<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">32617</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2023.032617</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>A Fused Machine Learning Approach for Intrusion Detection System</article-title>
<alt-title alt-title-type="left-running-head">A Fused Machine Learning Approach for Intrusion Detection System</alt-title>
<alt-title alt-title-type="right-running-head">A Fused Machine Learning Approach for Intrusion Detection System</alt-title>
</title-group>
<contrib-group content-type="authors">
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Farooq</surname><given-names>Muhammad Sajid</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Abbas</surname><given-names>Sagheer</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Atta-ur-Rahman</surname><given-names> </given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Sultan</surname><given-names>Kiran</given-names></name><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<contrib id="author-5" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Khan</surname><given-names>Muhammad Adnan</given-names></name><xref ref-type="aff" rid="aff-4">4</xref><email>adnan@gachon.ac.kr</email></contrib>
<contrib id="author-6" contrib-type="author">
<name name-style="western"><surname>Mosavi</surname><given-names>Amir</given-names></name><xref ref-type="aff" rid="aff-5">5</xref>
<xref ref-type="aff" rid="aff-6">6</xref>
<xref ref-type="aff" rid="aff-7">7</xref></contrib>
<aff id="aff-1"><label>1</label><institution>School of Computer Science, National College of Business Administration and Economics</institution>, <addr-line>Lahore, 54000</addr-line>, <country>Pakistan</country></aff>
<aff id="aff-2"><label>2</label><institution>Department of Computer Science, College of Computer Science and Information Technology, Imam Abdulrahman Bin Faisal University</institution>, <addr-line>P.O. Box 1982, Dammam 31441</addr-line>, <country>Saudi Arabia</country></aff>
<aff id="aff-3"><label>3</label><institution>Department of CIT, The Applied College, King Abdulaziz University</institution>, <addr-line>Jeddah, 21589</addr-line>, <country>Saudi Arabia</country></aff>
<aff id="aff-4"><label>4</label><institution>Department of Software, Gachon University</institution>, <addr-line>Seongnam, 13120</addr-line>, <country>Korea</country></aff>
<aff id="aff-5"><label>5</label><institution>John von Neumann Faculty of Informatics, Obuda University</institution>, <addr-line>Budapest, 1034</addr-line>, <country>Hungary</country></aff>
<aff id="aff-6"><label>6</label><institution>Institute of Information Engineering, Automation and Mathematics, Slovak University of Technology in Bratislava</institution>, <addr-line>Bratislava, 81107</addr-line>, <country>Slovakia</country></aff>
<aff id="aff-7"><label>7</label><institution>Faculty of Civil Engineering, TU-Dresden</institution>, <addr-line>Dresden, 01062</addr-line>, <country>Germany</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Muhammad Adnan Khan. Email: <email>adnan@gachon.ac.kr</email></corresp>
</author-notes>
<pub-date pub-type="epub" date-type="pub" iso-8601-date="2022-10-28"><day>28</day>
<month>10</month>
<year>2022</year></pub-date>
<volume>74</volume>
<issue>2</issue>
<fpage>2607</fpage>
<lpage>2623</lpage>
<history>
<date date-type="received"><day>23</day><month>5</month><year>2022</year></date>
<date date-type="accepted"><day>24</day><month>6</month><year>2022</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2023 Farooq et al.</copyright-statement>
<copyright-year>2023</copyright-year>
<copyright-holder>Farooq et al.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_32617.pdf"></self-uri>
<abstract>
<p>The rapid growth in data generation and increased use of computer network devices has amplified the infrastructures of internet. The interconnectivity of networks has brought various complexities in maintaining network availability, consistency, and discretion. Machine learning based intrusion detection systems have become essential to monitor network traffic for malicious and illicit activities. An intrusion detection system controls the flow of network traffic with the help of computer systems. Various deep learning algorithms in intrusion detection systems have played a prominent role in identifying and analyzing intrusions in network traffic. For this purpose, when the network traffic encounters known or unknown intrusions in the network, a machine-learning framework is needed to identify and/or verify network intrusion. The Intrusion detection scheme empowered with a fused machine learning technique (IDS-FMLT) is proposed to detect intrusion in a heterogeneous network that consists of different source networks and to protect the network from malicious attacks. The proposed IDS-FMLT system model obtained 95.18&#x0025; validation accuracy and a 4.82&#x0025; miss rate in intrusion detection.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Fused machine learning</kwd>
<kwd>heterogeneous network</kwd>
<kwd>intrusion detection</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1"><label>1</label><title>Introduction</title>
<p>During the last few years, rapidly increasing network data transfer has created significant complications in network data management, which may lead to network intrusion in the future [<xref ref-type="bibr" rid="ref-1">1</xref>]. Anti-virus software, Intrusion detection methods and firewalls are main cyber security techniques and such techniques are responsible to protect the net-work from external and internal attacks [<xref ref-type="bibr" rid="ref-2">2</xref>]. Various intrusion detection techniques are being used, but these methods face problems due to the high-speed of the networks and unidentified attacks. As a result, an effective network attack detection mechanism is required. Different intrusion detection systems based on machine learning methodologies have recently become popular [<xref ref-type="bibr" rid="ref-3">3</xref>]. Machine learning has an advanced branch called deep learning that consisted of multiple layers that indicate the learning process [<xref ref-type="bibr" rid="ref-4">4</xref>]. On the other hand deep learning techniques have been considered by some researchers as a way to develop more effective and efficient intrusion detection systems than the present machine learning methodologies [<xref ref-type="bibr" rid="ref-5">5</xref>]. The authors of [<xref ref-type="bibr" rid="ref-6">6</xref>] developed a deep learning-based solution for detecting network attacks and monitoring flow computations. A real-time detection method based on traffic calculations and common patterns, as well as a classification method based on Deep belief networks and support vector machines (DBN-SVM). The DBN-SVM approach was applied to improve classification accuracy, and real-time detection was achieved via Sliding window (SW) stream data processing.</p>
<p>A system is based on the CICDS2017 open-source dataset was used to verify the suggested method by implementing a series of experiments. The proficiency and real-time competency of the proposed method were greater than those of other typical machine learning algorithms.</p>
<p>In [<xref ref-type="bibr" rid="ref-7">7</xref>], the authors introduced an intrusion detection scheme that consists of Apache Spark to detect malicious traffic. A stack auto encoder network was applied to extract features, and a support vector machine was used as a classifier. Huang&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-8">8</xref>] addressed intrusion detection system problems by proposing a novel model based on an extreme learning machine. The extreme learning machine consisted of a single hidden layer based on a feed forward neural network that used random input weights, a bias for the hidden layer and output weights. Another study [<xref ref-type="bibr" rid="ref-9">9</xref>] was based on a fast learning network that consisted of a single-layer feed-forward neural network and a multilayer feed-forward neural network.</p>
<p>Ali&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-10">10</xref>] presented an anomaly detection system that combined a quick learning network with particle swarm optimization. The findings revealed that the proposed mod-el outperformed other algorithms in terms of accuracy.</p>
<p>The content of this article is organized in the following manner. The second section provides a quick overview of the relevant studies. The suggested detection framework is detailed in Section 3. The experimental data and analysis are presented in Section 4 and summarize the study with limitations and future work.</p>
</sec>
<sec id="s2"><label>2</label><title>Related Work</title>
<p>The excessive use of the internet and other communication technologies has become a great challenge for the network and it creates the need to secure from malicious traffic [<xref ref-type="bibr" rid="ref-11">11</xref>]. Various intrusion detection systems have been offered to enhance malicious traffic detection in heterogeneous networks. An efficient technique is presented in [<xref ref-type="bibr" rid="ref-12">12</xref>] based on a hybrid network, namely, RULA-intrusion detection system (RULA-IDS), for intrusion detection. RULA-IDS performed intrusion detection at a large scale of statistical data in the network traffic. The global attention mechanism layer, completely linked layer, feature extraction layer, and Support vector machine (SVM) classification layer are normally four layers. The temporal and spatial characteristics in network traffic attributes were extracted using the feature extraction layer, so the global attention layer was used to preserve essential information from the components. Finally, an SVM classifier was applied for output for the RULA-IDS system.</p>
<p>Similarly, another study [<xref ref-type="bibr" rid="ref-13">13</xref>] presented a novel system for intrusion detection based on weighted class classification. The intrusion detection scheme consisted of two parts. In the first part, the supervised Machine learning (ML) algorithm worked on the past information in the network. The ML algorithm created a classifier that segregated the investigated attacks, and these decisions were stored in a database. Second, a specifically designed iterative algorithm was used to increase the accuracy of detectable attacks and enhance class&#x2019; weights. This system improved the performance and maximized the number of correctly discernible types. The University of new south wales network (UNSW) dataset was utilized to analyse the system&#x2019;s performance.</p>
<p>In [<xref ref-type="bibr" rid="ref-14">14</xref>], the researchers presented a model based on the Stacked contracted auto encoder (SCAE) approach and SVM classification algorithm. The deep learning approach was applied to extract features automatically and evaluate the performance. The SCAE method was used for both low-dimensional features and high-dimensional features of the network traffic. The SVM and SCAE techniques combined shallow and deep learning approaches and helped decrease the systematic overhead significantly. The proposed model used the NSL-KDD and KDD Cup 99 datasets, and the analysis of the experiments demonstrated that the proposed model obtained 95&#x0025; accuracy. The authors [<xref ref-type="bibr" rid="ref-15">15</xref>] explored data set characteristics and evaluated cyber security data set characteristics for the detection of anomalies in the network.</p>
<p>The detailed analysis of numerous detection techniques based on machine learning technologies was conducted to examine or defend network traffic from malicious assaults [<xref ref-type="bibr" rid="ref-16">16</xref>]. In order to reduce computational complexity during detection performance, a novel multistage optimized machine learning-based network intrusion detection system was introduced. The effect of the oversampling strategy on the training sample size of the proposed model was investigated in order to find the minimum suitable training sample size. Moreover, the temporal complexity and detection effectiveness of two feature selection algorithms based on information gain and correlation were examined. Moreover, various machine learning hyper parameter optimization methods were examined to increase the performance of the proposed system.</p>
<p>Deep and shallow learning strategies were both used in the particular learning approach for intrusion detection systems [<xref ref-type="bibr" rid="ref-17">17</xref>]. However, these approaches encountered various problems in recognizing complicated intrusion patterns. In a lack no of samples, the single deep learning model was not useful for detecting intrusion attacks. In order to enhance the act of a machine learning-based intrusion detection system, the researchers proposed a Big data-based hierarchical deep learning system (BDHDLS). The suggested model used content and behaviour based features to recognize information in the payload and network traffic characteristics. Each model in the BDHDLS focused on learning a characteristic data circulation in one cluster. This approach improved the detection ratio of intrusion attacks in the network. In another study [<xref ref-type="bibr" rid="ref-18">18</xref>] introduced two stages hierarchical hybrid approach for intrusion detection in IoT scenarios. In the first stage, a multimodal deep auto encoder is applied for the anomaly detection, and in the second stage soft-output classifiers are used for attack classification.</p>
