Detection of attacks on computer networks using machine learning - predictive model
Więcej
Ukryj
1
1. Faculty of Computer Science and Information Technology, West Pomeranian University of Technology in Szczecin
2. Faculty of Applied Informatics and Mathematics, Warsaw University of Life Sciences, Warsaw
2
Faculty of Computer Science and Information Technology, West Pomeranian University of Technology in Szczecin
Data publikacji: 05-08-2026
Autor do korespondencji
Imed El Fray
1. Faculty of Computer Science and Information Technology, West Pomeranian University of Technology in Szczecin
2. Faculty of Applied Informatics and Mathematics, Warsaw University of Life Sciences, Warsaw
Adv. Sci. Technol. Res. J. 2026;
SŁOWA KLUCZOWE
DZIEDZINY
STRESZCZENIE
Intrusion detection systems based on machine learning achieve high effectiveness in optimal testing conditions. However, real environments come with limitations such as changing data characteristics, previously unknown attacks or low and delayed label availability. To address these challenges, this paper proposes an approach of continuous adaptation to streaming data in the form of active incremental learning. This solution further incorporates a semi-supervised learning approach to reduce expert involvement. The effectiveness of the approach was assessed under conditions simulating real-time system operation. The results of the performed tests show that selective use of expert assistance maintains high classification performance while minimizing labelling costs. An F1 score of 0.9930 was achieved using 6% of labels, and 0.9803 with approximately 2%, indicating that a limited number of expert labels is sufficient for effective model adaptation. These findings confirm the effectiveness of the proposed adaptation mechanism for intrusion detection in streaming environments.