Neural Network-Based DDoS Attack Detection in the Context of Unbalanced Classes: A Comparative Study of Resampling Methods
Kalala Kanyinda Norbert, Kafunda Katalayi Pierre
Asian Journal of Research in Computer Science · pp. 1–23 · Published 4 Jun 2026
10.9734/ajrcos/2026/v19i6867Abstract
Cyberattacks have been steadily increasing for the past twenty years. DDoS attacks, in particular, represent one of the greatest threats to organizations. A DDoS attack aims to render an information system's resources unavailable by overwhelming them with numerous requests originating from networks known as "botnets." In this study, we propose an automatic DDoS attack detection model based on neural networks. The objective is to classify network traffic into two categories: normal traffic and abnormal traffic. However, in real-world scenarios, abnormal cases are often marginal within network traffic, leading to class imbalance. Most machine learning algorithms tend to predict the majority of normal cases more accurately. To mitigate the negative effects of this imbalance, methods exist to rebalance the classes before training the model. Among these, we can mention: 1) the choice of evaluation metrics, 2) data resampling, and 3) algorithm tuning. In this work, we opted for the resampling method to balance the data. The study was conducted within the Department of Mathematics and Computer Science at the National Pedagogical University of the Democratic Republic of Congo. In this study, we used the "unbalaced_20_80_dataset.csv" data from the Kaggle platform. This data shows an imbalance between normal (benign) cases, representing 80%, and DDoS attacks, representing 20%. Resampling was performed to rebalance the classes. After training the model using oversampled, undersampled, and hybrid sampling data, the results revealed few differences in the outcomes obtained. However, the model trained with oversampled data using the SMOTE technique demonstrated better learning and generalization capabilities to new data. Conclusion: Detecting DDoS attacks presents a significant challenge for organizations. A neural network-based DDoS detection model appears to be a reliable and effective solution to this threat. By using unbalanced class data to train the model, we simulated real-world conditions where anomalous cases are rare and in the minority. Therefore, resampling was necessary to avoid bias. The model trained with oversampled data using the SMOTE technique yielded better results in terms of learning speed and its ability to generalize to unknown data.
Cited by 0
No indexed citations yet.
Related research
- Effective Earth Radius Factor Prediction and Mapping for Ondo State, South Western Nigeria — shares topic coverage
- Wavelet LPC with Neural Network for Spoken Arabic Digits Recognition System — shares topic coverage
- Fuzzy Model, Neural Network and Empirical Model for the Estimation of Global Solar Radiation for Port-Harcourt, Nigeria — shares topic coverage
- A Spatial and Temporal Analysis of Atmospherics Parameters Retrieved by a Neuro-varationnal Method off the West African Coast — shares topic coverage
- Efficient Image Registration Using Discrete Orthogonal Stockwell Transform and SIFT — shares topic coverage
Article metrics
Real usage data collected on this platform.
2
Page views
0
PDF downloads
0
Outbound clicks
0
Citations
Views over time
Views by country
Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".
Traffic sources
Referring site, by host.
Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.