GDEGWO: Enhancing grey wolf optimization with gradient descent and dynamic balance factors for optimized exploration-exploitation in network intrusion detection

Abstract Network intrusion detection remains a critical cybersecurity challenge, as existing metaheuristic optimizers suffer from premature convergence due to poor exploration–exploitation balance, and black-box AI models undermine analyst trust by lacking decision transparency. Addressing these gaps is essential, since ineffective detection and opaque decisions directly compromise network security and impede human oversight in high-stakes environments. This paper introduces GDEGWO (Gradient Descent Enhanced Grey Wolf Optimization), a hybrid optimizer designed to improve both detection accuracy and model interpretability in Network Intrusion Detection Systems (NIDS). GDEGWO integrates gradient descent into Grey Wolf Optimization (GWO) via a dynamic balance factor λ(t) that decreases linearly from 0.9 to 0.1, directly governing the transition from global exploration to local refinement across iterations. The optimizer was evaluated on the CEC2022 benchmark suite against ten baselines and applied to hyperparameter tuning of six machine learning and four deep learning classifiers on the NSL-KDD dataset, complemented by an explainable AI (XAI) framework combining SHAP and LIME. Benchmark results show statistically significant improvements over eight competitors (Wilcoxon signed-rank test), with 20–35% fewer iterations to converge compared to GWO, GMGWO, and PSO, despite a 20–30% higher per-iteration cost due to gradient computation. On NSL-KDD, GDEGWO achieves 100% binary classification accuracy with KNN and DT, and 99.99% multi-class accuracy with KNN, surpassing all previously reported results on this benchmark. In a controlled human-in-the-loop experiment, security analysts leveraging SHAP and LIME explanations reduced false positives by 15–20% through rule-based filtering. These findings position GDEGWO as a practical, high-performance optimization framework for intrusion detection, offering faster convergence, near-perfect accuracy, and the transparency needed to support trustworthy deployment in operational security environments.

Authors

Institutions

Publication Details

Journal
Journal of King Saud University - Computer and Information Sciences
Published
2026-09-25
DOI
https://doi.org/10.1007/s44443-026-01020-x
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

GDEGWO: Enhancing grey wolf optimization with gradient descent and dynamic balance factors for optimized exploration-exploitation in network intrusion detection

Sarah M. Ayyad, Norhan S. ElMongy, M. S. Saraya
Journal of King Saud University - Computer and Information Sciences
Network Security and Intrusion Detection
article

GDEGWO: Enhancing grey wolf optimization with gradient descent and dynamic balance factors for optimized exploration-exploitation in network intrusion detection

Sarah M. Ayyad, Norhan S. ElMongy, M. S. Saraya
article en

Abstract

Abstract Network intrusion detection remains a critical cybersecurity challenge, as existing metaheuristic optimizers suffer from premature convergence due to poor exploration–exploitation balance, and black-box AI models undermine analyst trust by lacking decision transparency. Addressing these gaps is essential, since ineffective detection and opaque decisions directly compromise network security and impede human oversight in high-stakes environments. This paper introduces GDEGWO (Gradient Descent Enhanced Grey Wolf Optimization), a hybrid optimizer designed to improve both detection accuracy and model interpretability in Network Intrusion Detection Systems (NIDS). GDEGWO integrates gradient descent into Grey Wolf Optimization (GWO) via a dynamic balance factor λ(t) that decreases linearly from 0.9 to 0.1, directly governing the transition from global exploration to local refinement across iterations. The optimizer was evaluated on the CEC2022 benchmark suite against ten baselines and applied to hyperparameter tuning of six machine learning and four deep learning classifiers on the NSL-KDD dataset, complemented by an explainable AI (XAI) framework combining SHAP and LIME. Benchmark results show statistically significant improvements over eight competitors (Wilcoxon signed-rank test), with 20–35% fewer iterations to converge compared to GWO, GMGWO, and PSO, despite a 20–30% higher per-iteration cost due to gradient computation. On NSL-KDD, GDEGWO achieves 100% binary classification accuracy with KNN and DT, and 99.99% multi-class accuracy with KNN, surpassing all previously reported results on this benchmark. In a controlled human-in-the-loop experiment, security analysts leveraging SHAP and LIME explanations reduced false positives by 15–20% through rule-based filtering. These findings position GDEGWO as a practical, high-performance optimization framework for intrusion detection, offering faster convergence, near-perfect accuracy, and the transparency needed to support trustworthy deployment in operational security environments.

Journal of King Saud University - Computer and Information SciencesVol. 38(8)
Mansoura University (EG), Scientific Research Group in Egypt (EG), Mansoura National University (EG)
Openalex Percentile: Top 9%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.