TITANIUM-4: A Low-Latency Four-Layer Intrusion Detection Pipeline and the Limits of Benchmark-Trained Thresholds under Domain Shift

Authors

  • Muhammad Younas University of Engineering and Technology, Peshawar, Pakistan
  • Sadeeda Nisar University of Engineering and Technology, Peshawar, Pakistan
  • Hoor Ul Ain University of Engineering and Technology, Peshawar, Pakistan
  • Huzaifa Shahzad University of Engineering and Technology, Peshawar, Pakistan
  • Wasim Habib University of Engineering and Technology, Peshawar, Pakistan
  • Salman Ilahi Siddiqui University of Engineering and Technology, Peshawar, Pakistan
  • Ihsan Ul haq University of Engineering and Technology, Peshawar, Pakistan
  • Muhammad Farooq University of Engineering and Technology, Peshawar, Pakistan

Keywords:

Intrusion Detection System, LightGBM;, One-Class SVM, CSE-CIC-IDS2018, Isotonic Calibration, Domain Shift, Threshold Transfer

Abstract

Firewalls enforce access rules within tight latency budgets but give no behavioral visibility; deep classifiers name attack families at a cost that inline placement cannot absorb. TITANIUM-4 addresses both with a four-layer pipeline: a calibrated LightGBM gatekeeper forwards only attack candidate flows to eight-class forensics, while benign flows bypass it and are processed by a One-Class SVM sentinel trained on normal traffic alone. On the cleaned CSE-CIC-IDS2018 benchmark, the gatekeeper attains F1 = 0.99987 and AUC = 0.99997 with zero false positives, routing 82.5% of test flows around the forensic classifier, which reaches macro F1 = 0.99 over eight families; the sentinel flags 45.06% of held-out Botnet and Infiltration flows at 5% FPR. Weighted end-to-end latency is 6.32 ms per flow, against 7.280 ms without early exit. Two findings qualify these results. The cleaned CSV carries no flow identifiers, so duplicates across splits cannot be excluded and the scores are a best-case estimate. Live DoS Hulk captures then expose domain shift: calibrated probabilities reach a maximum of 0.0138 against an operating point of τB = 1.0, so nothing is labeled until τB is lowered by hand. Two captures processed at manually chosen thresholds of 1 × 10⁻⁸ and 1 × 10⁻⁴ label 87.3% and 52.2% of an identical attack, so the reported fraction is governed by an unconstrained parameter rather than by the traffic. The sentinel flags nothing in either run, its 95th-percentile rule having been computed over the flows it was applied to, though its live scores stay sharply bimodal, locating that failure in the thresholding rule rather than the model. Benchmark-derived thresholds do not transfer to CICFlowMeter output

References

A. Khraisat, I. Gondal, P. Vamplew, and J. Kamruzzaman, “Survey of intrusion detection systems: techniques, datasets and challenges,” Cybersecurity, vol. 2, no. 1, pp. 1–22, Dec. 2019, doi: 10.1186/S42400-019-0038-7/FIGURES/8.

H. J. Liao, C. H. Richard Lin, Y. C. Lin, and K. Y. Tung, “Intrusion detection system: A comprehensive review,” J. Netw. Comput. Appl., vol. 36, no. 1, pp. 16–24, 2013, doi: 10.1016/j.jnca.2012.09.004.

A. B. Bouidaine, D. Moussaoui, M. Hadjila, W. Ferhi, and M. H. Hachemi, “Deep learning-based anomaly and intrusion detection using the CSE-CIC-IDS2018 dataset,” Eng. Technol. Appl. Sci. Res., vol. 15, no. 4, pp. 24782–24787, 2025, [Online]. Available: https://etasr.com/index.php/ETASR/article/view/11173

Isuru Udayangani Hewapathirana, “A Comparative Study of Two-Stage Intrusion Detection Using Modern Machine Learning Approaches on the CSE-CIC-IDS2018 Dataset,” Knowledge, vol. 5, no. 1, p. 6, 2025, doi: https://doi.org/10.3390/knowledge5010006.

Q. M. Alzubi, S. N. Makhadmeh, and Y. Sanjalawe, “Optimizing Intrusion Detection: Advanced Feature Selection and Machine Learning Techniques Using the CSE-CIC-IDS2018 Dataset,” J. Adv. Inf. Technol., vol. 16, no. 3, pp. 283–302, 2025, doi: 10.12720/JAIT.16.3.283-302.