<p>With extensive efforts to enhance the accuracy of an intrusion detection system, the authors in [<xref ref-type="bibr" rid="ref-19">19</xref>] described that the rapid increase in data and excess usage of the internet created a need to segregate network traffic in the form of routine flow and anomalies. Therefore, intrusion detection systems with a machine learning approach could play a dynamic role in protecting national security and the economy. Moreover, the authors presented a Convolutional neural network and long short-term memory network (CNN-LSTM) model for intrusion detection. The study normalized spatial feature learning through UTF-8 character encoding and extracted the features from real-time Hypertext transfer protocol (HTTP) traffic without compression, encryption, and entropy calculations. Fixed real-time data and two CSIC-2010 and CICIDS2017 public datasets were used to train and validate the model. During the training phase, the network traffic was analyzed and labelled as true or false. As a result, artificially intelligent intrusion detection systems separated unknown patterns and obfuscated attacks from network traffic.</p>
<p>The system is calculated the intrusion probability through continuous training that lead to accurate analysis of malicious traffic. Since thresh holding and deviation play an essential role in intrusion detection, the authors in [<xref ref-type="bibr" rid="ref-20">20</xref>] introduced a novel distance function that could detect similarity in two patterns. The dimension of features is a significant issue in machine learning. A feature transformation technique was used to reduce the number of features through the Gaussian distance function in the proposed model. The new computation expression was applied to determine the threshold and deviation in Gaussian space. The NSL-KDD and KDD datasets were used for training and validation purposes. Since K-fold cross-validation is used in machine learning models to collect attractive performance parameters such as accuracy, recall, and precision, the performance evaluation was based on these metrics in the aforementioned research; which demonstrated that the feature transformation technique was better. Feature engineering hitches and low accuracy in intrusion detection systems are the leading causes of obtaining the unwanted results. To solve these issues, the study in [<xref ref-type="bibr" rid="ref-21">21</xref>], the authors proposed a model to detect network traffic anomalies and to discover and fix the issues with feature engineering and low intrusion detection accuracy. Bidirectional long short-term memory (BLSTM) and an attention mechanism were combined in the suggested framework. The major goal of the attention method was to manage packet vector network flow. In order to capture the characteristics of network traffic data, many convolutional layers were employed, and Softmax was used for network traffic categorization. The proposed method did not use any feature skills or important features to train automatically. By defining network traffic behaviour the abovementioned system efficiently increased the performance of intrusion detection.</p>
<p>In another study [<xref ref-type="bibr" rid="ref-22">22</xref>], the researchers suggested a novel model based on a Whale optimization algorithm (WOA) and generic variables for a wireless network&#x2019;s intrusion detection system. To avoid being caught in the local optimum, the mutation operator was utilized, and the crossover operator was used to assist whales increase their search space. First, the model chose the beneficial features that aided in the detection of invasions. Then, to recognize distinct forms of invasions, a support vector machine was deployed. The datasets from Linux and the Canadian Institute of Cyber Security were used to measure the model&#x2019;s performance. When compared to the traditional whale optimization technique and the current evolutionary algorithm, the experimental findings demonstrated that the system had a higher attack detection rate. In [<xref ref-type="bibr" rid="ref-23">23</xref>], researchers concentrated on intrusion detection in network traffic with flow-based data by using two different deep learning techniques, unsupervised deep learning and semi-supervised learning. Variation auto encoder and auto encoder approaches were applied to classify unidentified network traffic attacks using flow features. The model was tested on standard traffic and anomaly data, and the variation auto encoder performance was found to be better than the auto encoder. The literature review found that intrusion detection methods based on artificial intelligence approaches have attracted the attention of researchers. Nevertheless, all existing models need standard/normal traffic patterns to compare with anomalies to detect anomalous traffic. In [<xref ref-type="bibr" rid="ref-24">24</xref>], a Deep extreme learning machine (DELM), neural network, decision tree, and support vector machine were applied to detect malicious traffic in an intelligent home network. The DELM model achieved 93.91&#x0025; accuracy for the NSL-KDD dataset and 94.6&#x0025; accuracy for the CUP-99 dataset. For intrusion detection in the networks, the proposed IDS-FMLT in our study focuses on an intrusion finding structure in a diverse network enabled with a joined machine learning system model. The IDS-FMLT model uses fused machine learning approaches to protect the networks from malicious attacks. Various dataset such as KDD dataset [<xref ref-type="bibr" rid="ref-25">25</xref>], CUP-99 dataset [<xref ref-type="bibr" rid="ref-26">26</xref>], and NetML-2020 dataset [<xref ref-type="bibr" rid="ref-27">27</xref>] and NSL-KDD dataset [<xref ref-type="bibr" rid="ref-28">28</xref>] were used in RNN [<xref ref-type="bibr" rid="ref-29">29</xref>], adaptive voting algorithm [<xref ref-type="bibr" rid="ref-30">30</xref>], ANN [<xref ref-type="bibr" rid="ref-31">31</xref>], DELM [<xref ref-type="bibr" rid="ref-32">32</xref>], SVM [<xref ref-type="bibr" rid="ref-33">33</xref>], SOMNN [<xref ref-type="bibr" rid="ref-34">34</xref>], ANN [<xref ref-type="bibr" rid="ref-35">35</xref>], NA&#x00CF;VE BAYES&#x2009;&#x002B;&#x2009;RP [<xref ref-type="bibr" rid="ref-36">36</xref>] and GANS [<xref ref-type="bibr" rid="ref-37">37</xref>].</p>
<p><xref ref-type="table" rid="table-1">Tab. 1</xref> shows that most of the researchers used the different state-of-the-art approaches like RNN, adaptive voting algorithm, ANN, DELM, SVM, SOMNN and GANs for the detection of intrusion in networks. It observe that the mostly researchers used single machine learning technique without pre-processing in their proposed intrusion detection models.</p>
<table-wrap id="table-1"><label>Table 1</label><caption><title>Summary of state-of-the-art literature survey</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Authors</th>
<th align="left">Approaches</th>
<th align="left">Data splitting during training and validation</th>
<th align="left">Accuracy (&#x0025;)</th>
<th align="left">Limitations</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Farhan [<xref ref-type="bibr" rid="ref-29">29</xref>]</td>
<td align="left">RNN</td>
<td align="left">Training (60&#x0025;)</td>
<td align="left">93.8</td>
<td align="left">No pre-processing</td>
</tr>
<tr>
<td/>
<td/>
<td align="left">Validation (40&#x0025;)</td>
<td/>
<td/>
</tr>
<tr>
<td align="left">Chen<break/>et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-30">30</xref>]</td>
<td align="left">Adaptive voting algorithm</td>
<td align="left">Training (85&#x0025;)</td>
<td align="left">84.5</td>
<td align="left">No pre-processing and low accuracy</td>
</tr>
<tr>
<td/>
<td/>
<td align="left">Validation (15&#x0025;)</td>
<td/>
<td/>
</tr>
<tr>
<td align="left">Khan<break/>et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-31">31</xref>]</td>
<td align="left">ANN</td>
<td align="left">Training (85&#x0025;)</td>
<td align="left" >79.9</td>
<td align="left" >No pre-processing and low accuracy</td>
</tr>
<tr>
<td/>
<td/>
<td align="left">Validation (15&#x0025;)</td>
<td/>
<td/>
</tr>
<tr>
<td align="left">Avallaee<break/>et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-32">32</xref>]</td>
<td align="left">DELM</td>
<td align="left">Training (70&#x0025;)</td>
<td align="left">91.3</td>
<td align="left">Less number of samples are used during training</td>
</tr>
<tr>
<td/>
<td/>
<td align="left">Validation (30&#x0025;)</td>
<td/>
<td/>
</tr>
<tr>
<td align="left">Ibrahim<break/>et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-33">33</xref>]</td>
<td align="left">SVM</td>
<td align="left">Training (85&#x0025;)</td>
<td align="left">92.1</td>
<td align="left">No pre-processing</td>
</tr>
<tr>
<td/>
<td/>
<td align="left">Validation (15&#x0025;)</td>
<td/>
<td/>
</tr>
<tr>
<td align="left">Panda<break/>et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-34">34</xref>]</td>
<td align="left">SOMNN</td>
<td align="left">Training (65&#x0025;)</td>
<td align="left">73.1</td>
<td align="left">No pre-processing, less number of samples are used during training and low accuracy</td>
</tr>
<tr>
<td/>
<td/>
<td align="left">Validation (35&#x0025;)</td>
<td/>
<td/>
</tr>
<tr>
<td align="left" >Alshinina<break/>et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-35">35</xref>]</td>
<td align="left">ANN</td>
<td align="left">Training (45&#x0025;)</td>
<td align="left">79.9</td>
<td align="left">No pre-processing, less number of samples are used during training and low accuracy</td>
</tr>
<tr>
<td/>
<td/>
<td align="left">Validation (55&#x0025;)</td>
<td/>
<td/>
</tr>
<tr>
<td align="left">Rahman<break/>et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-36">36</xref>]</td>
<td align="left">Discriminative Multinomial Na&#x00EF;ve Bayes&#x2009;&#x002B;&#x2009;RP</td>
<td align="left">Training (93&#x0025;)</td>
<td align="left">80.6</td>
<td align="left">Less samples are used in validation and low accuracy</td>
</tr>
<tr>
<td/>
<td/>
<td align="left">Validation (7&#x0025;)</td>
<td/>
<td/>
</tr>
<tr>
<td align="left" >Saleem<break/>et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-37">37</xref>]</td>
<td align="left">GANs</td>
<td align="left">Training (85&#x0025;)</td>
<td align="left">81.1</td>
<td align="left">No pre-processing and low accuracy</td>
</tr>
<tr>
<td/>
<td/>
<td align="left">Validation (15&#x0025;)</td>
<td/>
<td/>
</tr>
</tbody>
</table>
</table-wrap>
<p>The following are the proposed study key contributions:
<list list-type="alpha-lower">
<list-item><label>a.</label><p>The main goals are increase intrusion detection accuracy in heterogeneous networks and reduce the miss rate as well.</p></list-item>
<list-item><label>b.</label><p>A novel approach Fused machine learning is presented for a better approximation of intrusion traffic in heterogeneous networks.</p></list-item>
<list-item><label>c.</label><p>The suggested model also makes it possible to assess network performance in order to increase the accuracy of the existing model.</p></list-item>
<list-item><label>d.</label><p>Finally, the proposed fused machine learning algorithm is assessed on three well-known datasets, KDD, CUP-99, and NetML-2020, which include two classes. Simulation outcomes have revealed that the proposed fused ML method reports better results than other existing techniques, such as Artificial Neural Networks [<xref ref-type="bibr" rid="ref-24">24</xref>], Support Vector Machines [<xref ref-type="bibr" rid="ref-24">24</xref>], Decision Trees [<xref ref-type="bibr" rid="ref-24">24</xref>], and DELM [<xref ref-type="bibr" rid="ref-24">24</xref>].</p></list-item>
</list></p>
</sec>
<sec id="s3"><label>3</label><title>Proposed IDS-FMLT Model</title>
<p>The automated detection process is an essential part of any intrusion detection system in a network. However, it is difficult to determine whether the network traffic is anomalous or legitimate. Therefore, automated detection systems that detect malicious network traffic are primarily based on machine learning methods [<xref ref-type="bibr" rid="ref-16">16</xref>]. The suggested model empowered with fused machine learning methods for intrusion detection in a heterogeneous network is shown in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>.</p>
<fig id="fig-1"><label>Figure 1</label><caption><title>The proposed IDS-FMLT system model</title></caption><graphic mimetype="image" mime-subtype="png" xlink:href="CMC_32617-fig-1.png"/></fig>
