In contemporary 5G network environments, intrusion detection systems must balance detection accuracy with operational efficiency, as improvements in one dimension are often achieved at the expense of the other. This study addresses this trade-off by proposing a lightweight two-stage intrusion detection architecture that augments a standard decision-tree classifier with a conditional counter-inspection mechanism. At inference time, a global decision tree produces an initial classification for each traffic record, which is selectively validated by a small set of class-biased expert trees trained under controlled minority exposure. Only experts associated with the opposite class of the initial prediction are activated, and decision revision is governed by a unanimous-dissent rule, ensuring conservative and deterministic correction while avoiding over-correction. Experiments conducted on the 5G-NIDD dataset in a binary benign/malicious setting show that the proposed architecture consistently improves upon the standalone decision tree, reducing false negatives from 51 to 27 (−47.1%) and false positives from 48 to 30 (−37.5%), and achieving an F1-score of 0.99981 on a held-out test set. Ablation and paired statistical tests confirm that these gains arise from selective validation and the unanimous-dissent mechanism rather than from uniform ensembling. The complete pipeline operates in the microsecond inference regime per record, evaluates fewer models on average than flat voting strategies, and preserves full interpretability through deterministic decision paths, making it suitable for practical and resource-constrained 5G intrusion detection deployments.
TAHORI et al. (Wed,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: