A Comprehensive Review of SDN Intrusion Detection Using Ensemble Machine Learning
Main Article Content
Abstract
Software Defined Networking (SDN) refers to a programmable networking architecture with centralizing capabilities that facilitates network management. However, such centralization exposes SDN networks to potential cyber threats. IDS plays an essential role in securing SDN since it helps in recognizing malicious traffic in the network. Despite the success achieved in traditional IDS, there is still room for improvement considering their high levels of false alarms and inefficiency in dealing with complex and zero-day attacks. Machine learning can help address some of these challenges associated with IDS. In this regard, this study highlights some commonly used data sets and different types of machine learning algorithms while conducting an extensive analysis of ensemble learning methods. Based on the obtained results, it can be said that ensemble learning outperforms all others concerning accuracy, reliability, and generalization. However, several challenges exist, among which dataset limitations, such as imbalanced classes, scalability problem, and real-time application limitation can be noted. this review further identifies key research gaps and outlines potential future directions for developing more efficient and reliable intrusion detection systems in SDN environments.
Article Details
Section

This work is licensed under a Creative Commons Attribution 4.0 International License.
How to Cite
References
[1] B. Isong, R. R. S. Molose, A. M. Abu-Mahfouz, and N. Dladlu, “Comprehensive Review of SDN Controller Placement Strategies,” IEEE Access, vol. 8, pp. 170070–170092, 2020, doi: 10.1109/ACCESS.2020.3023974.
[2] S. Scott-Hayward, G. O’Callaghan, and S. Sezer, “Sdn Security: A Survey,” in 2013 IEEE SDN for Future Networks and Services (SDN4FNS), IEEE, Nov. 2013, pp. 1–7. doi: 10.1109/SDN4FNS.2013.6702553.
[3] M. B. Jimenez, D. Fernandez, J. E. Rivadeneira, L. Bellido, and A. Cardenas, “A Survey of the Main Security Issues and Solutions for the SDN Architecture,” IEEE Access, vol. 9, pp. 122016–122038, 2021, doi: 10.1109/ACCESS.2021.3109564.
[4] I. Rakine et al., “Comprehensive Review of Intrusion Detection Techniques: ML and DL in Different Networks,” IEEE Access, vol. 13, no. May, pp. 104345–104367, 2025, doi: 10.1109/ACCESS.2025.3579990.
[5] G. Logeswari, S. Bose, and T. Anitha, “An Intrusion Detection System for SDN Using Machine Learning,” Intell. Autom. Soft Comput., vol. 35, no. 1, pp. 867–880, 2023, doi: 10.32604/iasc.2023.026769.
[6] J. Xie et al., “A Survey of Machine Learning Techniques Applied to Software Defined Networking (SDN): Research Issues and Challenges,” IEEE Commun. Surv. Tutorials, vol. 21, no. 1, pp. 393–430, 2019, doi: 10.1109/COMST.2018.2866942.
[7] M. Kaleem, M. A. Mushtaq, S. Rashid, and M. Saleemi, “A Comprehensive Review of Intrusion Detection Systems in IoT Landscape,” in Communications in Computer and Information Science, vol. 2381 CCIS, no. 2, 2025, pp. 287–302. doi: 10.1007/978-3-031-82931-4_22.
[8] B. Shyryn, T. A. Ahanger, and A. Zhumadillayeva, “Enhancing software-defined network security with deep learning: a comprehensive review,” Int. J. Inf. Secur., vol. 25, no. 2, pp. 1–37, 2026, doi: 10.1007/s10207-026-01232-2.
[9] A. A. J. Al-Hchaimi et al., “Enhancing Cybersecurity in Cyber-Physical Systems: an Explainable AI Approach for Intrusion Detection,” in 2025 5th International Conference on Emerging Smart Technologies and Applications (eSmarTA), IEEE, Aug. 2025, pp. 1–8. doi: 10.1109/eSmarTA66764.2025.11132126.
[10] A. Wani, R. S, and R. Khaliq, “SDN‐based intrusion detection system for IoT using deep learning classifier (IDSIoT‐SDL),” CAAI Trans. Intell. Technol., vol. 6, no. 3, pp. 281–290, Sep. 2021, doi: 10.1049/cit2.12003.
[11] E. Tsogbaatar et al., “SDN-Enabled IoT Anomaly Detection Using Ensemble Learning,” in IFIP Advances in Information and Communication Technology, Springer International Publishing, 2020, pp. 268–280. doi: 10.1007/978-3-030-49186-4_23.