<p>The training and validation phases of the proposed model are divided into two parts. First, the data repository layer has been used to gather data from various datasets, such as KDD [<xref ref-type="bibr" rid="ref-25">25</xref>], CUP-99 [<xref ref-type="bibr" rid="ref-26">26</xref>], and NetML-2020 [<xref ref-type="bibr" rid="ref-27">27</xref>]. After storing the data, the pre-processing layer activates and handles repeated and missing values using different techniques, such as the mean, mode, and moving average. All three datasets are used at the application layer to train the model using a real-time sequential deep extreme learning machine approach. A mathematical model of Real-time sequential deep extreme learning machine (RTS-DELM) [&#x0060;&#x0060;&#x0060;&#x0060;&#x0060;&#x0060;&#x0060;&#x0060;&#x0060;&#x0060;] model is given below. A DELM is applied to train a feed-forward neural network with hidden layers. Initially, the DELM consists of back-propagation input burdens that are updated casually. The RTS-DELM method involves multiple feed forward hidden layers which contains k hidden nodes neurons as well as a training dataset of <italic>K</italic> records<inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mi>&#x00A5;</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>W</mml:mi><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>, where <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:msub><mml:mrow><mml:mi>&#x00A5;</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> represent the input features and <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:msub><mml:mi>W</mml:mi><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> represents the output features.</p>
<p>The RTS-DELM operates as follows:<inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:msub><mml:mi>&#x00A5;</mml:mi><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>m</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:msub><mml:mi>W</mml:mi><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mi>N</mml:mi><mml:mrow><mml:mi>l</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. The results of multiple hidden layers are represent in <xref ref-type="disp-formula" rid="eqn-1">Eq. (1)</xref> [<xref ref-type="bibr" rid="ref-24">24</xref>]:
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:msub><mml:mrow><mml:mtext>W</mml:mtext></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mo>&#x2211;</mml:mo></mml:mrow><mml:mrow><mml:mi>z</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0B5;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>a</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mi>a</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mi>K</mml:mi><mml:mo>]</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>The learning variables are <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0B5;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>a</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> and<inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, the output is <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> at weight<inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:mi>z</mml:mi></mml:math></inline-formula>, and <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mo>:</mml:mo></mml:mrow><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mrow><mml:mi mathvariant="normal">N</mml:mi></mml:mrow></mml:math></inline-formula> represents the activation function (AF).</p>
<p>An ideal reconciliation of feed-forward neural network based on the multiple hidden layers with zero error simplifies that distinct intervals <inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:msub><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> occur [<xref ref-type="bibr" rid="ref-24">24</xref>] such that:</p>
<p><xref ref-type="disp-formula" rid="eqn-2">Eq. (2)</xref> [<xref ref-type="bibr" rid="ref-28">28</xref>] shown as:
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B2;</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mtext>Y</mml:mtext></mml:mrow></mml:math></disp-formula>where
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0B5;</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mo>&#x22EE;</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mo>&#x22EE;</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0B5;</mml:mi></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr></mml:mtable><mml:mo>&#x2026;</mml:mo><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0B5;</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mo>&#x22EE;</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mo>&#x22EE;</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0B5;</mml:mi></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr></mml:mtable><mml:mo>]</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>And the output function is representing in <xref ref-type="disp-formula" rid="eqn-4">Eq. (4)</xref> [<xref ref-type="bibr" rid="ref-28">28</xref>]
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:mi>&#x03B2;</mml:mi><mml:mo>=</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2026;</mml:mo><mml:msubsup><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo><mml:mrow><mml:mtext>&#xA0;Y</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mrow><mml:mrow><mml:mtext>w</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2026;</mml:mo><mml:msubsup><mml:mrow><mml:mrow><mml:mtext>w</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msup></mml:math></disp-formula></p>
<p>The outcome weights are solved by hidden layer neurons with the following relationship [<xref ref-type="bibr" rid="ref-32">32</xref>] <xref ref-type="disp-formula" rid="eqn-5">Eq. (5)</xref>:
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:mi>&#x03B2;</mml:mi><mml:mo>=</mml:mo><mml:msup><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup><mml:mi>Y</mml:mi></mml:math></disp-formula></p>
<p><inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:msup><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula> Represents the inverse matrix of <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow></mml:math></inline-formula>. The RTS-DELM [<xref ref-type="bibr" rid="ref-24">24</xref>] shows the computational model applicable for this study.</p>
<p>The deep extreme learning machine model depends on batch learning. An IDS-RTS-DELM is provided a method for dealing with information that arrives in a logical order. When additional information becomes available, the IDS-RTS-DELM model upgrades the batch learning and operates on it.</p>
<p>Let <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0B5;</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>w</mml:mtext></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:msubsup><mml:mrow><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>k</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:msubsup></mml:math></inline-formula> represent the training dataset. <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:msub><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> show the performance matrix of the hidden layer [<xref ref-type="bibr" rid="ref-28">28</xref>]. The output layer weights are as shown in <xref ref-type="disp-formula" rid="eqn-6">Eq. (6)</xref>:
<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:msub><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0B5;</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mo>&#x22EE;</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mo>&#x22EE;</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0B5;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr></mml:mtable><mml:mo>&#x2026;</mml:mo><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0B5;</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mo>&#x22EE;</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mo>&#x22EE;</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0B5;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr></mml:mtable><mml:mo>]</mml:mo></mml:mrow></mml:math></disp-formula>
<disp-formula id="eqn-7"><label>(7)</label><mml:math id="mml-eqn-7" display="block"><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:msubsup><mml:mrow><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mrow><mml:mtext>Y</mml:mtext></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></disp-formula>where
<disp-formula id="eqn-8"><label>(7a)</label><mml:math id="mml-eqn-8" display="block"><mml:msub><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mrow><mml:mrow><mml:mtext>w</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mrow><mml:mtext>&#xA0;R</mml:mtext></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup><mml:mspace width="thinmathspace" /><mml:mrow><mml:mtext>And</mml:mtext></mml:mrow><mml:mspace width="thinmathspace" /><mml:msub><mml:mrow><mml:mtext>Y</mml:mtext></mml:mrow><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mrow><mml:mrow><mml:mtext>w</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x2026;</mml:mo><mml:msubsup><mml:mrow><mml:mrow><mml:mtext>w</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msup></mml:math></disp-formula></p>
<p>The creation of the <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mi>j</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mtext>th</mml:mtext></mml:mrow></mml:mrow></mml:msup></mml:math></inline-formula> record with <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:msup><mml:mrow><mml:mtext>K</mml:mtext></mml:mrow><mml:mrow><mml:mi>j</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula> records and the performance of the partially hidden layer are as follows <xref ref-type="disp-formula" rid="eqn-9">Eq. (8)</xref> [<xref ref-type="bibr" rid="ref-28">28</xref>]:
<disp-formula id="eqn-9"><label>(8)</label><mml:math id="mml-eqn-9" display="block"><mml:msub><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0B5;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mrow><mml:mo>&#x2211;</mml:mo></mml:mrow><mml:mrow><mml:mi>z</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msubsup><mml:mrow><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mo>&#x22EE;</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mo>&#x22EE;</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0B5;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mrow><mml:mo>&#x2211;</mml:mo></mml:mrow><mml:mrow><mml:mi>z</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msubsup><mml:mrow><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr></mml:mtable><mml:mo>&#x2026;</mml:mo><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0B5;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mrow><mml:mo>&#x2211;</mml:mo></mml:mrow><mml:mrow><mml:mi>z</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msubsup><mml:mrow><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mtable columnalign="left" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mo>&#x22EE;</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mo>&#x22EE;</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mi>&#x03B4;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0B5;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mrow><mml:mo>&#x2211;</mml:mo></mml:mrow><mml:mrow><mml:mi>z</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msubsup><mml:mrow><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr></mml:mtable><mml:mo>]</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>The performance weights can be adjusted by using the following <xref ref-type="disp-formula" rid="eqn-10">Eq. (9)</xref>:
<disp-formula id="eqn-10"><label>(9)</label><mml:math id="mml-eqn-10" display="block"><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:msubsup><mml:mrow><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow></mml:mrow></mml:msubsup><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>Y</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mrow><mml:mtext>&#xA0;R</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>
<disp-formula id="eqn-11"><label>(10)</label><mml:math id="mml-eqn-11" display="block"><mml:msub><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:msubsup><mml:mrow><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow></mml:mrow></mml:msubsup><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>BG</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:msub><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:msub><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:msubsup><mml:mrow><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup><mml:msub><mml:mrow><mml:mtext>&#xA0;R</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:msub><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></disp-formula>
<disp-formula id="ueqn-1">
<mml:math id="mml-ueqn-1" display="block"><mml:mi>c</mml:mi><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>g</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="bold">j</mml:mi></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>where <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mrow><mml:mtext>g</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="bold">j</mml:mi></mml:mrow><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> represents the sigmoid activation function in the hidden layer [<xref ref-type="bibr" rid="ref-32">32</xref>].
