{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T14:21:59Z","timestamp":1781533319889,"version":"3.54.5"},"reference-count":32,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T00:00:00Z","timestamp":1780444800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Princess Nourah bint Abdulrahman University, Riyadh, Saudi Arabia","award":["PNURSP2026R904"],"award-info":[{"award-number":["PNURSP2026R904"]}]},{"award":["PNURSP2026R904"],"award-info":[{"award-number":["PNURSP2026R904"]}],"id":[{"id":"https:\/\/ror.org\/05b0cyh02","id-type":"ROR","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computers"],"abstract":"<jats:p>The evolution of 5G networks has introduced new challenges in securing mobile infrastructures against increasingly sophisticated cyber threats. Intrusion detection in such environments has been widely studied using traditional datasets such as the Canadian Institute for Cybersecurity Intrusion Detection Systems CICIDS2017, the University of New South Wales-Network Behavior UNSW-NB15, and The Network Security Laboratory-Knowledge Discovery in Databases NSL-KDD; however, these benchmarks lack the architectural complexity and protocol diversity inherent to 5G networks. More recent research has adopted the 5G-NIDD dataset (5G Network Intrusion Detection Dataset), which provides realistic traffic generated from a live 5G testbed, including various attack scenarios targeting MEC servers and core network components. Nevertheless, existing works using 5G-NIDD often focus on limited subsets of attacks, rely on unsupervised or federated learning approaches, and lack comprehensive evaluations of supervised learning models. In contrast, this study leverages the entire 5G-NIDD dataset, encompassing all available attack scenarios, and conducts a systematic comparison of multiple supervised learning algorithms. A systematic evaluation of supervised learning algorithms is conducted using key performance metrics such as accuracy, precision, recall and F1-score to identify the most effective model for intrusion detection in 5G environments. Specifically, this study focuses on four supervised learning algorithms, K-Nearest Neighbors (KNNs), Support Vector Machines (SVMs), Logistic Regression (LR), and Naive Bayes (NB), to determine not only which achieves the highest detection accuracy but also which offers the best balance between predictive performance and computational efficiency in realistic 5G environments. To assess robustness and adaptability, the proposed models are further validated on two widely used benchmark datasets, namely CICIDS2017 and UNSW-NB15, as part of an extended analysis. This cross-dataset evaluation highlights each algorithm\u2019s strengths and limitations under diverse network traffic conditions and attack scenarios. The results aim to validate the applicability of supervised learning approaches to intrusion detection in next-generation network infrastructures, while also emphasizing the importance of balancing predictive accuracy with computational efficiency for real-world deployment.<\/jats:p>","DOI":"10.3390\/computers15060362","type":"journal-article","created":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T13:46:48Z","timestamp":1780494408000},"page":"362","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Supervised Machine Learning-Based Intrusion Detection for 5G Networks: Evaluation on the 5G-NIDD Dataset"],"prefix":"10.3390","volume":"15","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0622-1229","authenticated-orcid":false,"given":"Narjes","family":"Lassoued","sequence":"first","affiliation":[{"name":"Innovation of Communicating and Cooperative Mobile Laboratory, National Engineering School of Gabes, Gabes University, Gabes 6029, Tunisia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Imen","family":"Filali","sequence":"additional","affiliation":[{"name":"Department of Computer Sciences, College of Computer and Information Sciences, Princess Nourah bint Abdulrahman University, P.O. Box 84428, Riyadh 11671, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8148-1621","authenticated-orcid":false,"given":"Ridha","family":"Ejbali","sequence":"additional","affiliation":[{"name":"Research Team on Intelligent Machines, National School of Engineers of Gabes, University of Gabes, Gabes 6029, Tunisia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2026,6,3]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Sudhamani, C., Roslee, M., Tiang, J.J., and Rehman, A.U. (2023). A Survey on 5G Coverage Improvement Techniques: Issues and Future Challenges. Sensors, 23.","DOI":"10.3390\/s23042356"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Mijwil, M.M., Abotaleb, M., and Dutta, P.K. (2025). The 5G Era: Transforming Connectivity and Enabling New Use Cases Across Industries. Building Embodied AI Systems: The Agents, the Architecture, Springer.","DOI":"10.1007\/978-3-031-68256-8_22"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Dias, J., Pinto, P., Santos, R., and Malta, S. (2025). 