{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,3]],"date-time":"2026-08-03T21:45:46Z","timestamp":1785793546617,"version":"3.56.0"},"reference-count":24,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,10,21]],"date-time":"2025-10-21T00:00:00Z","timestamp":1761004800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,10,21]],"date-time":"2025-10-21T00:00:00Z","timestamp":1761004800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Manipal Academy of Higher Education, Manipal"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["EURASIP J. on Info. Security"],"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>This research aims to develop a Network Detection System (NDS) utilizing various machine learning techniques to enhance network security through anomaly detection. It evaluates the effectiveness of K-nearest neighbors (KNN), gradient boosting, support vector machines (SVM), random forests, and logistic regression in identifying deviations from normal network behavior. Furthermore, ensemble learning methods, including voting and stacking techniques, are explored to improve detection accuracy. The study proposes and tests a hybrid multi-layered stacking model using the CICIDS 2017 dataset, which encompasses both historical and modern attack patterns, providing a comprehensive benchmark for evaluation. Model performance is assessed using metrics such as accuracy, precision, recall, and F1 score. Special emphasis is placed on feature importance and reduction in dimensionality to enhance model efficiency. Additionally, the study addresses the critical challenge of minimizing false positives and false negatives for practical deployment. Results indicate that the hybrid ensemble stacking model achieves superior performance, with an accuracy of 98.79%, significantly improving network anomaly detection. The research highlights the potential for further advances through deep learning and real-time detection methodologies to improve network security in the future.<\/jats:p>","DOI":"10.1186\/s13635-025-00216-4","type":"journal-article","created":{"date-parts":[[2025,10,21]],"date-time":"2025-10-21T10:03:03Z","timestamp":1761040983000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Adaptive network anomaly detection using machine learning approaches"],"prefix":"10.1186","volume":"2025","author":[{"given":"Vasudeva","family":"Pai","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Karthik","family":"Pai","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Manjunatha","family":"S.","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Srujan","family":"Hirmeti","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vaibhav V.","family":"Bhat","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,10,21]]},"reference":[{"key":"216_CR1","doi-asserted-by":"publisher","unstructured":"T. Hagemann and K. Katsarou, A Systematic Review on Anomaly Detection for Cloud Computing Environments. In Proceedings of the 2020 3rd Artificial Intelligence and Cloud Computing Conference (AICCC '20). Association for Computing Machinery, New York, NY, USA, 83\u201396. https:\/\/doi.org\/10.1145\/3442536.3442550","DOI":"10.1145\/3442536.3442550"},{"key":"216_CR2","doi-asserted-by":"publisher","unstructured":"F. Shahzad et al., Cloud -based multiclass anomaly detection and categorization using ensemble learning. J Cloud Comput 11, 74 (2022). https:\/\/doi.org\/10.1186\/s13677-022-00329-y","DOI":"10.1186\/s13677-022-00329-y"},{"key":"216_CR3","doi-asserted-by":"publisher","unstructured":"D. Gupta, O. Kayode, S. Bhatt, M. Gupta and A. S. Tosun, \"Hierarchical Federated Learning based Anomaly Detection using Digital Twins for Smart Healthcare,\" 2021 IEEE 7th International Conference on Collaboration and Internet Computing (CIC), Atlanta, GA, USA 16-25 (2021). https:\/\/doi.org\/10.1109\/CIC52973.2021.00013","DOI":"10.1109\/CIC52973.2021.00013"},{"key":"216_CR4","doi-asserted-by":"publisher","first-page":"12699","DOI":"10.1109\/ACCESS.2024.3355312","volume":"12","author":"YY Ghadi","year":"2024","unstructured":"Y.Y. Ghadi et al., Machine learning solutions for the security of wireless sensor networks: a review. IEEE Access 12, 12699\u201312719 (2024). https:\/\/doi.org\/10.1109\/ACCESS.2024.3355312","journal-title":"IEEE