Intrusion Detection With Machine and Deep Learning: A Comparative Study on CICIDS‐2017 and NSL‐KDD
Gulay Cicek, Nazlı Buldağ, Elif AydınABSTRACT
With the rapid advancement of technology, the complexity and frequency of cyberattacks are increasing, necessitating advanced defensive measures. Intrusion detection systems (IDS) play a critical role in mitigating these threats. This study investigates the effectiveness of diverse algorithmic architectures—including Machine Learning (ML) (Random Forest, Decision Tree [DT], KNN), Deep Learning (DL) (CNN, DNN, LSTM, BiLSTM, GRU, BiGRU), and Hybrid models (CNN+BiLSTM, GRU+Random Forest)—using the NSL‐KDD and CICIDS‐2017 datasets as established benchmark datasets. To optimize performance, Principal Component Analysis (PCA) and SelectKBest + Mutual Information (SKB+MI) were applied for feature selection. Experimental results show that while the DT algorithm achieved a peak accuracy of 99% on the CICIDS‐2017 dataset, it demonstrated sensitivity to dataset‐specific artifacts. In contrast, the GRU+Random Forest hybrid model demonstrated favorable performance and operational efficiency, achieving a testing latency of 0.03 s. This research provides a comparative framework for examining the trade‐off between detection precision and computational overhead, offering insights into cross‐dataset generalizability and potential deployment considerations for high‐throughput network environments.