Hayretdin Bahsi

dblp:97/8851 · DBLP profile ↗
← Back
37ranked-venue papers
2as first author
28since 2021 · last 2026
0000-0001-8882-4095ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 24 · 1 first-author · 20 since 2021Artificial intelligence and machine learning · 7 · 1 first-author · 3 since 2021Computer networks · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-authorSystems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A Scrutiny of SLMs' Performances for Mobile Malware Detection
Ants Torim, Hayretdin Bahsi, Sadok Ben Yahia
ICISSP (1)3
2026 Enhancing Continual Learning for Software Vulnerability Prediction: Addressing Catastrophic Forgetting via Hybrid‑Confidence‑Aware Selective Replay for Temporal LLM Fine-Tuning
Xuhui Dou, Hayretdin Bahsi, Alejandro Guerra-Manzanares
ICISSP (1)2
2026 Evaluating the Effectiveness of Multi-Agent Large Language Models for Automated Vulnerable Code Repair
Martin Kilgi, Hayretdin Bahsi
ICISSP (1)2
2026 Advancing Security Incident Analysis with LLMs: A Study Using a Novel Security Log Dataset
Artur Nikitchuk, Hayretdin Bahsi
ICISSP (1)2
2026 Incremental Federated Learning for Intrusion Detection in IoT Networks under Evolving Threat Landscape
abstract
International audience
Muaan ur Rehman, Hayretdin Bahsi, Rajesh Kalakoti
ICISSP (1)2
2026 Bridging industrial control systems design and testing through threat modeling-driven penetration testing - a microgrid case study
abstract
While threat modeling is widely recommended to support penetration test planning, penetration testing can, in turn, serve to verify and validate design-phase threat modeling outcomes. Yet, this interrelation remains largely overlooked in academic research. To address this gap, this study proposes BRIDGE, a nine-stage threat modeling-driven penetration testing methodology that connects the design and testing phases. Guided by design-phase threat modeling results, the methodology supports structured test selection, enabling a more focused and efficient testing process. The study introduces a mapping of MITRE ATT&CK for ICS techniques to STRIDE threat categories, establishing a key link between high-level threat analysis performed during system design and the intermediate-level attack representation required for penetration test planning. The methodology’s practical applicability is demonstrated through a real-world case study of a recently deployed microgrid system. The study also examines the effectiveness of CVSS v4.0 compared to v3.1 in representing the distinctive risk profile of ICS vulnerabilities, considering both security requirements and potential safety impacts. This research provides practical guidance for ICS cybersecurity practitioners to enhance penetration test planning efficiency, ensure adequate coverage of critical threat testing, and streamline collaboration with third-party testers. Researchers can leverage the proposed methodology and the MITRE ATT&CK to STRIDE mapping to develop detailed ICS testing procedures, thereby contributing to the advancement of structured ICS security testing practices.
Shaymaa Mamdouh Khalil, Hayretdin Bahsi, Tarmo Korõtko
Comput. Secur.2
2026 Synthetic Data-Driven Explainability for Federated Learning-Based Intrusion Detection System
abstract
An Intrusion Detection System (IDS) is vital for monitoring network traffic and alerting users to threats. Unlike traditional IDS, which relies on centralized data processing and raises privacy concerns, Federated Learning (FL)-based IDSs enable collaborative model training among multiple clients while keeping user data private. However, explaining model behavior in FL using Explainable AI (XAI) is challenging due to its distributed nature and lack of access to client data. Traditional XAI methods like LIME and SHAP require input data, which conflicts with FL’s privacy constraints. In this work, we develop a deep neural network (DNN)-based IDS in FL setup in Non-IID (non-independent and identically distributed) settings. Our FL-DNN model achieves high performance in binary classification for detecting malicious network traffic. In this work, we propose a novel privacy-preserving, explainable federated learning framework that uses high-quality synthetic data to enable explainability of the Global DNN model without exposing client data to the server. To generate synthetic data, we train multiple federated generative models in Non-IID settings. Among them, the Federated Wasserstein Conditional GAN with Gradient Penalty (FL-WCGAN-GP) produces synthetic samples with high data quality at the server. These synthetic samples on the server side are then used as reference inputs for post-hoc XAI methods for explaining the global DNN model. We assess the sufficiency of synthetic data-based explanations for the Global DNN model using SHAP, showing that Synthetic data-based explanations closely approximate the explanations derived from real client data. Further, we quantitatively evaluate post-local explanations of LIME and SHAP based on faithfulness and robustness. Results show that SHAP provides more faithful and robust explanations than LIME for client-side models using real data and server-side models using synthetic data, supporting privacy-preserving explainability in trustworthy FL-based IDS.