<disp-formula id="eqn-12"><label>(11)</label><mml:math id="mml-eqn-12" display="block"><mml:mrow><mml:mtext mathvariant="italic">Error</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac></mml:mstyle><mml:munder><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:munder><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mi>m</mml:mi><mml:mi>z</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>c</mml:mi><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></disp-formula>where</p>
<p><inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>&#x2009;&#x003D;&#x2009;desired outcome</p>
<p><inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:mi>c</mml:mi><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>&#x2009;&#x003D;&#x2009;calculated outcome</p>
<p><xref ref-type="disp-formula" rid="eqn-12">Eq. (11)</xref> represents a back propagation error. The weights can be updated to minimize this error [<xref ref-type="bibr" rid="ref-28">28</xref>]. The change in weight is shown in <xref ref-type="disp-formula" rid="eqn-13">Eq. (12)</xref> as follows:
<disp-formula id="eqn-13"><label>(12)</label><mml:math id="mml-eqn-13" display="block"><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:msubsup><mml:mrow><mml:mrow><mml:mtext>F</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mo>,</mml:mo><mml:mi>z</mml:mi></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mo>=</mml:mo><mml:mi>n</mml:mi></mml:mrow></mml:msubsup><mml:mo>&#x221D;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mi mathvariant="normal">&#x2202;</mml:mi><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2202;</mml:mi><mml:msup><mml:mrow><mml:mtext>F</mml:mtext></mml:mrow><mml:mrow><mml:mi>r</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:mtext>n</mml:mtext></mml:mrow></mml:mrow></mml:msup></mml:mrow></mml:mfrac></mml:mstyle></mml:math></disp-formula>
<disp-formula id="ueqn-2">
<mml:math id="mml-ueqn-2" display="block"><mml:mi>r</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mn>3</mml:mn><mml:mo>&#x2026;</mml:mo><mml:mi>n</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>n</mml:mi><mml:mi>o</mml:mi><mml:mo>.</mml:mo><mml:mi>o</mml:mi><mml:mi>f</mml:mi><mml:mrow><mml:mtext mathvariant="italic">neurons</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>And <inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:mrow><mml:mtext>z</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mtext>Layer of Output Value</mml:mtext></mml:mrow></mml:math></inline-formula></p>
<p><xref ref-type="disp-formula" rid="eqn-14">Eq. (13)</xref> demonstrates the weight update and biases, where <inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:mi>&#x03C3;</mml:mi></mml:math></inline-formula> represents the learning rate [<xref ref-type="bibr" rid="ref-24">24</xref>&#x2013;<xref ref-type="bibr" rid="ref-28">28</xref>].
<disp-formula id="eqn-14"><label>(13)</label><mml:math id="mml-eqn-14" display="block"><mml:msubsup><mml:mrow><mml:mi>F</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mo>,</mml:mo><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>r</mml:mi></mml:mrow></mml:msubsup><mml:mrow><mml:mo>(</mml:mo><mml:mi>h</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mi>F</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mo>,</mml:mo><mml:mi>k</mml:mi></mml:mrow><mml:mrow><mml:mi>r</mml:mi></mml:mrow></mml:msubsup><mml:mrow><mml:mo>(</mml:mo><mml:mi>h</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:msubsup><mml:mrow><mml:mi>F</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mo>,</mml:mo><mml:mi>z</mml:mi></mml:mrow><mml:mrow><mml:mi>r</mml:mi></mml:mrow></mml:msubsup></mml:math></disp-formula></p>
<p><xref ref-type="disp-formula" rid="eqn-14">Eq. (13)</xref> shows the updated weights of the RTS-DELM with ith weight. The standard evaluation layer is again activated and assesses the performance of the recommended system model. If the learning standards do not satisfy the proposed model&#x2019;s requirements, the model must be retrained; otherwise, the decision level fusion layer is activated and the trained model is kept in a cloud database. In the fusion layer, decision-level fusion empowered with fuzzy logic is applied to train the model. In this article we used mamdani fuzzy inference system for decision level fusion. As we know that the performance of any decision based system is rely on knowledgebase. The proposed decision level fusion is shown below: IF (KDD-RTS-DELM is no and CUP-99-RTS-DELM is no and NetML-2020 is no) THEN (Intrusion Detection is no)</p>
<p>IF (KDD-RTS-DELM is no and CUP-99-RTS-DELM is no and NetML-2020 is yes) THEN (Intrusion Detection is yes)</p>
<p>IF (KDD-RTS-DELM is no and CUP-99-RTS-DELM is yes and NetML-2020 is no) THEN (Intrusion Detection is yes)</p>
<p>IF (KDD-RTS-DELM is no and CUP-99-RTS-DELM is yes and NetML-2020 is yes) THEN (Intrusion Detection is yes)</p>
<p>IF (KDD-RTS-DELM is yes and CUP-99-RTS-DELM is no and NetML-2020 is no) THEN (Intrusion Detection is yes)</p>
<p>IF (KDD-RTS-DELM is yes and CUP-99-RTS-DELM is no and NetML-2020 is yes) THEN (Intrusion Detection is yes)</p>
<p>IF (KDD-RTS-DELM is yes and CUP-99-RTS-DELM is yes and NetML-2020 is no) THEN (Intrusion Detection is yes)</p>
<p>IF (KDD-RTS-DELM is yes and CUP-99-RTS-DELM is yes and NetML-2020 is yes) THEN (Intrusion Detection is yes)</p>
<p>The performance evaluation of the fusion layer is activated to evaluate the fused machine learning approaches. If the learning criteria do not meet the requirements, then retune the fusion layer parameters, otherwise, the fused trained model are stored in the fused database in the cloud for future use.</p>
<p>In the validation phase, the KDD, CUP-99 and NetML-2020 datasets are used to evaluate the proposed IDS-FMLT model. The fused model is imported from the cloud for the prediction of network traffic. The proposed IDS-FMLT model predicts two types of network traffic, namely, normal and malicious attacks. If the proposed IDS-FMLT model predicts normal traffic, then traffic is granted access. If the proposed IDS-FMLT model predicts malicious traffic, then traffic is blocked and stored as a marked attack in the database in the cloud.</p>
</sec>
<sec id="s4"><label>4</label><title>Results and Discussion</title>
<p>In this research, MATLAB 2020a tool is used for the simulation purpose. The (RTS-DELM) is applied to input KDD data, CUP-99 data, and NetML-2020 data. The data are separated into two stages: training &#x0026; validation. Seventy percent of the data (855600 fused samples) and 30&#x0025; (366685 fused samples) data are used for validation in the training phase which are shown in <xref ref-type="table" rid="table-2">Tabs. 2</xref> and <xref ref-type="table" rid="table-3">3</xref>.</p>
<table-wrap id="table-2"><label>Table 2</label><caption><title>Training data for the proposed intrusion detection scheme in heterogeneous networks empowered with fused machine learning model</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="center" colspan="4">Proposed fusion based IDS-FMLT (training)</th>
</tr>
<tr>
<th align="center" colspan="2">fused samples (FS&#x2009;&#x003D;&#x2009;855600)</th>
<th align="center" colspan="2">Output results (&#x20AC;<sub>A</sub>, &#x20AC;<sub>B</sub>)</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Input</td>
<td align="left">Expected output (I<sub>A</sub>, I<sub>B</sub>)</td>
<td align="left">&#x20AC;<sub>A</sub> (Access)</td>
<td align="left">&#x20AC;<sub>B</sub> (Block)</td>
</tr>
<tr>
<td/>
<td align="left">I<sub>A</sub>&#x2009;&#x003D;&#x2009;784077 access</td>
<td align="left">776738</td>
<td align="left">7339</td>
</tr>
<tr>
<td/>
<td align="left">I<sub>B</sub>&#x2009;&#x003D;&#x2009;71523 block</td>
<td align="left">20639</td>
<td align="left">50884</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-3"><label>Table 3</label><caption><title>Validation data for the proposed intrusion detection scheme in heterogeneous networks empowered with a fused machine learning model</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="center" colspan="4">Proposed fusion IDS-FMLT (validation)</th>
</tr>
<tr>
<th align="center" colspan="2">Total number of fused samples (FS&#x2009;&#x003D;&#x2009;366685)</th>
<th align="center" colspan="2">Output results (&#x20AC;<sub>A</sub>, &#x20AC;<sub>B</sub>)</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Input</td>
<td align="left">Expected output (I<sub>A</sub>, I<sub>B</sub>)</td>
<td align="left">&#x20AC;<sub>A</sub> (Access)</td>
<td align="left">&#x20AC;<sub>B</sub> (Block)</td>
</tr>
<tr>
<td/>
<td align="left">I<sub>A</sub>&#x2009;&#x003D;&#x2009;336033 (Access)</td>
<td align="left">330109</td>
<td align="left">5924</td>
</tr>
<tr>
<td/>
<td align="left">I<sub>B</sub>&#x2009;&#x003D;&#x2009;30652 (Block)</td>
<td align="left">11751</td>
<td align="left">18901</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The various statistical analysis parameters [<xref ref-type="bibr" rid="ref-38">38</xref>&#x2013;<xref ref-type="bibr" rid="ref-41">41</xref>] like accuracy, miss rate, probability of detection, true negative rate, incidence, positive predicted value, and negative projected importance of the proposed IDS-FMLT model are all evaluated in the following way:
<disp-formula id="eqn-15"><label>(14)</label><mml:math id="mml-eqn-15" display="block"><mml:mrow><mml:mtext>Accuracy</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>True positive (access)</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>True negative (block)</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>Total population</mml:mtext></mml:mrow></mml:mrow></mml:mfrac></mml:mstyle></mml:math></disp-formula>
<disp-formula id="eqn-16"><label>(15)</label><mml:math id="mml-eqn-16" display="block"><mml:mrow><mml:mtext>Miss rate</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>False positive&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>access</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>False negative (block)</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>Total population</mml:mtext></mml:mrow></mml:mrow></mml:mfrac></mml:mstyle></mml:math></disp-formula>