[12] W. Xia, Y. Wen, C. H. Foh, D. Niyato, and H. Xie, “A Survey on Software-Defined Networking,” IEEE Commun. Surv. Tutorials, vol. 17, no. 1, pp. 27–51, 2015, doi: 10.1109/COMST.2014.2330903.
[13] S. Khan, A. Gani, A. W. Abdul Wahab, M. Guizani, and M. K. Khan, “Topology Discovery in Software Defined Networks: Threats, Taxonomy, and State-of-the-Art,” IEEE Commun. Surv. Tutorials, vol. 19, no. 1, pp. 303–324, 2017, [Online]. Available: https://ieeexplore.ieee.org/document/7534866/
[14] K. Giotis, C. Argyropoulos, G. Androulidakis, D. Kalogeras, and V. Maglaris, “Combining OpenFlow and sFlow for an effective and scalable anomaly detection and mitigation mechanism on SDN environments,” Comput. Networks, vol. 62, pp. 122–136, Apr. 2014, doi: 10.1016/j.bjp.2013.10.014.
[15] and A. R. A. R. A. Abduljabbar Ali, A. Muhammed, M. D. H. Abdullah, “Software-Defined Networks Topology Discovery Security and Drawbacks: A Survey of Attacks and Defenses,” IAENG Int. J. Comput. Sci., vol. 52, no. 7, pp. 2333–2357, 2025.
[16] A. Shaghaghi, M. A. Kaafar, R. Buyya, and S. Jha, “Software-Defined Network (SDN) data plane security: Issues, solutions, and future directions,” Handb. Comput. Networks Cyber Secur. Princ. Paradig., pp. 341–387, 2019, doi: 10.1007/978-3-030-22277-2_14.
[17] A. N. Alhaj and N. Dutta, Analysis of Security Attacks in SDN Network: A Comprehensive Survey, vol. 281, no. November. Springer Singapore, 2022. doi: 10.1007/978-981-16-4244-9_3.
[18] A. Abdou, P. C. van Oorschot, and T. Wan, “Comparative Analysis of Control Plane Security of SDN and Conventional Networks,” IEEE Commun. Surv. Tutorials, vol. 20, no. 4, pp. 3542–3559, 2018, doi: 10.1109/COMST.2018.2839348.
[19] S. Scott-Hayward, “Design and deployment of secure, robust, and resilient SDN controllers,” in Proceedings of the 2015 1st IEEE Conference on Network Softwarization (NetSoft), IEEE, Apr. 2015, pp. 1–5. doi: 10.1109/NETSOFT.2015.7258233.
[20] L. Wang and Y. Liu, “A DDoS Attack Detection Method Based on Information Entropy and Deep Learning in SDN,” in 2020 IEEE 4th Information Technology, Networking, Electronic and Automation Control Conference (ITNEC), IEEE, Jun. 2020, pp. 1084–1088. doi: 10.1109/ITNEC48623.2020.9085007.
[21] A. Patwardhan, D. Jayarama, N. Limaye, S. Vidhale, Z. Parekh, and K. Harfoush, “SDN Security: Information Disclosure and Flow Table Overflow Attacks,” in 2019 IEEE Global Communications Conference (GLOBECOM), IEEE, Dec. 2019, pp. 1–6. doi: 10.1109/GLOBECOM38437.2019.9014048.
[22] S. Scott-Hayward, S. Natarajan, and S. Sezer, “A Survey of Security in Software Defined Networks,” IEEE Commun. Surv. Tutorials, vol. 18, no. 1, pp. 623–654, 2016, doi: 10.1109/COMST.2015.2453114.
[23] I. Ahmad, S. Namal, M. Ylianttila, and A. Gurtov, “Security in Software Defined Networks: A Survey,” IEEE Commun. Surv. Tutorials, vol. 17, no. 4, pp. 2317–2346, 2015, doi: 10.1109/COMST.2015.2474118.
[24] Q. Yan, F. R. Yu, Q. Gong, and J. Li, “Software-Defined Networking (SDN) and Distributed Denial of Service (DDoS) Attacks in Cloud Computing Environments: A Survey, Some Research Issues, and Challenges,” IEEE Commun. Surv. Tutorials, vol. 18, no. 1, pp. 602–622, 2016, doi: 10.1109/COMST.2015.2487361.
