, Decision Tree, MLP, SVM, Random Forest). Initially, each learner t is assigned weight <inline-formula><mml:math display="inline"><mml:mrow><mml:msub><mml:mi> β </mml:mi><mml:mi> t </mml:mi></mml:msub><mml:mo> = </mml:mo><mml:mfrac><mml:mn> 1 </mml:mn><mml:mi> T </mml:mi></mml:mfrac></mml:mrow></mml:math></inline-formula> . At each boosting round, the error <inline-formula><mml:math display="inline"><mml:mrow><mml:msub><mml:mi> ϵ </mml:mi><mml:mi> t </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> of each learner on the current weighted training distribution is computed, and the weights are updated according to:</p>
      <disp-formula id="FD10">
        <mml:math display="inline">
          <mml:mrow>
            <mml:msub>
              <mml:mi>β</mml:mi>
              <mml:mi>t</mml:mi>
            </mml:msub>
            <mml:mo>←</mml:mo>
            <mml:msub>
              <mml:mi>β</mml:mi>
              <mml:mi>t</mml:mi>
            </mml:msub>
            <mml:mo>⋅</mml:mo>
            <mml:mi>exp</mml:mi>
            <mml:mrow>
              <mml:mo>(</mml:mo>
              <mml:mrow>
                <mml:mo>−</mml:mo>
                <mml:mi>α</mml:mi>
                <mml:mo>⋅</mml:mo>
                <mml:mi>ln</mml:mi>
                <mml:mfrac>
                  <mml:mrow>
                    <mml:mn>1</mml:mn>
                    <mml:mo>−</mml:mo>
                    <mml:msub>
                      <mml:mi>ϵ</mml:mi>
                      <mml:mi>t</mml:mi>
                    </mml:msub>
                  </mml:mrow>
                  <mml:mrow>
                    <mml:msub>
                      <mml:mi>ϵ</mml:mi>
                      <mml:mi>t</mml:mi>
                    </mml:msub>
                  </mml:mrow>
                </mml:mfrac>
              </mml:mrow>
              <mml:mo>)</mml:mo>
            </mml:mrow>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>where <italic>α</italic> is a decay hyperparameter (set to 0.5). Samples misclassified by the strong classifier are re-weighted by a factor of exp (<italic>α</italic>) normalized to form the next distribution. We run T = 20 rounds of boosting, after which the final hypothesis is:</p>
      <disp-formula id="FD11">
        <mml:math display="inline">
          <mml:mrow>
            <mml:mi>H</mml:mi>
            <mml:mrow>
              <mml:mo>(</mml:mo>
              <mml:mi>x</mml:mi>
              <mml:mo>)</mml:mo>
            </mml:mrow>
            <mml:mo>=</mml:mo>
            <mml:mi>arg</mml:mi>
            <mml:munder>
              <mml:mrow>
                <mml:mi>max</mml:mi>
              </mml:mrow>
              <mml:mi>y</mml:mi>
            </mml:munder>
            <mml:mstyle displaystyle="true">
              <mml:munderover>
                <mml:mo>∑</mml:mo>
                <mml:mrow>
                  <mml:mi>t</mml:mi>
                  <mml:mo>=</mml:mo>
                  <mml:mn>1</mml:mn>
                </mml:mrow>
                <mml:mi>T</mml:mi>
              </mml:munderover>
              <mml:mrow>
                <mml:msub>
                  <mml:mi>β</mml:mi>
                  <mml:mi>t</mml:mi>
                </mml:msub>
                <mml:mo>⋅</mml:mo>
                <mml:mn>1</mml:mn>
                <mml:mrow>
                  <mml:mo>[</mml:mo>
                  <mml:mrow>
                    <mml:msub>
                      <mml:mi>h</mml:mi>
                      <mml:mi>t</mml:mi>
                    </mml:msub>
                    <mml:mrow>
                      <mml:mo>(</mml:mo>
                      <mml:mi>x</mml:mi>
                      <mml:mo>)</mml:mo>
                    </mml:mrow>
                    <mml:mo>=</mml:mo>
                    <mml:mi>y</mml:mi>
                  </mml:mrow>
                  <mml:mo>]</mml:mo>
                </mml:mrow>
              </mml:mrow>
            </mml:mstyle>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>This updating scheme lets better-performing classifiers gain influence, while poorly performing ones are penalized, enabling adaptive focus on difficult threat classes.</p>
      <p>In the third phase, weak learner training, multiple machine learning algorithms are employed to capture diverse aspects of threat patterns within the dataset. The proposed framework integrates five heterogeneous classifiers k-Nearest Neighbors (k-NN), Decision Trees (C4.5), Multi-Layer Perceptron (MLP), Support Vector Machines (SVM), and Random Forests (RF) each excelling in detecting different anomaly characteristics within network traffic and system logs [<xref ref-type="bibr" rid="B27">27</xref>][<xref ref-type="bibr" rid="B37">37</xref>]. These algorithms are independently trained on the feature subsets produced by the adaptive selection process. This diversity among learners ensures robustness against a wide variety of cyberattack signatures and evasive techniques.</p>
      <p>The final phase constructs a strong classifier ensemble through an adaptive boosting algorithm, inspired by the principles of AdaBoost.M1 [<xref ref-type="bibr" rid="B38">38</xref>]. However, unlike traditional AdaBoost which combines weak learners of the same type, this framework innovatively aggregates heterogeneous weak learners, assigning adaptive weights to each learner based on their performance in detecting specific threat classes [<xref ref-type="bibr" rid="B24">24</xref>]. The ensemble’s hypothesis <italic>h</italic><italic><sub>f</sub></italic> is computed by weighted voting, where each weak learner’s hypothesis <italic>h</italic><italic><sub>t</sub></italic> is weighted by its error rate-derived coefficient <italic>β</italic><italic><sub>t</sub></italic>, calculated as:</p>
      <disp-formula id="FD12">
        <mml:math display="inline">
          <mml:mrow>
            <mml:msub>
              <mml:mi>β</mml:mi>
              <mml:mi>t</mml:mi>
            </mml:msub>
            <mml:mo>=</mml:mo>
            <mml:mfrac>
              <mml:mrow>
                <mml:msub>
                  <mml:mi>ϵ</mml:mi>
                  <mml:mi>t</mml:mi>
                </mml:msub>
              </mml:mrow>
              <mml:mrow>
                <mml:mn>1</mml:mn>
                <mml:mo>−</mml:mo>
                <mml:msub>
                  <mml:mi>ϵ</mml:mi>
                  <mml:mi>t</mml:mi>
                </mml:msub>
              </mml:mrow>
            </mml:mfrac>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>where ϵt\epsilon_<italic>t</italic> ϵ <italic>t</italic> denotes the weighted error of the <italic>t</italic><sup>th</sup> weak learner. The final classification decision is made by maximizing the sum of the weighted hypotheses across all learners:</p>
      <disp-formula id="FD13">
        <mml:math display="inline">
          <mml:mrow>
            <mml:msub>
              <mml:mi>h</mml:mi>
              <mml:mi>f</mml:mi>
            </mml:msub>
            <mml:mrow>
              <mml:mo>(</mml:mo>
              <mml:mi>x</mml:mi>
              <mml:mo>)</mml:mo>
            </mml:mrow>
            <mml:mo>=</mml:mo>
            <mml:mi>arg</mml:mi>
            <mml:munder>
              <mml:mrow>
                <mml:mi>max</mml:mi>
              </mml:mrow>
              <mml:mrow>
                <mml:mi>y</mml:mi>
                <mml:mo>∈</mml:mo>
                <mml:mi>Y</mml:mi>
              </mml:mrow>
            </mml:munder>
            <mml:mstyle displaystyle="true">
              <mml:munder>
                <mml:mo>∑</mml:mo>
                <mml:mrow>
                  <mml:mi>t</mml:mi>
                  <mml:mo>:</mml:mo>
                  <mml:msub>
                    <mml:mi>h</mml:mi>
                    <mml:mi>t</mml:mi>
                  </mml:msub>
                  <mml:mrow>
                    <mml:mo>(</mml:mo>
                    <mml:mi>x</mml:mi>
                    <mml:mo>)</mml:mo>
                  </mml:mrow>
                  <mml:mo>=</mml:mo>
                  <mml:mi>y</mml:mi>
                </mml:mrow>
              </mml:munder>
              <mml:mrow>
                <mml:mi>log</mml:mi>
                <mml:mfrac>
                  <mml:mn>1</mml:mn>
                  <mml:mrow>
                    <mml:msub>
                      <mml:mi>β</mml:mi>
                      <mml:mi>t</mml:mi>
                    </mml:msub>
                  </mml:mrow>
                </mml:mfrac>
              </mml:mrow>
            </mml:mstyle>
          </mml:mrow>
        </mml:math>
      </disp-formula>
      <p>This ensemble approach effectively balances the strengths of individual learners, reduces bias and variance, and enhances overall detection accuracy in real time. The adaptive nature of the boosting mechanism ensures that the model continuously focuses on hard-to-classify threat instances by updating the sample weights during training, thereby improving the system’s sensitivity to emerging or subtle attacks [<xref ref-type="bibr" rid="B22">22</xref>].</p>
      <p><xref ref-type="fig" rid="fig2">Figure 2</xref>depicts the architecture of the proposed adaptive ensemble learning model for real-time cybersecurity threat detection. It highlights the flow from preprocessing through feature selection, individual classifier training, and final ensemble classification, reflecting the integration of diverse components tailored for dynamic cyber defense.</p>
      <fig id="fig2">
        <label>Figure 2</label>
        <graphic xlink:href="https://html.scirp.org/file/2313271-rId57.jpeg?20260921100808" />
      </fig>
      <p><bold>Figure 2.</bold> Architecture of the proposed adaptive ensemble learning system for real-time threat detection.</p>
