Home / Journals / CMC / Online First / doi:10.32604/cmc.2026.083860
Special Issues
Table of Content

Open Access

ARTICLE

TS-SCHO–TSE: A Hybrid Optimization Framework for Feature Selection and Ensemble Learning in DDoS Detection

Sultan Shutyan Albalawi1, Mohd Yamani Idna Idris1,2,*, Ainuddin Wahid Bin Abdul Wahab1
1 Department of Computer System and Technology, Faculty of Computer Science & Information Technology, Universiti Malaya, 50603 Kuala Lumpur, Malaysia
2 Center for Mobile Cloud Computing, Universiti Malaya, Kuala Lumpur, Malaysia
* Corresponding Author: Mohd Yamani Idna Idris. Email: email
(This article belongs to the Special Issue: Intelligent and Privacy-Preserving Malware Detection: Advances in Deep Learning, Memory Forensics, and Federated Security)

Computers, Materials & Continua https://doi.org/10.32604/cmc.2026.083860

Received 12 April 2026; Accepted 25 June 2026; Published online 31 July 2026

Abstract

As Distributed Denial-of-Service (DDoS) attacks grow in size and complexity, standard intrusion detection systems are hitting a wall. Most struggle to generalize well, require too much computational power, or lack model diversity. To tackle this, we developed TS-SCHO-TSE, a unified hybrid framework for DDoS detection. Unlike traditional methods that treat feature selection and ensemble building as isolated, step-by-step tasks, our approach combines everything. We map feature masks, classifier states, voting weights, and hyperparameters into a single mixed discrete-continuous search space to optimize them all at once. We tested our system against classical functions (F1–F23), the CEC2019 benchmark suite, and three concrete network datasets: public traffic from CICIDS2017 and CICDDoS2019, plus a real-world dataset we captured using Wireshark. The results show that TS-SCHO-TSE outperforms existing methods, hitting 99.58% accuracy on CICIDS2017, 98.94% on CICDDoS2019, and 98.47% on our captured data. Crucially, the framework thins out the feature space by 46%—dropping from 41 features down to 22—and cuts inference latency to just 6.74 ms per 1000 flows. This proves the framework serves as a fast, highly accurate, and scalable alternative to heavy deep-learning models in live security environments.

Keywords

DDoS detection; intrusion detection systems; feature selection; metaheuristic optimization; TS-SCHO; ensemble learning
  • 252

    View

  • 29

    Download

  • 0

    Like

Share Link