Network Intrusion Detection based on Feature Fusion of Attack Dimension | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Network Intrusion Detection based on Feature Fusion of Attack Dimension Xiaolong Sun, Zhengyao Gu, Hao Zhang, Jason Gu, Yanhua Liu, Chen Dong, and 1 more This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-5714403/v1 This work is licensed under a CC BY 4.0 License Status: Under Review Version 1 posted 14 You are reading this latest preprint version Abstract Network traffic anomaly detection involves the rapid identification of intrusions within a network through the detection, analysis, and classification of network traffic data.The variety of cyber attacks encompasses diverse attack principles. Employing an indiscriminate feature selection strategy may lead to the neglect of key features highly correlated with specific attack types. This oversight could diminish the recognition rate for that category, thereby impacting the overall performance of the detection model.To address this issue, this paper proposes a network traffic anomaly detection model based on the fusion of attack-dimensional features. Firstly, construct binary classification datasets independently for each attack class and perform individual feature selection to extract positively correlated features for each class. The features are then fused by employing a combination methods. Subsequently, based on the fused sub-datasets, base classifiers are trained. Finally, an ensemble learning approach is introduced to integrate the predictions of individual classifiers, enhancing the robustness of the model.The proposed approach, validated on NSL-KDD and UNSW-NB15 benchmark datasets, outperforms the latest methods in the field by achieving a \(2%\) and \(7%\) increase in precision on weighted averages. Network intrusion detection Attack dimension Feature fusion Ensemble learning Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Under Review Version 1 posted Editorial decision: Revision requested 01 Feb, 2025 Reviews received at journal 31 Jan, 2025 Reviews received at journal 29 Jan, 2025 Reviews received at journal 28 Jan, 2025 Reviewers agreed at journal 18 Jan, 2025 Reviewers agreed at journal 14 Jan, 2025 Reviewers agreed at journal 14 Jan, 2025 Reviewers agreed at journal 13 Jan, 2025 Reviewers agreed at journal 12 Jan, 2025 Reviewers agreed at journal 12 Jan, 2025 Reviewers invited by journal 12 Jan, 2025 Editor assigned by journal 27 Dec, 2024 Submission checks completed at journal 27 Dec, 2024 First submitted to journal 26 Dec, 2024 You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-5714403","acceptedTermsAndConditions":true,"allowDirectSubmit":false,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":394952926,"identity":"913d6b9f-d5e4-4acc-8ab6-7aa7e17abb92","order_by":0,"name":"Xiaolong Sun","email":"","orcid":"","institution":"Fuzhou University","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Xiaolong","middleName":"","lastName":"Sun","suffix":""},{"id":394952927,"identity":"98dd8e20-8ca1-4f14-89ac-5cff4de654a3","order_by":1,"name":"Zhengyao Gu","email":"","orcid":"","institution":"Fuzhou University","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Zhengyao","middleName":"","lastName":"Gu","suffix":""},{"id":394952928,"identity":"e338a5e9-9923-4700-8a7a-adb846d87257","order_by":2,"name":"Hao Zhang","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA30lEQVRIie3PQQcCQRTA8RnD7mXo+laqrxDDFtFnmRHtZXVMFA3xrl2jPkREOkZMl+3eLV0616HUJe0euk7bLZo/wzzebxhCXK5fDNJDNSEFts5G9gUJUH5LqiYvqUxHp+N11SwL45+A9BpK+7u1ldCZqYlS0hKhIW0gSaQ070grYSDDYoBMLQ/aAMWN0sCrVuJBdEvJUC2QItBnDsIhDoNL+vjcYx5QnYMAxN0ixa0A47G6NJFAHttJZRItgwf2ywX0j/vzoFEa+4mdZDH+vsnsdx/30+g9z5bL5XL9by9ymj6r0pPWNAAAAABJRU5ErkJggg==","orcid":"","institution":"Fuzhou University","correspondingAuthor":true,"submittingAuthor":false,"prefix":"","firstName":"Hao","middleName":"","lastName":"Zhang","suffix":""},{"id":394952929,"identity":"f542ea06-fe68-4e09-b1d6-ac4d472bad14","order_by":3,"name":"Jason Gu","email":"","orcid":"","institution":"Dalhousie University","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Jason","middleName":"","lastName":"Gu","suffix":""},{"id":394952930,"identity":"98c5cb9b-9939-4dc0-b179-981ed24c33b8","order_by":4,"name":"Yanhua Liu","email":"","orcid":"","institution":"Fuzhou University","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Yanhua","middleName":"","lastName":"Liu","suffix":""},{"id":394952931,"identity":"0dd8b2e4-61ac-430e-ac41-791a7acfce7c","order_by":5,"name":"Chen Dong","email":"","orcid":"","institution":"Fuzhou University","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Chen","middleName":"","lastName":"Dong","suffix":""},{"id":394952932,"identity":"058cbd8f-b6d5-4f9a-b4aa-fd424437f74f","order_by":6,"name":"Junwei Ye","email":"","orcid":"","institution":"Fuzhou University","correspondingAuthor":false,"submittingAuthor":false,"prefix":"","firstName":"Junwei","middleName":"","lastName":"Ye","suffix":""}],"badges":[],"createdAt":"2024-12-26 07:38:05","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-5714403/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-5714403/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":72574150,"identity":"0f23d764-e26f-431e-8709-bbee4dea3594","added_by":"auto","created_at":"2024-12-30 03:45:45","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":3582787,"visible":true,"origin":"","legend":"","description":"","filename":"Networkintrusiondetection.pdf","url":"https://assets-eu.researchsquare.com/files/rs-5714403/v1_covered_3d4f0549-2d59-4be6-866f-045e5679565b.