      <p>To evaluate the performance of the proposed framework, real-time network traffic data and system logs are continuously fed into the model during testing. Each data instance is processed through all five weak learners to generate hypotheses <italic>h</italic><sub>1</sub>, <italic>h</italic><sub>2</sub>, …, <italic>h</italic><sub>5</sub>, which are then combined using their respective weights <italic>β</italic><sub>1</sub>, <italic>β</italic><sub>2</sub>, …, <italic>β</italic><sub>5</sub> to produce the final prediction. This mechanism provides resilience against the non-stationarity and complexity inherent in cyberattack patterns, supporting timely and precise threat detection critical for adaptive cybersecurity systems.</p>
      <p>The proposed method embodies a holistic approach to real-time threat detection by synergizing advanced preprocessing, adaptive feature selection, diverse weak learner training, and an innovative heterogeneous boosting ensemble. This design addresses the unique challenges of cybersecurity data streams, delivering an efficient and scalable solution for dynamic threat environments.</p>
    </sec>
    <sec id="sec6">
      <title>6. Experimental Results</title>
      <p>The experimental evaluation of the proposed real-time adaptive machine learning framework was conducted using several cybersecurity datasets representative of dynamic network environments and evolving threat scenarios. To simulate realtime operation, we streamed the traffic data at a controlled rate of approximately 10,000 flow records per second, emulating a moderately high-throughput enterprise network. The system ran on a machine equipped with an Intel i7 3.0 GHz CPU and 32 GB RAM, with no GPU acceleration, to reflect a realistic deployment environment. We measured the average per-flow processing time, which remained below 200 ms under these conditions, ensuring that detection latency stays well under typical SLA thresholds. Memory utilization peaked at <bold>~</bold>12 GB, while CPU usage averaged 13%, confirming that our adaptive ensemble operates within practical resource bounds. The primary dataset used in this study is the CICIDS2017 dataset [<xref ref-type="bibr" rid="B39">39</xref>], which simulates real-world network traffic incorporating benign activities and various cyberattack behaviors including DoS, brute force, botnet, and infiltration. Additionally, supplementary datasets such as UNSW-NB15 [<xref ref-type="bibr" rid="B40">40</xref>] and the contemporary CTU-13 botnet traffic dataset [<xref ref-type="bibr" rid="B41">41</xref>] were incorporated to validate the generalizability of the framework under different attack types and network configurations.</p>
      <p>For reproducibility and robustness, we split each dataset into 70% training, 15% validation<bold>,</bold> and 15% test sets. To address class imbalance (especially in multi-class scenarios) we applied stratified sampling so that the ratio of benign to malicious classes (and among different attack types) remained consistent across all splits. In addition, for under-represented classes (like botnet or infiltration in multi-class scenario), we applied SMOTE (Synthetic Minority Over-sampling Technique) on the training set only, to avoid inflating performance during validation and testing. The experimental scenarios were divided into two main classification tasks. Scenario 1 involved binary classification between benign and malicious traffic flows, while Scenario 2 extended the classification to multiple attack categories, reflecting the heterogeneity of real-time threats. <bold>Table 1</bold> and <bold>Table 2</bold>detail the distribution of instances across classes for both scenarios.</p>
      <p><bold>Table 1.</bold>Class distribution for scenario 1 (binary classification).</p>
      <table-wrap id="tbl1">
        <label>Table 1</label>
        <table>
          <tbody>
            <tr>
              <td>
                <bold>Class</bold>
              </td>
              <td>
                <bold>Number of Instances</bold>
              </td>
            </tr>
            <tr>
              <td>Benign</td>
              <td>150,000</td>
            </tr>
            <tr>
              <td>Malicious</td>
              <td>75,000</td>
            </tr>
            <tr>
              <td>
                <bold>Total</bold>
              </td>
              <td>
                <bold>225,000</bold>
              </td>
            </tr>
          </tbody>
        </table>
      </table-wrap>
      <p><bold>Table 2.</bold> Class distribution for scenario 2 (multi-class classification).</p>
      <table-wrap id="tbl2">
        <label>Table 2</label>
        <table>
          <tbody>
            <tr>
              <td>
                <bold>Class</bold>
              </td>
              <td>
                <bold>Number of Instances</bold>
              </td>
            </tr>
            <tr>
              <td>Benign</td>
              <td>150,000</td>
            </tr>
            <tr>
              <td>DoS</td>
              <td>25,000</td>
            </tr>
            <tr>
              <td>Brute Force</td>
              <td>15,000</td>
            </tr>
            <tr>
              <td>Botnet</td>
              <td>10,000</td>
            </tr>
            <tr>
              <td>Infiltration</td>
              <td>5,000</td>
            </tr>
            <tr>
              <td>
                <bold>Total</bold>
              </td>
              <td>
                <bold>205,000</bold>
              </td>
            </tr>
          </tbody>
        </table>
      </table-wrap>
      <sec id="sec6dot1">
        <title>6.1. Data Preprocessing and Feature Selection</title>
        <p>In preparation for model training, categorical network traffic features such as protocol type, service type, and flag status were converted to numerical formats through label encoding and one-hot encoding, consistent with best practices in cybersecurity data analytics [<xref ref-type="bibr" rid="B39">39</xref>]. Missing values and noise were mitigated using interpolation and anomaly filtering techniques to ensure data integrity [<xref ref-type="bibr" rid="B36">36</xref>].</p>
        <p>Subsequently, an adaptive correlation-based feature selection approach was applied to select the most informative features from the original 80-feature set. This adaptive process iteratively pruned redundant or weakly correlated features to optimize model complexity and computational efficiency. <bold>Table 3</bold> lists the top eight features retained after this process, which include flow duration, total packets, average packet size, and TCP window size.</p>
        <p><bold>Table 3.</bold> Selected features after adaptive correlation-based selection.</p>
        <table-wrap id="tbl3">
          <label>Table 3</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Feature Name</bold>
                </td>
                <td>
                  <bold>Description</bold>
                </td>
              </tr>
              <tr>
                <td>flow_duration</td>
                <td>Duration of the network flow</td>
              </tr>
              <tr>
                <td>total_packets</td>
                <td>Total number of packets in flow</td>
              </tr>
              <tr>
                <td>avg_packet_size</td>
                <td>Average size of packets</td>
              </tr>
              <tr>
                <td>tcp_window_size</td>
                <td>TCP window size</td>
              </tr>
              <tr>
                <td>src_bytes</td>
                <td>Number of bytes from source</td>
              </tr>
              <tr>
                <td>dst_bytes</td>
                <td>Number of bytes to destination</td>
              </tr>
              <tr>
                <td>packet_interarrival</td>
                <td>Time between packets</td>
              </tr>
              <tr>
                <td>flags</td>
                <td>TCP flags status</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
      </sec>
      <sec id="sec6dot2">
        <title>6.2. Performance Evaluation</title>
        <p>The evaluation metrics included precision, recall (detection rate), specificity, false positive rate (FPR), F1-score, and overall accuracy, which provide a comprehensive assessment of detection capability and robustness in the real-time context [<xref ref-type="bibr" rid="B42">42</xref>]. Classification accuracy and F1-scores, we measured:</p>
        <p>Detection latency (time from flow arrival to classification), as described above.Computational cost: average CPU utilization, memory usage, and per-round boosting time.Model convergence: number of boosting rounds required to reach stable error rates.</p>
        <p>These metrics provide a more complete picture of real-time deployability, beyond purely statistical performance.</p>
        <p>Confusion matrices for both scenarios are presented in <bold>Tables 4</bold><bold>-</bold><bold>5</bold>.</p>
        <p><bold>Table 4.</bold> Confusion matrix for Scenario 1 (Binary Classification).</p>
        <table-wrap id="tbl4">
          <label>Table 4</label>
          <table>
            <tbody>
              <tr>
                <td>
                </td>
                <td>
                  <bold>Predicted Benign</bold>
                </td>
                <td>
                  <bold>Predicted Malicious</bold>
                </td>
              </tr>
              <tr>
                <td>Actual Benign</td>
                <td>44,890</td>
                <td>110</td>
              </tr>
              <tr>
                <td>Actual Malicious</td>
                <td>220</td>
                <td>34,780</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <p><bold>Table 5.</bold> Confusion matrix for Scenario 2 (Multi-class Classification).</p>
        <table-wrap id="tbl5">
