SecureEnsembleNet: Intelligent Cyber Threat Detection with Ensemble Learning
Abstract
The rapid growth of network-connected systems has made cyber threat detection a critical priority for modern infrastructures. Traditional signature-based intrusion detection systems (IDSs) struggle to detect novel and evolving attacks, creating the need for intelligent learning-based approaches. This paper presents SecureEnsembleNet, an ensemble learning model for intelligent cyber threat detection that combines Random Forest and Extremely Randomized Trees through a soft-voting strategy over a compact feature subspace selected with mutual information. The model is evaluated on a benchmark dataset of 25,192 TCP/IP connection records generated from a simulated United States Air Force local area network, where each connection is described by 41 features and labeled as normal or anomalous, against Logistic Regression, a linear Support Vector Machine, and a Deep Neural Network baseline. On a stratified holdout set the proposed model achieves 99.65% accuracy, 99.76% precision, 99.49% recall, a 99.62% F1 score, and an AUC of 0.9999, and repeated stratified five-fold cross-validation confirms 99.74 ± 0.10% accuracy with statistically significant gains over every baseline $(p<0.001)$. The study further reports an ablation over the number of selected features, a categorical encoding comparison, SHAP-based explainability, and a complete computational profile (20,333 records per second on a single CPU core). These results demonstrate that ensemble learning combined with information-theoretic feature selection provides an accurate, stable, explainable, and computationally practical defense layer against network intrusions.