{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T20:34:32Z","timestamp":1776976472791,"version":"3.51.4"},"reference-count":0,"publisher":"Slovenian Association Informatika","issue":"11","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IJCAI"],"abstract":"<jats:p>Cyberattacks, especially Distributed Denial-of-Service (DDoS) attacks, are highly dangerous to online infrastructure, as they use network resources and cause disruption of services. It is also hard to detect such attacks in real-time because the traditional rule-based intrusion detection system (IDS) and single machine-based learning models fail to contend with threat variations. In this paper, NEAT-ID (Neuro- Symbolic Ensemble of Anomaly-based Threat Detection) is described, which is a hybrid framework that combines both network and biometric signals to enhance the accuracy and interpretability of the detection. NEAT-ID is based on a wavelet-transformed feature extractor of temporal network patterns, a Transformer encoder with attention on biometric feature integration, a rulefit model of symbolic reasoning, a stacked ensemble of five classifiers (TabNet, LightGBM, Histogram-based GB, Naive Bayes, Logistic Regression), and an XGBoost meta-learner to provide the final prediction. The framework was tested on the CIC-dDoS2019 dataset, with NEAT-ID scoring 96% accuracy, 97% F1-score, and 0.9949 ROC-AUC, which is better than baseline IDS models and shows robust, interpretable, and high- performance intrusion detection.<\/jats:p>","DOI":"10.31449\/inf.v50i11.10770","type":"journal-article","created":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T19:36:24Z","timestamp":1776972984000},"source":"Crossref","is-referenced-by-count":0,"title":["NEAT-ID: A Novel Method for Enhancing Threat Detection Process DDoS in Cybersecurity"],"prefix":"10.31449","volume":"50","author":[{"given":"Hui","family":"Ek","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"16141","published-online":{"date-parts":[[2026,4,23]]},"container-title":["Informatica"],"original-title":[],"link":[{"URL":"https:\/\/www.informatica.si\/index.php\/informatica\/article\/download\/10770\/6648","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.informatica.si\/index.php\/informatica\/article\/download\/10770\/6648","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T19:36:25Z","timestamp":1776972985000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.informatica.si\/index.php\/informatica\/article\/view\/10770"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,23]]},"references-count":0,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2026,4,23]]}},"URL":"https:\/\/doi.org\/10.31449\/inf.v50i11.10770","relation":{},"ISSN":["1854-3871","0350-5596"],"issn-type":[{"value":"1854-3871","type":"electronic"},{"value":"0350-5596","type":"print"}],"subject":[],"published":{"date-parts":[[2026,4,23]]}}}