[25] N. Sultana, N. Chilamkurti, W. Peng, and R. Alhadad, “Survey on SDN based network intrusion detection system using machine learning approaches,” Peer-to-Peer Netw. Appl., vol. 12, no. 2, pp. 493–501, Mar. 2019, doi: 10.1007/s12083-017-0630-0.
[26] M. R. Ahmed, S. Islam, S. Shatabda, A. K. M. Muzahidul Islam, M. Towhidul, and I. Robin, “Intrusion Detection System in Software-Defined Networks Using Machine Learning and Deep Learning Techniques-A Comprehensive Survey,” Ieee, no. Ml, pp. 1–47, 2023, [Online]. Available: https://doi.org/10.36227/techrxiv.17153213.v1
[27] U. S. Musa, S. Chakraborty, M. M. Abdullahi, and T. Maini, “A Review on Intrusion Detection System using Machine Learning Techniques,” in 2021 International Conference on Computing, Communication, and Intelligent Systems (ICCCIS), IEEE, Feb. 2021, pp. 541–549. doi: 10.1109/ICCCIS51004.2021.9397121.
[28] A. ARQANE, O. Boutkhoum, H. Boukhriss, and A. El Moutaouakkil, “Intrusion Detection System using Ensemble Learning Approaches: A Systematic Literature Review,” Int. J. Online Biomed. Eng., vol. 18, no. 13, pp. 160–175, Oct. 2022, doi: 10.3991/ijoe.v18i13.33519.
[29] N. S. Shaji, R. Muthalagu, and P. M. Pawar, “SD-IIDS: intelligent intrusion detection system for software-defined networks,” Multimed. Tools Appl., vol. 83, no. 4, pp. 11077–11109, Jan. 2024, doi: 10.1007/s11042-023-15725-y.
[30] D. Jankowski and M. Amanowicz, “Intrusion detection in software defined networks with self-organized maps,” J. Telecommun. Inf. Technol., vol. 2015, no. 4, pp. 3–9, 2015, doi: 10.26636/jtit.2015.4.977.
[31] D. Kreutz, F. M. V. Ramos, P. Esteves Verissimo, C. Esteve Rothenberg, S. Azodolmolky, and S. Uhlig, “Software-Defined Networking: A Comprehensive Survey,” Proc. IEEE, vol. 103, no. 1, pp. 14–76, Jan. 2015, doi: 10.1109/JPROC.2014.2371999.
[32] A. H. Janabi, T. Kanakis, and M. Johnson, “Survey: Intrusion Detection System in Software-Defined Networking,” IEEE Access, vol. 12, no. October, pp. 164097–164120, 2024, doi: 10.1109/ACCESS.2024.3493384.
[33] S. Dahiya, V. Siwach, and H. Sehrawat, “Review of AI Techniques in development of Network Intrusion Detection System in SDN Framework,” in 2021 International Conference on Computational Performance Evaluation, ComPE 2021, IEEE, 2021, pp. 168–174. doi: 10.1109/ComPE53109.2021.9752430.
[34] B. Laha, D. Basu, S. Biswas, P. Gupta, and B. Sadhukhan, “Intrusion Detection in IoT Systems Using Ensemble Machine Learning Techniques,” in 2023 IEEE 4th Annual Flagship India Council International Subsections Conference: Computational Intelligence and Learning Systems, INDISCON 2023, IEEE, Aug. 2023, pp. 1–7. doi: 10.1109/INDISCON58499.2023.10270505.
[35] N. W. Khan et al., “A hybrid deep learning-based intrusion detection system for IoT networks,” Math. Biosci. Eng., vol. 20, no. 8, pp. 13491–13520, 2023, doi: 10.3934/mbe.2023602.
[36] H.-J. Liao, C.-H. Richard Lin, Y.-C. Lin, and K.-Y. Tung, “Intrusion detection system: A comprehensive review,” J. Netw. Comput. Appl., vol. 36, no. 1, pp. 16–24, Jan. 2013, doi: 10.1016/j.jnca.2012.09.004.
[37] A. L. Buczak and E. Guven, “A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection,” IEEE Commun. Surv. Tutorials, vol. 18, no. 2, pp. 1153–1176, 2016, doi: 10.1109/COMST.2015.2494502.
[38] A. Khraisat, I. Gondal, P. Vamplew, and J. Kamruzzaman, “Survey of intrusion detection systems: techniques, datasets and challenges,” Cybersecurity, vol. 2, no. 1, p. 20, Dec. 2019, doi: 10.1186/s42400-019-0038-7.