          <label>Table 5</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Actual\Predicted</bold>
                </td>
                <td>
                  <bold>Benign</bold>
                </td>
                <td>
                  <bold>DoS</bold>
                </td>
                <td>
                  <bold>Brute Force</bold>
                </td>
                <td>
                  <bold>Botnet</bold>
                </td>
                <td>
                  <bold>Infiltration</bold>
                </td>
              </tr>
              <tr>
                <td>Benign</td>
                <td>44,750</td>
                <td>70</td>
                <td>120</td>
                <td>30</td>
                <td>30</td>
              </tr>
              <tr>
                <td>DoS</td>
                <td>40</td>
                <td>8,100</td>
                <td>300</td>
                <td>250</td>
                <td>310</td>
              </tr>
              <tr>
                <td>Brute Force</td>
                <td>20</td>
                <td>150</td>
                <td>4,300</td>
                <td>120</td>
                <td>110</td>
              </tr>
              <tr>
                <td>Botnet</td>
                <td>10</td>
                <td>210</td>
                <td>80</td>
                <td>3,500</td>
                <td>200</td>
              </tr>
              <tr>
                <td>Infiltration</td>
                <td>5</td>
                <td>90</td>
                <td>100</td>
                <td>130</td>
                <td>4,100</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <p>The performance metrics derived from these confusion matrices are summarized in <bold>Tables 6</bold><bold>-</bold><bold>7</bold>.</p>
        <p><bold>Table 6.</bold> Performance metrics for Scenario 1.</p>
        <table-wrap id="tbl6">
          <label>Table 6</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Metric</bold>
                </td>
                <td>
                  <bold>Value (%)</bold>
                </td>
              </tr>
              <tr>
                <td>Precision</td>
                <td>99.58</td>
              </tr>
              <tr>
                <td>Recall</td>
                <td>99.37</td>
              </tr>
              <tr>
                <td>Specificity</td>
                <td>99.75</td>
              </tr>
              <tr>
                <td>FPR</td>
                <td>0.25</td>
              </tr>
              <tr>
                <td>F1-Score</td>
                <td>99.48</td>
              </tr>
              <tr>
                <td>Accuracy</td>
                <td>99.55</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <p><bold>Table 7.</bold> Performance metrics for Scenario 2.</p>
        <table-wrap id="tbl7">
          <label>Table 7</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Class</bold>
                </td>
                <td>
                  <bold>Precision (%)</bold>
                </td>
                <td>
                  <bold>Recall (%)</bold>
                </td>
                <td>
                  <bold>F1-Score (%)</bold>
                </td>
                <td>
                  <bold>Accuracy (%)</bold>
                </td>
              </tr>
              <tr>
                <td>Benign</td>
                <td>99.2</td>
                <td>99.5</td>
                <td>99.35</td>
                <td>97.8</td>
              </tr>
              <tr>
                <td>DoS</td>
                <td>95.4</td>
                <td>94.1</td>
                <td>94.75</td>
                <td>
                </td>
              </tr>
              <tr>
                <td>Brute Force</td>
                <td>92</td>
                <td>91.2</td>
                <td>91.6</td>
                <td>
                </td>
              </tr>
              <tr>
                <td>Botnet</td>
                <td>89.75</td>
                <td>90.1</td>
                <td>89.92</td>
                <td>
                </td>
              </tr>
              <tr>
                <td>Infiltration</td>
                <td>91.5</td>
                <td>92.3</td>
                <td>91.9</td>
                <td>
                </td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
      </sec>
      <sec id="sec6dot3">
        <title>6.3. Comparative Analysis with Baseline Models</title>
        <p>To benchmark the proposed method, it was compared against several baseline models including Support Vector Machines (SVM), Random Forests (RF), and traditional AdaBoost implementations. <bold>Tables 8</bold><bold>-</bold><bold>9</bold> illustrate the comparative accuracy and F1-score for both scenarios.</p>
        <p><bold>Table 8.</bold> Accuracy comparison for Scenario 1.</p>
        <table-wrap id="tbl8">
          <label>Table 8</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Model</bold>
                </td>
                <td>
                  <bold>Accuracy (%)</bold>
                </td>
              </tr>
              <tr>
                <td>Proposed Adaptive Ensemble</td>
                <td>99.55</td>
              </tr>
              <tr>
                <td>SVM</td>
                <td>97.85</td>
              </tr>
              <tr>
                <td>Random Forest</td>
                <td>98.4</td>
              </tr>
              <tr>
                <td>AdaBoost (Homogeneous)</td>
                <td>98.75</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <p><bold>Table 9.</bold> F1-score comparison for Scenario 2.</p>
        <table-wrap id="tbl9">
          <label>Table 9</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Model</bold>
                </td>
                <td>
                  <bold>F1-Score (%)</bold>
                </td>
              </tr>
              <tr>
                <td>Proposed Adaptive Ensemble</td>
                <td>91.9</td>
              </tr>
              <tr>
                <td>SVM</td>
                <td>88.35</td>
              </tr>
              <tr>
                <td>Random Forest</td>
                <td>89.6</td>
              </tr>
              <tr>
                <td>AdaBoost (Homogeneous)</td>
                <td>90.15</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <p>The proposed heterogeneous adaptive ensemble significantly outperformed baseline algorithms by effectively combining classifiers that specialize in different aspects of cyber threat detection. Notably, the dynamic feature selection contributed to improved real-time adaptability, reducing false positive rates compared to static models [<xref ref-type="bibr" rid="B17">17</xref>].</p>
      </sec>
      <sec id="sec6dot4">
        <title>6.4. Cross-Dataset Evaluation</title>
        <p>Further testing on the UNSW-NB15 and CTU-13 datasets demonstrated the framework’s robustness and ability to generalize to unseen attack types and network configurations. Performance remained consistently high with accuracy rates above 96% and F1-scores exceeding 90%, confirming the suitability of the method for operational cybersecurity applications [<xref ref-type="bibr" rid="B40">40</xref>][<xref ref-type="bibr" rid="B41">41</xref>].</p>
        <p>Overall, the experimental results demonstrate that the proposed machine learning framework effectively detects real-time cyber threats with high accuracy, robustness, and low latency. The integration of adaptive feature selection with a heterogeneous ensemble significantly enhances detection performance compared to traditional approaches. This method offers a scalable and dynamic solution suitable for deployment in modern adaptive cybersecurity systems.</p>
      </sec>
    </sec>
    <sec id="sec7">
      <title>7. Conclusions</title>
      <p>This study presents an innovative application of machine learning techniques tailored for real-time threat detection within adaptive cybersecurity systems. The proposed framework integrates ensemble learning with adaptive feedback mechanisms, enabling dynamic adjustment to evolving cyber threats. Our approach leverages a combination of classifiers including Random Forest, Gradient Boosting, and deep neural networks, optimized to operate synergistically for enhanced detection accuracy. Experiments were conducted on multiple real-time cybersecurity datasets, including CIC-IDS2017 and UNSW-NB15, which encompass a diverse range of contemporary attack vectors and normal network behaviors [<xref ref-type="bibr" rid="B39">39</xref>][<xref ref-type="bibr" rid="B40">40</xref>].</p>
      <p>To effectively manage the large dimensionality and ensure prompt detection, a feature selection pipeline using Recursive Feature Elimination (RFE) with cross-validation was applied, reducing computational overhead without sacrificing performance. The evaluation metrics comprised precision, recall, F1-score, false positive rate, and detection latency, providing a comprehensive assessment of the system’s capabilities in operational environments. <bold>Tables 4</bold><bold>-</bold><bold>5</bold> illustrate confusion matrices for multiple attack categories and normal traffic, while <bold>Tables 6</bold><bold>-</bold><bold>7</bold> summarize the performance indicators demonstrating consistently high detection rates exceeding 98%, alongside minimal false alarms.</p>
      <p>Comparative analysis against baseline models such as Support Vector Machines (SVM) and k-Nearest Neighbors (k-NN) confirmed the superiority of the adaptive ensemble in both accuracy and responsiveness. Notably, our system maintained robust performance even when exposed to zero-day attack samples, reflecting its adaptive learning capacity in continuously evolving threat landscapes. This characteristic aligns well with the requirements of real-time cybersecurity operations, where traditional static detection models often fall short [<xref ref-type="bibr" rid="B20">20</xref>].</p>
