Modified Multi-Stage Ensemble Feature Selection (MMSE-FS) for Network Intrusion Detection

PDF (828KB), PP.95-110

Views: 0 Downloads: 0

Author(s)

Faruq A. Al-Omari 1,* Alaa Y. Mhesin 2 Mohammad M. Al-Shurman 2

1. College of Engineering and Technology, American University in the Emirates, International Academic City, Dubai, UAE Computer Engineering Department, Yarmouk University, Irbid, Jordan

2. Network Engineering and Security Dept., Jordan University of Science and Technology, Irbid, Jordan

* Corresponding author.

DOI: https://doi.org/10.5815/ijwmt.2026.04.07

Received: 5 Jun. 2026 / Revised: 24 Jun. 2026 / Accepted: 16 Jul. 2026 / Published: 8 Aug. 2026

Index Terms

Intrusion detection systems (IDS), Feature selection framework, Ensemble learning, Dimensionality reduction, Network security

Abstract

Intrusion Detection Systems (IDS) are essential for protecting modern networks against unauthorized access and evolving cyber threats. A persistent challenge in IDS design is the high dimensionality of network traffic data, which complicates the identification of the most relevant features for effective detection. This study introduces a modified multi-stage ensemble feature selection (MMSE-FS) framework that incorporates algorithmic adaptations of Random Forest (RF), Principal Component Analysis (PCA), and KBest methods. These enhanced variants are integrated through an intelligent ensemble voting mechanism, followed by a refinement stage that further strengthens feature relevance and discriminative capability. 
To validate the proposed framework, experiments were conducted on the UNSW-NB15 benchmark dataset, reducing 49 initial features to 18 critical ones. The dataset was partitioned into 70% training and 30% testing subsets, and classification performance was evaluated using five machine learning classifiers (DT, RF, GB, KNN, and LR). Key hyperparameters of the proposed MMSE-FS framework (α = 0.75, λ = 1.0, and B = 50 bootstrap repetitions) were determined through 5-fold cross-validation on the training partition and subsequently fixed for all experiments. The proposed framework achieved detection accuracies ranging from 99.03% to 99.83% for binary classification and from 94.20% to 96.60% for multi-class classification.
Compared with conventional feature selection methods, the proposed MMSE-FS framework substantially reduced the feature space while maintaining high detection performance across both binary and multi-class intrusion detection tasks. The reported results were obtained using the UNSW-NB15 dataset following the adopted preprocessing strategy, which excluded extremely underrepresented attack classes.

Cite This Paper

Faruq A. Al-Omari, Alaa Y. Mhesin, Mohammad M. Al-Shurman, "Modified Multi-Stage Ensemble Feature Selection (MMSE-FS) for Network Intrusion Detection", International Journal of Wireless and Microwave Technologies(IJWMT), Vol.16, No.4, pp. 95-110, 2026. DOI:10.5815/ijwmt.2026.04.07

Reference

[1]Mukherjee, B., Heberlein, L. T., & Levitt, K. N. (1994). Network intrusion detection. IEEE Network, 8(3), 26-41. https://api.semanticscholar.org/CorpusID:263738512 
[2]Stavroulakis, P., & Stamp, M. (Eds.). (2010). Handbook of Information and Communication Security. Springer. DOI: 10.1007/978-3-642-04117-4
[3]Modi, C. N., Patel, D. R., Patel, A., & Rajarajan, M. (2012). Integrating signature apriori based network intrusion detection system (NIDS) in cloud computing. Procedia Technology, 6, 905-912. DOI: http://dx.doi.org/10.1016/j.protcy.2012.10.110 
[4]Kanimozhi, V., & Jacob, P. (2019). UNSW-NB15 dataset feature selection and network intrusion detection using deep learning. International Journal of Recent Technology and Engineering, 7(5). DOI: 10.35940/ijrte.D5002.078519 
[5]Parimala, G., & Kayalvizhi, R. (2021). An effective intrusion detection system for securing IoT using feature selection and deep learning. In 2021 International Conference on Computer Communication and Informatics (ICCCI), 1-4 IEEE. DOI: 10.1109/ICCCI50826.2021.9402562
[6]Ayo, F. E., Folorunso, S. O., Abayomi-Alli, A. A., Adekunle, A. O., & Awotunde, J. B. (2020). Network intrusion detection based on deep learning model optimized with rule-based hybrid feature selection. Information Security Journal: A Global Perspective, 29(6), 267-283. DOI: 10.1080/19393555.2020.1767240
[7]Verma, J., Bhandari, A., & Singh, G. (2022). Feature selection algorithm characterization for NIDS using machine and deep learning. In 2022 IEEE International IOT, Electronics and Mechatronics Conference (IEMTRONICS), 1-7 IEEE. DOI: 10.1109/IEMTRONICS55184.2022.9795709
[8]Pranto, M. B., Ratul, M. H. A., Rahman, M. M., Diya, I. J., & Zahir, Z.-B. (2022). Performance of machine learning techniques in anomaly detection with basic feature selection strategy-a network intrusion detection system. Journal of Advances in Information Technology, 13(1). DOI: 10.12720/jait.13.1.36-44 
[9]Dey, S. K., & Rahman, M. M. (2018). Flow based anomaly detection in software defined networking: A deep learning approach with feature selection method. In 2018 4th International Conference on Electrical Engineering and Information & Communication Technology (iCEEiCT), 630-635. IEEE. DOI: 10.1109/CEEICT.2018.8628122
[10]Farhan, R. I., Maolood, A. T., & Hassan, N. (2021). Hybrid feature selection approach to improve the deep neural network on new flow-based dataset for NIDS. Wasit Journal of Computer and Mathematics Science, 66-83. DOI: 10.31185/wjcm.2021.1.1.6
[11]Li, X., Chen, W., Zhang, Q., & Wu, L. (2020). Building auto-encoder intrusion detection system based on random forest feature selection. Computers & Security, 95, 101851. DOI: 10.1016/j.cose.2020.101851
[12]Hammad, M., El-Medany, W., & Ismail, Y. (2020). Intrusion detection system using feature selection with clustering and classification machine learning algorithms on the UNSW-NB15 dataset. In 2020 International Conference on Innovation and Intelligence for Informatics, Computing and Technologies (3ICT), 1-6. IEEE. DOI: 10.1109/3ICT51146.2020.9311973
[13]Moustafa, N., & Slay, J. (2016). The evaluation of network anomaly detection systems: Statistical analysis of the UNSW-NB15 data set and the comparison with the KDD99 data set. Information Security Journal: A Global Perspective, 25(1-3), 18-31. DOI: 10.1080/19393555.2015.1125974
[14]Zong, W., Chow, Y.-W., & Susilo, W. (2018). A two-stage classifier approach for network intrusion detection. In Information Security Practice and Experience: 14th International Conference, ISPEC 2018, Tokyo, Japan, September 25-27, 329-340. Springer. DOI: 10.1007/978-3-319-99807-7_20
[15]Meftah, S., Rachidi, T., & Assem, N. (2019). Network based intrusion detection using the UNSW-NB15 dataset. International Journal of Computing and Digital Systems, 8(5), 478-487. DOI: 10.12785/ijcds/080505
[16]Kasongo, S. M., & Sun, Y. (2020). Performance analysis of intrusion detection systems using a feature selection method on the UNSW-NB15 dataset. Journal of Big Data, 7, 1-20. DOI: 10.1186/s40537-020-00379-6
[17]Roy, A., & Singh, K. J. (2021). Multi-classification of UNSW-NB15 dataset for network anomaly detection system. In International Conference on Communication and Computational Technologies: ICCCT-2019, 429-451. Springer. DOI: 10.1007/978-981-15-5341-7_38
[18]Eunice, A. D., Gao, Q., Zhu, M.-Y., Chen, Z., & Na, L. (2021). Network anomaly detection technology based on deep learning. In 2021 IEEE 3rd International Conference on Frontiers Technology of Information and Computer (ICFTIC), 6-9. IEEE. DOI: 10.1109/ICFTIC54222.2021.9644165
[19]Kocher, G., & Kumar, G. (2021). Analysis of machine learning algorithms with feature selection for intrusion detection using UNSW-NB15 dataset. Available at SSRN 3784406. DOI: 10.2139/ssrn.3784406
[20]Prasad, M., Gupta, R. K., & Tripathi, S. (2022). A multi-level correlation-based feature selection for intrusion detection. Arabian Journal for Science and Engineering, 47(8), 10719-10729. DOI: 10.1007/s13369-022-06601-4
[21]Yin, Y., Jang-Jaccard, J., Xu, W., Singh, A., Zhu, J., Sabrina, F., & Kwak, J. (2023). IGRF-RFE: A hybrid feature selection method for MLP-based network intrusion detection on UNSW-NB15 dataset. Journal of Big Data, 10(1), 1-26. DOI: 10.1186/s40537-023-00612-5