[39] N. Hubballi and V. Suryanarayanan, “False alarm minimization techniques in signature-based intrusion detection systems: A survey,” Comput. Commun., vol. 49, pp. 1–17, Aug. 2014, doi: 10.1016/j.comcom.2014.04.012.
[40] A. Patcha and J.-M. Park, “An overview of anomaly detection techniques: Existing solutions and latest technological trends,” Comput. Networks, vol. 51, no. 12, pp. 3448–3470, Aug. 2007, doi: 10.1016/j.comnet.2007.02.001.
[41] F. Rahim and A. P. D. S. Ali Abd Alradha Alsaidi, “A Comprehensive Review of Intrusion Detection Systems in IoT networks Using ML and DL Techniques,” AlKadhim J. Comput. Sci., vol. 3, no. 2, pp. 84–95, Jun. 2025, doi: 10.61710/kjcs.v3i2.111.
[42] H. Polat, O. Polat, and A. Cetin, “Detecting DDoS attacks in software-defined networks through feature selection methods and machine learning models,” Sustain., vol. 12, no. 3, 2020, doi: 10.3390/su12031035.
[43] S. Stolfo, W. Fan, W. Lee, and A. L. Prodromidis, “Cost-based Modeling and Evaluation for Data Mining With Application to Fraud and Intrusion Detection : Results from the JAM Project ∗,” 2008 . Available: https://api.semanticscholar.org/CorpusID:16061051
[44] M. Tavallaee, E. Bagheri, W. Lu, and A. A. Ghorbani, “A detailed analysis of the KDD CUP 99 data set,” in 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications, IEEE, Jul. 2009, pp. 1–6. doi: 10.1109/CISDA.2009.5356528.
[45] J. Stolfo, W. Fan, W. Lee, A. Prodromidis, and P. K. Chan, Cost-based modeling and evaluation for data mining with application to fraud and intrusion detection. 2000.
[46] N. Moustafa and J. Slay, “UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set),” in 2015 Military Communications and Information Systems Conference (MilCIS), IEEE, Nov. 2015, pp. 1–6. doi: 10.1109/MilCIS.2015.7348942.
[47] I. Sharafaldin, A. Gharib, A. H. Lashkari, and A. A. Ghorbani, “Towards a Reliable Intrusion Detection Benchmark Dataset,” Softw. Netw., vol. 2017, no. 1, pp. 177–200, 2017, doi: 10.13052/jsn2445-9739.2017.009.
[48] I. Sharafaldin, A. H. Lashkari, S. Hakak, and A. A. Ghorbani, “Developing Realistic Distributed Denial of Service (DDoS) Attack Dataset and Taxonomy,” in 2019 International Carnahan Conference on Security Technology (ICCST), IEEE, Oct. 2019, pp. 1–8. doi: 10.1109/CCST.2019.8888419.
[49] A. Kaur, C. Rama Krishna, and N. V. Patil, “A comprehensive review on Software-Defined Networking (SDN) and DDoS attacks: Ecosystem, taxonomy, traffic engineering, challenges and research directions,” Comput. Sci. Rev., vol. 55, p. 100692, Feb. 2025, doi: 10.1016/j.cosrev.2024.100692.
[50] M. S. Elsayed, N.-A. A. Le-Khac, and A. D. Jurcut, “InSDN: A novel SDN intrusion dataset,” IEEE Access, vol. 8, no. September, pp. 165263–165284, 2020, doi: 10.1109/ACCESS.2020.3022633.
[51] N. Koroniotis, N. Moustafa, E. Sitnikova, and B. Turnbull, “Towards the development of realistic botnet dataset in the Internet of Things for network forensic analytics: Bot-IoT dataset,” Futur. Gener. Comput. Syst., vol. 100, pp. 779–796, Nov. 2019, doi: 10.1016/j.future.2019.05.041.
[52] A. Alsaedi, N. Moustafa, Z. Tari, A. Mahmood, and Adna N Anwar, “TON-IoT telemetry dataset: A new generation dataset of IoT and IIoT for data-driven intrusion detection systems,” IEEE Access, vol. 8, pp. 165130–165150, 2020, doi: 10.1109/ACCESS.2020.3022862.
[53] S. K. Dey and M. M. Rahman, “Effects of Machine Learning Approach in Flow-Based Anomaly Detection on Software-Defined Networking,” Symmetry (Basel)., vol. 12, no. 1, p. 7, Dec. 2019, doi: 10.3390/sym12010007.