<disp-formula id="eqn-17"><label>(16)</label><mml:math id="mml-eqn-17" display="block"><mml:mrow><mml:mtext>Probability of detection&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>PD</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>True positive&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>access</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>True positive&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>access</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>False negative&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>block</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:mfrac></mml:mstyle></mml:math></disp-formula>
<disp-formula id="eqn-18"><label>(17)</label><mml:math id="mml-eqn-18" display="block"><mml:mrow><mml:mtext>True Negative Rate&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>TNR</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>True negative (block)</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>True negative (block)</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>False Positive (access)</mml:mtext></mml:mrow></mml:mrow></mml:mfrac></mml:mstyle></mml:math></disp-formula>
<disp-formula id="eqn-19"><label>(18)</label><mml:math id="mml-eqn-19" display="block"><mml:mrow><mml:mtext>Prevelance</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>Condition Positive</mml:mtext></mml:mrow></mml:mrow><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>Condition Positive</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext mathvariant="italic">Condition Negative</mml:mtext></mml:mrow></mml:mrow></mml:mfrac></mml:mstyle></mml:math></disp-formula>
<disp-formula id="eqn-20"><label>(19)</label><mml:math id="mml-eqn-20" display="block"><mml:mrow><mml:mtext>Positive Predicted Value</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>True positive&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>accesss</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>True Positive&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>access</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>False Positive (access)</mml:mtext></mml:mrow></mml:mrow></mml:mfrac></mml:mstyle></mml:math></disp-formula>
<disp-formula id="eqn-21"><label>(20)</label><mml:math id="mml-eqn-21" display="block"><mml:mrow><mml:mtext>Negative Predicted Value</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>True Negative&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>block</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>True Negative&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>block</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>False Negative (block)</mml:mtext></mml:mrow></mml:mrow></mml:mfrac></mml:mstyle></mml:math></disp-formula>
<disp-formula id="eqn-22"><label>(21)</label><mml:math id="mml-eqn-22" display="block"><mml:mrow><mml:mtext>False Alarm Rate</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>True Negative&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>block</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>True Negative&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>block</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>False Negative (block)</mml:mtext></mml:mrow></mml:mrow></mml:mfrac></mml:mstyle></mml:math></disp-formula>
<disp-formula id="eqn-23"><label>(22)</label><mml:math id="mml-eqn-23" display="block"><mml:mrow><mml:mtext>Specificity</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>True Negative&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>block</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>True Negative&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>block</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>False Negative (block)</mml:mtext></mml:mrow></mml:mrow></mml:mfrac></mml:mstyle></mml:math></disp-formula>
<disp-formula id="eqn-24"><label>(23)</label><mml:math id="mml-eqn-24" display="block"><mml:mrow><mml:mtext>Sensititvity</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>True Negative&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>block</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>True Negative&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>block</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mtext>False Negative (block)</mml:mtext></mml:mrow></mml:mrow></mml:mfrac></mml:mstyle></mml:math></disp-formula></p>
<p><xref ref-type="fig" rid="fig-2">Fig. 2</xref> shows the training statistical measures of different parameters, such as accuracy, miss rate, and probability of detection, specificity, prevalence, positive predicted value, and negative predicted value. The proposed IDS-FMLT model has obtained an accuracy of 96.73&#x0025; and 95.18&#x0025; during the training and validation phases, respectively. Other statistical parameters, such as the miss rate, probability of detection, specificity, prevalence, positive predicted value, specificity, sensitivity and negative predicted value are reported as 3.27&#x0025;, 97.41&#x0025;, 87.40&#x0025;, 93.20&#x0025;, 99.06&#x0025;, 87.40&#x0025;, 97.41&#x0025; and 71.14&#x0025;, respectively, in the training phase.</p>
<fig id="fig-2"><label>Figure 2</label><caption><title>Performance evaluation with statistical parameters for proposed IDS-FMLT model (training)</title></caption><graphic mimetype="image" mime-subtype="png" xlink:href="CMC_32617-fig-2.png"/></fig>
<p><xref ref-type="fig" rid="fig-3">Fig. 3</xref> illustrates the proposed model&#x2019;s validation performance for a variety of statistical parameters, including miss rate, rate of detection, specificity, prevalence, positive projected value, specificity, sensitivity and negative predicted value. The suggested model obtained 4.82&#x0025;, 96.56&#x0025;, 76.14&#x0025;, 93.20&#x0025;, 98.24&#x0025;, 76.14&#x0025;, 96.56&#x0025; and 61.70&#x0025; for miss rate, probability of detection, specificity, prevalence, positive predicted value, and negative projected value, respectively, during the validation stage.</p>
<fig id="fig-3"><label>Figure 3</label><caption><title>Performance evaluation with statistical parameters for the proposed IDS-FMLT model (validation)</title></caption><graphic mimetype="image" mime-subtype="png" xlink:href="CMC_32617-fig-3.png"/></fig>
<p><xref ref-type="table" rid="table-3">Tabs. 3</xref> and <xref ref-type="table" rid="table-4">4</xref> demonstrates the overall performance of the proposed IDS-FMLT model and compare it with other state-of-the-art techniques. The experimental results of the IDS-FMLT model achieved an accuracy of 95.18&#x0025; and a missing rate of 4.82&#x0025;, which are better than those of different existing approaches, such as a neural network [<xref ref-type="bibr" rid="ref-24">24</xref>], support vector machine [<xref ref-type="bibr" rid="ref-24">24</xref>], decision tree [<xref ref-type="bibr" rid="ref-24">24</xref>], deep extreme learning machine [<xref ref-type="bibr" rid="ref-24">24</xref>], RNN [<xref ref-type="bibr" rid="ref-29">29</xref>], adaptive voting algorithm [<xref ref-type="bibr" rid="ref-30">30</xref>], ANN [<xref ref-type="bibr" rid="ref-31">31</xref>], DELM [<xref ref-type="bibr" rid="ref-32">32</xref>], SVM [<xref ref-type="bibr" rid="ref-33">33</xref>], SOMNN [<xref ref-type="bibr" rid="ref-34">34</xref>], ANN [<xref ref-type="bibr" rid="ref-35">35</xref>], NA&#x00CF;VE BAYES&#x2009;&#x002B;&#x2009;RP [<xref ref-type="bibr" rid="ref-36">36</xref>] and GANS [<xref ref-type="bibr" rid="ref-37">37</xref>].</p>
<table-wrap id="table-4"><label>Table 4</label><caption><title>Comparison of the proposed IDS-FMLT system model with various techniques across multiple datasets</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Method</th>
<th align="left">Accuracy (Dataset KDD) [<xref ref-type="bibr" rid="ref-25">25</xref>]</th>
<th align="left">Accuracy, (Dataset CUP-99) [<xref ref-type="bibr" rid="ref-26">26</xref>]</th>
<th align="left">Accuracy (Dataset NetML-2020) [<xref ref-type="bibr" rid="ref-27">27</xref>]</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Neural network [<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td align="left">81.2&#x0025;</td>
<td align="left">90.39&#x0025;</td>
<td align="left">91.23&#x0025;</td>
</tr>
<tr>
<td align="left">Support vector machine [<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td align="left">69.52&#x0025;</td>
<td align="left">89.94&#x0025;</td>
<td align="left">90.07&#x0025;</td>
</tr>
<tr>
<td align="left">Decision tree [<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td align="left">81.5&#x0025;</td>
<td align="left">91.12&#x0025;</td>
<td align="left">92.79&#x0025;</td>
</tr>
<tr>
<td align="left">Deep extreme learning machine [<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td align="left">93.91&#x0025;</td>
<td align="left">94.6&#x0025;</td>
<td align="left">94.93&#x0025;</td>
</tr>
<tr>
<td align="left"><bold>Proposed IDS-FMLT model</bold></td>
<td align="left" colspan="3"><bold>Fused</bold> [(RTS-KDD)&#x2009;&#x002B;&#x2009;(RTS-CUP-99)&#x2009;&#x002B;&#x2009;(RTS-NetML-2020)] <bold>95.18&#x0025;</bold></td>
</tr>
<tr>
<td align="left">Method</td>
<td align="left">Miss rate (Dataset KDD) [<xref ref-type="bibr" rid="ref-25">25</xref>]</td>
<td align="left">Miss rate (Dataset CUP-99) [265]</td>
<td align="left">Miss rate (Dataset NetML-2020) [<xref ref-type="bibr" rid="ref-27">27</xref>]</td>
</tr>
<tr>
<td align="left">Neural network [<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td align="left">18.8&#x0025;</td>
<td align="left">9.61&#x0025;</td>
<td align="left">8.77&#x0025;</td>
</tr>
<tr>
<td align="left">Support vector machine [<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td align="left">30.48&#x0025;</td>
<td align="left">10.06&#x0025;</td>
<td align="left">9.93&#x0025;</td>
</tr>
<tr>
<td align="left">Decision tree [<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td align="left">18.5&#x0025;</td>
<td align="left">8.88&#x0025;</td>
<td align="left">7.21&#x0025;</td>
</tr>
<tr>
<td align="left">Deep extreme learning machine [<xref ref-type="bibr" rid="ref-24">24</xref>]</td>
<td align="left">6.09&#x0025;</td>
<td align="left">5.4&#x0025;</td>
<td align="left">5.07&#x0025;</td>
