GDEGWO: Enhancing grey wolf optimization with gradient descent and dynamic balance factors for optimized exploration-exploitation in network intrusion detection
Abstract Network intrusion detection remains a critical cybersecurity challenge, as existing metaheuristic optimizers suffer from premature convergence due to poor exploration–exploitation balance, and black-box AI models undermine analyst trust by lacking decision transparency. Addressing these gaps is essential, since ineffective detection and opaque decisions directly compromise network security and impede human oversight in high-stakes environments. This paper introduces GDEGWO (Gradient Descent Enhanced Grey Wolf Optimization), a hybrid optimizer designed to improve both detection accuracy and model interpretability in Network Intrusion Detection Systems (NIDS). GDEGWO integrates gradient descent into Grey Wolf Optimization (GWO) via a dynamic balance factor λ(t) that decreases linearly from 0.9 to 0.1, directly governing the transition from global exploration to local refinement across iterations. The optimizer was evaluated on the CEC2022 benchmark suite against ten baselines and applied to hyperparameter tuning of six machine learning and four deep learning classifiers on the NSL-KDD dataset, complemented by an explainable AI (XAI) framework combining SHAP and LIME. Benchmark results show statistically significant improvements over eight competitors (Wilcoxon signed-rank test), with 20–35% fewer iterations to converge compared to GWO, GMGWO, and PSO, despite a 20–30% higher per-iteration cost due to gradient computation. On NSL-KDD, GDEGWO achieves 100% binary classification accuracy with KNN and DT, and 99.99% multi-class accuracy with KNN, surpassing all previously reported results on this benchmark. In a controlled human-in-the-loop experiment, security analysts leveraging SHAP and LIME explanations reduced false positives by 15–20% through rule-based filtering. These findings position GDEGWO as a practical, high-performance optimization framework for intrusion detection, offering faster convergence, near-perfect accuracy, and the transparency needed to support trustworthy deployment in operational security environments.
Authors
- Sarah M. Ayyad (ORCID: https://orcid.org/0000-0001-8356-1644)
- Norhan S. ElMongy
- M. S. Saraya
Institutions
- Mansoura University (EG)
- Scientific Research Group in Egypt (EG)
- Mansoura National University (EG)
Publication Details
- Journal
- Journal of King Saud University - Computer and Information Sciences
- Published
- 2026-09-25
- DOI
- https://doi.org/10.1007/s44443-026-01020-x
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00