A Hybrid Ensemble and Multi-Agent Reinforcement Learning Framework for Explainable Real-Time Network Intrusion Detection

Authors

  • Megha.M. Shete Department of Computer Network and Engineering, PDA College of Engineering, Kalaburagi, Karnataka India
  • Anuradha T Department of Computer Science and Engineering, PDA College of Engineering, Kalaburagi, Karnataka, India
  • Radha B.K Department of Computer Science and Engineering, PDA College of Engineering, Kalaburagi, Karnataka, India
  • Syed Umraz Department of Computer Science and Engineering, PDA College of Engineering, Kalaburagi, Karnataka, India

DOI:

https://doi.org/10.70917/ijcisim-2026-3762

Keywords:

NSL-KDD dataset, SHAP feature attribution, Random Forest classification, Isolation Forest anomaly scoring, Q-learning consensus, ensemble score fusion, security operations decision support

Abstract

Background: Signature-based intrusion detection systems (IDS) struggle against novel and evolving network attacks, while single-model machine-learning IDS often trade accuracy for interpretability and adaptability, limiting their trust and utility in operational security operations centers (SOCs).
Methods: We present a layered detection architecture that combines a supervised Random Forest classifier (100 estimators, max depth 10) with an unsupervised Isolation Forest (contamination = 0.05) via weighted score fusion (α = 0.7/0.3), refined by a multi-agent reinforcement learning (MARL) consensus layer of Q-learning agents (learning rate 0.1, discount factor 0.99, exploration rate 0.1), and interpreted post-hoc with SHAP feature attribution. The pipeline operates on the NSL-KDD benchmark (41 base features plus 3 engineered ratio/error features), with feature standardization and stratified train/test splitting, and is exposed through a Flask/Socket.IO real-time dashboard for streaming packet-level inference.
Results: Preliminary, literature-referenced benchmarks suggest accuracy in the 95–98% range for the supervised component, with ensemble and MARL-refined variants trading a small amount of raw accuracy for improved robustness and consensus confidence (>80%). These figures must be replaced with actual run output before this abstract is finalized.
Conclusion: The proposed framework demonstrates that combining supervised, unsupervised, ensemble, and reinforcement-learning-based consensus mechanisms with explainable AI is architecturally feasible for real-time network intrusion detection. Empirical validation against held-out data and comparison under identical experimental conditions to prior work is required to substantiate performance claims.

Downloads

Download data is not yet available.

Downloads

Published

2026-07-27

How to Cite

Megha.M. Shete, Anuradha T, Radha B.K, & Syed Umraz. (2026). A Hybrid Ensemble and Multi-Agent Reinforcement Learning Framework for Explainable Real-Time Network Intrusion Detection. International Journal of Computer Information Systems and Industrial Management Applications, 18(11s), 395–413. https://doi.org/10.70917/ijcisim-2026-3762

Issue

Section

Original Articles