This work investigates the impact of severe class imbalance on the performance of automated machine learning (AutoML) frameworks for multiclass network intrusion detection using the NSL-KDD dataset. Unlike previous studies that simplify the problem through binary classification or minority-class removal, we preserve the original five-class distribution, including highly underrepresented attacks such as R2L and U2R, enabling a realistic evaluation of imbalance-sensitive learning behavior. Nine open-source AutoML frameworks were analyzed under a unified and reproducible experimental protocol, considering differences in architectural design, ensemble strategies, validation procedures, hyperparameter optimization, and imbalance-handling mechanisms. The results demonstrate that frameworks incorporating ensemble learning and imbalance-aware optimization achieve better minority-class discrimination. PyCaret obtained the best overall performance, reaching 66\% macro-F1, followed by AutoGluon with 55\%, whereas frameworks lacking native balancing support exhibited significant degradation in minority-class detection capability. The analysis further shows that accuracy-oriented optimization alone is insufficient for highly imbalanced IDS scenarios, since high-weighted metrics may coexist with poor generalization on rare attack categories. As a contribution, this work establishes a standardized benchmark for AutoML-based intrusion detection under severe multiclass imbalance, highlighting current architectural limitations and the need for native integration of imbalance-aware optimization, resampling, and stratified evaluation strategies into automated learning pipelines. The source code is publicly available.


翻译:本研究探讨了在使用NSL-KDD数据集进行多类网络入侵检测时,严重类别不平衡对自动化机器学习(AutoML)框架性能的影响。与以往通过二分类或剔除少数类别来简化问题的研究不同,我们保留了原始的五个类别分布,包括高度代表性的攻击类型(如R2L和U2R),从而实现了对不平衡敏感学习行为的现实评估。在统一且可重复的实验协议下,分析了九种开源AutoML框架,考虑了架构设计、集成策略、验证流程、超参数优化以及不平衡处理机制等方面的差异。结果表明,集成学习与不平衡感知优化相结合的框架在少数类别判别上表现更优。PyCaret取得了最佳整体性能,宏F1值达到66%,紧随其后的是AutoGluon(55%),而缺乏原生平衡支持的框架在少数类别检测能力上出现显著下降。进一步分析表明,仅以准确率优化为导向无法应对高度不平衡的入侵检测场景,因为高加权指标可能与罕见攻击类别上的泛化能力差并存。作为贡献,本研究为严重多类不平衡条件下的AutoML入侵检测建立了标准化基准,揭示了当前架构的局限性,以及将不平衡感知优化、重采样和分层评估策略原生集成到自动化学习流水线的必要性。源代码已公开提供。

0
下载
关闭预览

相关内容

对抗机器学习在网络入侵检测领域的应用
专知会员服务
35+阅读 · 2022年1月4日
专知会员服务
28+阅读 · 2021年9月10日
专知会员服务
25+阅读 · 2021年7月8日
概述自动机器学习(AutoML)
人工智能学家
19+阅读 · 2019年8月11日
用深度学习揭示数据的因果关系
专知
28+阅读 · 2019年5月18日
AutoML研究综述:让AI学习设计AI
机器之心
15+阅读 · 2019年5月7日
【综述】自动机器学习AutoML最新65页综述,带你了解最新进展
中国人工智能学会
48+阅读 · 2019年5月3日
基于机器学习的KPI自动化异常检测系统
运维帮
13+阅读 · 2017年8月16日
国家自然科学基金
5+阅读 · 2015年12月31日
国家自然科学基金
3+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
17+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
国家自然科学基金
5+阅读 · 2014年12月31日
国家自然科学基金
4+阅读 · 2014年12月31日
VIP会员
最新内容
《无人机对海面作战影响评估》
专知会员服务
7+阅读 · 7月21日
印度精确打击与指挥架构的断层
专知会员服务
5+阅读 · 7月20日
美空军AI完成F-16战斗机自主空战历史性试飞
专知会员服务
6+阅读 · 7月20日
深入Project Maven:为何人工智能在战场上依然失灵
锻造未来士兵:外骨骼、基因工程与赛博格
专知会员服务
7+阅读 · 7月19日
相关VIP内容
对抗机器学习在网络入侵检测领域的应用
专知会员服务
35+阅读 · 2022年1月4日
专知会员服务
28+阅读 · 2021年9月10日
专知会员服务
25+阅读 · 2021年7月8日
相关基金
国家自然科学基金
5+阅读 · 2015年12月31日
国家自然科学基金
3+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
17+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
国家自然科学基金
5+阅读 · 2014年12月31日
国家自然科学基金
4+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员