A Deep Reinforcement Learning–Based Adaptive Framework for Early DDoS Attack Detection and Prevention in Heterogeneous Networks

Authors

  • Sujit Sutradhar IT Department, ICFAI University, India https://orcid.org/0009-0003-4064-6180
  • Joy Lal Sarkar Department of Computer Science and Engineering, ICFAI University, India
  • Abhijit Biswas Faculty of Science & Technology, ICFAI University, India

DOI:

https://doi.org/10.47852/bonviewJDSIS62029543

Keywords:

deep reinforcement learning, DDoS detection, network security, adaptive intrusion detection, traffic classification

Abstract

Distributed Denial-of-Service (DDoS) attacks are constantly growing in scale, intensity, and attack plan strategies, which are causing significant threats to the heterogeneous network environments, including Internet of Things, edge, cloud, Software-Defined Networks, and 5G networks. This paper presents an adaptive framework of deep reinforcement learning (DRL) in early-stage detection and proactive mitigation of DDoS attacks. The proposed DRL agent operates in active network environments to develop policies through online learning. This helps it address new and unexpected attack patterns. Traditional machine learning and deep learning models depend on unchanging training methods, which run their training process from a fixed point in time. The framework combines the flow-level feature analysis and the packet-level feature analysis with the Deep Q-Network–based learning mechanism to facilitate real-time decision-making. Numerous experiments were carried out on benchmark datasets and heterogeneous traffic simulations. This indicates that the suggested methodology can be considered stable and offers an approximation of 98% accuracy, 96% precision, 96% recall, and 96% macro F1-score on the datasets with up to 300,000 network flows. Further flow analysis shows that flow duration, packet-level variability, and distribution of destination ports are critical in differentiating between benign and malicious traffic. The findings prove that the developed framework can offer detection and mitigation of DDoS threats, which are scalable, robust, and adaptive, to facilitate the creation of intelligent and self-educating cybersecurity systems in complex network settings.

 

Received: 6 March 2026 | Revised: 3 June 2026 | Accepted: 23 June 2026

 

Conflicts of Interest

The authors declare that they have no conflicts of interest to this work.

 

Data Availability Statement

The datasets used in this study, including CICDDoS2019, NSL-KDD, and UNSW-NB15, are publicly available through their respective repositories. The implementation details, preprocessing procedures, model configurations, and experimental settings are described within the manuscript to facilitate reproducibility. The source code and trained model configurations are available from the corresponding author upon reasonable request and will be considered for public repository release in future work to further enhance research transparency and reproducibility or can be accessed at https://www.kaggle.com/datasets/dhoogla/cicddos2019, https://www.kaggle.com/datasets/hassan06/nslkdd, and https://www.kaggle.com/datasets/mrwellsdavid/unswnb15.

 

Author Contribution Statement

Sujit Sutradhar: Conceptualization, Methodology, Software, Validation, Formal analysis, Investigation, Resources, Data curation, Writing – original draft, Writing – review & editing, Visualization, Project administration. Joy Lal Sarkar: Writing – review & editing, Visualization, Supervision, Project administration. Abhijit Biswas: Writing – review & editing, Supervision, Project administration.

Downloads

Published

2026-07-27

Issue

Section

Research Articles

How to Cite

Sutradhar, S., Sarkar, J. L., & Biswas, A. (2026). A Deep Reinforcement Learning–Based Adaptive Framework for Early DDoS Attack Detection and Prevention in Heterogeneous Networks. Journal of Data Science and Intelligent Systems. https://doi.org/10.47852/bonviewJDSIS62029543