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Network Intrusion Detection based on Feature Fusion of Attack Dimension","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":true,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"the-journal-of-supercomputing","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"","sideBox":"Learn more about [The Journal of Supercomputing](https://www.springer.com/journal/11227)","snPcode":"11227","submissionUrl":"https://submission.nature.com/new-submission/11227/3","title":"The Journal of Supercomputing","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"stoa","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false},"keywords":"Network intrusion detection,Attack dimension,Feature fusion,Ensemble learning","lastPublishedDoi":"10.21203/rs.3.rs-5714403/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-5714403/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eNetwork traffic anomaly detection involves the rapid identification of intrusions within a network through the detection, analysis, and classification of network traffic data.The variety of cyber attacks encompasses diverse attack principles. Employing an indiscriminate feature selection strategy may lead to the neglect of key features highly correlated with specific attack types. This oversight could diminish the recognition rate for that category, thereby impacting the overall performance of the detection model.To address this issue, this paper proposes a network traffic anomaly detection model based on the fusion of attack-dimensional features. Firstly, construct binary classification datasets independently for each attack class and perform individual feature selection to extract positively correlated features for each class. The features are then fused by employing a combination methods. Subsequently, based on the fused sub-datasets, base classifiers are trained. Finally, an ensemble learning approach is introduced to integrate the predictions of individual classifiers, enhancing the robustness of the model.The proposed approach, validated on NSL-KDD and UNSW-NB15 benchmark datasets, outperforms the latest methods in the field by achieving a \u003cspan class=\"InlineEquation\"\u003e\u003cspan class=\"mathinline\"\u003e\\(2%\\)\u003c/span\u003e\u003c/span\u003e and \u003cspan class=\"InlineEquation\"\u003e\u003cspan class=\"mathinline\"\u003e\\(7%\\)\u003c/span\u003e\u003c/span\u003e increase in precision on weighted averages.\u003c/p\u003e","manuscriptTitle":"Network Intrusion Detection based on Feature Fusion of Attack Dimension","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2024-12-30 03:21:37","doi":"10.21203/rs.3.rs-5714403/v1","editorialEvents":[{"type":"communityComments","content":0},{"type":"decision","content":"Revision requested","date":"2025-02-01T16:14:08+00:00","index":"","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2025-02-01T03:11:06+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2025-01-29T15:35:48+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2025-01-28T13:15:37+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"48598464387623382418566152605510877000","date":"2025-01-18T14:05:07+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"115842086942754693874377849173993538831","date":"2025-01-15T02:44:52+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"203566378181221251666748582837913276895","date":"2025-01-15T02:06:11+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"89569059663409014131786769232673657687","date":"2025-01-13T05:19:28+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"105075991088449789671758567794865476277","date":"2025-01-13T02:28:26+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"247663800680239945600384159804507855650","date":"2025-01-13T01:22:58+00:00","index":"hide","fulltext":""},{"type":"reviewersInvited","content":"","date":"2025-01-13T01:17:32+00:00","index":"","fulltext":""},{"type":"editorAssigned","content":"","date":"2024-12-27T10:34:11+00:00","index":"","fulltext":""},{"type":"checksComplete","content":"","date":"2024-12-27T10:32:27+00:00","index":"","fulltext":""},{"type":"submitted","content":"The Journal of Supercomputing","date":"2024-12-26T07:23:13+00:00","index":"","fulltext":""}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"the-journal-of-supercomputing","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"","sideBox":"Learn more about [The Journal of Supercomputing](https://www.springer.com/journal/11227)","snPcode":"11227","submissionUrl":"https://submission.nature.com/new-submission/11227/3","title":"The Journal of Supercomputing","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"stoa","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false}}],"origin":"","ownerIdentity":"45f1f762-a14a-4bc5-96aa-107e0eafdd3d","owner":[],"postedDate":"December 30th, 2024","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"under-review","subjectAreas":[],"tags":[],"updatedAt":"2025-03-30T22:08:12+00:00","versionOfRecord":[],"versionCreatedAt":"2024-12-30 03:21:37","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-5714403","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-5714403","identity":"rs-5714403","version":["v1"]},"buildId":"WrCJVZZCHTDjtuVLN7oU0","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.