“(PDF) Multi-Stage Enhanced Zero Trust Intrusion Detection System for Unknown Attack Detection in Internet of Things and Traditional Networks.” Accessed: Jul. 17, 2026. [Online]. Available: https://www.researchgate.net/publication/390007608_Multi-Stage_Enhanced_Zero_Trust_Intrusion_Detection_System_for_Unknown_Attack_Detection_in_Internet_of_Things_and_Traditional_Networks

“Sequential Intrusion Detection System For Zero-Trust Cyber Defense Of Iot/Iiot Networks.” Accessed: Jul. 17, 2026. [Online]. Available: https://www.researchgate.net/publication/384425126_SEQUENTIAL_INTRUSION_DETECTION_SYSTEM_FOR_ZERO-TRUST_CYBER_DEFENSE_OF_IOTIIOT_NETWORKS

“The Base-Rate Fallacy and the Difficulty of Intrusion Detection,” Underst. Intrusion Detect. Through Vis., pp. 31–47, May 2006, doi: 10.1007/0-387-27636-X_3.

“Intrusion Detection on CSE-CIC-IDS2018 Dataset Using Machine Learning Methods - Artificial Intelligence Theory and Applications.” Accessed: Jul. 17, 2026. [Online]. Available: https://dergipark.org.tr/en/pub/aita/article/1553769

Chaofei Tang, Nurbol Luktarhan, “An Efficient Intrusion Detection Method Based on LightGBM and Autoencoder,” Symmetry (Basel)., vol. 12, no. 9, p. 1458, 2020, doi: https://doi.org/10.3390/sym12091458.

Baraa Ismael Farhan, Ammar D. Jasim, “Performance analysis of intrusion detection for deep learning model based on CSE‑CIC‑IDS2018 dataset,” Indones. J. Electr. Eng. Comput. Sci., vol. 26, no. 2, p. 1165, 2022, doi: 10.11591/ijeecs.v26.i2.pp1165-1172.

“LightGBM: A Highly Efficient Gradient Boosting Decision Tree.” Accessed: Jul. 17, 2026. [Online]. Available: https://papers.nips.cc/paper_files/paper/2017/hash/6449f44a102fde848669bdd9eb6b76fa-Abstract.html

Muzun Althunayyan, Amir Javed, “A robust multi-stage intrusion detection system for in-vehicle network security using hierarchical federated learning,” Veh. Commun., vol. 49, p. 100837, 2024, doi: https://doi.org/10.1016/j.vehcom.2024.100837.

B. Schölkopf, J. C. Platt, J. Shawe-Taylor, A. J. Smola, and R. C. Williamson, “Estimating the support of a high-dimensional distribution,” Neural Comput., vol. 13, no. 7, pp. 1443–1471, Jul. 2001, doi: 10.1162/089976601750264965.

Polyzois Bountzis, Dimitris Kavallieros, “A deep one-class classifier for network anomaly detection using autoencoders and one-class support vector machines,” Front. Comput. Sci., vol. 7, 2025, doi: https://doi.org/10.3389/fcomp.2025.1646679.

Sevvandi Kandanaarachchi, Mahdi Abolghasemi, “Detection of Anomalous Network Nodes via Hierarchical Prediction and Extreme Value Theory,” arXiv:2304.13941, 2026, doi: https://arxiv.org/abs/2304.13941.

T. T. Nguyen, C. S. Shieh, C. H. Chen, and D. Miu, “Detection of unknown DDoS attacks with deep learning and Gaussian mixture model,” Proc. - 2021 4th Int. Conf. Inf. Comput. Technol. ICICT 2021, pp. 27–32, Mar. 2021, doi: 10.1109/ICICT52872.2021.00012.

“A deep learning approach for intrusion detection in Internet of Things using focal loss function | Request PDF.” Accessed: Jul. 17, 2026. [Online]. Available: https://www.researchgate.net/publication/367192516_A_deep_learning_approach_for_intrusion_detection_in_Internet_of_Things_using_focal_loss_function

M. W. Nawaz, R. Munawar, M. K. Bhatti, A. Mehmood, M. M. U. Rahman, and Q. H. Abbasi, “Multi-Class Network Intrusion Detection with Class Imbalance via LSTM & SMOTE,” Proc. - 2025 27th IEEE Int. Conf. High Perform. Comput. Commun. 11th IEEE Int. Conf. Data Sci. Syst. 23rd IEEE Int. Conf. Smart City, 11th IEEE Int. Conf. o…, pp. 824–831, 2025, doi: 10.1109/HPCC67675.2025.00123.

