TY - GEN
T1 - IDSLab
T2 - ACM International Conference on the Foundations of Software Engineering, FSE 2026
AU - Morsli, Reda
AU - Kara, Nadjia
AU - Ould-Slimane, Hakima
AU - Lahlou, Laaziz
N1 - Publisher Copyright:
© 2026 Copyright held by the owner/author(s).
PY - 2026/7/17
Y1 - 2026/7/17
N2 - Developing machine learning-based intrusion detection systems (IDS) remains a fragmented and engineering-intensive process, often relying on ad-hoc pipelines for data collection, preprocessing, labeling, and experimentation. Moreover, most existing IDS datasets focus primarily on network-level data, despite growing evidence that combining heterogeneous sources can improve detection robustness. We present IDSLab, a low-code experimental platform designed to support data-centric IDS research and prototyping. IDSLab integrates environment management, adversary simulation, scalable multi-source data collection, and graph-based dataset construction within a single extensible framework, exposed through an interactive graphical interface. We describe the architecture and implementation of IDSLab and demonstrate its utility through an end-to-end use case involving dataset construction and ML-based DoS detection in a Kubernetes environment.
AB - Developing machine learning-based intrusion detection systems (IDS) remains a fragmented and engineering-intensive process, often relying on ad-hoc pipelines for data collection, preprocessing, labeling, and experimentation. Moreover, most existing IDS datasets focus primarily on network-level data, despite growing evidence that combining heterogeneous sources can improve detection robustness. We present IDSLab, a low-code experimental platform designed to support data-centric IDS research and prototyping. IDSLab integrates environment management, adversary simulation, scalable multi-source data collection, and graph-based dataset construction within a single extensible framework, exposed through an interactive graphical interface. We describe the architecture and implementation of IDSLab and demonstrate its utility through an end-to-end use case involving dataset construction and ML-based DoS detection in a Kubernetes environment.
KW - data collection
KW - dataset construction
KW - intrusion detection systems (IDS)
KW - machine learning
UR - https://www.scopus.com/pages/publications/105045846741
U2 - 10.1145/3803437.3806411
DO - 10.1145/3803437.3806411
M3 - Contribution to conference proceedings
AN - SCOPUS:105045846741
T3 - FSE Companion 2026 - Proceedings of the 34th ACM International Conference on the Foundations of Software Engineering
SP - 157
EP - 161
BT - FSE Companion 2026 - Proceedings of the 34th ACM International Conference on the Foundations of Software Engineering
A2 - Tan, Shin Hwei
A2 - Khomh, Foutse
PB - Association for Computing Machinery, Inc
Y2 - 5 July 2026 through 9 July 2026
ER -