</tr>
<tr>
<td align="left"><bold>Proposed IDS-FMLT model</bold></td>
<td align="left" colspan="3"><bold>Fused</bold> [(RTS-KDD)&#x2009;&#x002B;&#x2009;(RTS-CUP-99)&#x2009;&#x002B;&#x2009;(RTS-NetML-2020)]<bold>4.82&#x0025;</bold></td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="table" rid="table-5">Tab. 5</xref> shows the in-contrast of proposed IDS-FMLT model with various state-of-the-art existing approaches [<xref ref-type="bibr" rid="ref-29">29</xref>&#x2013;<xref ref-type="bibr" rid="ref-37">37</xref>]. The performance the proposed IDS-FMLT model in terms of different statistical parameters like &#x201C;accuracy and miss rate&#x201D;, during the training the proposed IDS-FMLT model is achieved 96.73&#x0025; and validation phase the proposed IDS-FMLT model achieved the accuracy 95.18&#x0025;. The summary of existing literature results analysis that clearly shows the accuracy is enhanced as compared to various state-of-the-art existing ML approaches.</p>
<table-wrap id="table-5"><label>Table 5</label><caption><title>Performances of state-of-the-art approaches and the proposed IDS-FMLT system model</title></caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th align="left">Authors</th>
<th align="left">Pre-processing</th>
<th align="left">Approaches</th>
<th align="left">Training/Validation</th>
<th align="left">Accuracy (&#x0025;)</th>
<th align="left">Miss-rate (&#x0025;)</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left">Farhan [<xref ref-type="bibr" rid="ref-29">29</xref>]</td>
<td align="left">No</td>
<td align="left">RNN</td>
<td align="left">Training (60&#x0025;)</td>
<td align="left">94.1</td>
<td align="left">5.9</td>
</tr>
<tr>
<td/>
<td/>
<td/>
<td align="left">Validation (40&#x0025;)</td>
<td align="left">93.8</td>
<td align="left">6.2</td>
</tr>
<tr>
<td align="left">Chen<break/>et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-30">30</xref>]</td>
<td align="left">No</td>
<td align="left">Adaptive voting algorithm</td>
<td align="left">Training (85&#x0025;)</td>
<td align="left">85.2</td>
<td align="left">14.8</td>
</tr>
<tr>
<td/>
<td/>
<td/>
<td align="left">Validation (15&#x0025;)</td>
<td align="left">84.5</td>
<td align="left">15.5</td>
</tr>
<tr>
<td align="left">Khan<break/>et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-31">31</xref>]</td>
<td align="left">No</td>
<td align="left">ANN</td>
<td align="left">Training (85&#x0025;)</td>
<td align="left">81.2</td>
<td align="left">18.8</td>
</tr>
<tr>
<td/>
<td/>
<td/>
<td align="left">Validation (15&#x0025;)</td>
<td align="left">79.9</td>
<td align="left">20.1</td>
</tr>
<tr>
<td align="left">Avallaee<break/>et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-32">32</xref>]</td>
<td align="left">Yes</td>
<td align="left">DELM</td>
<td align="left">Training (70&#x0025;)</td>
<td align="left">92.1</td>
<td align="left">7.9</td>
</tr>
<tr>
<td/>
<td/>
<td/>
<td align="left">Validation (30&#x0025;)</td>
<td align="left">91.3</td>
<td align="left">8.7</td>
</tr>
<tr>
<td align="left">Ibrahim<break/>et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-33">33</xref>]</td>
<td align="left">No</td>
<td align="left">SVM</td>
<td align="left">Training (85&#x0025;)</td>
<td align="left">93.5</td>
<td align="left">6.5</td>
</tr>
<tr>
<td/>
<td/>
<td/>
<td align="left">Validation (15&#x0025;)</td>
<td align="left">92.1</td>
<td align="left">7.9</td>
</tr>
<tr>
<td align="left">Panda<break/>et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-34">34</xref>]</td>
<td align="left">No</td>
<td align="left">SOMNN</td>
<td align="left">Training (65&#x0025;)</td>
<td align="left">75.4</td>
<td align="left">24.6</td>
</tr>
<tr>
<td/>
<td/>
<td/>
<td align="left">Validation (35&#x0025;)</td>
<td align="left">73.1</td>
<td align="left">26.9</td>
</tr>
<tr>
<td align="left">Alshinina<break/>et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-35">35</xref>]</td>
<td align="left">No</td>
<td align="left">ANN</td>
<td align="left">Training (45&#x0025;)</td>
<td align="left">81.2</td>
<td align="left">18.8</td>
</tr>
<tr>
<td/>
<td/>
<td/>
<td align="left">Validation (55&#x0025;)</td>
<td align="left">79.9</td>
<td align="left">20.1</td>
</tr>
<tr>
<td align="left">Rahman<break/>et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-36">36</xref>]</td>
<td align="left">No</td>
<td align="left">Discriminative multinomial Na&#x00EF;ve Bayes&#x2009;&#x002B;&#x2009;RP</td>
<td align="left">Training (93&#x0025;)</td>
<td align="left">81.5</td>
<td align="left">18.5</td>
</tr>
<tr>
<td/>
<td/>
<td/>
<td align="left">Validation (7&#x0025;)</td>
<td align="left">80.6</td>
<td align="left">19.4</td>
</tr>
<tr>
<td align="left">Saleem<break/>et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-37">37</xref>]</td>
<td align="left">No</td>
<td align="left">GANs</td>
<td align="left">Training (85&#x0025;)</td>
<td align="left">86.5</td>
<td align="left">13.5</td>
</tr>
<tr>
<td/>
<td/>
<td/>
<td align="left">Validation (15&#x0025;)</td>
<td align="left">81.1</td>
<td align="left">18.9</td>
</tr>
<tr>
<td align="left">Proposed IDS-FMLT model</td>
<td align="left">Yes</td>
<td align="left">Fused ML (RTS-DELM)</td>
<td align="left">Training (70&#x0025;)</td>
<td align="left">96.73</td>
<td align="left">3.27</td>
</tr>
<tr>
<td/>
<td/>
<td/>
<td align="left">Validation (30&#x0025;)</td>
<td align="left">95.18</td>
<td align="left">4.82</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s5"><label>5</label><title>Conclusion</title>
<p>The rapid growth of data necessitates securing networks from malicious attacks. The proposed IDS-FMLT model is used to predict malicious and regular traffic in the networks. Moreover, the proposed approach is tested on various heterogeneous datasets, namely, KDD, CUP-99, and NetML-2020. Statistical significance is analyzed and compared to state-of-the-art methods for malicious attacks in networks.</p>
<p>The experimental results of the proposed IDS-FMLT model demonstrated an accuracy of 96.73&#x0025; for training and 95.18&#x0025; for validation. The proposed IDS-FMLT model achieved satisfactory performance as compared to other state-of-the-art studies.</p>
</sec>
<sec id="s6"><label>6</label><title>Limitations and Future Work</title>
<p>The proposed IDS-FMLT classifies the network traffic into two categories: malicious and regular. The proposed Fused Machine Learning algorithm was used to increase the system performance in terms of detection of malicious and regular traffic. On the other hand, the IDS-FMLT framework may increase the computational complexity of the system. In future work, Long short-term memory (LSTM), federated learning, and hybrid computational intelligence can be applied, which may improve the system&#x2019;s accuracy. In future, we may use the other latest published intrusion detection data set like IoT datasets for intrusion detection systems such as CIC IoT Dataset 2022 and other bench marks dataset as well like NSL-KDD or UGR16 or UNSW-NB15 or CICDS-17, 18, and 19 during training phase, which make our system more reliable in real time application</p>
</sec>
</body>
<back>
<ack>
<p>We thank our families and colleagues who provided us with moral support.</p>
</ack>
<fn-group>
<fn fn-type="other"><p><bold>Funding Statement:</bold> The authors received no specific funding for this study.</p></fn>
<fn fn-type="conflict"><p><bold>Conflicts of Interest:</bold> The authors declare that they have no conflicts of interest to report regarding the present study.</p></fn>
</fn-group>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Han</surname></string-name>, <string-name><given-names>M. D.</given-names> <surname>Marino</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Wang</surname></string-name> and <string-name><given-names>K. C.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>An evolutionary-based approach for low-complexity intrusion detection in wireless sensor networks</article-title>,&#x201D; <source>Wireless Personal Communications</source>, vol. <volume>119</volume>, no. <issue>4</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>24</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Liu</surname></string-name> and <string-name><given-names>B.</given-names> <surname>Lang</surname></string-name></person-group>, &#x201C;<article-title>Machine learning and deep learning methods for intrusion detection systems: A survey</article-title>,&#x201D; <source>Applied Sciences</source>, vol. <volume>9</volume>, no. <issue>20</issue>, pp. <fpage>4396</fpage>&#x2013;<lpage>4405</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>I. F.</given-names> <surname>Kilincer</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Ertam</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Sengur</surname></string-name></person-group>, &#x201C;<article-title>Machine learning methods for cyber security intrusion detection: Datasets and comparative study</article-title>,&#x201D; <source>Computer Networks</source>, vol. <volume>188</volume>, pp. <fpage>107840</fpage>&#x2013;<lpage>107848</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Aldweesh</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Derhab</surname></string-name> and <string-name><given-names>A. Z.</given-names> <surname>Emam</surname></string-name></person-group>, &#x201C;<article-title>Deep learning approaches for anomaly-based intrusion detection systems: A survey, taxonomy, and open issue</article-title>,&#x201D; <source>Knowledge-Based Systems</source>, vol. <volume>189</volume>, pp. <fpage>105124</fpage>&#x2013;<lpage>105132</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G.</given-names> <surname>Kocher</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Kumar</surname></string-name></person-group>, &#x201C;<article-title>Machine learning and deep learning methods for intrusion detection systems: Recent developments and challenges</article-title>,&#x201D; <source>Soft Computing</source>, vol. <volume>25</volume>, no. <issue>15</issue>, pp. <fpage>9731</fpage>&#x2013;<lpage>9763</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Lv</surname></string-name>, <string-name><given-names>A. K.