[54] A. O. Alzahrani and M. J. F. Alenazi, “Designing a Network Intrusion Detection System Based on Machine Learning for Software Defined Networks,” Futur. Internet, vol. 13, no. 5, p. 111, Apr. 2021, doi: 10.3390/fi13050111.
[55] H. A. Alamri and V. Thayananthan, “Bandwidth Control Mechanism and Extreme Gradient Boosting Algorithm for Protecting Software-Defined Networks Against DDoS Attacks,” IEEE Access, vol. 8, no. November, pp. 194269–194288, 2020, doi: 10.1109/ACCESS.2020.3033942.
[56] H. A. Alamri and V. Thayananthan, “Analysis of Machine Learning for Securing Software-Defined Networking,” Procedia Comput. Sci., vol. 194, pp. 229–236, 2021, doi: 10.1016/j.procs.2021.10.078.
[57] N. Omer, A. H. Samak, A. I. Taloba, and R. M. Abd El-Aziz, “A novel optimized probabilistic neural network approach for intrusion detection and categorization,” Alexandria Eng. J., vol. 72, pp. 351–361, Jun. 2023, doi: 10.1016/j.aej.2023.03.093.
[58] H. Alshahrani, A. Khan, M. Rizwan, M. S. Al Reshan, A. Sulaiman, and A. Shaikh, “Intrusion Detection Framework for Industrial Internet of Things Using Software Defined Network,” Sustain., vol. 15, no. 11, pp. 1–18, 2023, doi: 10.3390/su15119001.
[59] S. R. Rafin, M. S. S. Dip, and N. A. Arabi, “Enhancing SDN Security: A Balanced and Interpretable Machine Learning Framework for Intrusion Detection,” in 2026 IEEE 15th International Conference on Communication Systems and Network Technologies (CSNT), IEEE, Apr. 2026, pp. 576–582. doi: 10.1109/CSNT69054.2026.11502483.
[60] M. M. Ahmed and H. Abdulkader, “An ensemble-based approach for effective distributed denial of service attack detection in software defined networking,” IAES Int. J. Artif. Intell., vol. 13, no. 2, p. 2019, Jun. 2024, doi: 10.11591/ijai.v13.i2.pp2019-2026.
[61] S. A. More and A. V. Kachavimath, “SDN Intrusion Detection using Meta-Heuristic Optimization and K-Nearest Neighbors Classifier,” Procedia Comput. Sci., vol. 260, pp. 1137–1144, 2025, doi: 10.1016/j.procs.2025.03.299.
[62] M. T. Saleh and A. H. Hamad, “SICA: Generation and Deep Learning-Based Evaluation of a Novel Dataset for Intrusion Detection in SDN-IoT Environments,” J. Eur. des Systèmes Autom., vol. 59, no. 1, pp. 69–77, Jan. 2026, doi: 10.18280/jesa.590108.
[63] L. Boukraa, S. Essahraui, Y. Maleh, K. El Makkaoui, I. Ouahbi, and R. Esbai, “Machine Learning-Based Intrusion Detection Systems for Sdn: an Empirical Study Using Knime,” Edpacs, vol. 69, no. 6, pp. 46–59, 2024, doi: 10.1080/07366981.2024.2360840.
[64] C. Kannan, R. Muthusamy, V. Srinivasan, V. Chidambaram, and K. Karunakaran, “Machine learning based detection of DDoS attacks in software defined network,” Indones. J. Electr. Eng. Comput. Sci., vol. 32, no. 3, pp. 1503–1511, 2023, doi: 10.11591/ijeecs.v32.i3.pp1503-1511.
[65] A. H. Abdi, G. S. Member, S. Ahmed, and A. Tahir, “Security Control and Data Planes of SDN : A Comprehensive Review of Traditional , AI , and MTD Approaches to Security Solutions,” vol. 12, no. April, pp. 69941–69980, 2024.
[66] G. Kumar and H. Alqahtani, “Machine Learning Techniques for Intrusion Detection Systems in SDN-Recent Advances, Challenges and Future Directions,” Comput. Model. Eng. Sci., vol. 134, no. 1, pp. 89–119, 2023, doi: 10.32604/cmes.2022.020724.
