Skip to content

Adaptive Context-Aware Confidence-Weighted Hybrid Ensemble for Real-Time Intrusion Detection in Software-Defined Networks

Aug 2026 · International Scientific Journal of Engineering and Management · Vol 05, pp. 1-9 · 0 citations

TL;DR

The proposed ACA-CWHE framework is intended to provide an adaptive, computationally efficient, and explainable intrusion detection solution suitable for real-time SDN security environments.

Abstract

Abstract The rapid adoption of Software-Defined Networking (SDN) has transformed modern network management by providing centralized control, flexible configuration, and efficient traffic management. However, the centralized architecture of SDN also exposes the network controller to a wide range of cyber threats, including Distributed Denial-of-Service (DDoS), brute-force, probing, and botnet attacks. Existing intrusion detection methods often rely on fixed learning strategies or static ensemble models, which struggle to adapt to continuously changing network traffic and attack patterns. To overcome these limitations, this paper presents an Adaptive Context-Aware Confidence-Weighted Hybrid Ensemble (ACA-CWHE) framework for intelligent intrusion detection in SDN. The proposed framework introduces a Context-Aware Adaptive Confidence Weighting (CAACW) mechanism that dynamically determines the contribution of Random Forest, LightGBM, and XGBoost classifiers by considering prediction confidence, network traffic context, and classifier reliability. In addition, an adaptive feature selection technique is employed to eliminate redundant traffic attributes, reducing computational cost while preserving detection capability. To improve the transparency of the detection process, SHapley Additive exPlanations (SHAP) are integrated to identify the network features that have the greatest influence on classification decisions. The framework is assessed using benchmark intrusion detection datasets and evaluated through performance measures such as Accuracy, Precision, Recall, F1-score, ROC-AUC, False Positive Rate (FPR), and Detection Time. The proposed ACA-CWHE framework is intended to provide an adaptive, computationally efficient, and explainable intrusion detection solution suitable for real-time SDN security environments. Keywords— Software-Defined Networking (SDN), Intrusion Detection System (IDS), Adaptive Ensemble Learning, Context-Aware Confidence Weighting, Explainable Artificial Intelligence (XAI), SHAP, Random Forest, LightGBM, XGBoost, Network Security.

View source

Similar papers

Sep 2026

SA-IDS: a self-supervised and adaptive intrusion detection system for edge-based IIoT security with label-free drift resilience

SA-IDS is proposed, a self-supervised and adaptive intrusion detection framework designed for resource-constrained IIoT edge devices that leverages contrastive self-supervised learning to learn robust representations of benign telemetry data without requiring labeled attacks.

Mahdi Ajdani, Maziar Asmani · 0 citations
Open access 2026

Detection and Prevention of Internet Control Message Protocol Flood Attack in Software-Defined Network Using Dynamic Threshold and Machine Learning

This paper proposes a hybrid ICMP flood detection and mitigation strategy that combines a Support Vector Machine (SVM) classifier installed directly on the RYU controller with a real-time dynamic threshold mechanism (based on continuous mean and standard deviation computation).

Tsehaynesh Babil Wassie, Bayew Dessie Fenta, Habtamu Molla Belachew et al. · 0 citations
Open access Sep 2026

An intelligent real-time intrusion detection and prevention strategy for emergency response MANETs

In recent years, Mobile Ad Hoc Networks (MANETs) have emerged as a pivotal domain within wireless technologies. Emergency Response MANETs (ER-MANETs) support communication among emergency responders during critical scenarios. Ensuring the real-time integrity and availability of these highly dynamic networks requires ro...

Parsa Parsafar, Romina Ramezani, Vahid Ebrahimian · 0 citations
#software testing Open access Sep 2026

Intelligent DDoS Attack Detection in Software-Defined Networks Using Explainable Machine Learning

An explainable machine learning-based framework for accurate, transparent, and reliable DDoS attack detection in an SDN environment that combines reliable DDoS detection with transparent, analyst-oriented decision support for SDN security monitoring is developed.

J. Malik, N. Naz, Muhammad Saleem et al. · 0 citations
Open access Sep 2026

Intrusion detection in evolving internet of things environments using decentralized data systems

A hybrid IDS framework built on a stacking ensemble of four heterogeneous base classifiers, namely random forest, extreme gradient boosting, light gradient-boosting machine, and a shallow multi-layer perceptron (MLP), coupled with a PyTorch-based neural network meta-classifier, establishing that pairing meta-learning w...

Zobayer Alam, Arnab Bishakh Sarker, Jariatun Islam et al. · 0 citations
Open access Aug 2026

MOO-IDS: multi-objective optimization-based lightweight intrusion detection system for in-vehicle networks

With the proliferation of intelligent connected vehicles, the Controller Area Network (CAN) bus, as the backbone of in-vehicle communication, is vulnerable to cyberattacks due to lack of authentication and encryption. Existing Intrusion Detection Systems (IDS) exhibit limitations in addressing data imbalance, complex a...

Ya-Li Hao, He Bai, A. Siya et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.