Feature-guided transformer approach for detecting distributed denial of service attacks
Abstract
Distributed denial of service (DDoS) attacks continues to pose serious risks to modern networks, with their growing intensity making early detection both critical and challenging. Conventional machine learning (ML) models often struggle with the nonlinear and highly dynamic nature of attack traffic, which motivates the use of advanced architectures. In this study investigate a transformer-based classifier for DDoS detection on the CIC-DDoS2019 dataset. The workflow included preprocessing, feature scaling, and domain-guided feature selection. Logistic regression (LR) was employed as a baseline, achieving 92.1% accuracy and F1-score of 0.90, thereby revealing the limitations of linear models. The transformer, after hyperparameter tuning and 5-fold cross-validation, reached an average accuracy of 99.95% with precision, recall, and F1-scores all above 99.9%. The model demonstrated stable convergence and generalization across folds. These results highlight the strength of attention mechanisms in capturing feature dependencies, while also pointing to future directions such as real-time deployment, explainability, and resilience to zero-day attacks.
Keywords
Deep learning for cybersecurity; Distributed denial of service; Intrusion detection systems; Network traffic classification; Transformer model
Full Text:
PDFDOI: http://doi.org/10.11591/ijai.v15.i4.pp3712-3721
Refbacks
- There are currently no refbacks.
Copyright (c) 2026 Lokeshwaran Kanagaraj, Raguraman Purushothaman, Sathya Subramanian, Durga Devi Saravanan, Komal Kumar Napa, Cornelius Karunakaran, Billa Manindhar

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
IAES International Journal of Artificial Intelligence (IJ-AI)
ISSN/e-ISSN 2089-4872/2252-8938
This journal is published by the Institute of Advanced Engineering and Science (IAES).