Feature Selection for Machine Learning-Based Multiclass Cyberattack Classification
How to cite (IJASCE) :
Cyberattack classification supports timely threat identification and network security monitoring. However, model effectiveness depends not only on the selected algorithm but also on whether the available features contain sufficient information to distinguish attack classes. This study evaluates the effect of feature selection on multiclass cyberattack classification and assesses the discriminative capability of a synthetic cybersecurity dataset. The dataset contains 40,000 records from three nearly balanced classes: distributed denial-of-service, malware, and intrusion. Preprocessing included removing high-cardinality and potentially post-detection attributes, handling missing security indicators, one-hot encoding categorical variables, and applying a stratified 80:20 training/testing split. We evaluated Random Forest, Logistic Regression, and XGBoost using all usable features and the ten highest-ranked features identified through Random Forest importance. We measured performance using accuracy, macro precision, macro recall, and macro F1-score, and included a stratified dummy classifier as a baseline. Logistic Regression using all features achieved the highest accuracy of 33.95%, while XGBoost using the Top-10 subset achieved the highest macro F1-score of 33.69%. The dummy baseline obtained 33.90% accuracy, showing that none of the models produced a practically meaningful improvement over chance-level classification. Feature reduction slightly improved Random Forest and XGBoost but reduced Logistic Regression performance. These findings indicate that the dataset features have limited discriminative capability for separating the three attack categories. Further research should validate the analysis using real-world traffic, alternative feature-selection methods, and cross-dataset experiments before interpreting model complexity and reported accuracy.
A. S. Dina and D. Manivannan, "Intrusion detection based on Machine Learning techniques in computer networks," Internet Things, vol. 16, p. 100462, Dec. 2021, doi:10.1016/j.iot.2021.100462.
S. V. Golande, S. Vaidya, A. Pardeshi, V. Katkade, and V. Pawar, "An efficient network intrusion detection and classification system using machine learning," Int. J. Adv. Res. Sci. Commun. Technol., pp. 267–272, Nov. 2024, doi:10.48175/ijarsct-22045.
M. Bacevicius and A. Paulauskaite-Taraseviciene, "Machine learning algorithms for raw and unbalanced intrusion detection data in a multi-class classification problem," Appl. Sci., vol. 13, no. 12, p. 7328, Jun. 2023, doi:10.3390/app13127328.
H. Kamal and M. Mashaly, "Enhanced hybrid deep learning models-based anomaly detection method for two-stage binary and multi-class classification of attacks in intrusion detection systems," Algorithms, vol. 18, no. 2, p. 69, Jan. 2025, doi:10.3390/a18020069.
M. Maseno and Z. Wang, "Hybrid wrapper feature selection method based on genetic algorithm and extreme learning machine for intrusion detection," J. Big Data, vol. 11, no. 1, Feb. 2024, doi:10.1186/s40537-024-00887-9.
E. Kocyigit, M. Korkmaz, O. K. Sahingoz, and B. Diri, "Enhanced feature selection using genetic algorithm for machine-learning-based phishing URL detection," Appl. Sci., vol. 14, no. 14, p. 6081, Jul. 2024, doi:10.3390/app14146081.
M. Cantone, C. Marrocco, and A. Bria, "Machine learning in network intrusion detection: A cross-dataset generalization study," IEEE Access, vol. 12, pp. 144489–144508, 2024, doi:10.1109/ACCESS.2024.3472907.
M. Verkerken, L. D'hooge, T. Wauters, B. Volckaert, and F. De Turck, "Towards model generalization for intrusion detection: Unsupervised machine learning techniques," J. Netw. Syst. Manage., vol. 30, no. 1, Oct. 2021, doi:10.1007/s10922-021-09615-7.
Incribo, "Cyber security attacks," Kaggle, 2024. [Online]. Available: https://www.kaggle.com/datasets/teamincribo/cyber-security-attacks.
H. Güney, "Preprocessing impact analysis for machine learning-based network intrusion detection," Sakarya Univ. J. Comput. Inf. Sci., vol. 6, no. 1, pp. 67–79, Apr. 2023, doi:10.35377/saucis...1223054.
E. Jaw and X. Wang, "Feature selection and ensemble-based intrusion detection system: An efficient and comprehensive approach," Symmetry, vol. 13, no. 10, p. 1764, Sep. 2021, doi:10.3390/sym13101764.
M. A. Bouke and A. Abdullah, "An empirical study of pattern leakage impact during data preprocessing on machine learning-based intrusion detection models reliability," Expert Syst. Appl., vol. 230, p. 120715, Nov. 2023, doi:10.1016/j.eswa.2023.120715.
A. M. Alsaffar, M. Nouri-Baygi, and H. M. Zolbanin, "Shielding networks: Enhancing intrusion detection with hybrid feature selection and stack ensemble learning," J. Big Data, vol. 11, no. 1, Sep. 2024, doi:10.1186/s40537-024-00994-7.
M. A. Abdel-Rahman et al., "Feature importance guided autoencoder for dimensionality reduction in intrusion detection systems," Sci. Rep., vol. 16, no. 1, Feb. 2026, doi:10.1038/s41598-026-36695-9.
B. M. Kouassi, A. B. Ballo, K. J. Ayikpa, D. Mamadou, and M. Z. J. Coulibaly, "Top-K feature selection for IoT intrusion detection: Contributions of XGBoost, LightGBM, and random forest," Future Internet, vol. 17, no. 11, p. 529, Nov. 2025, doi:10.3390/fi17110529.
A. Shaikhanova, O. Kuznetsov, A. Tokkuliyeva, K. Ayapbergenov, S. Olzhas, and T. Danir, "Security audit of IoT device networks: A reproducible machine learning framework for threat detection and performance benchmarking," Sensors, vol. 25, no. 24, p. 7519, Dec. 2025, doi:10.3390/s25247519.
Z. Fan and Z. You, "Research on network intrusion detection based on XGBoost algorithm and multiple machine learning algorithms," Theor. Nat. Sci., vol. 31, no. 1, pp. 161–166, Mar. 2024, doi:10.54254/2753-8818/31/20241171.
H. F. Soon, A. Amir, H. Nishizaki, N. A. H. Zahri, L. M. Kamarudin, and S. N. Azemi, "Evaluating tree-based ensemble strategies for imbalanced network attack classification," Int. J. Adv. Comput. Sci. Appl., vol. 15, no. 1, 2024, doi:10.14569/IJACSA.2024.01501111.
L. K. S. Kumar et al., "Anomaly-based intrusion detection on benchmark datasets for network security: A comprehensive evaluation," Sci. Rep., vol. 16, no. 1, Mar. 2026, doi:10.1038/s41598-026-38317-w.
M. Zakariah, S. A. AlQahtani, and M. S. Al-Rakhami, "Machine learning-based adaptive synthetic sampling technique for intrusion detection," Appl. Sci., vol. 13, no. 11, p. 6504, May 2023, doi:10.3390/app13116504.
R. Almuhanna and S. Dardouri, "A deep learning/machine learning approach for anomaly based network intrusion detection," Front. Artif. Intell., vol. 8, Sep. 2025, doi:10.3389/frai.2025.1625891.

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.