5G Network Slicing: Security Challenges, Attack Vectors, and Mitigation Approaches. Sensors, 25.","DOI":"10.3390\/s25133940"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"3569","DOI":"10.1007\/s10207-024-00900-5","article-title":"Securing 5G Virtual Networks: A Critical Analysis of SDN, NFV, and Network Slicing Security","volume":"23","author":"Alnaim","year":"2024","journal-title":"Int. J. Inf. Secur."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Trabelsi, Z., and Zeidan, S. (2014, January 10\u201314). IDS Performance Enhancement Technique Based on Dynamic Traffic Awareness Histograms. Proceedings of the 2014 IEEE International Conference on Communications (ICC), Sydney, NSW, Australia. Available online: https:\/\/research.uaeu.ac.ae\/en\/publications\/ids-performance-enhancement-technique-based-on-dynamic-traffic-aw.","DOI":"10.1109\/ICC.2014.6883446"},{"key":"ref_6","first-page":"6610675","article-title":"A Novel Framework Design of Network Intrusion Detection Based on Machine Learning Techniques","volume":"2021","author":"Zhang","year":"2021","journal-title":"Secur. Commun. Netw."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"40950","DOI":"10.1109\/ACCESS.2025.3546338","article-title":"Intrusion Detection in 5G and Wi-Fi Networks: A Survey of Current Methods, Challenges and Perspectives","volume":"13","author":"Hamroun","year":"2025","journal-title":"IEEE Access"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"150","DOI":"10.54254\/2755-2721\/106\/20241340","article-title":"Application of Deep Learning-Based Intrusion Detection System (IDS) in Network Anomaly Traffic Detection","volume":"8","author":"Zhao","year":"2024","journal-title":"Appl. Comput. Eng."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"1717","DOI":"10.1109\/JSYST.2020.2992966","article-title":"A Comprehensive Survey of Databases and Deep Learning Methods for Cybersecurity and Intrusion Detection Systems","volume":"15","author":"Genovese","year":"2021","journal-title":"IEEE Syst. J."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Liu, H., and Lang, B. (2019). Machine Learning and Deep Learning Methods for Intrusion Detection Systems: A Survey. Appl. Sci., 9.","DOI":"10.3390\/app9204396"},{"key":"ref_11","unstructured":"Zhang, D., Zhou, F., Albu, F., Wei, Y., Yang, X., Gu, Y., and Li, Q. (2023). Unleashing the power of self-supervised image denoising: A comprehensive review. arXiv."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Zhang, D., Zhou, F., Jiang, Y., and Fu, Z. (2023, January 18\u201322). Mm-bsn: Self-supervised image denoising for real-world with multi-mask based on blind-spot network. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Vancouver, BC, Canada.","DOI":"10.1109\/CVPRW59228.2023.00441"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Tavallaee, M., Bagheri, E., Lu, W., and Ghorbani, A.A. (2009, January 8\u201310). A detailed analysis of the KDD CUP 99 data set. Proceedings of the 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications, Ottawa, ON, Canada.","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"ref_14","unstructured":"Adel, A.M. (2025, December 18). NSL-KDD Dataset. Available online: https:\/\/github.com\/AhmedMohammedAdel\/NSL_KDD."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Moustafa, N., and Slay, J. (2015, January 10\u201312). UNSW-NB15: A comprehensive data set for network intrusion detection systems. Proceedings of the 2015 MilCIS, Canberra, Australia.","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"ref_16","unstructured":"Islam, R.R. (2025, December 18). UNSW-NB15 Dataset. Available online: https:\/\/github.com\/rokibulroni\/CIC-IDS-2017-Dataset."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., and Ghorbani, A.A. (2018, January 22\u201324). Toward generating a new intrusion detection dataset and intrusion traffic characterization. Proceedings of the ICISSP, Madeira, Portugal.","DOI":"10.5220\/0006639801080116"},{"key":"ref_18","unstructured":"Pervez, N. (2025, December 18). CICIDS2017 Dataset. Available online: https:\/\/github.com\/noushinpervez\/Intrusion-Detection-CICIDS2017."