CONSISTENT CLASSIFICATION OF NORMAL TRAFFIC AND UDP FLOOD ATTACKS IN FIFTH-GENERATION NETWORKS USING THE HYBRID AWRED METHOD
DOI:
https://doi.org/10.31673/2412-4338.2026.038414Abstract
The article considered the problem of multiclass network intrusion detection in fifth-generation network traffic. The main attention was paid not only to the average recognition quality, but also to the character of errors between normal traffic and a UDP-based flood attack. This was important for practical monitoring systems, because a high value of an aggregated metric did not yet mean that the model worked equally acceptably for all important classes. It could look good on average, but at the same time too often assign normal traffic to an attack class.
The study was carried out on the 5G-NIDD dataset. Before the final comparison, a preliminary fractional factorial experiment was conducted and used to select the working area of the Hybrid AWRED parameters. A detailed description of this stage was given in the main part of the article. The final comparison was performed for eight approaches: BoostedTrees, RandomForest, MLP-CE, MLP-Focal, MLP-SupCon, LSTM, Transformer, and Hybrid AWRED v8. The evaluation was carried out in five runs with initial random seeds 1081–1085.
In this work, Hybrid AWRED was not considered as just another ordinary classifier. Its role was different: it was treated as a hybrid mechanism for correcting the decision profile in a critical pair of classes. It had to reduce the undesirable shift between normal traffic and a UDP-based flood attack, but without losing the overall quality of multiclass recognition.
According to the results of five runs, Hybrid AWRED v8 achieved a Macro-F1 value of 0.92747 ± 0.00048, which kept it at the level of the strongest competitors. At the same time, the main result was not a formal advantage in one metric. The method provided the highest recall of normal traffic, 0.66373, the lowest share of the Benign→UDPFlood error, 0.33490, competitive recall of the UDPFlood class, 0.73703, and the highest corridor index, 0.77618. MLP-Focal became the closest competitor in this direction. It also showed a good profile for the critical pair, but it was inferior to Hybrid AWRED v8 in normal traffic recall, critical error share, Macro-F1, and corridor index.
The obtained results showed that Hybrid AWRED should be considered as a means of forming a more balanced classification of normal traffic and a UDP-based flood attack in fifth-generation networks.
Keywords: fifth-generation networks, network intrusion detection, Hybrid AWRED, multiclass classification, normal traffic, UDP-based flood attack, critical class pair