Anomaly detection is a critical task for identifying unusual patterns that may indicate security breaches, fraudulent transactions, or system failures in various application domains. Conventional anomaly detection techniques often experience high false positive rates and limited adaptability when handling complex, uncertain, or evolving datasets. To overcome these limitations, this study proposes a novel Fuzzy Cuckoo-Based Clustering Technique (F-CBCT) that integrates fuzzy logic with cuckoo search-based clustering and optimization. The proposed framework employs a decision tree classifier enhanced with fuzzy membership functions, enabling effective management of uncertainty during classification. Model parameters are optimized using a hybrid strategy based on Mean Square Error (MSE) and the Silhouette Index, improving clustering quality and classification accuracy. Experimental evaluations conducted on benchmark datasets demonstrate the effectiveness of the proposed approach, achieving a 96.86% detection rate, 97.77% accuracy, a 1.297% false positive rate, and an F-measure of 98.30%. Comparative analysis with existing state-of-the-art anomaly detection methods confirms that F-CBCT consistently outperforms conventional approaches in terms of detection capability, robustness, and reliability. The proposed technique effectively reduces false alarms while maintaining high detection performance, making it a promising solution for real-world anomaly detection applications across diverse and dynamic environments.
| Published in | Machine Learning Research (Volume 11, Issue 2) |
| DOI | 10.11648/j.mlr.20261102.11 |
| Page(s) | 63-75 |
| Creative Commons |
This is an Open Access article, distributed under the terms of the Creative Commons Attribution 4.0 International License (http://creativecommons.org/licenses/by/4.0/), which permits unrestricted use, distribution and reproduction in any medium or format, provided the original work is properly cited. |
| Copyright |
Copyright © The Author(s), 2026. Published by Science Publishing Group |
Fuzzy Clustering, Cuckoo-Inspired Optimization, Membership Functions, RMSE Analysis, Anomaly Detection, Intrusion Detection System (IDS)
Study / Year | Method Type | Technique Used | Detection Rate (DR%) | FPR (%) | Accuracy (%) | Key Strength | Key Limitation |
|---|---|---|---|---|---|---|---|
Kuang et al. (2007) | Statistical | Rule-based | 94.6 | 3.0 | 95.1 | Simple implementation | Moderate false alarms |
Hwang et al. (2007) | Statistical | Statistical model | 94.71 | 3.8 | N/A | Stable detection | Higher FPR |
Zhang et al. (2008) | Statistical | Statistical | ~94.7 | 2.0 | N/A | Improved FPR | Limited reporting |
Mukherjee et al. (2012) | ML | Predictive model | 90.92 | N/A | 97.78 | High accuracy | Lower DR |
Sharma et al. (2012) | ML | Classification model | 93.41 | 0.275 | >99 | Very low FPR | Moderate DR |
Panda et al. (2012) | ML | Hybrid ML | 99.5 | 0.1 | N/A | Very high DR/F-score | Dataset dependency |
Bhat et al. (2013) | ML | Classification | 99.1 | 2.0 | 99 | High precision | FPR still notable |
Elbasiony et al. (2013) | ML | Hybrid | 98.0 | 1.5 | N/A | Balanced performance | Missing accuracy |
Nadiammai et al. (2014) | ML | Decision-based | 96.86 | 0.5 | 98.12 | Balanced DR & FPR | Limited adaptability |
Mohammadi et al. (2014) | ML | Classification | 98.0 | 3.0 | N/A | High DR | Higher FPR |
Ghanem et al. (2015) | ML | Optimized model | N/A | 0.033 | 96.1 | Extremely low FPR | DR not reported |
Duque et al. (2015) | ML | Detection model | 70.75 | N/A | N/A | N/A | Very poor DR |