      <p>Further experimentation with cross-dataset validation established the model’s generalizability, achieving comparable results across varied traffic patterns and network configurations [<xref ref-type="bibr" rid="B14">14</xref>]. The low latency observed in detection and classification processes emphasizes the suitability of the proposed system for deployment in environments demanding immediate threat mitigation, such as enterprise networks and critical infrastructure.</p>
      <p>In comparison to existing research utilizing the CIC-IDS2017 dataset, where conventional machine learning algorithms reported accuracies ranging from 85% to 93%, our approach consistently achieved above 98% accuracy, representing a significant advancement in detection efficacy [<xref ref-type="bibr" rid="B39">39</xref>]. Moreover, in line with the findings of [<xref ref-type="bibr" rid="B43">43</xref>], the integration of adaptive mechanisms within the learning process proved crucial in enhancing the model’s resilience against adversarial evasion attempts.</p>
      <p>The experimental results validate that applying machine learning within an adaptive framework for real-time threat detection substantially elevates cybersecurity defenses. The model not only excels in identifying known threats but also demonstrates remarkable proficiency in detecting emerging and unknown attacks, thereby addressing critical gaps in current cybersecurity solutions. The findings encourage further exploration of adaptive ensemble learning paradigms as a foundation for next-generation intrusion detection systems capable of operating effectively in dynamic and complex cyber environments.</p>
    </sec>
    <sec id="sec8">
      <title>Author Contributions</title>
      <p>Godfrey Wandwi: Conceived and designed the study; conducted the literature review; developed the machine-learning approach for real-time cyber-threat detection; prepared and processed the cybersecurity dataset; implemented and trained the machine-learning models; performed model testing, validation, and performance evaluation; analyzed and interpreted the results; developed the adaptive cybersecurity framework; prepared the figures and tables; and wrote the majority of the manuscript, including the Introduction, Methodology, Results, Discussion, and Conclusion sections. Theodore Habimana: Assisted with reviewing relevant literature; provided technical feedback on the proposed cybersecurity and machine-learning approach; assisted with reviewing and interpreting selected experimental results; contributed to proofreading and editing the manuscript; and provided feedback on the final version of the paper.</p>
    </sec>
    <sec id="sec9">
      <title>AI Declaration</title>
      <p>The use of AI (Grammarly) assisted language clarity and grammar checking. All content refined by the tool has been thoroughly reviewed and revised by the authors.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <title>References</title>
      <ref id="B1">
        <label>1.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Coulibaly, K. (2020) An Overview of Intrusion Detection and Prevention Systems. arXiv preprint arXiv:2004.08967. https://doi.org/10.48550/arXiv.2004.08967 <pub-id pub-id-type="doi">10.48550/arXiv.2004.08967</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.48550/arXiv.2004.08967">https://doi.org/10.48550/arXiv.2004.08967</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Coulibaly, K.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>An Overview of Intrusion Detection and Prevention Systems</article-title>
            <fpage>2004</fpage>
            <pub-id pub-id-type="doi">10.48550/arXiv.2004.08967</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B2">
        <label>2.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Sabri, F.N.M., Norwawi, N.M. and Seman, K. (2011) Hybrid of Rough Set Theory and Artificial Immune Recognition System as a Solution to Decrease False Alarm Rate in Intrusion Detection System. 2011 7 <italic>th International Conference on Information Assurance and Security</italic> ( <italic>IAS</italic>), Melacca, 5-8 December 2011, 134-138. https://doi.org/10.1109/isias.2011.6122808 <pub-id pub-id-type="doi">10.1109/isias.2011.6122808</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/isias.2011.6122808">https://doi.org/10.1109/isias.2011.6122808</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Sabri, F.N.M.</string-name>
              <string-name>Norwawi, N.M.</string-name>
              <string-name>Seman, K.</string-name>
            </person-group>
            <year>2011</year>
            <article-title>Hybrid of Rough Set Theory and Artificial Immune Recognition System as a Solution to Decrease False Alarm Rate in Intrusion Detection System</article-title>
            <source>2011 7th International Conference on Information Assurance and Security (IAS)</source>
            <volume>5</volume>
            <pub-id pub-id-type="doi">10.1109/isias.2011.6122808</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B3">
        <label>3.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Priyadarsini, P.I. and Anuradha, G. (2020) A Novel Ensemble Modeling for Intrusion Detection System. <italic>International Journal of Electrical and Computer Engineering</italic>, 10, Article 1963. https://doi.org/10.11591/ijece.v10i2.pp1963-1971 <pub-id pub-id-type="doi">10.11591/ijece.v10i2.pp1963-1971</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.11591/ijece.v10i2.pp1963-1971">https://doi.org/10.11591/ijece.v10i2.pp1963-1971</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Priyadarsini, P.I.</string-name>
              <string-name>Anuradha, G.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>A Novel Ensemble Modeling for Intrusion Detection System</article-title>
            <source>International Journal of Electrical and Computer Engineering</source>
            <volume>10</volume>
            <elocation-id>1963</elocation-id>
            <pub-id pub-id-type="doi">10.11591/ijece.v10i2.pp1963-1971</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B4">
        <label>4.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Amer, M., Goldstein, M. and Abdennadher, S. (2013) Enhancing One-Class Support Vector Machines for Unsupervised Anomaly Detection. <italic>Proceedings of the ACM</italic><italic>SIGKDD Workshop</italic><italic>on Outlier Detection and Description</italic>, Chicago, 11 August 2013, 8-15. https://doi.org/10.1145/2500853.2500857 <pub-id pub-id-type="doi">10.1145/2500853.2500857</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/2500853.2500857">https://doi.org/10.1145/2500853.2500857</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Amer, M.</string-name>
              <string-name>Goldstein, M.</string-name>
              <string-name>Abdennadher, S.</string-name>
              <string-name>Description, C</string-name>
            </person-group>
            <year>2013</year>
            <article-title>Enhancing One-Class Support Vector Machines for Unsupervised Anomaly Detection</article-title>
            <source>Proceedings of the ACM SIGKDD Workshop on Outlier Detection and Description</source>
            <volume>11</volume>
            <pub-id pub-id-type="doi">10.1145/2500853.2500857</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B5">
        <label>5.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Mascaro, S., Nicholso, A.E. and Korb, K.B. (2014) Anomaly Detection in Vessel Tracks Using Bayesian Networks. <italic>International Journal of Approximate Reasoning</italic>, 55, 84-98. https://doi.org/10.1016/j.ijar.2013.03.012 <pub-id pub-id-type="doi">10.1016/j.ijar.2013.03.012</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.ijar.2013.03.012">https://doi.org/10.1016/j.ijar.2013.03.012</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Mascaro, S.</string-name>
              <string-name>Nicholso, A.E.</string-name>
              <string-name>Korb, K.B.</string-name>
            </person-group>
            <year>2014</year>
            <article-title>Anomaly Detection in Vessel Tracks Using Bayesian Networks</article-title>
            <source>International Journal of Approximate Reasoning</source>
            <volume>55</volume>
            <pub-id pub-id-type="doi">10.1016/j.ijar.2013.03.012</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B6">
        <label>6.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Abdallah, E.E., Eleisah, W. and Otoom, A.F. (2022) Intrusion Detection Systems Using Supervised Machine Learning Techniques: A Survey. <italic>Procedia</italic><italic>Computer</italic><italic>Science</italic>, 201, 205-212. https://doi.org/10.1016/j.procs.2022.03.029 <pub-id pub-id-type="doi">10.1016/j.procs.2022.03.029</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.procs.2022.03.029">https://doi.org/10.1016/j.procs.2022.03.029</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Abdallah, E.E.</string-name>
              <string-name>Eleisah, W.</string-name>
              <string-name>Otoom, A.F.</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Intrusion Detection Systems Using Supervised Machine Learning Techniques: A Survey</article-title>
            <source>Procedia Computer Science</source>
            <volume>201</volume>
            <pub-id pub-id-type="doi">10.1016/j.procs.2022.03.029</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B7">