Abdullah Alzaqebah, Ibrahim Aljarah, “A hierarchical intrusion detection system based on extreme learning machine and nature-inspired optimization,” Comput. Secur., vol. 124, p. 102957, 2023, doi: https://doi.org/10.1016/j.cose.2022.102957.

Y. A. Rani, K. Deepthi Reddy, and R. U. Rani, “A Novel Network Intrusion Detection Model using Residual Recurrent Neural Network with Improved Garter Snake-based Optimization Strategy,” 2023 Glob. Conf. Inf. Technol. Commun. GCITC 2023, 2023, doi: 10.1109/GCITC60406.2023.10426136.

Marija Gombar, Amir Topalović, “Cost-Aware Lightweight Deep Learning for Intrusion Detection: A Comparative Study on UNSW-NB15 and CIC-IDS2017,” Electronics, vol. 15, no. 8, p. 1603, 2026, doi: 10.3390/electronics15081603.

C. Guida, A. Nascita, A. Montieri, and A. Pescape, “Cross-Evaluation of Deep Learning-based Network Intrusion Detection Systems,” Proc. - 2023 Int. Conf. Futur. Internet Things Cloud, FiCloud 2023, pp. 328–335, 2023, doi: 10.1109/FICLOUD58648.2023.00055.

Bianca Zadrozny, Charles Elkan, “Transforming Classifier Scores into Accurate Multiclass Probability Estimates,” Proc. ACM SIGKDD Int. Conf. Knowl. Discov. Data Min., 2002, doi: 10.1145/775047.775151.

Eugene Berta (SIERRA), Francis Bach (SIERRA), Michael Jordan (SIERRA), “Classifier Calibration with ROC-Regularized Isotonic Regression,” arXiv:2311.12436, 2023, [Online]. Available: https://arxiv.org/abs/2311.12436

Ehssan Mousavipour, Andrey Dimanchev, Majid Ghaderi, “Shift Detection and Adaptation for Network Intrusion Detection,” arXiv:2508.15100, 2026, [Online]. Available: https://arxiv.org/abs/2508.15100

M. Pawlicki, S. Szelest, R. Kozik, and M. Choraś, “SHAP Insights into Domain Adaptation in Netflow-Based Network Intrusion Detection Powered by Deep Learning,” Lect. Notes Comput. Sci., vol. 15999 LNCS, pp. 292–309, 2025, doi: 10.1007/978-3-032-00644-8_18/SAVE-RESEARCH.

Chaonan Xin, Keqing Xu, “Cross-Dataset Transformer-IDS with Calibration and AUC Optimization (Evaluated on NSL-KDD, UNSW-NB15, CIC-IDS2017),” J. Cyber Secur., vol. 7, no. 1, 2025, [Online]. Available: https://www.semanticscholar.org/paper/Cross-Dataset-Transformer-IDS-with-Calibration-and-Xin-Xu/daf8e3d4ae33e5ecb04ab5da524deb75d47b2d27

“CSE-CIC-IDS2018 on AWS”, [Online]. Available: https://www.unb.ca/cic/datasets/ids-2018.html

I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, “Toward generating a new intrusion detection dataset and intrusion traffic characterization,” ICISSP 2018 - Proc. 4th Int. Conf. Inf. Syst. Secur. Priv., vol. 2018-January, pp. 108–116, 2018, doi: 10.5220/0006639801080116.

N. Moustafa and J. Slay, “UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set),” 2015 Mil. Commun. Inf. Syst. Conf. MilCIS 2015 - Proc., Dec. 2015, doi: 10.1109/MILCIS.2015.7348942.

Downloads

Published

2026-07-11

How to Cite

Younas, M., Nisar, S., Hoor Ul Ain, Huzaifa Shahzad, Wasim Habib, Salman Ilahi Siddiqui, Ihsan Ul haq, & Muhammad Farooq. (2026). TITANIUM-4: A Low-Latency Four-Layer Intrusion Detection Pipeline and the Limits of Benchmark-Trained Thresholds under Domain Shift. International Journal of Innovations in Science & Technology, 8(4), 1559–1582. Retrieved from https://journal.50sea.com/index.php/IJIST/article/view/1956

Most read articles by the same author(s)