[67] M. Learning, Machine learning Tom Micheal, vol. 45, no. 13. 2017. [Online]. Available: https://books.google.ca/books?id=EoYBngEACAAJ&dq=mitchell+machine+learning+1997&hl=en&sa=X&ved=0ahUKEwiomdqfj8TkAhWGslkKHRCbAtoQ6AEIKjAA
[68] S. M. Doğan, A. Koçak, and M. Alkan, “Detection and mitigation of cyber-attacks in software defined networks using machine learning/deep learning: a systematic literature review, research challenges and future directions,” Int. J. Inf. Secur., vol. 24, no. 5, p. 209, Oct. 2025, doi: 10.1007/s10207-025-01114-z.
[69] F. A. Vadhil, M. L. Salihi, and M. F. Nanne, “Machine learning-based intrusion detection system for detecting web attacks,” IAES Int. J. Artif. Intell., vol. 13, no. 1, pp. 711–721, 2024, doi: 10.11591/ijai.v13.i1.pp711-721.
[70] A. A. Abu-Shareha, M. M. Abualhaj, A. Hussein, O. Almomani, A. Amer, and A. Achuthan, “Supervised machine learning intrusion detection review and multi-criteria evaluation,” Sci. Rep., Mar. 2026, doi: 10.1038/s41598-026-44773-1.
[71] M. Ahmed, A. Naser Mahmood, and J. Hu, “A survey of network anomaly detection techniques,” J. Netw. Comput. Appl., vol. 60, pp. 19–31, Jan. 2016, doi: 10.1016/j.jnca.2015.11.016.
[72] P. García-Teodoro, J. Díaz-Verdejo, G. Maciá-Fernández, and E. Vázquez, “Anomaly-based network intrusion detection: Techniques, systems and challenges,” Comput. Secur., vol. 28, no. 1–2, pp. 18–28, Feb. 2009, doi: 10.1016/j.cose.2008.08.003.
[73] R. Sommer and V. Paxson, “Outside the Closed World: On Using Machine Learning for Network Intrusion Detection,” in 2010 IEEE Symposium on Security and Privacy, IEEE, 2010, pp. 305–316. doi: 10.1109/SP.2010.25.
[74] S. A. Alomari et al., “The Evolution of Machine Learning: From Traditional Algorithms to Deep Learning Paradigms,” in Mastering the Minds of Machines, Boca Raton: CRC Press, 2025, pp. 9–15. doi: 10.1201/9781003516385-2.
[75] X. Zhu and A. B. Goldberg, “Introduction to Semi-Supervised Learning,” Synth. Lect. Artif. Intell. Mach. Learn., vol. 3, no. 1, pp. 1–130, Jan. 2009, doi: 10.2200/S00196ED1V01Y200906AIM006.
[76] R. A. R. Ashfaq, X.-Z. Wang, J. Z. Huang, H. Abbas, and Y.-L. He, “Fuzziness based semi-supervised learning approach for intrusion detection system,” Inf. Sci. (Ny)., vol. 378, pp. 484–497, Feb. 2017, doi: 10.1016/j.ins.2016.04.019.
[77] T.-P. Nguyen, J. Cho, and D. Kim, “Semi-supervised intrusion detection system for in-vehicle networks based on variational autoencoder and adversarial reinforcement learning,” Knowledge-Based Syst., vol. 304, p. 112563, Nov. 2024, doi: 10.1016/j.knosys.2024.112563.
[78] C. Chen, Y. Gong, and Y. Tian, “Semi-supervised learning methods for network intrusion detection,” Conf. Proc. - IEEE Int. Conf. Syst. Man Cybern., pp. 2603–2608, 2008, doi: 10.1109/ICSMC.2008.4811688.
[79] J. E. van Engelen and H. H. Hoos, “A survey on semi-supervised learning,” Mach. Learn., vol. 109, no. 2, pp. 373–440, 2020, doi: 10.1007/s10994-019-05855-6.
[80] Q. Shambour, M. Al-Zyoud, and O. Almomani, “Quantum-Inspired Hybrid Metaheuristic Feature Selection with SHAP for Optimized and Explainable Spam Detection,” Symmetry (Basel)., vol. 17, no. 10, pp. 1–34, 2025, doi: 10.3390/sym17101716.
[81] A. H. K. Janabi, T. Kanakis, and M. Johnson, “A Survey of Intrusion Detection Systems based Machine Learning Approaches Applied to Software-Defined Networks (SDN): Research Issues and Challenges,” 2023, doi: 10.20944/preprints202312.1449.v1.
[82] R. Fu, “Design and Implementation of Network Intrusion Detection System based on Machine Learning,” in 2025 International Conference on Intelligent Systems and Computational Networks (ICISCN), IEEE, Jan. 2025, pp. 1–6. doi: 10.1109/ICISCN64258.2025.10934502.