Pandeeswari et al. (2015) | ML | Classification | 98.0 | 3.05 | N/A | Good DR | Moderate F-score |
CNN-based IDS (Recent DL) | Deep Learning | CNN | ~98–99 | ~1–2 | ~98–99 | Automatic feature extraction | High computational cost |
LSTM-based IDS (Recent DL) | Deep Learning | LSTM | ~97–99 | ~1–3 | ~98 | Temporal learning capability | Training complexity |
Autoencoder-based IDS | Deep Learning | Autoencoder | ~96–98 | ~1–2 | ~97–98 | Unsupervised detection | Reconstruction bias |
Proposed F-CBCT | Hybrid | Fuzzy + Cuckoo Optimization | ~99+ (expected) | Very Low | High (~99) | Low complexity, interpretable, no large dataset requirement | Requires parameter tuning |
Parameter | Symbol | Tested Range | Selected Value | Justification |
|---|---|---|---|---|
Number of Clusters | K | 2 – 10 | 5 | Provided best balance between intra-cluster compactness and inter-cluster separation across datasets |
Population Size (Cuckoo Search) | N | 10 – 50 | 25 | Moderate size ensures sufficient exploration without high computational cost |
Discovery Rate | Pa | 0.1 – 0.5 | 0.25 | Balanced exploration and exploitation, minimizing premature convergence |
Step Size Scaling Factor | α | 0.01 – 1.0 | 0.1 | Smaller values improved convergence stability and reduced oscillations |
Maximum Iterations | Iter_max | 50 – 200 | 100 | Achieved convergence without excessive computation |
Membership Function Type | MF | trimf, trapmf, gaussmf, gbellmf, psigmf | psigmf | Lowest mean error and variance based on statistical evaluation |
Fuzzification Parameter | m | 1.5 – 3.0 | 2.0 | Standard value ensuring balanced fuzziness and cluster separation |
Fitness Function | N/A | MSE, SI, (MSE+SI) | MSE + SI | Combined metric improved both accuracy and cluster validity |
Threshold for Anomaly Detection | T | 0.2 – 0.8 | 0.5 | Optimal trade-off between detection rate and false positives |
Parameters | Alert | |||||
|---|---|---|---|---|---|---|
C Measure | AD-Measure | trimf | trapmf | gaussmf | gbellmf | psigmf |
0.00 | 0.00 | 0.113 | 0.110 | 0.101 | 0.099 | 0.112 |
0.00 | 0.25 | 0.133 | 0.121 | 0.126 | 0.120 | 0.120 |
0.00 | 0.50 | 0.113 | 0.110 | 0.198 | 0.132 | 0.161 |
0.00 | 0.75 | 0.625 | 0.600 | 0.608 | 0.622 | 0.576 |
0.00 | 1.00 | 0.625 | 0.600 | 0.623 | 0.624 | 0.583 |
0.25 | 0.00 | 0.137 | 0.130 | 0.137 | 0.164 | 0.127 |
0.25 | 0.25 | 0.137 | 0.130 | 0.162 | 0.173 | 0.135 |
0.25 | 0.50 | 0.332 | 0.249 | 0.374 | 0.367 | 0.271 |
0.25 | 1.00 | 0.625 | 0.600 | 0.623 | 0.622 | 0.579 |
0.50 | 0.00 | 0.113 | 0.110 | 0.150 | 0.106 | 0.137 |
0.50 | 0.25 | 0.133 | 0.121 | 0.189 | 0.130 | 0.148 |
0.50 | 0.50 | 0.625 | 0.600 | 0.573 | 0.601 | 0.564 |
0.50 | 0.75 | 0.886 | 0.878 | 0.800 | 0.892 | 0.830 |
0.50 | 1.00 | 0.903 | 0.888 | 0.848 | 0.903 | 0.841 |
0.75 | 0.00 | 0.375 | 0.379 | 0.390 | 0.376 | 0.380 |
0.75 | 0.25 | 0.375 | 0.379 | 0.411 | 0.377 | 0.385 |
0.75 | 0.50 | 0.625 | 0.600 | 0.610 | 0.603 | 0.585 |
0.75 | 0.75 | 0.883 | 0.868 | 0.836 | 0.849 | 0.841 |
0.75 | 1.00 | 0.883 | 0.868 | 0.857 | 0.872 | 0.848 |
1.00 | 0.00 | 0.375 | 0.375 | 0.391 | 0.375 | 0.379 |
1.00 | 0.25 | 0.375 | 0.377 | 0.403 | 0.376 | 0.383 |
1.00 | 0.50 | 0.625 | 0.600 | 0.616 | 0.617 | 0.587 |
1.00 | 0.75 | 0.886 | 0.878 | 0.863 | 0.883 | 0.854 |
1.00 | 1.00 | 0.903 | 0.888 | 0.897 | 0.909 | 0.866 |
Average | N/A | 0.4918 | 0.4774 | 0.4910 | 0.4913 | 0.4705 |
Dataset | Method | Accuracy (%) (Mean ± SD) | Variance | FPR (%) (Mean ± SD) | t-test (p-value) | Wilcoxon (p-value) | Significance |
|---|---|---|---|---|---|---|---|
Zoo | TVCPSO | 95.80 ± 1.22 | 1.49 | 2.78 ± 0.40 | <0.05 | <0.05 | Significant |