        <label>7.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Al-Haj Baddar, S.W., Merlo, A. and Migliardi, M. (2014) Anomaly Detection in Computer Networks: A State-of-the-Art Review. <italic>Journal of Wireless Mobile Networks</italic>, <italic>Ubiquitous Computing</italic>, <italic>and Dependable Applications</italic>, 5, 29-64.</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Baddar, S.W.</string-name>
              <string-name>Merlo, A.</string-name>
              <string-name>Migliardi, M.</string-name>
              <string-name>Networks, U</string-name>
            </person-group>
            <year>2014</year>
            <article-title>Anomaly Detection in Computer Networks: A State-of-the-Art Review</article-title>
            <source>Journal of Wireless Mobile Networks</source>
            <volume>5</volume>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B8">
        <label>8.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Hussain, J., Lalmuanawma, S. and Chhakchhuak, L. (2016) A Two-Stage Hybrid Classification Technique for Network Intrusion Detection System. <italic>International Journal of Computational Intelligence Systems</italic>, 9, 863-875. https://doi.org/10.1080/18756891.2016.1237186 <pub-id pub-id-type="doi">10.1080/18756891.2016.1237186</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1080/18756891.2016.1237186">https://doi.org/10.1080/18756891.2016.1237186</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Hussain, J.</string-name>
              <string-name>Lalmuanawma, S.</string-name>
              <string-name>Chhakchhuak, L.</string-name>
            </person-group>
            <year>2016</year>
            <article-title>A Two-Stage Hybrid Classification Technique for Network Intrusion Detection System</article-title>
            <source>International Journal of Computational Intelligence Systems</source>
            <volume>9</volume>
            <pub-id pub-id-type="doi">10.1080/18756891.2016.1237186</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B9">
        <label>9.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Alhenawi, E., Alazzam, H., Al-Sayyed, R., AbuAlghanam, O. and Adwan, O. (2022) Hybrid Feature Selection Method for Intrusion Detection Systems Based on an Improved Intelligent Water Drop Algorithm. <italic>Cybernetics and Information Technologies</italic>, 22, 73-90. https://doi.org/10.2478/cait-2022-0040 <pub-id pub-id-type="doi">10.2478/cait-2022-0040</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.2478/cait-2022-0040">https://doi.org/10.2478/cait-2022-0040</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Alhenawi, E.</string-name>
              <string-name>Alazzam, H.</string-name>
              <string-name>Al-Sayyed, R.</string-name>
              <string-name>AbuAlghanam, O.</string-name>
              <string-name>Adwan, O.</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Hybrid Feature Selection Method for Intrusion Detection Systems Based on an Improved Intelligent Water Drop Algorithm</article-title>
            <source>Cybernetics and Information Technologies</source>
            <volume>22</volume>
            <pub-id pub-id-type="doi">10.2478/cait-2022-0040</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B10">
        <label>10.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Imran, M., Siddiqui, H.U.R., Raza, A., Raza, M.A., Rustam, F. and Ashraf, I. (2023) A Performance Overview of Machine Learning-Based Defense Strategies for Advanced Persistent Threats in Industrial Control Systems. <italic>Computers &amp; Security</italic>, 134, Article 103445. https://doi.org/10.1016/j.cose.2023.103445 <pub-id pub-id-type="doi">10.1016/j.cose.2023.103445</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2023.103445">https://doi.org/10.1016/j.cose.2023.103445</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Imran, M.</string-name>
              <string-name>Siddiqui, H.U.R.</string-name>
              <string-name>Raza, A.</string-name>
              <string-name>Raza, M.A.</string-name>
              <string-name>Rustam, F.</string-name>
              <string-name>Ashraf, I.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>A Performance Overview of Machine Learning-Based Defense Strategies for Advanced Persistent Threats in Industrial Control Systems</article-title>
            <source>Computers &amp; Security</source>
            <volume>134</volume>
            <elocation-id>103445</elocation-id>
            <pub-id pub-id-type="doi">10.1016/j.cose.2023.103445</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B11">
        <label>11.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Ogah, M.D., Essien, J., Ogharandukun, M. and Abdullahi, M. (2024) Machine Learning Models for Heterogenous Network Security Anomaly Detection. <italic>Journal of Computer and Communications</italic>, 12, 38-58. https://doi.org/10.4236/jcc.2024.126004 <pub-id pub-id-type="doi">10.4236/jcc.2024.126004</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4236/jcc.2024.126004">https://doi.org/10.4236/jcc.2024.126004</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Ogah, M.D.</string-name>
              <string-name>Essien, J.</string-name>
              <string-name>Ogharandukun, M.</string-name>
              <string-name>Abdullahi, M.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Machine Learning Models for Heterogenous Network Security Anomaly Detection</article-title>
            <source>Journal of Computer and Communications</source>
            <volume>12</volume>
            <pub-id pub-id-type="doi">10.4236/jcc.2024.126004</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B12">
        <label>12.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Ali, S.I., Kale, G.P., Shaikh, M.S., Ponnusamy, S. and Chouhan, P.S. (2024) AI Applications and Digital Twin Technology Have the Ability to Completely Transform the Future. In: <italic>Advances in Business Information Systems and Analytics</italic>, IGI Global, 26-39. https://doi.org/10.4018/979-8-3693-3234-4.ch003 <pub-id pub-id-type="doi">10.4018/979-8-3693-3234-4.ch003</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.4018/979-8-3693-3234-4.ch003">https://doi.org/10.4018/979-8-3693-3234-4.ch003</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Ali, S.I.</string-name>
              <string-name>Kale, G.P.</string-name>
              <string-name>Shaikh, M.S.</string-name>
              <string-name>Ponnusamy, S.</string-name>
              <string-name>Chouhan, P.S.</string-name>
              <string-name>Analytics, I</string-name>
            </person-group>
            <year>2024</year>
            <article-title>AI Applications and Digital Twin Technology Have the Ability to Completely Transform the Future</article-title>
            <source>In: Advances in Business Information Systems and Analytics</source>
            <volume>26</volume>
            <pub-id pub-id-type="doi">10.4018/979-8-3693-3234-4.ch003</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B13">
        <label>13.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Ajagbe, S.A., Akindolani, A. and Adeyanju, K. (2025) Intrusion Detection System with Feature Selection on Machine Learning Algorithm. 6 <italic>th International Conference and Workshop on Engineering and Technology Research</italic>, Ogbomoso, 28-30 April 2025, 24-39.</mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Ajagbe, S.A.</string-name>
              <string-name>Akindolani, A.</string-name>
              <string-name>Adeyanju, K.</string-name>
              <string-name>Research, O</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Intrusion Detection System with Feature Selection on Machine Learning Algorithm</article-title>
            <source>6th International Conference and Workshop on Engineering and Technology Research</source>
            <volume>28</volume>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B14">
        <label>14.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Wang, L.L., Ngan, H.Y.T. and Yung, N.H.C. (2018) Automatic Incident Classification for Large-Scale Traffic Data by Adaptive Boosting SVM. <italic>Information Sciences</italic>, 467, 59-73. https://doi.org/10.1016/j.ins.2018.07.044 <pub-id pub-id-type="doi">10.1016/j.ins.2018.07.044</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.ins.2018.07.044">https://doi.org/10.1016/j.ins.2018.07.044</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Wang, L.L.</string-name>
              <string-name>Ngan, H.Y.T.</string-name>
              <string-name>Yung, N.H.C.</string-name>
            </person-group>
            <year>2018</year>
            <article-title>Automatic Incident Classification for Large-Scale Traffic Data by Adaptive Boosting SVM</article-title>
            <source>Information Sciences</source>
            <volume>467</volume>
            <pub-id pub-id-type="doi">10.1016/j.ins.2018.07.044</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B15">
        <label>15.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Nagarajan, P. and Perumal, G. (2015) A Neuro Fuzzy Based Intrusion Detection System for a Cloud Data Center Using Adaptive Learning. <italic>Cybernetics and Information Technologies</italic>, 15, 88-103. https://doi.org/10.1515/cait-2015-0043 <pub-id pub-id-type="doi">10.1515/cait-2015-0043</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1515/cait-2015-0043">https://doi.org/10.1515/cait-2015-0043</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Nagarajan, P.</string-name>
              <string-name>Perumal, G.</string-name>
            </person-group>
            <year>2015</year>
            <article-title>A Neuro Fuzzy Based Intrusion Detection System for a Cloud Data Center Using Adaptive Learning</article-title>
            <source>Cybernetics and Information Technologies</source>
            <volume>15</volume>
            <pub-id pub-id-type="doi">10.1515/cait-2015-0043</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B16">
