ISSN :2582-9793

Density-Aware Hybrid Clustering for Dynamic Attack Detection in Network Traffic: A Coreset-Driven Approach with Adaptive k-Means and DBSCAN

Original Research (Published On: 12-Aug-2026 )
DOI : https://doi.org/10.54364/AAIML.2026.64330

Heba Adnan Raheem

Adv. Artif. Intell. Mach. Learn., 6 (4):5965-5982

1. Heba Adnan Raheem: College of computer science and information technology

Download PDF Here

DOI: 10.54364/AAIML.2026.64330

Article History: Received on: 17-Apr-26, Accepted on: 05-Aug-26, Published on: 12-Aug-26

Corresponding Author: Heba Adnan Raheem

Email: hiba.adnan@uokerbala.edu.iq

Citation: Heba Adnan Raheem. Density-Aware Hybrid Clustering for Dynamic Attack Detection in Network Traffic: A CoresetDriven Approach with Adaptive k-Means and DBSCAN. Advances in Artificial Intelligence and Machine Learning. 2026;6(4):330. https://dx.doi.org/10.54364/AAIML.2026.64330


Abstract

Dynamic attack detection is a significant challenge in the face of fast-changing network traffic and new and changing threats. In this paper, we present a novel density-aware hybrid clustering framework, combining the probability density-aware coreset selection, density-weighted incremental k-means, and localized adaptive DBSCAN. The framework is implemented with an initial coreset size of |C| = 5000, learning rate of λ = 0.1, α = 0.5, and β = 0.7, and has a memory complexity of O(|C| + Kd2). The adaptive DBSCAN part adopts the following thresholds: the scaling parameter gamma = 1.2 and the minimum density fraction delta = 0.05, scaling the threshold values for each cluster. The proposed framework has analyzed the CIC-IDS2017 dataset, with a DR of 91.5%, low FPR of 5.2%, and an F1-Score of 0.92. These metrics significantly outperform standard baselines such as k-means++ (78.2% DR, 12.4% FPR, 0.81 F1), traditional DBSCAN (85.7% DR, 8.9% FPR, 0.86 F1), and streaming micro-cluster outlier detection (MCOD) (83.1% DR, 6.8% FPR, 0.87 F1). The computational evaluations show high streaming efficiency, with total processing time of 78ms/1000 instances (25ms for preprocessing and 53ms for clustering).  Furthermore, the framework identifies 89% of injected concept drifts with a mean detection latency of 127 instances. This combination of dynamic sampling, incremental updates, and localized parameter adaptation provides a highly efficient solution for real-time intrusion detection.


Statistics

Article Views: 292
PDF Downloads: 6