[22]Hemanth, D., et al. (2021). Intrusion detection system using convolutional neural network on UNSW NB15 dataset. Advances in Parallel Computing Technologies and Applications, 40, 1. DOI: 10.3233/APC210001
[23]Husain, A., Salem, A., Jim, C., & Dimitoglou, G. (2019). Development of an efficient network intrusion detection model using extreme gradient boosting (XGBoost) on the UNSW-NB15 dataset. In 2019 IEEE International Symposium on Signal Processing and Information Technology (ISSPIT), 1-7 . IEEE. DOI: 10.1109/ISSPIT47144.2019.9001844
[24]Alabrah, A. (2022). A novel study: GAN-based minority class balancing and machine-learning-based network intruder detection using chi-square feature selection. Applied Sciences, 12(22), 11662. DOI: 10.3390/app122211662
[25]Abd, S. N., Alsajri, M., & Ibraheem, H. R. (2020). Rao-SVM machine learning algorithm for intrusion detection system. Iraqi Journal for Computer Science and Mathematics, 1(1), 23-27. DOI: 10.52866/ijcsm.2020.01.01.003
[26]University of New South Wales. (2015). UNSW-NB15 dataset. DOI: 10.4225/35/55e4d5bfee1e5 
[27]Ahmad, M., Riaz, Q., Zeeshan, M., Tahir, H., Haider, S. A., & Khan, M. S. (2021). Intrusion detection in internet of things using supervised machine learning based on application and transport layer features using UNSW-NB15 dataset. EURASIP Journal on Wireless Communications and Networking, 2021(1), 1-23. DOI: 10.1186/s13638-021-01893-8
[28]Alshaher, H. (2021). Studying the effects of feature scaling in machine learning PhD Dissertation, North Carolina Agricultural and Technical State University. Available at ProQuest: Link
[29]Al-Sarem, M., Saeed, F., Alkhammash, E. H., & Alghamdi, N. S. (2021). An aggregated mutual information based feature selection with machine learning methods for enhancing IoT botnet attack detection. Sensors, 22(1), 185. DOI: 10.3390/s22010185
[30]Chen, R.-C., Dewi, C., Huang, S.-W., & Caraka, R. E. (2020). Selecting critical features for data classification based on machine learning methods. Journal of Big Data, 7(1), 52. DOI: 10.1186/s40537-020-00327-4
[31]Hasan, B. M. S., & Abdulazeez, A. M. (2021). A review of principal component analysis algorithm for dimensionality reduction. Journal of Soft Computing and Data Mining, 2(1), 20-30. DOI: 10.30880/jscdm.2021.02.01.003
[32]Fan, W., Liu, K., Liu, H., Wang, P., Ge, Y., & Fu, Y. (2020). AutoFS: Automated feature selection via diversity-aware interactive reinforcement learning. In 2020 IEEE International Conference on Data Mining (ICDM), 1008-1013. IEEE. DOI: 10.1109/ICDM50108.2020.00123
[33]Krishnaveni, S., Sivamohan, S., Sridhar, S. and Prabhakaran, S., 2022. Network intrusion detection based on ensemble classification and feature selection method for cloud computing. Concurrency and Computation: Practice and Experience, 34(11), p.e6838. https://doi.org/10.1002/cpe.6838 
[34]Aleesa, A., Younis, M., Mohammed, A. A., & Sahar, N. (2021). Deep-intrusion detection system with enhanced UNSW-NB15 dataset based on deep learning techniques. Journal of Engineering Science and Technology, 16(1), 711-727. Available at: Link
[35]Kasongo, S. M., & Sun, Y. (2019). A deep learning method with filter based feature engineering for wireless intrusion detection system. IEEE Access, 7, 38597-38607. DOI: 10.1109/ACCESS.2019.2905633
[36]Ahmed, A., El-Aasser, M., Ghantous, M. (2025). Analyzing the Effect of Feature Selection Algorithms on ML Classifiers. In: Abdelgawad, A., Jamil, A., Hameed, A.A. (eds) Intelligent Systems, Blockchain, and Communication Technologies. ISBCom 2024. Lecture Notes in Networks and Systems, vol 1268. Springer, Cham. https://doi.org/10.1007/978-3-031-82377-0_35 
[37]Turukmane, Anil V., and Ramkumar Devendiran (2024). "M-MultiSVM: An efficient feature selection assisted network intrusion detection system using machine learning." Computers & Security 137: 103587. https://doi.org/10.1016/j.cose.2023.103587
[38]More, S., Idrissi, M., Mahmoud, H., & Asyhari, A. T. (2024). Enhanced Intrusion Detection Systems Performance with UNSW-NB15 Data Analysis. Algorithms, 17(2), 64. https://doi.org/10.3390/a17020064 
[39]Jouhari, M., Benaddi, H., & Ibrahimi, K. (2024, July). Efficient Intrusion Detection: Combining X 2 Feature Selection with CNN-BiLSTM on the UNSW-NB15 Dataset. In 2024 11th International Conference on Wireless Networks and Mobile Communications (WINCOM) (pp. 1-6). IEEE. https://doi.org/10.1109/WINCOM62286.2024.10658099 
[40]Louppe, G. (2014). Understanding Random Forests: From Theory to Practice. arXiv:1407.7502 arXiv:1407.7502. 
[41]Farrukh, Yasir Ali, Syed Wali, Irfan Khan, and Nathaniel D. Bastian (2025). Xg-nid: Dual-modality network intrusion detection using a heterogeneous graph neural network and large language model. Expert Systems with Applications, 287:128089. https://doi.org/10.1016/j.eswa.2025.128089 
[42]Eljialy EM, Uddin MY, Ahmad S. (2024). Novel Framework for an Intrusion Detection System Using Multiple Feature Selection Methods Based on Deep Learning. Tsinghua Science and Technology, 29(4):948–958. https://doi.org/10.26599/TST.2023.9010032.