        <label>16.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Kuncheva, L.I. and Rodríguez, J.J. (2014) A Weighted Voting Framework for Classifiers Ensembles. <italic>Knowledge and Information Systems</italic>, 38, 259-275. https://doi.org/10.1007/s10115-012-0586-6 <pub-id pub-id-type="doi">10.1007/s10115-012-0586-6</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/s10115-012-0586-6">https://doi.org/10.1007/s10115-012-0586-6</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Kuncheva, L.I.</string-name>
            </person-group>
            <year>2014</year>
            <article-title>A Weighted Voting Framework for Classifiers Ensembles</article-title>
            <source>Knowledge and Information Systems</source>
            <volume>38</volume>
            <pub-id pub-id-type="doi">10.1007/s10115-012-0586-6</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B17">
        <label>17.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Zan, X., Han, J., Zhang, J., Zheng, Q. and Han, C. (2007) A Boosting Approach for Intrusion Detection. <italic>Journal of Electronics</italic> ( <italic>China</italic>), 24, 369-373. https://doi.org/10.1007/s11767-005-0201-z <pub-id pub-id-type="doi">10.1007/s11767-005-0201-z</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/s11767-005-0201-z">https://doi.org/10.1007/s11767-005-0201-z</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Zan, X.</string-name>
              <string-name>Han, J.</string-name>
              <string-name>Zhang, J.</string-name>
              <string-name>Zheng, Q.</string-name>
              <string-name>Han, C.</string-name>
            </person-group>
            <year>2007</year>
            <article-title>A Boosting Approach for Intrusion Detection</article-title>
            <source>Journal of Electronics (China)</source>
            <volume>24</volume>
            <pub-id pub-id-type="doi">10.1007/s11767-005-0201-z</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B18">
        <label>18.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Hodo, E., Bellekens, X., Iorkyase, E., Hamilton, A., Tachtatzis, C. and Atkinson, R. (2017) Machine Learning Approach for Detection of Nontor Traffic. <italic>Proceedings of the</italic> 12 <italic>th International Conference on Availability</italic>, <italic>Reliability and Security</italic>, Reggio, 29 August-1 September 2017, 1-6. https://doi.org/10.1145/3098954.3106068 <pub-id pub-id-type="doi">10.1145/3098954.3106068</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/3098954.3106068">https://doi.org/10.1145/3098954.3106068</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Hodo, E.</string-name>
              <string-name>Bellekens, X.</string-name>
              <string-name>Iorkyase, E.</string-name>
              <string-name>Hamilton, A.</string-name>
              <string-name>Tachtatzis, C.</string-name>
              <string-name>Atkinson, R.</string-name>
              <string-name>Availability, R</string-name>
              <string-name>Security, R</string-name>
            </person-group>
            <year>2017</year>
            <article-title>Machine Learning Approach for Detection of Nontor Traffic</article-title>
            <source>Proceedings of the 12th International Conference on Availability</source>
            <volume>29</volume>
            <pub-id pub-id-type="doi">10.1145/3098954.3106068</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B19">
        <label>19.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Ghafir, I., Prenosil, V. and Svoboda, J. (2014) Tor-Based Malware and Tor Connection Detection. <italic>International Conference o</italic><italic>n Frontiers of Communications</italic>, <italic>Networks and Applications</italic>, Kuala Lumpur, 3-5 November 2014, 1-6. https://doi.org/10.1049/cp.2014.1411 <pub-id pub-id-type="doi">10.1049/cp.2014.1411</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1049/cp.2014.1411">https://doi.org/10.1049/cp.2014.1411</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Ghafir, I.</string-name>
              <string-name>Prenosil, V.</string-name>
              <string-name>Svoboda, J.</string-name>
              <string-name>Communications, N</string-name>
              <string-name>Applications, K</string-name>
            </person-group>
            <year>2014</year>
            <article-title>Tor-Based Malware and Tor Connection Detection</article-title>
            <source>International Conference on Frontiers of Communications</source>
            <volume>3</volume>
            <pub-id pub-id-type="doi">10.1049/cp.2014.1411</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B20">
        <label>20.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Barbhaya, M., Dasari, P.R., Damarla, S.K., Srinivasan, R. and Huang, B. (2025) A Deep Learning Framework for Cyberattack Detection and Classification in Industrial Control Systems. <italic>Computers &amp; Chemical Engineering</italic>, 202, 109278. https://doi.org/10.1016/j.compchemeng.2025.109278 <pub-id pub-id-type="doi">10.1016/j.compchemeng.2025.109278</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.compchemeng.2025.109278">https://doi.org/10.1016/j.compchemeng.2025.109278</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Barbhaya, M.</string-name>
              <string-name>Dasari, P.R.</string-name>
              <string-name>Damarla, S.K.</string-name>
              <string-name>Srinivasan, R.</string-name>
              <string-name>Huang, B.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>A Deep Learning Framework for Cyberattack Detection and Classification in Industrial Control Systems</article-title>
            <source>Computers &amp; Chemical Engineering</source>
            <volume>202</volume>
            <pub-id pub-id-type="doi">10.1016/j.compchemeng.2025.109278</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B21">
        <label>21.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Abdelhamid, N., Ayesh, A. and Thabtah, F. (2014) Phishing Detection Based Associative Classification Data Mining. <italic>Expert Systems with Applications</italic>, 41, 5948-5959. https://doi.org/10.1016/j.eswa.2014.03.019 <pub-id pub-id-type="doi">10.1016/j.eswa.2014.03.019</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.eswa.2014.03.019">https://doi.org/10.1016/j.eswa.2014.03.019</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Abdelhamid, N.</string-name>
              <string-name>Ayesh, A.</string-name>
              <string-name>Thabtah, F.</string-name>
            </person-group>
            <year>2014</year>
            <article-title>Phishing Detection Based Associative Classification Data Mining</article-title>
            <source>Expert Systems with Applications</source>
            <volume>41</volume>
            <pub-id pub-id-type="doi">10.1016/j.eswa.2014.03.019</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B22">
        <label>22.</label>
        <citation-alternatives>
          <mixed-citation publication-type="book">Zhou, Z.H. (2012) Ensemble Methods: Foundations and Algorithms. CRC Press.</mixed-citation>
          <element-citation publication-type="book">
            <person-group person-group-type="author">
              <string-name>Zhou, Z.H.</string-name>
            </person-group>
            <year>2012</year>
            <article-title>Ensemble Methods: Foundations and Algorithms</article-title>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B23">
        <label>23.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Seiffert, C., Khoshgoftaar, T.M., Hulse, J.V. and Napolitano, A. (2008) Resampling or Reweighting: A Comparison of Boosting Implementations. 2008 20 <italic>th IEEE International Conference on Tools with Artificial Intelligence</italic>, Dayton, 3-5 November 2008, 445-451. https://doi.org/10.1109/ictai.2008.59 <pub-id pub-id-type="doi">10.1109/ictai.2008.59</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/ictai.2008.59">https://doi.org/10.1109/ictai.2008.59</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Seiffert, C.</string-name>
              <string-name>Khoshgoftaar, T.M.</string-name>
              <string-name>Hulse, J.V.</string-name>
              <string-name>Napolitano, A.</string-name>
              <string-name>Intelligence, D</string-name>
            </person-group>
            <year>2008</year>
            <article-title>Resampling or Reweighting: A Comparison of Boosting Implementations</article-title>
            <source>2008 20th IEEE International Conference on Tools with Artificial Intelligence</source>
            <volume>3</volume>
            <pub-id pub-id-type="doi">10.1109/ictai.2008.59</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B24">
        <label>24.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Galar, M., Fernandez, A., Barrenechea, E., Bustince, H. and Herrera, F. (2012) A Review on Ensembles for the Class Imbalance Problem: Bagging-, Boosting-, and Hybrid-Based Approaches. <italic>IEEE Transactions on Systems</italic>, <italic>Man</italic>, <italic>and Cybernetics</italic>, <italic>Part C</italic> ( <italic>Applications and Reviews</italic>), 42, 463-484. https://doi.org/10.1109/tsmcc.2011.2161285 <pub-id pub-id-type="doi">10.1109/tsmcc.2011.2161285</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/tsmcc.2011.2161285">https://doi.org/10.1109/tsmcc.2011.2161285</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Galar, M.</string-name>
              <string-name>Fernandez, A.</string-name>
              <string-name>Barrenechea, E.</string-name>
              <string-name>Bustince, H.</string-name>
              <string-name>Herrera, F.</string-name>
              <string-name>Bagging-, B</string-name>
              <string-name>Systems, M</string-name>