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Mishra, N., and Mishra, S. (2024, January 19\u201321). NSL-KDD Dataset Analysis: A Machine Learning Implementation to Detect Intrusions in the Computer Network. Proceedings of the 2024 2nd International Conference on Signal Processing, Communication, Power and Embedded System (SCOPES), Parlakhemundi, India.","DOI":"10.1109\/SCOPES64467.2024.10990794"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1109\/MC.2018.2888764","article-title":"KDD Cup 99 Data Sets: A Perspective on the Role of Data Sets in Network Intrusion Detection Research","volume":"52","author":"Siddique","year":"2019","journal-title":"Computer"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Kabir, M.H., Rajib, M.S., Rahman, A.S.M.T., Rahman, M.M., and Dey, S.K. (2022, January 24\u201326). Network Intrusion Detection Using UNSW-NB15 Dataset: Stacking Machine Learning Based Approach. Proceedings of the 2022 International Conference on Advancement in Electrical and Electronic Engineering (ICAEEE), Gazipur, Bangladesh.","DOI":"10.1109\/ICAEEE54957.2022.9836404"},{"key":"ref_22","first-page":"633","article-title":"Improving Intrusion Detection with Hybrid Deep Learning Models: A Study on CIC-IDS2017, UNSW-NB15, and KDD CUP 99","volume":"10","author":"Sharma","year":"2022","journal-title":"J. Inf. Syst. Eng. Manag."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"132911","DOI":"10.1109\/ACCESS.2020.3009843","article-title":"CICIDS-2017 Dataset Feature Analysis With Information Gain for Anomaly Detection","volume":"8","author":"Kurniabudi","year":"2020","journal-title":"IEEE Access"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Sheikhi, S., and Kostakos, P. (2023, January 6\u20139). DDoS Attack Detection Using Unsupervised Federated Learning for 5G Networks and Beyond. Proceedings of the 2023 Joint EuCNC\/6G Summit, Gothenburg, Sweden.","DOI":"10.1109\/EuCNC\/6GSummit58263.2023.10188245"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Sheikhi, S., and Kostakos, P. (2024, January 2\u20134). Advancing Security in 5G Core Networks through Unsupervised Federated Time Series Modeling. Proceedings of the 2024 IEEE International Conference on Cyber Security and Resilience (CSR), London, UK.","DOI":"10.1109\/CSR61664.2024.10679491"},{"key":"ref_26","unstructured":"Sheikhi, S. (2025, December 18). 5G-Intrusion-Detection-Dataset. Available online: https:\/\/github.com\/saeidsheikhi\/5G-Intrusion-Detection-Dataset."},{"key":"ref_27","first-page":"421","article-title":"Critical Analysis of 5G Networks Traffic Intrusion using PCA, t-SNE and UMAP Visualization and Classifying Attacks","volume":"Volume 785","author":"Ghani","year":"2023","journal-title":"Proceedings of ICDAM 2023"},{"key":"ref_28","first-page":"886","article-title":"AI Driven Anomaly Detection in Network Traffic Using Hybrid CNN-GAN","volume":"15","author":"Rao","year":"2024","journal-title":"Int. J. Adv. Inf. Technol."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"4222827","DOI":"10.1155\/2022\/4222827","article-title":"Automatic Traffic Anomaly Detection on the Road Network with Spatial-Temporal Graph Neural Network Representation Learning","volume":"2022","author":"Zhang","year":"2022","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"ref_30","unstructured":"Ziya07 (2025, December 18). Network Traffic Anomaly Detection Dataset. Available online: https:\/\/www.kaggle.com\/datasets\/ziya07\/network-traffic-anomaly-detection-dataset."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"105","DOI":"10.1186\/s40537-024-00957-y","article-title":"Advancing Cybersecurity: A Comprehensive Review of AI-Driven Detection Techniques","volume":"11","author":"Salem","year":"2024","journal-title":"J. Big Data"},{"key":"ref_32","unstructured":"Hoger, T., and Owezarski, P. (2025). Multi-domain anomaly detection in a 5G network. arXiv."}],"container-title":["Computers"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-431X\/15\/6\/362\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T14:04:43Z","timestamp":1780495483000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-431X\/15\/6\/362"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,3]]},"references-count":32,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2026,6]]}},"alternative-id":["computers15060362"],"URL":"https:\/\/doi.org\/10.3390\/computers15060362","relation":{},"ISSN":["2073-431X"],"issn-type":[{"value":"2073-431X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,3]]}}}