A lightweight blockchain-inspired hybrid intrusion detection system with ensemble learning for tamper-proof auditing
Shailendra Mishra,
Reem Alshenaifi and
Ruba Ahmed Alfahidah
PLOS ONE, 2026, vol. 21, issue 9, 1-34
Abstract:
The rapid expansion of digital systems has intensified the complexity of cyber threats, rendering traditional intrusion detection systems (IDS) inadequate against evolving attacks. This study proposes a hybrid IDS (H-IDS) that integrates supervised (SVM, Random Forest, CatBoost, DNN) and unsupervised (Isolation Forest, One-Class SVM, Autoencoder) models within an ensemble framework. Preprocessing employs PCA for dimensionality reduction and SMOTE for class balancing, while weighted voting based on cross-validation F1-scores optimizes ensemble decisions. A lightweight blockchain-inspired hash-chained audit log provides tamper-evident logging of detection events in a single-node deployment without decentralized consensus. Evaluated on NSL-KDD and CIC-IDS2017 datasets, H-IDS achieves 98.85% accuracy (pre-blockchain) and 98.15% (post-blockchain). The ledger operates in a private, single-node setting and introduces minimal local logging overhead and observed reductions in false positives (paired t-test, n = 3, p
Date: 2026
References: Add references at CitEc
Citations:
Downloads: (external link)
https://journals.plos.org/plosone/article?id=10.1371/journal.pone.0356878 (text/html)
https://journals.plos.org/plosone/article/file?id= ... 56878&type=printable (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:plo:pone00:0356878
DOI: 10.1371/journal.pone.0356878
Access Statistics for this article
More articles in PLOS ONE from Public Library of Science
Bibliographic data for series maintained by plosone ().