Please use this identifier to cite or link to this item: http://irepo.futminna.edu.ng:8080/jspui/handle/123456789/31997
Title: DEVELOPMENT OF A HYBRID ANOMALY-BASED INTRUSION DETECTION SYSTEM USING AUTOENCODER AND ISOLATION FOREST
Authors: Chinedu, Somtochukwu
Uduimoh, Andrew
Anyaora, Peter
Alhassan, John
Yusuf, Hadiza
Keywords: Anomaly Detection
Autoencoder,
Cybersecurity
Hybrid Model
Intrusion Detection System,
Isolation Forest
Issue Date: Dec-2025
Publisher: nigerian journal of technological research,federal university of technology minna,nigeria.
Citation: Das et al. (2024),(Abuabed et al., 2023; Prabu & Sudhakar, 2023),(Mirsky et al., 2018),Alsaleh et al. (2024),Alhassan et al. (2024),(Marteau et al., 2017; Kulkarni et al., 2022),Sadaf and Sultana (2020),Mohammed and Telek (2023)(Elsaid & Binbusayyis, 2024; Engelen et al., 2021)(Ali et al., 2023; Alsaleh et al., 2024)(Hnamte et al., 2023; Hariharan et al., 2025)(Moraboena et al., 2020; Alrayes et al., 2024)(Kimanzi et al., 2024),Alhassan et al. (2024)(Fuhnwi et al., 2023; Kulkarni et al., 2022)Ajagbe et al. (2024)(Ali et al., 2023; Onyekpeze et al., 2021)(Prabu & Sudhakar, 2023; Labonne, 2020)(Elsaid & Binbusayyis, 2024; Engelen et al., 2021).(Kimanzi et al., 2024; Adebayo et al., 2020)(Labonne, 2020., Mirsky et al., 2018; Engelen et al., 2021).(Ali et al., 2023; Mohammed & Telek, 2023).(Wang et al., 2023; Abuabed et al., 2023).
Series/Report no.: Volume 20, No. 2;
Abstract: As cyberattacks advance in sophistication and fluidity, modern intrusion detection systems (IDS) must progress from static, signature-based models to adaptive models that can detect known and zero-day threats (Labonne, 2020; Ali et al., 2023). This study proposes a hybrid anomaly-based IDS that integrates an Autoencoder (AE) for deep feature representation with an Isolation Forest (IF) for statistical anomaly scoring. The objective is to enhance detection performance for both known and zero-day attacks within an unsupervised learning framework. The proposed model is an adaptation of the hybrid AE–IF framework devised by Mohammed and Telek (2023) and the fog-computing adaptation by Sadaf and Sultana (2020). The hybrid model deploys a logical fusion framework—Hybrid OR and Hybrid AND—dynamically balancing precision and recall in anomaly detection. The model is implemented in Python and trained using unsupervised learning on two benchmark datasets, NSL-KDD and CICIDS2017, so the model operates without any prior knowledge of attack signatures (Engelen et al., 2021). Experimental responses to model anomaly detection capabilities support that the Hybrid OR configuration of the model provided the most balanced anomaly detection performance scores recording F1-score of 0.85 and 0.69 on NSL-KDD and CICIDS2017 datasets respectively—both hybrid performance metrics outperforming the stand-alone AE and IF models. These results are in line with more recent evidence supporting the position that combining feature-reconstruction learning with statistical isolation increases the resilience and adaptability towards network intrusion detection (Elsaid & Binbusayyis, 2024; Alhassan et al., 2024). While performance declined on the more complex CICIDS2017 dataset, the hybrid approach demonstrated improved generalisation relative to individual models. The results suggest that logical fusion of representation learning and isolation-based scoring provides a lightweight and adaptable framework for network intrusion detection, although further validation in live network environments is required before operational deployment (Abuabed et al., 2023; Wang et al., 2023).
URI: http://irepo.futminna.edu.ng:8080/jspui/handle/123456789/31997
ISSN: 0795-5111
Appears in Collections:Cyber Security Science

Files in This Item:
File Description SizeFormat 
Chinedu et al 2025, 20(2)b, 48-60.pdfDEVELOPMENT OF A HYBRID ANOMALY-BASED INTRUSION DETECTION SYSTEM USING AUTOENCODER AND ISOLATION FOREST1.85 MBAdobe PDFView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.