[83] W.-C. Lin, S.-W. Ke, and C.-F. Tsai, “CANN: An intrusion detection system based on combining cluster centers and nearest neighbors,” Knowledge-Based Syst., vol. 78, pp. 13–21, Apr. 2015, doi: 10.1016/j.knosys.2015.01.009.
[84] M. Shehab, A. Smerat, and L. Abualigah, “Reinforcement Learning-based Optimization Algorithms: A Survey,” in Mastering the Minds of Machines, Boca Raton: CRC Press, 2025, pp. 172–177. doi: 10.1201/9781003516385-22.
[85] Y. Li, J. Xia, S. Zhang, J. Yan, X. Ai, and K. Dai, “An efficient intrusion detection system based on support vector machines and gradually feature removal method,” Expert Syst. Appl., vol. 39, no. 1, pp. 424–430, Jan. 2012, doi: 10.1016/j.eswa.2011.07.032.
[86] T. M. Cover and P. E. Hart, “Nearest Neighbor Pattern Classification,” IEEE Trans. Inf. Theory, vol. 13, no. 1, pp. 21–27, 1967, doi: 10.1109/TIT.1967.1053964.
[87] K. Noor, A. L. Imoize, C.-T. Li, and C.-Y. Weng, “A Review of Machine Learning and Transfer Learning Strategies for Intrusion Detection Systems in 5G and Beyond,” Mathematics, vol. 13, no. 7, p. 1088, Mar. 2025, doi: 10.3390/math13071088.
[88] S. A. Alomari et al., “Supervised Learning: Teaching Machines with Labeled Data,” in Mastering the Minds of Machines, Boca Raton: CRC Press, 2025, pp. 26–33. doi: 10.1201/9781003516385-4.
[89] Simon Haykin, “Neural Networks - A Comprehensive Foundation - Simon Haykin.pdf,” 2005.
[90] K. C. Khor, C. Y. Ting, and S. P. Amnuaisuk, “A feature selection approach for network intrusion detection,” Proc. - 2009 Int. Conf. Inf. Manag. Eng. ICIME 2009, vol. 3, no. December, pp. 133–137, 2009, doi: 10.1109/ICIME.2009.68.
[91] C. Khammassi and S. Krichen, “A GA-LR wrapper approach for feature selection in network intrusion detection,” Comput. Secur., vol. 70, pp. 255–277, Sep. 2017, doi: 10.1016/j.cose.2017.06.005.
[92] A. M. Oyelakin and J. R. G, “A Survey of Feature Extraction and Feature Selection Techniques used in Machine Learning-Based Botnet Detection Schemes,” VAWKUM Trans. Comput. Sci., vol. 9, no. 1, pp. 01–07, 2021, doi: 10.21015/vtcs.v9i1.604.
[93] J. Miao and L. Niu, “A Survey on Feature Selection,” Procedia Comput. Sci., vol. 91, no. Itqm, pp. 919–926, 2016, doi: 10.1016/j.procs.2016.07.111.
[94] V. Bolón-Canedo, N. Sánchez-Maroño, and A. Alonso-Betanzos, “A review of feature selection methods on synthetic data,” Knowl. Inf. Syst., vol. 34, no. 3, pp. 483–519, 2013, doi: 10.1007/s10115-012-0487-8.
[95] I. Guyon, “An Introduction to Variable and Feature Selection Isabelle,” J. ofMachine Learn. Res. 3 1157-1182, vol. 1, pp. 1–26, 2003, doi: 10.1162/153244303322753616.
[96] R. Kohavi, G. H. John, H. Rd, and S. Jose, “Wrappers for Feature Subset Selection 2 Feature Subset Selection,” Focus (Madison)., pp. 1–43, 2011.
[97] A. Wiliński and S. Osowski, “Gene selection for cancer classification,” COMPEL - Int. J. Comput. Math. Electr. Electron. Eng., vol. 28, no. 1, pp. 231–241, 2009, doi: 10.1108/03321640910919020.
[98] M. B. Imani, M. R. Keyvanpour, and R. Azmi, “A novel embedded feature selection method: A comparative study in the application of text categorization,” Appl. Artif. Intell., vol. 27, no. 5, pp. 408–427, 2013, doi: 10.1080/08839514.2013.774211.