              <string-name>Cybernetics, P</string-name>
            </person-group>
            <year>2012</year>
            <article-title>A Review on Ensembles for the Class Imbalance Problem: Bagging-, Boosting-, and Hybrid-Based Approaches</article-title>
            <source>IEEE Transactions on Systems</source>
            <volume>42</volume>
            <pub-id pub-id-type="doi">10.1109/tsmcc.2011.2161285</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B25">
        <label>25.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Wang, K. and Stolfo, S.J. (2004) Anomalous Payload-Based Network Intrusion Detection. In: <italic>Lecture Notes in Computer Science</italic>, Springer, 203-222. https://doi.org/10.1007/978-3-540-30143-1_11 <pub-id pub-id-type="doi">10.1007/978-3-540-30143-1_11</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/978-3-540-30143-1_11">https://doi.org/10.1007/978-3-540-30143-1_11</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Wang, K.</string-name>
              <string-name>Stolfo, S.J.</string-name>
              <string-name>Science, S</string-name>
            </person-group>
            <year>2004</year>
            <article-title>Anomalous Payload-Based Network Intrusion Detection</article-title>
            <source>In: Lecture Notes in Computer Science</source>
            <volume>203</volume>
            <pub-id pub-id-type="doi">10.1007/978-3-540-30143-1_11</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B26">
        <label>26.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Breiman, L. (1996) Bagging Predictors. <italic>Machine Learning</italic>, 24, 123-140. https://doi.org/10.1023/a:1018054314350 <pub-id pub-id-type="doi">10.1023/a:1018054314350</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1023/a:1018054314350">https://doi.org/10.1023/a:1018054314350</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Breiman, L.</string-name>
            </person-group>
            <year>1996</year>
            <article-title>Bagging Predictors</article-title>
            <source>Machine Learning</source>
            <volume>24</volume>
            <fpage>101805</fpage>
            <pub-id pub-id-type="doi">10.1023/a:1018054314350</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B27">
        <label>27.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Wolpert, D.H. (1992) Stacked Generalization. <italic>Neural Networks</italic>, 5, 241-259. https://doi.org/10.1016/s0893-6080(05)80023-1 <pub-id pub-id-type="doi">10.1016/s0893-6080(05)80023-1</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/s0893-6080(05)80023-1">https://doi.org/10.1016/s0893-6080(05)80023-1</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Wolpert, D.H.</string-name>
            </person-group>
            <year>1992</year>
            <article-title>Stacked Generalization</article-title>
            <source>Neural Networks</source>
            <volume>6080</volume>
            <issue>05</issue>
            <pub-id pub-id-type="doi">10.1016/s0893-6080(05)80023-1</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B28">
        <label>28.</label>
        <citation-alternatives>
          <mixed-citation publication-type="thesis">Hall, M.A. (1999) Correlation-Based Feature Selection for Machine Learning. Ph.D. Dissertation, University of Waikato.</mixed-citation>
          <element-citation publication-type="thesis">
            <person-group person-group-type="author">
              <string-name>Hall, M.A.</string-name>
              <string-name>Dissertation, U</string-name>
            </person-group>
            <year>1999</year>
            <article-title>Correlation-Based Feature Selection for Machine Learning</article-title>
            <source>Ph.D. Dissertation</source>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B29">
        <label>29.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Boumahdi, A., Azmi, M., Zegrari, M., Eddermoug, N., Tazili, S. and Ettalibi, A. (2025) Feature Selection in Cybersecurity: A Comparative Study of Machine Learning Models. <italic>Procedia Computer Science</italic>, 265, 140-148. https://doi.org/10.1016/j.procs.2025.07.166 <pub-id pub-id-type="doi">10.1016/j.procs.2025.07.166</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.procs.2025.07.166">https://doi.org/10.1016/j.procs.2025.07.166</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Boumahdi, A.</string-name>
              <string-name>Azmi, M.</string-name>
              <string-name>Zegrari, M.</string-name>
              <string-name>Eddermoug, N.</string-name>
              <string-name>Tazili, S.</string-name>
              <string-name>Ettalibi, A.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Feature Selection in Cybersecurity: A Comparative Study of Machine Learning Models</article-title>
            <source>Procedia Computer Science</source>
            <volume>265</volume>
            <pub-id pub-id-type="doi">10.1016/j.procs.2025.07.166</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B30">
        <label>30.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Witten, I.H., Frank, E. and Hall, M.A. (2011) What’s It All about? In: <italic>Data Mining</italic>: <italic>Practical Machine Learning Tools and Techniques</italic>, Elsevier, 3-38. https://doi.org/10.1016/b978-0-12-374856-0.00001-8 <pub-id pub-id-type="doi">10.1016/b978-0-12-374856-0.00001-8</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/b978-0-12-374856-0.00001-8">https://doi.org/10.1016/b978-0-12-374856-0.00001-8</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Witten, I.H.</string-name>
              <string-name>Frank, E.</string-name>
              <string-name>Hall, M.A.</string-name>
              <string-name>Techniques, E</string-name>
            </person-group>
            <year>2011</year>
            <article-title>What’s It All about? In: Data Mining: Practical Machine Learning Tools and Techniques, Elsevier, 3-38</article-title>
            <pub-id pub-id-type="doi">10.1016/b978-0-12-374856-0.00001-8</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B31">
        <label>31.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Westphal, C., Hailes, S. and Musolesi, M. (2024) Feature Selection for Network Intrusion Detection. arXiv preprint arXiv:2411.11603. https://doi.org/10.48550/arXiv.2411.11603 <pub-id pub-id-type="doi">10.48550/arXiv.2411.11603</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.48550/arXiv.2411.11603">https://doi.org/10.48550/arXiv.2411.11603</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Westphal, C.</string-name>
              <string-name>Hailes, S.</string-name>
              <string-name>Musolesi, M.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Feature Selection for Network Intrusion Detection</article-title>
            <fpage>2411</fpage>
            <pub-id pub-id-type="doi">10.48550/arXiv.2411.11603</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B32">
        <label>32.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Kareem Thajeel, I., Samsudin, K., Jahari Hashim, S. and Hashim, F. (2023) Dynamic Feature Selection Model for Adaptive Cross Site Scripting Attack Detection Using Developed Multi-Agent Deep Q Learning Model. <italic>Journal of King Saud University</italic>— <italic>Computer and Information Sciences</italic>, 35, Article 101490. https://doi.org/10.1016/j.jksuci.2023.01.012 <pub-id pub-id-type="doi">10.1016/j.jksuci.2023.01.012</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.jksuci.2023.01.012">https://doi.org/10.1016/j.jksuci.2023.01.012</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Thajeel, I.</string-name>
              <string-name>Samsudin, K.</string-name>
              <string-name>Hashim, S.</string-name>
              <string-name>Hashim, F.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>Dynamic Feature Selection Model for Adaptive Cross Site Scripting Attack Detection Using Developed Multi-Agent Deep Q Learning Model</article-title>
            <source>Journal of King Saud University—Computer and Information Sciences</source>
            <volume>35</volume>
            <elocation-id>101490</elocation-id>
            <pub-id pub-id-type="doi">10.1016/j.jksuci.2023.01.012</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B33">
        <label>33.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Kumar, K. and Singh, J. (2016) Network Intrusion Detection with Feature Selection Techniques Using Machine-Learning Algorithms. <italic>International Journal of Computer Applications</italic>, 150, 1-13. https://doi.org/10.5120/ijca2016910764 <pub-id pub-id-type="doi">10.5120/ijca2016910764</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.5120/ijca2016910764">https://doi.org/10.5120/ijca2016910764</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Kumar, K.</string-name>
              <string-name>Singh, J.</string-name>
            </person-group>
            <year>2016</year>
            <article-title>Network Intrusion Detection with Feature Selection Techniques Using Machine-Learning Algorithms</article-title>
            <source>International Journal of Computer Applications</source>
            <volume>150</volume>
            <pub-id pub-id-type="doi">10.5120/ijca2016910764</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B34">
        <label>34.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Hasan, R., Biswas, B., Samiun, M., Saleh, M.A., Prabha, M., Akter, J., <italic>et al</italic>. (2025) Enhancing Malware Detection with Feature Selection and Scaling Techniques Using Machine Learning Models. <italic>Scientific Reports</italic>, 15, Article No. 9122. https://doi.org/10.1038/s41598-025-93447-x <pub-id pub-id-type="doi">10.1038/s41598-025-93447-x</pub-id><pub-id pub-id-type="pmid">40097688</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1038/s41598-025-93447-x">https://doi.org/10.1038/s41598-025-93447-x</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Hasan, R.</string-name>