SSAD | 96.90 ± 0.95 | 0.90 | 1.85 ± 0.32 | <0.05 | <0.05 | Significant | |
F-CBCT | 97.75 ± 0.68 | 0.46 | 1.21 ± 0.25 | N/A | N/A | Best | |
Diabetes | K-Means | 90.45 ± 1.80 | 3.24 | 5.10 ± 0.62 | <0.05 | <0.05 | Significant |
SADA | 96.20 ± 1.05 | 1.10 | 2.05 ± 0.35 | <0.05 | <0.05 | Significant | |
F-CBCT | 97.35 ± 0.74 | 0.55 | 1.30 ± 0.28 | N/A | N/A | Best | |
Iris | Decision Tree | 92.10 ± 1.60 | 2.56 | 4.60 ± 0.58 | <0.05 | <0.05 | Significant |
FCOAC | 96.85 ± 1.02 | 1.04 | 2.12 ± 0.33 | <0.05 | <0.05 | Significant | |
F-CBCT | 97.90 ± 0.70 | 0.49 | 1.18 ± 0.26 | N/A | N/A | Best | |
Vehicle | TVCPSO | 95.25 ± 1.28 | 1.64 | 2.95 ± 0.45 | <0.05 | <0.05 | Significant |
SSAD | 96.95 ± 0.98 | 0.96 | 1.92 ± 0.30 | <0.05 | <0.05 | Significant | |
F-CBCT | 97.62 ± 0.75 | 0.56 | 1.27 ± 0.27 | N/A | N/A | Best | |
Wine | K-Means | 91.35 ± 1.75 | 3.06 | 4.85 ± 0.60 | <0.05 | <0.05 | Significant |
FCOAC | 96.70 ± 1.08 | 1.17 | 2.15 ± 0.34 | <0.05 | <0.05 | Significant | |
F-CBCT | 97.80 ± 0.72 | 0.52 | 1.22 ± 0.26 | N/A | N/A | Best | |
Glass | Decision Tree | 92.75 ± 1.58 | 2.49 | 4.72 ± 0.55 | <0.05 | <0.05 | Significant |
SADA | 97.05 ± 0.97 | 0.94 | 1.88 ± 0.29 | <0.05 | <0.05 | Significant | |
F-CBCT | 97.68 ± 0.70 | 0.49 | 1.25 ± 0.27 | N/A | N/A | Best | |
NSL-KDD | TVCPSO | 96.10 ± 1.25 | 1.56 | 2.85 ± 0.42 | <0.05 | <0.05 | Significant |
SSAD | 97.20 ± 0.94 | 0.88 | 1.80 ± 0.30 | <0.05 | <0.05 | Significant | |
F-CBCT | 98.05 ± 0.68 | 0.46 | 1.19 ± 0.24 | N/A | N/A | Best |
F-CBCT | Fuzzy Cuckoo-Based Clustering Technique |
MSE | Mean Square Error |
PSO | Particle Swarm Optimization |
CSO | Cuckoo Search Optimization |
DR | Detection Rate |
FPR | False Positive Rate |
CNNs | Convolutional Neural Networks |
LSTM | Long Short-Term Memory |
CSO | Cuckoo Search Optimization |
MFs | Membership functions |
MSE | Mean Square Error |
SI | Silhouette Index |
PSO | Particle Swarm Optimization |
SSAD | Self-Supervised Anomaly Detection |
SADA | Self-Adaptive Anomaly Detection algorithm |
TVCPSO | Time-Varying Coefficients Particle Swarm Optimization |
FCOAC | Fuzzy Cuckoo Optimization Ant Colony |
| [1] | S. Alam and M. A. Faisal, “A comprehensive review: Anomaly detection techniques on social networking and its applications,” Advances in Science, Engineering and Technology, vol. 303, p. 303, 2025, |
| [2] | M. Tahir, A. Abdullah, N. I. Udzir, and K. A. Kasmiran, “A systematic review of machine learning and deep learning techniques for anomaly detection in data mining,” International Journal of Computers and Applications, vol. 47, no. 2, p. 169, 2025, |
| [3] | A. M. Abdallah et al., “Cloud network anomaly detection using machine and deep learning techniques—recent research advancements,” IEEE Access, vol. 12, p. 56749, 2024, |
| [4] | A. Momand, S. U. Jan, and N. Ramzan, “A systematic and comprehensive survey of recent advances in intrusion detection systems using machine learning: Deep learning, datasets, and attack taxonomy,” Journal of Sensors, vol. 2023, p. 6048087, 2023, |
| [5] | S. A. Varma and K. G. Reddy, “A review of DDoS attacks and its countermeasures in cloud computing,” in Proc. 5th Int. Conf. Inf. Syst. Comput. Netw. (ISCON), 2021, p. 1, |
| [6] | L. Kuang and M. Zulkernine, “DNIDS: A dependable network intrusion detection system using the CSI-KNN algorithm,” 2007. Available: |
| [7] | T. S. Hwang, T. J. Lee, and Y. J. Lee, “A three-tier IDS via data mining approach,” in Proc. 3rd ACM Workshop Mining Netw. Data, 2007, p. 1, |