</given-names> <surname>Sangaiah</surname></string-name> and <string-name><given-names>T.</given-names> <surname>Huang</surname></string-name></person-group>, &#x201C;<article-title>A real-time and ubiquitous network attack detection based on a deep belief network and support vector machine</article-title>,&#x201D; <source>IEEE/CAA Journal of Automatica Sinica</source>, vol. <volume>7</volume>, no. <issue>3</issue>, pp. <fpage>790</fpage>&#x2013;<lpage>799</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S. N.</given-names> <surname>Mighan</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Kahani</surname></string-name></person-group>, &#x201C;<article-title>A novel scalable intrusion detection system based on deep learning</article-title>,&#x201D; <source>International Journal of Information Security</source>, vol. <volume>20</volume>, no. <issue>3</issue>, pp. <fpage>387</fpage>&#x2013;<lpage>403</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G. B.</given-names> <surname>Huang</surname></string-name>, <string-name><given-names>Q. Y.</given-names> <surname>Zhu</surname></string-name> and <string-name><given-names>C. K.</given-names> <surname>Siew</surname></string-name></person-group>, &#x201C;<article-title>Extreme learning machine: Theory and applications</article-title>,&#x201D; <source>Neurocomputing</source>, vol. <volume>70</volume>, no. <issue>1&#x2013;3</issue>, pp. <fpage>489</fpage>&#x2013;<lpage>501</lpage>, <year>2006</year>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Niu</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Duan</surname></string-name> and <string-name><given-names>X.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Fast learning network: A novel artificial neural network with a fast learning speed</article-title>,&#x201D; <source>Neural Computing and Applications</source>, vol. <volume>24</volume>, no. <issue>7</issue>, pp. <fpage>1683</fpage>&#x2013;<lpage>1695</lpage>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. H.</given-names> <surname>Ali</surname></string-name>, <string-name><given-names>B. A. D. A.</given-names> <surname>Mohammed</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Ismail</surname></string-name> and <string-name><given-names>M. F.</given-names> <surname>Zolkipli</surname></string-name></person-group>, &#x201C;<article-title>A new intrusion detection system based on a fast learning network and particle swarm optimization</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>6</volume>, pp. <fpage>20255</fpage>&#x2013;<lpage>20261</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Ahmad</surname></string-name>, <string-name><given-names>A. S.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>C. W.</given-names> <surname>Shiang</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Abdullah</surname></string-name> and <string-name><given-names>F.</given-names> <surname>Ahmad</surname></string-name></person-group>, &#x201C;<article-title>Network intrusion detection system: A systematic study of machine learning and deep learning approaches</article-title>,&#x201D; <source>Transactions on Emerging Telecommunications Technologies</source>, vol. <volume>32</volume>, no. <issue>1</issue>, pp. <fpage>4150</fpage>&#x2013;<lpage>4179</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Cao</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Lv</surname></string-name> and <string-name><given-names>Y.</given-names> <surname>Cao</surname></string-name></person-group>, &#x201C;<article-title>A hybrid feature extraction network for intrusion detection based on a global attention mechanism</article-title>,&#x201D; in <conf-name>Int. Conf. on Computer Information and Big Data Applications</conf-name>, <conf-loc>Atlanta, GA, USA</conf-loc>, pp. <fpage>481</fpage>&#x2013;<lpage>485</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Chkirbene</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Erbad</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Hamila</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Gouissem</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Mohamed</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Machine learning-based cloud computing anomalies detection</article-title>,&#x201D; <source>IEEE Network</source>, vol. <volume>34</volume>, no. <issue>6</issue>, pp. <fpage>178</fpage>&#x2013;<lpage>183</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Du</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Shan</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Qin</surname></string-name> and <string-name><given-names>N.</given-names> <surname>Wang</surname></string-name></person-group>, &#x201C;<article-title>Cloud intrusion detection method based on stacked contractive auto-encoder and support vector machine</article-title>,&#x201D; <source>IEEE Transactions on Cloud Computing</source>, vol. early access, pp. <fpage>1</fpage>&#x2013;<lpage>14</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X. A. L.</given-names> <surname>Novo</surname></string-name>, <string-name><given-names>M. V.</given-names> <surname>Barbas</surname></string-name>, <string-name><given-names>V. A.</given-names> <surname>Villagr&#x00E1;</surname></string-name> and <string-name><given-names>M. S.</given-names> <surname>Rodrigo</surname></string-name></person-group>, &#x201C;<article-title>Evaluation of cybersecurity data set characteristics for their applicability to neural networks algorithms detecting cybersecurity anomalies</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>8</volume>, pp. <fpage>9005</fpage>&#x2013;<lpage>9014</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Injadat</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Moubayed</surname></string-name>, <string-name><given-names>A. B.</given-names> <surname>Nassif</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Shami</surname></string-name></person-group>, &#x201C;<article-title>Multi-stage optimized machine-learning framework for network intrusion detection</article-title>,&#x201D; <source>IEEE Transactions on Network and Service Management</source>, vol. <volume>18</volume>, no. <issue>2</issue>, pp. <fpage>1803</fpage>&#x2013;<lpage>1816</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Zhong</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Yu</surname></string-name> and <string-name><given-names>C.</given-names> <surname>Ai</surname></string-name></person-group>, &#x201C;<article-title>Applying big data-based deep learning system to intrusion detection</article-title>,&#x201D; <source>Big Data Mining and Analytics</source>, vol. <volume>3</volume>, no. <issue>3</issue>, pp. <fpage>181</fpage>&#x2013;<lpage>195</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>G.</given-names> <surname>Bovenzi</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Aceto</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Ciuonzo</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Persico</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Pescap&#x00E9;</surname></string-name></person-group>, &#x201C;<article-title>A hierarchical hybrid intrusion detection approach in IoT scenarios</article-title>,&#x201D; in <conf-name>IEEE Global Communications Conf.</conf-name>, <conf-loc>Taipei, Taiwan</conf-loc>, pp. <fpage>1</fpage>&#x2013;<lpage>7</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Kim</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Park</surname></string-name> and <string-name><given-names>D. H.</given-names> <surname>Lee</surname></string-name></person-group>, &#x201C;<article-title>Ai-ids: Application of deep learning to real-time web intrusion detection</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>8</volume>, pp. <fpage>70245</fpage>&#x2013;<lpage>70261</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Nagaraja</surname></string-name>, <string-name><given-names>U.</given-names> <surname>Boregowda</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Khatatneh</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Vangipuram</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Nuvvusetty</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Similarity-based feature transformation for network anomaly detection</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>8</volume>, pp. <fpage>39184</fpage>&#x2013;<lpage>39196</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Su</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Sun</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Zhu</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Wang</surname></string-name> and <string-name><given-names>Y.</given-names> <surname>Li</surname></string-name></person-group>, &#x201C;<article-title>Bat: Deep learning methods on network intrusion detection using NSL-KDD dataset</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>8</volume>, pp. <fpage>29575</fpage>&#x2013;<lpage>29585</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Vijayanand</surname></string-name> and <string-name><given-names>D.</given-names> <surname>Devaraj</surname></string-name></person-group>, &#x201C;<article-title>A novel feature selection method using whale optimization algorithm and genetic operators for intrusion detection system in wireless mesh network</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>8</volume>, pp. <fpage>56847</fpage>&#x2013;<lpage>56854</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Zavrak</surname></string-name> and <string-name><given-names>M.</given-names> <surname>&#x0130;skefiyeli</surname></string-name></person-group>, &#x201C;<article-title>Anomaly-based intrusion detection from network flow features using variational autoencoder</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>8</volume>, pp. <fpage>108346</fpage>&#x2013;<lpage>108358</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. A.