CORTEXA
← Browse
openalexFuture Internet2026-07-23Cited by 0

AutoML for Network-Based Intrusion Detection: Evaluation Practice, Dataset Quality, and Deployment Constraints

Abdulla Amin Aburomman, Mamun Bin Ibne Reaz

Machine learning techniques for network-based intrusion detection systems (NIDS) have advanced considerably over the past decade. Still, improvements are inhibited by handcrafted feature pipelines, isolated public benchmark data, and evaluation procedures that do not reflect real-life deployment. AutoML, a branch of ML automating model selection, automated architecture search, and the creation of model pipelines, may help overcome these shortcomings. While numerous NIDS applications employing automated ML techniques have been proposed, and recent surveys have mapped the AutoML framework landscape for network intrusion detection, no existing review critically audits the evaluation practice of this literature: the quality of its benchmark datasets, the reproducibility of its reported results, and the realism of its deployment assumptions. This paper critically reviews 26 research works published between January 2023 and June 2026, collected via a two-phase structured search: a documented keyword search across five databases (Scopus, IEEE Xplore, Web of Science, ACM Digital Library, and Google Scholar), followed by full-text eligibility screening, citation chaining, and expert evaluation. Findings drawn from this collection capture trends observed among the selected studies, rather than reflecting the broader state of the field. Analysis of the corpus reveals that 88% of dataset-verified studies evaluate exclusively or partly on the legacy benchmark family (KDD-derived, CICIDS, UNSW-NB15, CIDDS), 21% evaluate on a single dataset only, and among attribute-verified studies only 32% release source code, 40% report statistical significance testing, and 36% include variance analysis, findings that collectively motivate the four contributions of this study. First, a recommended evaluation framework is proposed, addressing baseline parity, transparent search-space and budget reporting, nested cross-validation for selection-bias control, and stability reporting across multiple random seeds. Second, a dataset quality scoring framework is introduced, assessing five dimensions: overlap rate, duplication rate, label correctness, attack-type representativeness, and coverage of benign, IoT, and IIoT traffic. Third, a cross-domain justification is provided for neural architecture search (NAS) and meta-learning in NIDS, grounded in advances in federated NAS, out-of-distribution robustness, edge-constrained search cost reduction, and few-shot adaptation. Fourth, a structured research roadmap is outlined, targeting real-world validation, standardized benchmarks, curated datasets, resource-aware AutoML, and privacy-preserving federated NAS. In contrast to prior surveys of AutoML for network intrusion detection, which map frameworks and computational paradigms, this review contributes a formalized evaluation checklist, an explicit and partially empirically validated dataset quality scoring scheme, and evidence-based methodological guidance grounded in a transparent, fully enumerated study corpus.

View free PDFSource page

Related papers

crossrefFuture Internet2026-07-25

Machine Learning-Based Short-Term Visibility Classification for Wireless Optical Communication Systems Using METAR and Microwave-Link Features at Bangkok Airports

Sabai Phuchortham, Hakilo Sabit

Rapid growth in connected devices, artificial intelligence applications, and the Internet of Things (IoT) is driving demand for ultra-high data rates, low latency, and energy-efficient communication infrastructure. Wireless optical communication (WOC), including free-space optica…

View free PDFSource page
crossrefFuture Internet2026-06-29

MS-SENet: A Multi-Scale Squeeze–Excitation Network for Deep-Learning-Based Automatic Modulation Classification in Cognitive Radio Systems

Evelio Astaiza Hoyos, Héctor Fabio Bermúdez-Orozco, Nasly Cristina Rodriguez-Idrobo

Automatic modulation classification (AMC) is a critical enabler of cognitive radio (CR) systems, allowing secondary users to identify primary user modulation schemes and adapt transmission parameters in real time. Traditional AMC approaches, based on likelihood functions or hand-…

View free PDFSource page
crossrefFuture Internet2026-06-21

Machine Learning-Based Diabetes Risk Prediction via DiaHealth Dataset with Explainable AI and Streamlit Deployment

Samson Adeyemi, Muhammad Zahid Iqbal, Md Golam Muttaquee Talukder

The growing worldwide prevalence of Diabetes Mellitus highlights the urgent need for effective early detection methods to enable prompt intervention. This study develops a machine learning-based decision-support prototype for predicting diabetes risk using health metrics from the…

View free PDFSource page
crossrefFuture Internet2026-06-16

Computing Incentive and Data Offloading in Digital Twin Networks: A Contract Theory and Multi-Agent Deep Reinforcement Learning Approach

Nan Zhao, Henan Xu, Yuxiang Su, Bokun He, Fan Zhang, Jing Tang, et al.

In the digital twin (DT) network, effective edge data processing is essential to meet the real-time requirements of DT models. However, edge servers (ESs) are self-interested and have limited computation resources. The virtual content operator (VCO) cannot observe their true comp…

View free PDFSource page
crossrefFuture Internet2026-05-28

Data-Driven and Machine Learning-Based Analysis of Handover Behavior and Network Stability in Mobile Networks

Akzhibek Amirova, Aliya Abdiraman, Laura Aldasheva, Ibraheem Shayea, Didar Yedilkhan, Akhmet Tussupov

Handover management is a fundamental process in modern mobile networks, ensuring service continuity under user mobility. However, the relationship between network conditions and handover behavior remains insufficiently understood under real-world measurement conditions. This stud…

View free PDFSource page
crossrefFuture Internet2026-05-24

Enhancing the Adoption of Zero Trust in Organizations Using Machine Learning

Aeshah Mohammed Alshehri, Samer H. Atawneh, Hussein Al Bazar, Roxane Elias Mallouhy

Cybersecurity has become a critical concern for individuals, organizations, and governments, especially with the rise of sophisticated cyberattacks and remote work environments. Traditional security approaches are no longer sufficient, leading to the adoption of advanced framewor…

View free PDFSource page