| [8] | J. Zhang, M. Zulkernine, and A. Haque, “Random-forests-based network intrusion detection systems,” IEEE Trans. Syst., Man, Cybern. C, vol. 38, no. 5, p. 649, 2008, |
| [9] | S. Mukherjee and N. Sharma, “Intrusion detection using Naive Bayes classifier with feature reduction,” Procedia Technology, vol. 4, p. 119, 2012, |
| [10] | N. Sharma and S. Mukherjee, “A novel multi-classifier layered approach to improve minority attack detection in IDS,” Procedia Technology, vol. 6, p. 913, 2012, |
| [11] | M. Panda, A. Abraham, and M. R. Patra, “A hybrid intelligent approach for network intrusion detection,” Procedia Engineering, vol. 30, p. 1, 2012, |
| [12] | Al-Ghuwairi, A.-R., Sharrab, Y., Al-Fraihat, D., AlElaimat, M., Alsarhan, A., & Algarni, A. (2023). Intrusion detection in cloud computing based on time series anomalies utilizing machine learning. Journal of Cloud Computing, 12, 127. |
| [13] | R. M. Elbasiony et al., “A hybrid network intrusion detection framework based on random forests and weighted K-means,” Ain Shams Eng. J., vol. 4, no. 4, p. 753, 2013, |
| [14] | G. V. Nadiammai and M. Hemalatha, “Effective approach toward intrusion detection system using data mining techniques,” Egyptian Informatics Journal, vol. 15, no. 1, p. 37, 2014, |
| [15] | M. Mohammadi et al., “A fast anomaly detection system using probabilistic artificial immune algorithm capable of learning new attacks,” Evolutionary Intelligence, vol. 6, no. 3, p. 135, 2014, |
| [16] | T. F. Ghanem, W. S. Elkilani, and H. M. Abdul-Kader, “A hybrid approach for efficient anomaly detection using metaheuristic methods,” Journal of Advanced Research, vol. 6, no. 4, pp. 609–619, 2015, |
| [17] | S. Duque and M. N. bin Omar, “Using data mining algorithms for developing a model for intrusion detection system (IDS),” Procedia Computer Science, vol. 61, p. 46, 2015, |
| [18] | N. Pandeeswari and G. Kumar, “Anomaly detection system in cloud environment using fuzzy clustering based ANN,” Mobile Networks and Applications, vol. 21, no. 3, p. 494, 2016, |
| [19] | I. Gupta, A. Bajaj, M. Malhotra, V. Sharma, and A. Abraham, “Heart disease prediction using a hybrid feature selection and ensemble learning approach”, IEEE Access, 2025, |
| [20] | O. Salima, N. Asri, and H. J. Hamid, “Machine learning techniques for anomaly detection: An overview,” International Journal of Computer Applications Volume 79 – No. 2, October 2013 (0975 – 8887), |
| [21] | R. Kaur and S. Singh, “A survey of data mining and social network analysis-based anomaly detection techniques,” Egyptian Informatics Journal, vol. 17, no. 2, pp. 199–216, Jul. 2016. |
APA Style
Lodhi, P. D., Nagarch, R. K., Nema, S. (2026). Improving Anomaly Detection Accuracy Using Fuzzy Cuckoo-Inspired Clustering and Optimization Techniques. Machine Learning Research, 11(2), 63-75. https://doi.org/10.11648/j.mlr.20261102.11
ACS Style
Lodhi, P. D.; Nagarch, R. K.; Nema, S. Improving Anomaly Detection Accuracy Using Fuzzy Cuckoo-Inspired Clustering and Optimization Techniques. Mach. Learn. Res. 2026, 11(2), 63-75. doi: 10.11648/j.mlr.20261102.11
@article{10.11648/j.mlr.20261102.11,
author = {Parmeshwar Dayal Lodhi and Ram Kumar Nagarch and Sujata Nema},
title = {Improving Anomaly Detection Accuracy Using Fuzzy Cuckoo-Inspired Clustering and Optimization Techniques},
journal = {Machine Learning Research},
volume = {11},
number = {2},
pages = {63-75},
doi = {10.11648/j.mlr.20261102.11},
url = {https://doi.org/10.11648/j.mlr.20261102.11},
eprint = {https://article.sciencepublishinggroup.com/pdf/10.11648.j.mlr.20261102.11},