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Abbas</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Rehman</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Saeed</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Zeb</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>A machine learning approach for blockchain-based smart home networks security</article-title>,&#x201D; <source>IEEE Network</source>, vol. <volume>35</volume>, no. <issue>3</issue>, pp. <fpage>223</fpage>&#x2013;<lpage>229</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Inam</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Sarwar</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Atta</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Naaseer</surname></string-name>, <string-name><given-names>S. Y.</given-names> <surname>Siddiqui</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Detection of COVID-19 enhanced by a deep extreme learning machine</article-title>,&#x201D; <source>Intelligent Automation and Soft Computing</source>, vol. <volume>27</volume>, no. <issue>3</issue>, pp. <fpage>701</fpage>&#x2013;<lpage>712</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Sheikhan</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Jadidi</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Farrokhi</surname></string-name></person-group>, &#x201C;<article-title>Intrusion detection using reduced-size RNN based on feature grouping</article-title>,&#x201D; <source>Neural Computing and Applications</source>, vol. <volume>21</volume>, no. <issue>6</issue>, pp. <fpage>1185</fpage>&#x2013;<lpage>1190</lpage>, <year>2012</year>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Gao</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Shan</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Hu</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Niu</surname></string-name> and <string-name><given-names>Z.</given-names> <surname>Liu</surname></string-name></person-group>, &#x201C;<article-title>An adaptive ensemble machine learning model for intrusion detection</article-title>,&#x201D; <source>IEEE Access</source>, vol. <volume>7</volume>, no. <issue>3</issue>, pp. <fpage>82512</fpage>&#x2013;<lpage>82521</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>B.</given-names> <surname>Ingre</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Yadav</surname></string-name></person-group>, &#x201C;<article-title>Performance analysis of NSL-KDD dataset using </article-title>,&#x201D; in <conf-name>IEEE Int. Conf. on Signal Processing and Communication Engineering Systems</conf-name>, <conf-loc>Guntur, India</conf-loc>, pp. <fpage>92</fpage>&#x2013;<lpage>96</lpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A. M.</given-names> <surname>Farhan</surname></string-name></person-group>, &#x201C;<article-title>Effect of rotation on the propagation of waves in hollow poroelastic circular cylinder with magnetic field</article-title>,&#x201D; <source>Computers, Materials &#x0026; Continua</source>, vol. <volume>53</volume>, no. <issue>2</issue>, pp. <fpage>129</fpage>&#x2013;<lpage>156</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Chen</surname></string-name> and <string-name><given-names>J. H.</given-names> <surname>Jiang</surname></string-name></person-group>, &#x201C;<article-title>A method of virtual machine placement for fault-tolerant cloud applications</article-title>,&#x201D; <source>Intelligent Automation &#x0026; Soft Computing</source>, vol. <volume>22</volume>, no. <issue>4</issue>, pp. <fpage>587</fpage>&#x2013;<lpage>597</lpage>, <year>2016</year>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. A.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Rehman</surname></string-name>, <string-name><given-names>K. M.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>M. A. A.</given-names> <surname>Ghamdi</surname></string-name> and <string-name><given-names>S. H.</given-names> <surname>Almotiri</surname></string-name></person-group>, &#x201C;<article-title>Enhance intrusion detection in computer networks based on deep extreme learning machine</article-title>,&#x201D; <source>Computers, Materials &#x0026; Continua</source>, vol. <volume>66</volume>, no. <issue>1</issue>, pp. <fpage>467</fpage>&#x2013;<lpage>480</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Avallaee</surname></string-name>, <string-name><given-names>E.</given-names> <surname>Bagheri</surname></string-name>, <string-name><given-names>W.</given-names> <surname>Lu</surname></string-name> and <string-name><given-names>A. A.</given-names> <surname>Ghorbani</surname></string-name></person-group>, &#x201C;<article-title>A detailed analysis of the kdd cup-99 dataset</article-title>,&#x201D; in <conf-name>IEEE Symp. on Computational Intelligence for Security and Defense Applications</conf-name>, <conf-loc>Guntur, India</conf-loc>, pp. <fpage>1</fpage>&#x2013;<lpage>6</lpage>, <year>2009</year>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L. M.</given-names> <surname>Ibrahim</surname></string-name>, <string-name><given-names>D. T.</given-names> <surname>Basheer</surname></string-name> and <string-name><given-names>M. S.</given-names> <surname>Mahmod</surname></string-name></person-group>, &#x201C;<article-title>A comparison study for intrusion database based on self-organization map artificial neural network</article-title>,&#x201D; <source>Journal of Engineering Science and Technology</source>, vol. <volume>8</volume>, no. <issue>1</issue>, pp. <fpage>107</fpage>&#x2013;<lpage>119</lpage>, <year>2013</year>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Panda</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Abraham</surname></string-name> and <string-name><given-names>M. R.</given-names> <surname>Patra</surname></string-name></person-group>, &#x201C;<article-title>Discriminative multinomial na&#x00EF;ve Bayes for network intrusion detection</article-title>,&#x201D; in <conf-name>Sixth Int. Conf. on Information Assurance and Security</conf-name>, <conf-loc>Atlanta, GA, USA</conf-loc>, pp. <fpage>5</fpage>&#x2013;<lpage>10</lpage>, <year>2010</year>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>R.</given-names> <surname>Alshinina</surname></string-name> and <string-name><given-names>K.</given-names> <surname>Elleithy</surname></string-name></person-group>, &#x201C;<article-title>A highly accurate machine learning approach for developing wireless sensor network middleware</article-title>,&#x201D; in <conf-name>Wireless Telecommunications System</conf-name>, <conf-loc>Phoenix, AZ, USA</conf-loc>, pp. <fpage>1</fpage>&#x2013;<lpage>7</lpage>, <year>2018</year>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Rahman</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Abbas</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Gollapalli</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Ahmed</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Aftab</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Rainfall prediction system using machine learning fusion for smart cities</article-title>,&#x201D; <source>Sensors</source>, vol. <volume>22</volume>, no. <issue>6</issue>, pp. <fpage>3504</fpage>&#x2013;<lpage>3519</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Saleem</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Abbas</surname></string-name>, <string-name><given-names>T. M.</given-names> <surname>Ghazal</surname></string-name>, <string-name><given-names>M. A.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Sahawneh</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Smart cities: Fusion-based intelligent traffic congestion control system for vehicular networks using machine learning techniques</article-title>,&#x201D; <source>Egyptian Informatics Journal</source>, vol. <volume>23</volume>, no. <issue>1</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>10</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. W.</given-names> <surname>Nadeem</surname></string-name>, <string-name><given-names>H. G.</given-names> <surname>Goh</surname></string-name>, <string-name><given-names>M. A.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Hussain</surname></string-name>, <string-name><given-names>M. F.</given-names> <surname>Mushtaq</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Fusion-based machine learning architecture for heart disease prediction</article-title>,&#x201D; <source>Computers, Materials &#x0026; Continua</source>, vol. <volume>67</volume>, no. <issue>2</issue>, pp. <fpage>2481</fpage>&#x2013;<lpage>2496</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S. Y.</given-names> <surname>Siddiqui</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Athar</surname></string-name>, <string-name><given-names>M. A.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Abbas</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Saeed</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Modelling, simulation and optimization of diagnosis cardiovascular disease using computational intelligence approaches</article-title>,&#x201D; <source>Journal of Medical Imaging and Health Informatics</source>, vol. <volume>10</volume>, pp. <fpage>1005</fpage>&#x2013;<lpage>1022</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Sun</surname></string-name> and <string-name><given-names>R.</given-names> <surname>Grishman</surname></string-name></person-group>, &#x201C;<article-title>Lexicalized dependency paths based supervised learning for relation extraction</article-title>,&#x201D; <source>Computer Systems Science and Engineering</source>, vol. <volume>43</volume>, no. <issue>3</issue>, pp. <fpage>861</fpage>&#x2013;<lpage>870</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>I.</given-names> <surname>Naseer</surname></string-name>, <string-name><given-names>B. S.</given-names> <surname>Khan</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Saqib</surname></string-name>, <string-name><given-names>S. N.</given-names> <surname>Tahir</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Tariq</surname></string-name> <etal>et al.,</etal></person-group> &#x201C;<article-title>Diagnosis heart disease using mamdani fuzzy inference expert system</article-title>,&#x201D; <source>EAI Endorsed Transactions on Scalable Information Systems</source>, vol. <volume>7</volume>, no. <issue>26</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>9</lpage>, <year>2020</year>.</mixed-citation></ref>
</ref-list>
</back>
</article>







