IJWMT Vol. 16, No. 5, 8 Oct. 2026
Cover page and Table of Contents: PDF (size: 1271KB)
PDF (1271KB), PP.158-173
Views: 0 Downloads: 0
Reinforcement Learning, Proximal Policy Optimization, Adaptive Intrusion Detection System, Multi-Class Network Security, Resource-Aware Optimization, Cybersecurity Analytics, Dynamic Network Environments, CIC-IDS2017 Dataset
The growing sophistication of contemporary network infrastructures has increased the pressure on the smart and dynamic intrusion detection systems that can react to the dynamic cyber threats. The machine learning (ML) and deep learning (DL) methods have high classification rates, but they work with fixed decision boundaries which reduces their ability to adapt to dynamic traffic distributions and emerging attack patterns. In order to overcome these issues, the resource-aware Proximal Policy Optimization (PPO)-based adaptive multi-class intrusion detection system (IDS) is suggested in this study. The system characterizes intrusion detection as a sequential decision-making and incorporates computational resource measures into the reinforcement learning (RL) rewarding framework, which allows optimizing detection performance and operational efficiency at the same time. In the ensemble comparison, PPO-Model achieved the highest accuracy (99.4%), recall (98.6%), and Macro AUC (0.998), while reducing CPU utilization by 25.8% and memory consumption by 27.1% compared with the Stacking model. These results demonstrate that the proposed approach can improve detection performance while reducing computational resource requirements. The results suggest that next-generation intrusion detection in the dynamic network environment can be achieved with a scalable and robust solution based on the combination of RL and resource-aware optimization.
Kiranjeet Kaur, Jaspreet Singh, "Resource-Aware Proximal Policy Optimization for Adaptive Intrusion Detection in Dynamic Networks", International Journal of Wireless and Microwave Technologies(IJWMT), Vol.16, No.5, pp. 158-173, 2026. DOI:10.5815/ijwmt.2026.05.10
[1]D. E. Denning, “An intrusion-detection model,” IEEE Transactions on Software Engineering, vol. 13, no. 2, pp. 222–232, 1987.
[2]Tavallaee, M., Bagheri, E., Lu, W., & Ghorbani, A. A. (2009, July). A detailed analysis of the KDD CUP 99 data set. In 2009 IEEE symposium on computational intelligence for security and defense applications (pp. 1-6).
[3]Sharafaldin, I., Lashkari, A. H., & Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. ICISSp, 1(2018), 108-116.
[4]M. Ring et al., “A survey of network-based intrusion detection data sets,” Computers & Security, vol. 86, 2019.
[5]A. Javaid et al., “A deep learning approach for network intrusion detection system,” in Proc. EAI Bio-inspired ICT, 2016.
[6]J. Kim et al., “Long short-term memory recurrent neural network classifier for intrusion detection,” in Proc. PlatCon, 2016.
[7]S.-G. Choi, S.-B. Cho, "Adaptive Database Intrusion Detection Using Evolutionary Reinforcement Learning," in Proc. Int. Joint Conf. SOCO'17-CISIS'17-ICEUTE'17 (Advances in Intelligent Systems and Computing), León, Spain, 2017, pp. 547-556, doi: 10.1007/978-3-319-67180-2_53.
[8]R. R. dos Santos, E. K. Viegas, A. O. Santin, and V. V. Cogo, “A long-lasting reinforcement learning intrusion detection model,” in Proc. 34th Int. Conf. Advanced Information Networking and Applications (AINA), Caserta, Italy, 2020, pp. 1437–1448, doi: 10.1007/978-3-030-44041-1_121.
[9]J. Schulman, F. Wolski, P. Dhariwal, A. Radford, and O. Klimov, “Proximal policy optimization algorithms,” arXiv preprint arXiv:1707.06347, 2017.
[10]V. Mnih et al., “Human-level control through deep reinforcement learning,” Nature, vol. 518, 2015.
[11]L. Xiao et al., “Cloud-based malware detection game for mobile devices with offloading,” IEEE Transactions on Mobile Computing, vol. 16, no. 10, pp. 2742–2750, 2017.
[12]M. H. Bhuyan et al., “Network anomaly detection: Methods, systems and tools,” IEEE Communications Surveys & Tutorials, vol. 16, 2014.
[13]Y. Bengio, A. Courville, and P. Vincent, “Representation learning: A review and new perspectives,” IEEE Transactions on Pattern Analysis and Machine Intelligence, vol. 35, no. 8, pp. 1798–1828, 2013.
[14]R. R. dos Santos, E. K. Viegas, A. O. Santin, and V. V. Cogo, “Reinforcement learning for intrusion detection: More model longness and fewer updates,” IEEE Trans. Netw. Service Manag., vol. 20, no. 2, pp. 2040–2055, Jun. 2023, doi: 10.1109/TNSM.2022.3207094.