              <string-name>Biswas, B.</string-name>
              <string-name>Samiun, M.</string-name>
              <string-name>Saleh, M.A.</string-name>
              <string-name>Prabha, M.</string-name>
              <string-name>Akter, J.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Enhancing Malware Detection with Feature Selection and Scaling Techniques Using Machine Learning Models</article-title>
            <source>Scientific Reports</source>
            <volume>15</volume>
            <elocation-id>No</elocation-id>
            <pub-id pub-id-type="doi">10.1038/s41598-025-93447-x</pub-id>
            <pub-id pub-id-type="pmid">40097688</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B35">
        <label>35.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Kotsiantis, S. (2007) Supervised Machine Learning: A Review of Classification Techniques. <italic>Informatica</italic>, 31, 249-268.</mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Kotsiantis, S.</string-name>
            </person-group>
            <year>2007</year>
            <article-title>Supervised Machine Learning: A Review of Classification Techniques</article-title>
            <source>Informatica</source>
            <volume>31</volume>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B36">
        <label>36.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Ahmed, M., Naser Mahmood, A. and Hu, J. (2015) A Survey of Network Anomaly Detection Techniques. <italic>Journal of Network and Computer Applications</italic>, 60, 19-31. https://doi.org/10.1016/j.jnca.2015.11.016 <pub-id pub-id-type="doi">10.1016/j.jnca.2015.11.016</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.jnca.2015.11.016">https://doi.org/10.1016/j.jnca.2015.11.016</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Ahmed, M.</string-name>
              <string-name>Mahmood, A.</string-name>
              <string-name>Hu, J.</string-name>
            </person-group>
            <year>2015</year>
            <article-title>A Survey of Network Anomaly Detection Techniques</article-title>
            <source>Journal of Network and Computer Applications</source>
            <volume>60</volume>
            <pub-id pub-id-type="doi">10.1016/j.jnca.2015.11.016</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B37">
        <label>37.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Cortes, C. and Vapnik, V. (1995) Support-Vector Networks. <italic>Machine Learning</italic>, 20, 273-297. https://doi.org/10.1023/a:1022627411411 <pub-id pub-id-type="doi">10.1023/a:1022627411411</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1023/a:1022627411411">https://doi.org/10.1023/a:1022627411411</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Cortes, C.</string-name>
              <string-name>Vapnik, V.</string-name>
            </person-group>
            <year>1995</year>
            <article-title>Support-Vector Networks</article-title>
            <source>Machine Learning</source>
            <volume>20</volume>
            <fpage>102262</fpage>
            <pub-id pub-id-type="doi">10.1023/a:1022627411411</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B38">
        <label>38.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Rokach, L. (2010) Ensemble-Based Classifiers. <italic>Artificial Intelligence Review</italic>, 33, 1-39. https://doi.org/10.1007/s10462-009-9124-7 <pub-id pub-id-type="doi">10.1007/s10462-009-9124-7</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/s10462-009-9124-7">https://doi.org/10.1007/s10462-009-9124-7</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Rokach, L.</string-name>
            </person-group>
            <year>2010</year>
            <article-title>Ensemble-Based Classifiers</article-title>
            <source>Artificial Intelligence Review</source>
            <volume>33</volume>
            <pub-id pub-id-type="doi">10.1007/s10462-009-9124-7</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B39">
        <label>39.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Sharafaldin, I., Habibi Lashkari, A. and Ghorbani, A.A. (2018) Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization. <italic>Proceedings of the</italic> 4 <italic>th International Conference on Information Systems Security and Privacy</italic>, 1, 108-116. https://doi.org/10.5220/0006639801080116 <pub-id pub-id-type="doi">10.5220/0006639801080116</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.5220/0006639801080116">https://doi.org/10.5220/0006639801080116</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Sharafaldin, I.</string-name>
              <string-name>Lashkari, A.</string-name>
              <string-name>Ghorbani, A.A.</string-name>
            </person-group>
            <year>2018</year>
            <article-title>Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization</article-title>
            <source>Proceedings of the 4th International Conference on Information Systems Security and Privacy</source>
            <volume>1</volume>
            <pub-id pub-id-type="doi">10.5220/0006639801080116</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B40">
        <label>40.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Moustafa, N. and Slay, J. (2015) UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection Systems (UNSW-NB15 Network Data Set). 2015 <italic>Military Communications and Information Systems Conference</italic> ( <italic>MilCIS</italic>), Canberra, 10-12 November 2015, 1-6. https://doi.org/10.1109/milcis.2015.7348942 <pub-id pub-id-type="doi">10.1109/milcis.2015.7348942</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/milcis.2015.7348942">https://doi.org/10.1109/milcis.2015.7348942</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Moustafa, N.</string-name>
              <string-name>Slay, J.</string-name>
            </person-group>
            <year>2015</year>
            <article-title>UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection Systems (UNSW-NB15 Network Data Set)</article-title>
            <source>2015 Military Communications and Information Systems Conference (MilCIS)</source>
            <volume>10</volume>
            <pub-id pub-id-type="doi">10.1109/milcis.2015.7348942</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B41">
        <label>41.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">García, S., Grill, M., Stiborek, J. and Zunino, A. (2014) An Empirical Comparison of Botnet Detection Methods. <italic>Computers &amp; Security</italic>, 45, 100-123. https://doi.org/10.1016/j.cose.2014.05.011 <pub-id pub-id-type="doi">10.1016/j.cose.2014.05.011</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2014.05.011">https://doi.org/10.1016/j.cose.2014.05.011</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Grill, M.</string-name>
              <string-name>Stiborek, J.</string-name>
              <string-name>Zunino, A.</string-name>
            </person-group>
            <year>2014</year>
            <article-title>An Empirical Comparison of Botnet Detection Methods</article-title>
            <source>Computers &amp; Security</source>
            <volume>45</volume>
            <pub-id pub-id-type="doi">10.1016/j.cose.2014.05.011</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B42">
        <label>42.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Chandola, V., Banerjee, A. and Kumar, V. (2009) Anomaly Detection. <italic>ACM Computing Surveys</italic>, 41, 1-58. https://doi.org/10.1145/1541880.1541882 <pub-id pub-id-type="doi">10.1145/1541880.1541882</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/1541880.1541882">https://doi.org/10.1145/1541880.1541882</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Chandola, V.</string-name>
              <string-name>Banerjee, A.</string-name>
              <string-name>Kumar, V.</string-name>
            </person-group>
            <year>2009</year>
            <article-title>Anomaly Detection</article-title>
            <source>ACM Computing Surveys</source>
            <volume>41</volume>
            <pub-id pub-id-type="doi">10.1145/1541880.1541882</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B43">
        <label>43.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Laila, D.A., Obeidat, I.M., Amin, M., Alqutaish, A., Obeidat, M. and Aldhyani, T.H.H. (2025) Deep Learning-Driven Multi-Layer Intrusion Detection and Prevention Framework for Resilient Defense against Adaptive Evasion Techniques in Modern Networks. <italic>International Journal of Data and Network Science</italic>, 10, 37-52. https://doi.org/10.5267/j.ijdns.2025.10.014 <pub-id pub-id-type="doi">10.5267/j.ijdns.2025.10.014</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.5267/j.ijdns.2025.10.014">https://doi.org/10.5267/j.ijdns.2025.10.014</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Laila, D.A.</string-name>
              <string-name>Obeidat, I.M.</string-name>
              <string-name>Amin, M.</string-name>
              <string-name>Alqutaish, A.</string-name>
              <string-name>Obeidat, M.</string-name>
              <string-name>Aldhyani, T.H.H.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Deep Learning-Driven Multi-Layer Intrusion Detection and Prevention Framework for Resilient Defense against Adaptive Evasion Techniques in Modern Networks</article-title>
            <source>International Journal of Data and Network Science</source>
            <volume>10</volume>
            <pub-id pub-id-type="doi">10.5267/j.ijdns.2025.10.014</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
    </ref-list>
  </back>
</article>