article · Discover Applied Sciences
The advent of 6G networks and the rapid expansion of IoT ecosystems, particularly in energy hub (EH) networks, present significant challenges in ensuring secure and reliable communication. Among these, Distributed Denial-of-Service (DDoS) attacks pose a critical threat to the stability of IoT-enabled infrastructures. This study addresses these challenges by systematically evaluating a range of machine learning models and hybrid ensemble techniques tailored for DDoS detection in IoT-driven 6G EH networks. The performance of Random Forest (RF), Gradient Boosting (GB), Support Vector Machines (SVM), Decision Trees (DT), and K-Nearest Neighbors (KNN), as well as hybrid combinations like RF + KNN, GB + KNN, and GB + DT, was rigorously assessed across three benchmark datasets (CICDDOS2019, KDD-CUP, and UNSW-NB) with varying training data sizes (80% and 60%). Among these, RF + KNN emerged as the most effective, achieving the highest accuracy (99.44%) and F1-score (66.62%) on CICDDOS2019 while maintaining robust performance on UNSW-NB. GB + DT demonstrated superior precision (70.95%) on KDD-CUP, while GB + KNN achieved the highest recall (66.67%) on CICDDOS2019, highlighting its capability to minimize false negatives. The findings emphasize the influence of dataset characteristics and training sizes on model performance. CICDDOS2019 consistently produced the highest accuracy due to its well-defined class separability, while KDD-CUP exhibited greater variability and UNSW-NB provided stable yet moderate precision and recall. Smaller training data sizes generally led to performance degradation in F1-score and recall, although occasional accuracy improvements suggested potential overfitting with larger datasets. This research underscores the importance of tailoring hybrid ensemble models to the specific properties of datasets and attack types, offering a scalable, real-time framework for intrusion detection. By enhancing the security and resilience of IoT-driven 6G EH networks, this study provides practical solutions to mitigate the evolving threats posed by DDoS attacks.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.1007/s42452-025-06716-9
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.