[15]M. Al-Hawawreh, N. Moustafa, and E. Sitnikova, “Identification of malicious activities in industrial internet of things based on deep learning models,” Journal of Information Security and Applications, vol. 41, pp. 1–11, 2018.
[16]S. M. Kasongo and Y. Sun, “A deep learning method with filter-based feature engineering for wireless intrusion detection system,” IEEE Access, vol. 7, pp. 38597–38607, 2019.
[17]A. Alrawashdeh and C. Purdy, “Toward an online anomaly intrusion detection system based on deep learning,” in Proc. IEEE ICMLA, 2016, pp. 195–200.
[18]H. Hindy et al., “A taxonomy of network threats and the effect of current datasets on intrusion detection systems,” IEEE Access, vol. 8, pp. 104650–104675, 2020.
[19]M. H. Bhuyan, D. K. Bhattacharyya, and J. K. Kalita, “Network anomaly detection: Methods, systems and tools,” IEEE Communications Surveys & Tutorials, vol. 16, no. 1, pp. 303–336, 2014.
[20]R. Sutton and A. Barto, Reinforcement Learning: An Introduction, 2nd ed. MIT Press, 2018.
[21]K. Arulkumaran, M. Deisenroth, M. Brundage, and A. Bharath, “Deep reinforcement learning: A brief survey,” IEEE Signal Processing Magazine, vol. 34, no. 6, pp. 26–38, 2017.
[22]Y. Li, “Deep reinforcement learning: An overview,” arXiv preprint arXiv:1701.07274, 2017.
[23]S. Garcia et al., “An empirical comparison of botnet detection methods,” Computers & Security, vol. 45, pp. 100–123, 2014.
[24]Z. Li, C. Huang, S. Deng, W. Qiu, and X. Gao, “A soft actor-critic reinforcement learning algorithm for network intrusion detection,” Comput. Secur., vol. 135, Art. no. 103502, Dec. 2023, doi: 10.1016/j.cose.2023. 103502.
[25]M. A. Merzouk, C. Neal, J. Delas, et al., “Adversarial robustness of deep reinforcement learning-based intrusion detection,” Int. J. Inf. Secur., vol. 23, pp. 3625–3651, Dec. 2024, doi: 10.1007/s10207-024-00903-2
[26]Y.-D. Lin, H.-X. Huang, D. Sudyana, and Y.-C. Lai, “AI for AI-based intrusion detection as a service: Reinforcement learning to configure models, tasks, and capacities,” J. Netw. Comput. Appl., vol. 229, Art. no. 103936, 2024, doi: 10.1016/j.jnca.2024.103936.
[27]S. Jamshidi, A. Nikanjam, K. W. Nafi, F. Khomh, and R. Rasta, “Application of deep reinforcement learning for intrusion detection in Internet of Things: A systematic review,” Internet Things, vol. 31, Art. no. 101531, 2025, doi: 10.1016/j.iot.2025.101531
[28]Z. Wang, T. Pan, Q. Zhou, and J. Wang, “Efficient exploration in resource-restricted reinforcement learning,” Proceedings of the AAAI Conference on Artificial Intelligence, vol. 37, no. 8, pp. 10279–10287, 2023, doi: 10.1609/aaai.v37i8.26224.
[29]M. A. Hossain, “Deep Q-learning intrusion detection system (DQ-IDS): A novel reinforcement learning approach for adaptive and self-learning cybersecurity,” ICT Express, vol. 11, no. 5, pp. 875–880, Oct. 2025, doi: 10.1016/j.icte.2025.05.007.
[30]E. Iturbe, A. Rego, O. Llorente-Vazquez, E. Rios, C. Dalamagkas, D. Merkouris, and N. Toledo, “Reinforcement Learning in action: Powering intelligent intrusion responses to advanced cyber threats in realistic scenarios,” Expert Syst. Appl., vol. 296, Art. no. 129168, Jan. 2026, doi: 10.1016/j.eswa.2025.129168.
[31]C. Cortes and V. Vapnik, “Support-vector networks,” Machine Learning, vol. 20, no. 3, pp. 273–297, 1995, doi: 10.1007/BF00994018.
[32]L. Breiman, “Random forests,” Machine Learning, vol. 45, no. 1, pp. 5–32, 2001, doi: 10.1023/A:1010933404324.
[33]T. Chen and C. Guestrin, “XGBoost: A scalable tree boosting system,” in Proc. 22nd ACM SIGKDD Int. Conf. Knowledge Discovery and Data Mining (KDD), 2016, pp. 785–794, doi: 10.1145/2939672.2939785.
[34]D. E. Rumelhart, G. E. Hinton, and R. J. Williams, “Learning representations by back-propagating errors,” Nature, vol. 323, no. 6088, pp. 533–536, 1986, doi: 10.1038/323533a0.
[35]A. Graves and J. Schmidhuber, “Framewise phoneme classification with bidirectional LSTM and other neural network architectures,” Neural Networks, vol. 18, no. 5–6, pp. 602–610, 2005, doi: 10.1016/j.neunet.2005.06.042.