[99] Z. Jin, J. Shang, Q. Zhu, C. Ling, W. Xie, and B. Qiang, “RFRSF: Employee Turnover Prediction Based on Random Forests and Survival Analysis,” Lect. Notes Comput. Sci. (including Subser. Lect. Notes Artif. Intell. Lect. Notes Bioinformatics), vol. 12343 LNCS, pp. 503–515, 2020, doi: 10.1007/978-3-030-62008-0_35.
[100] J. Tang, S. Alelyani, and H. Liu, “Feature selection for classification: A review,” Data Classif. Algorithms Appl., pp. 37–64, 2014, doi: 10.1201/b17320.
[101] V. Deepa, K. M. Sudar, and P. Deepalakshmi, “Design of Ensemble Learning Methods for DDoS Detection in SDN Environment,” Proc. - Int. Conf. Vis. Towar. Emerg. Trends Commun. Networking, ViTECoN 2019, pp. 17–22, 2019, doi: 10.1109/ViTECoN.2019.8899682.
[102] J. McNeill, Ensemble Methods Foundations and Algorithms, vol. 13, no. 2. 1984.
[103] A. Saleem and H. Beitollahi, “An Ensemble-based Machine Learning Framework for Advanced Distributed Denial of Service Attack Detection in Software Defined Networks,” UHD J. Sci. Technol., vol. 9, no. 2, pp. 184–197, Oct. 2025, doi: 10.21928/uhdjst.v9n2y2025.pp184-197.
[104] T. G. Dietterich, “Ensemble Methods in Machine Learning,” 2000, pp. 1–15. doi: 10.1007/3-540-45014-9_1.
[105] O. Sagi and L. Rokach, “Ensemble learning: A survey,” WIREs Data Min. Knowl. Discov., vol. 8, no. 4, Jul. 2018, doi: 10.1002/widm.1249.
[106] M. A. Ganaie, M. Hu, A. K. Malik, M. Tanveer, and P. N. Suganthan, “Ensemble deep learning: A review,” Eng. Appl. Artif. Intell., vol. 115, p. 105151, Oct. 2022, doi: 10.1016/j.engappai.2022.105151.
[107] S. S. Systems, “Ensemble Learning Framework for DDoS Detection in,” 2024.
[108] T. Ravichandran, K. Gavahi, K. Ponnambalam, V. Burtea, and S. J. Mousavi, “Ensemble-based machine learning approach for improved leak detection in water mains,” J. Hydroinformatics, vol. 23, no. 2, pp. 307–323, Mar. 2021, doi: 10.2166/hydro.2021.093.
[109] A. Hirsi, L. Audah, A. Salh, M. A. Alhartomi, and S. Ahmed, “Enhancing SDN security using ensemble-based machine learning approach for DDoS attack detection Enhancing SDN security using ensemble-based machine learning approach for DDoS attack detection,” no. March, pp. 1073–1085, 2025, doi: 10.11591/ijeecs.v38.i2.pp1073-1085.
[110] Z. Alomari, H. Sadineni, M. B. Taha, and Z. Li, “Hybrid Ensemble Learning Framework for Real-Time DDoS Detection and Mitigation in SDN Environments,” in 2025 3rd International Conference on Artificial Intelligence, Blockchain, and Internet of Things (AIBThings), IEEE, Sep. 2025, pp. 1–8. doi: 10.1109/AIBThings66987.2025.11296148.
[111] R. A. Elsayed, R. A. Hamada, M. I. Abdalla, and S. A. Elsaid, “Securing IoT and SDN systems using deep-learning based automatic intrusion detection,” Ain Shams Eng. J., vol. 14, no. 10, p. 102211, Oct. 2023, doi: 10.1016/j.asej.2023.102211.
[112] J. Wang and L. Wang, “SDN-Defend: A Lightweight Online Attack Detection and Mitigation System for DDoS Attacks in SDN,” Sensors, vol. 22, no. 21, p. 8287, Oct. 2022, doi: 10.3390/s22218287.
[113] A. S. Jose, L. R. Nair, and V. Paul, “Desinging Intrusion Detection System in Software Defined Networks Using Hybrid Gwo-Ae-Rf Model,” Indian J. Comput. Sci. Eng., vol. 13, no. 6, pp. 1951–1966, Dec. 2022, doi: 10.21817/indjcse/2022/v13i6/221306129.
[114] A. Abubakar and B. Pranggono, “Machine learning based intrusion detection system for software defined networks,” Proc. - 2017 7th Int. Conf. Emerg. Secur. Technol. EST 2017, vol. 9, no. 09, pp. 138–143, 2017, doi: 10.1109/EST.2017.8090413.