Access"},{"key":"216_CR5","doi-asserted-by":"publisher","unstructured":"Y. Yasin Ghadi, T. Mazhar, K. Aurangzeb, I. Haq, T. Shahzad, A. Ali Laghari, A.M. Shahid, Security risk models against attacks in smart grid using big data and artificial intelligence. PeerJ Comput. Sci. 10,\u00a0(2024). https:\/\/doi.org\/10.7717\/peerj-cs.1840","DOI":"10.7717\/peerj-cs.1840"},{"issue":"99","key":"216_CR6","first-page":"1","volume":"PP","author":"K Kurniabudi","year":"2020","unstructured":"K. Kurniabudi, D. Stiawan, D. Darmawijoyo, M.Y.B. Idris, A.M. Bamhdhi, R. Budiarto, Cicids-2017 dataset feature analysis with information gain for anomaly detection. IEEE Access PP(99), 1\u20131 (2020)","journal-title":"IEEE Access"},{"issue":"99","key":"216_CR7","first-page":"1","volume":"PP","author":"ZK Maseer","year":"2021","unstructured":"Z.K. Maseer, R. Yusof, N. Bahaman, S.A. Mostafa, C.F.M. Foozy, Benchmarking of machine learning for anomaly based intrusion detection systems in the CICIDS2017 dataset. IEEE Access PP(99), 1\u20131 (2021)","journal-title":"IEEE Access"},{"issue":"3","key":"216_CR8","doi-asserted-by":"publisher","first-page":"42","DOI":"10.32628\/IJSRSET5241134","volume":"11","author":"S Bakhare","year":"2024","unstructured":"S. Bakhare, S.W. Mohod, Evaluating the performance and challenges of machine learning models in network anomaly detection. Int. J. Sci. Res. Sci. Eng. Technol. 11(3), 42\u201352 (2024)","journal-title":"Int. J. Sci. Res. Sci. Eng. Technol."},{"key":"216_CR9","doi-asserted-by":"crossref","unstructured":"H. Neuschmied, M. Winter, K. Hofer-Schmitz, B. Stojanovic, U. Kleb, Two Stage Anomaly Detection for Network Intrusion Detection in Proc. 7th Int. Conf. on Information Systems Security and Privacy (ICISSP) 450-457 (2021)","DOI":"10.5220\/0010233404500457"},{"key":"216_CR10","first-page":"75","volume":"49","author":"M Adnan","year":"2023","unstructured":"M. Adnan, D. Bshara, A. Awad, Forensic analysis of apt attacks based on unsupervised machine learning. Avrupa Bilim ve Teknoloji Derg 49, 75\u201382 (2023)","journal-title":"Avrupa Bilim ve Teknoloji Derg"},{"key":"216_CR11","doi-asserted-by":"publisher","first-page":"205","DOI":"10.1016\/j.procs.2022.03.029","volume":"201","author":"EmadE. Abdallah","year":"2022","unstructured":"Emad E.. Abdallah, Ahmed Fawzi Otoom, Intrusion detection systems using supervised machine learning techniques: a survey. Procedia Comput. Sci. 201, 205\u2013212 (2022)","journal-title":"Procedia Comput. Sci."},{"key":"216_CR12","doi-asserted-by":"crossref","unstructured":"K. Noto, C. Brodley, D. Slonim, Anomaly detection using an ensemble of feature models, 2010 IEEE international conference on data mining\u00a0(2010)","DOI":"10.1109\/ICDM.2010.140"},{"key":"216_CR13","doi-asserted-by":"crossref","unstructured":"J. Vanerio, and P. Casas, Ensemble-learning approaches for network security and anomaly detection, Proceedings of the workshop on big data analytics and machine learning for data communication networks, (2017)","DOI":"10.1145\/3098593.3098594"},{"issue":"18","key":"216_CR14","doi-asserted-by":"publisher","first-page":"3799","DOI":"10.1016\/j.ins.2007.03.025","volume":"177","author":"T Shon","year":"2007","unstructured":"T. Shon, J. Moon, A hybrid machine learning approach to network anomaly detection. Inf. Sci. 177(18), 3799\u20133821 (2007)","journal-title":"Inf. Sci."},{"key":"216_CR15","doi-asserted-by":"crossref","unstructured":"Lai Kai Lok, V. Abdul. Hameed, Muhammad Ehsan Rana, Hybrid machine learning approach for anomaly detection. Indones. J. Electr. Eng. Comput. Sci. 27(2), 1016 (2022).","DOI":"10.11591\/ijeecs.v27.i2.pp1016-1024"},{"key":"216_CR16","doi-asserted-by":"publisher","unstructured":"M. Alkasassbeh, A novel hybrid method for network anomaly detection based on traffic prediction and change point detection, Journal of Computer Science, 14 , 2 (2018). https:\/\/doi.org\/10.3844\/jcssp.2018.153.162","DOI":"10.3844\/jcssp.2018.153.162"},{"key":"216_CR17","doi-asserted-by":"publisher","first-page":"152379","DOI":"10.1109\/ACCESS.2021.3126834","volume":"9","author":"S Wang","year":"2021","unstructured":"S. Wang et al., Machine learning in network anomaly detection: a survey. IEEE Access 9, 152379\u2013152396 (2021)","journal-title":"IEEE Access"},{"key":"216_CR18","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1080\/24751839.2023.2272484","volume":"8","author":"Y Saheed","year":"2023","unstructured":"Y. Saheed, T. Kehinde, M. Raji, U. Baba, Feature selection in intrusion detection systems: a new hybrid fusion of bat algorithm and residue number system. J. Inf. Telecommun. 