Original Research (Published On: 12-Aug-2026 )
DOI : https://doi.org/10.54364/AAIML.2026.64330Heba Adnan Raheem
Adv. Artif. Intell. Mach. Learn., 6 (4):5965-5982
1. Heba Adnan Raheem: College of computer science and information technology
DOI: 10.54364/AAIML.2026.64330
Article History: Received on: 17-Apr-26, Accepted on: 05-Aug-26, Published on: 12-Aug-26
Corresponding Author: Heba Adnan Raheem
Email: hiba.adnan@uokerbala.edu.iq
Citation: Heba Adnan Raheem. Density-Aware Hybrid Clustering for Dynamic Attack Detection in Network Traffic: A CoresetDriven Approach with Adaptive k-Means and DBSCAN. Advances in Artificial Intelligence and Machine Learning. 2026;6(4):330. https://dx.doi.org/10.54364/AAIML.2026.64330
Abstract
Dynamic
attack detection is a significant challenge in the face of fast-changing
network traffic and new and changing threats. In this paper, we present a novel
density-aware hybrid clustering framework, combining the probability
density-aware coreset selection, density-weighted incremental k-means, and
localized adaptive DBSCAN. The framework is implemented with an initial coreset
size of |C| = 5000, learning rate of λ = 0.1, α = 0.5, and β = 0.7, and has a memory
complexity of O(|C| + Kd2). The adaptive DBSCAN part adopts the
following thresholds: the scaling parameter gamma = 1.2 and the minimum density
fraction delta = 0.05, scaling the threshold values for each cluster. The
proposed framework has analyzed the CIC-IDS2017 dataset, with a DR of 91.5%, low
FPR of 5.2%, and an F1-Score of 0.92. These metrics significantly outperform
standard baselines such as k-means++ (78.2% DR, 12.4% FPR, 0.81 F1),
traditional DBSCAN (85.7% DR, 8.9% FPR, 0.86 F1), and streaming micro-cluster
outlier detection (MCOD) (83.1% DR, 6.8% FPR, 0.87 F1). The computational
evaluations show high streaming efficiency, with total processing time of
78ms/1000 instances (25ms for preprocessing and 53ms for clustering). Furthermore, the
framework identifies 89% of injected concept drifts with a mean detection
latency of 127 instances. This combination of dynamic sampling, incremental
updates, and localized parameter adaptation provides a highly efficient
solution for real-time intrusion detection.
Statistics
Article Views: 292
PDF Downloads: 6
