Feature Relevance is Contextual: A Class-Specific and Cross-Dataset Analysis for Network Intrusion Detection
Resumo
Current Network Intrusion Detection Systems (NIDS) often rely on global feature-selection strategies, assuming feature relevance remains stable across attack classes and environments. This paper challenges this assumption, demonstrating that feature importance is contextual, sparse, and class-dependent. A class-wise and cross-dataset analysis investigates feature specialization, semantic consistency, and relevance stability. Results reveal strong intraand inter-dataset variability, where class-specific relevance discrepancies can exceed 40x for the same attribute, demonstrating that globally dominant attributes fail to preserve discriminative consistency. Preserving class-specific discriminative structures is therefore essential for next-generation NIDS.
Referências
Awad, M., Fraihat, S., Salameh, K., and Redhaei, A. A. (2022). Examining the suitability of NetFlow features in detecting IoT network intrusions. Sensors, 22(16):6164.
Bendale, A. and Boult, T. E. (2016). Towards open set deep networks. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pages 1563–1572.
Bouguelia, M.-R., Belaı̈d, Y., and Belaı̈d, A. (2016). An adaptive streaming active learning strategy based on instance weighting. Pattern Recognition Letters, 70:38–44.
Disha, R. A. and Waheed, S. (2022). Performance analysis of machine learning models for intrusion detection system using gini impurity-based weighted random forest (GIWRF) feature selection technique. Cybersecurity, 5(1).
Göcs, L. and Johanyák, Z. C. (2024). Identifying relevant features of CSE-CIC-IDS2018 dataset for the development of an intrusion detection system. Intelligent Data Analysis, 28(6):1527–1553.
Han, M., Li, C., Meng, F., He, F., and Zhang, R. (2024). An adaptive active learning method for multiclass imbalanced data streams with concept drift. Applied Sciences, 14(16):7176.
Kasongo, S. M. and Sun, Y. (2020). Performance analysis of intrusion detection systems using a feature selection method on the UNSW-NB15 dataset. Journal of Big Data, 7(1).
Kurniabudi, Stiawan, D., Darmawijoyo, Idris, M. Y. B., Bamhdi, A. M., and Budiarto, R. (2020). CICIDS-2017 dataset feature analysis with information gain for anomaly detection. IEEE Access, 8:132911–132921.
Li, C., Zhang, E., Geng, C., and Chen, S. (2024). All beings are equal in open set recognition. Proceedings of the AAAI Conference on Artificial Intelligence, 38(12):13446–13454.
Liu, W., Zhang, H., Ding, Z., Liu, Q., and Zhu, C. (2021). A comprehensive active learning method for multiclass imbalanced data streams with concept drift. Knowledge-Based Systems, 215:106778.
Liu, W., Zhu, C., Ding, Z., Zhang, H., and Liu, Q. (2023). Multiclass imbalanced and concept drift network traffic classification framework based on online active learning. Engineering Applications of Artificial Intelligence, 117:105607.
Meemongkolkiat, N. and Suttichaya, V. (2021). Analysis on network traffic features for designing machine learning based IDS. Journal of Physics: Conference Series, 1993(1):012029.
Mhawi, D. N., Aldallal, A., and Hassan, S. (2022). Advanced feature-selection-based hybrid ensemble learning algorithms for network intrusion detection systems. Symmetry, 14(7):1461.
Moualla, S., Khorzom, K., and Jafar, A. (2021). Improving the performance of machine learning-based network intrusion detection systems on the UNSW-NB15 dataset. Computational Intelligence and Neuroscience, 2021:1–13.
Ning, K.-P., Ke, H.-J., Yao, J.-Y., Liu, Y.-Y., Tian, Y.-H., and Yuan, L. (2026). Evidence conflict sampling for open-set active learning. International Journal of Computer Vision, 134(1).
Niño-Adan, I., Manjarres, D., Landa-Torres, I., and Portillo, E. (2021). Feature weighting methods: A review. Expert Systems with Applications, 184:115424.
Sarhan, M., Layeghy, S., Moustafa, N., and Portmann, M. (2021a). NetFlow datasets for machine learning-based network intrusion detection systems. In Big Data Technologies and Applications, pages 117–135. Springer International Publishing.
Sarhan, M., Layeghy, S., and Portmann, M. (2021b). Towards a standard feature set for network intrusion detection system datasets. Mobile Networks and Applications, 27(1):357–370.
Sarhan, M., Layeghy, S., and Portmann, M. (2022). Evaluating standard feature sets towards increased generalisability and explainability of ML-based network intrusion detection. Big Data Research, 30:100359.
Scheirer, W. J., de Rezende Rocha, A., Sapkota, A., and Boult, T. E. (2013). Toward open set recognition. IEEE Transactions on Pattern Analysis and Machine Intelligence, 35(7):1757–1772.
Schmidt, S., Schenk, L., Schwinn, L., and Günnemann, S. (2025). Joint out-of-distribution filtering and data discovery active learning. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pages 25677–25687.
Shu, J., Yuan, X., Meng, D., and Xu, Z. (2022). CMW-Net: Learning a class-aware sample weighting mapping for robust deep learning. IEEE Transactions on Pattern Analysis and Machine Intelligence, 45:11521–11539.
Tripathi, G., Singh, V. K., Sharma, V., and Vinodbhai, M. V. (2024). Weighted feature selection for machine learning based accurate intrusion detection in communication networks. IEEE Access, 12:20973–20982.
Yin, T., Liu, N., Sun, H., and Xia, S. (2025). Boosting active learning via re-aligned feature space. Knowledge-Based Systems, 311:113085.
Zhang, Y., Zhang, H., and Zhang, B. (2022). An effective ensemble automatic feature selection method for network intrusion detection. Information, 13(7):314.
Zhao, R., Mu, Y., Zou, L., and Wen, X. (2022). A hybrid intrusion detection system based on feature selection and weighted stacking classifier. IEEE Access, 10:71414–71426.