8, 1\u201319 (2023). https:\/\/doi.org\/10.1080\/24751839.2023.2272484","journal-title":"J. Inf. Telecommun."},{"key":"216_CR19","doi-asserted-by":"publisher","DOI":"10.1016\/j.rineng.2024.103171","volume":"24","author":"YK Saheed","year":"2024","unstructured":"Y.K. Saheed, J.E. Chukwuere, XAIEnsembleTL-IoV: A new eXplainable artificial intelligence ensemble transfer learning for zero-day botnet attack detection in the Internet of Vehicles. Results Eng 24, 103171 (2024). https:\/\/doi.org\/10.1016\/j.rineng.2024.103171","journal-title":"Results Eng"},{"key":"216_CR20","doi-asserted-by":"publisher","DOI":"10.1007\/s10586-025-05325-w","volume":"28","author":"B Buyuktanir","year":"2025","unstructured":"B. Buyuktanir, \u015e Altinkaya, G. Karatas Baydogmus et al., Federated learning in intrusion detection: advancements, applications, and future directions. Cluster Comput. 28, 473 (2025). https:\/\/doi.org\/10.1007\/s10586-025-05325-w","journal-title":"Cluster Comput."},{"key":"216_CR21","doi-asserted-by":"publisher","first-page":"410","DOI":"10.1016\/j.procs.2024.05.048","volume":"236","author":"K Shalabi","year":"2024","unstructured":"K. Shalabi, Q.A. Al-Haija, M. Al-Fayoumi, A blockchain-based intrusion detection\/prevention systems in IoT network: a systematic review. Procedia Comput. Sci. 236, 410\u2013419 (2024). https:\/\/doi.org\/10.1016\/j.procs.2024.05.048","journal-title":"Procedia Comput. Sci."},{"issue":"2","key":"216_CR22","doi-asserted-by":"publisher","first-page":"72","DOI":"10.1109\/MWC.001.1900119","volume":"27","author":"J Kang","year":"2020","unstructured":"J. Kang, Z. Xiong, D. Niyato, Y. Zou, Y. Zhang, M. Guizani, Reliable federated learning for mobile networks. IEEE Wirel. Commun. 27(2), 72\u201380 (2020). https:\/\/doi.org\/10.1109\/MWC.001.1900119","journal-title":"IEEE Wirel. Commun."},{"key":"216_CR23","doi-asserted-by":"publisher","DOI":"10.1016\/j.iswa.2024.200462","volume":"25","author":"LKG Danquah","year":"2025","unstructured":"L.K.G. Danquah, S.Y. Appiah, V.A. Mantey, I. Danlard, E.K. Akowuah, Computationally efficient deep federated learning with optimized feature selection for IoT botnet attack detection. Intell. Syst. Appl. 25, 200462 (2025). https:\/\/doi.org\/10.1016\/j.iswa.2024.200462","journal-title":"Intell. Syst. Appl."},{"key":"216_CR24","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2023.12.042","author":"H Zhang","year":"2024","unstructured":"H. Zhang, S. Jiang, S. Xuan, Decentralized federated learning based on blockchain: concepts, framework, and challenges. Comput. Commun. (2024). https:\/\/doi.org\/10.1016\/j.comcom.2023.12.042","journal-title":"Comput. Commun."}],"container-title":["EURASIP Journal on Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-025-00216-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s13635-025-00216-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-025-00216-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,21]],"date-time":"2025-10-21T10:03:09Z","timestamp":1761040989000},"score":1,"resource":{"primary":{"URL":"https:\/\/jis-eurasipjournals.springeropen.com\/articles\/10.1186\/s13635-025-00216-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,21]]},"references-count":24,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["216"],"URL":"https:\/\/doi.org\/10.1186\/s13635-025-00216-4","relation":{},"ISSN":["2510-523X"],"issn-type":[{"value":"2510-523X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,21]]},"assertion":[{"value":"17 December 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 September 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 October 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"Not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}},{"value":"The authors declare that they have no competing interests.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"29"}}