abstract = {Anomaly detection is a critical task for identifying unusual patterns that may indicate security breaches, fraudulent transactions, or system failures in various application domains. Conventional anomaly detection techniques often experience high false positive rates and limited adaptability when handling complex, uncertain, or evolving datasets. To overcome these limitations, this study proposes a novel Fuzzy Cuckoo-Based Clustering Technique (F-CBCT) that integrates fuzzy logic with cuckoo search-based clustering and optimization. The proposed framework employs a decision tree classifier enhanced with fuzzy membership functions, enabling effective management of uncertainty during classification. Model parameters are optimized using a hybrid strategy based on Mean Square Error (MSE) and the Silhouette Index, improving clustering quality and classification accuracy. Experimental evaluations conducted on benchmark datasets demonstrate the effectiveness of the proposed approach, achieving a 96.86% detection rate, 97.77% accuracy, a 1.297% false positive rate, and an F-measure of 98.30%. Comparative analysis with existing state-of-the-art anomaly detection methods confirms that F-CBCT consistently outperforms conventional approaches in terms of detection capability, robustness, and reliability. The proposed technique effectively reduces false alarms while maintaining high detection performance, making it a promising solution for real-world anomaly detection applications across diverse and dynamic environments.},
year = {2026}
}
TY - JOUR T1 - Improving Anomaly Detection Accuracy Using Fuzzy Cuckoo-Inspired Clustering and Optimization Techniques AU - Parmeshwar Dayal Lodhi AU - Ram Kumar Nagarch AU - Sujata Nema Y1 - 2026/07/22 PY - 2026 N1 - https://doi.org/10.11648/j.mlr.20261102.11 DO - 10.11648/j.mlr.20261102.11 T2 - Machine Learning Research JF - Machine Learning Research JO - Machine Learning Research SP - 63 EP - 75 PB - Science Publishing Group SN - 2637-5680 UR - https://doi.org/10.11648/j.mlr.20261102.11 AB - Anomaly detection is a critical task for identifying unusual patterns that may indicate security breaches, fraudulent transactions, or system failures in various application domains. Conventional anomaly detection techniques often experience high false positive rates and limited adaptability when handling complex, uncertain, or evolving datasets. To overcome these limitations, this study proposes a novel Fuzzy Cuckoo-Based Clustering Technique (F-CBCT) that integrates fuzzy logic with cuckoo search-based clustering and optimization. The proposed framework employs a decision tree classifier enhanced with fuzzy membership functions, enabling effective management of uncertainty during classification. Model parameters are optimized using a hybrid strategy based on Mean Square Error (MSE) and the Silhouette Index, improving clustering quality and classification accuracy. Experimental evaluations conducted on benchmark datasets demonstrate the effectiveness of the proposed approach, achieving a 96.86% detection rate, 97.77% accuracy, a 1.297% false positive rate, and an F-measure of 98.30%. Comparative analysis with existing state-of-the-art anomaly detection methods confirms that F-CBCT consistently outperforms conventional approaches in terms of detection capability, robustness, and reliability. The proposed technique effectively reduces false alarms while maintaining high detection performance, making it a promising solution for real-world anomaly detection applications across diverse and dynamic environments. VL - 11 IS - 2 ER -