Rajesh Kalakoti, Hayretdin Bahsi, Sven Nomm
IEEE Internet Things J.2
2025 Evaluating Explainable AI for Deep Learning-Based Network Intrusion Detection System Alert Classification
abstract
A Network Intrusion Detection System (NIDS) monitors networks for cyber attacks and other unwanted activities. However, NIDS solutions often generate an overwhelming number of alerts daily, making it challenging for analysts to prioritize high-priority threats. While deep learning models promise to automate the prioritization of NIDS alerts, the lack of transparency in these models can undermine trust in their decision-making. This study highlights the critical need for explainable artificial intelligence (XAI) in NIDS alert classification to improve trust and interpretability. We employed a real-world NIDS alert dataset from Security Operations Center (SOC) of TalTech (Tallinn University Of Technology) in Estonia, developing a Long Short-Term Memory (LSTM) model to prioritize alerts. To explain the LSTM model's alert prioritization decisions, we implemented and compared four XAI methods: Local Interpretable Model-Agnostic Explanations (LIME), SHapley Additive exPlanations (SHAP), Integrated Gradients, and DeepLIFT. The quality of these XAI methods was assessed using a comprehensive framework that evaluated faithfulness, complexity, robustness, and reliability. Our results demonstrate that DeepLIFT consistently outperformed the other XAI methods, providing explanations with high faithfulness, low complexity, robust performance, and strong reliability. In collaboration with SOC analysts, we identified key features essential for effective alert classification. The strong alignment between these analyst-identified features and those obtained by the XAI methods validates their effectiveness and enhances the practical applicability of our approach.
Rajesh Kalakoti, Risto Vaarandi, Hayretdin Bahsi, Sven Nomm
ICISSP (1)3
2025 Cyber Threat Modeling of an LLM-Based Healthcare System
Neha Nagaraja, Hayretdin Bahsi
ICISSP (1)2
2025 Comprehensive Feature Selection for Machine Learning-Based Intrusion Detection in Healthcare IoMT Networks
abstract
International audience
Muaan ur Rehman, Rajesh Kalakoti, Hayretdin Bahsi
ICISSP (2)3
2025 Exploring the Impact of Feature Selection on Non-Stationary Intrusion Detection Models in IoT Networks
abstract
The proliferation of Internet of Things (IoT) devices has increased the attack surface of networks, necessitating robust and adaptive security mechanisms such as machine learning (ML)-based intrusion detection systems (IDS). However, the effectiveness of these systems can degrade over time due to concept drift, where patterns in data evolve as attackers develop new techniques. This study investigates the role of feature selection in enhancing the long-term performance of non-stationary IDS models in IoT networks. Specifically, we apply a filter-based feature reduction technique, Mutual Information, in conjunction with XGBoost models, to evaluate two learning paradigms i.e. static (trained once) and dynamic (periodically retrained). Using the CICIoMT2024 dataset, which includes 18 attack variants across five major categories, we conduct multiclass classification to provide a granular analysis of security threats. Our results demonstrate how selected features perform under different drift conditions and highlight critical network features for evolving attack detection. The study offers new insights into the interplay between feature selection and model adaptability in dynamic IoT environments, aiming to inform the development of more resilient IDS solutions.
Muaan ur Rehman, Hayretdin Bahsi, Rajesh Kalakoti
PST2
2025 Federated Learning of Explainable AI(FedXAI) for deep learning-based intrusion detection in IoT networks
Rajesh Kalakoti, Sven Nomm, Hayretdin Bahsi
Comput. Networks3
2024 The Design and Implementation of a Semantic Web Framework for the Event-Centric Digital Forensics Analysis
Pavel Chikul, Hayretdin Bahsi, Olaf Maennel
ICISSP2
2024 Explainable Transformer-based Intrusion Detection in Internet of Medical Things (IoMT) Networks
abstract
Internet of Medical Things (IoMT) systems have brought transformative benefits to patient monitoring and remote diagnosis in healthcare. However, these systems are prone to various cyber attacks that have a high impact on security and privacy. Detecting such attacks is crucial for implementing timely and effective countermeasures. Machine learning methods have been applied for intrusion detection tasks in various networks, but explaining the reasons for detection decisions remains an obstacle for security analysts. In this paper, we demonstrate that Transformer architecture, the core of the recent revolutionary large language models, constitutes a promising solution for intrusion detection in IoMT networks. We utilized a comprehensive dataset, CICIoMT2024, recently released specifically for these networks. We created a binary classification model for discriminating attacks from benign traffic and a multi-class model for the identification of specific attack types. We applied Explainable AI (XAi) methods such as LIME and SHAP to generate posthoc explanations for the model decisions. We evaluated and compared the quality of explanations based on three metrics: faithfulness, sensitivity, and complexity. Our findings demonstrate that the applied XAI methods enhance transparency in the predictions of Transformer-based intrusion detection models for IoMT networks, proving that both transparency and high performance can be achieved simultaneously.
Rajesh Kalakoti, Sven Nomm, Hayretdin Bahsi
ICMLA3
2024 Threat modeling of industrial control systems: A systematic literature review
abstract
Threat modeling is the process of identifying and mitigating potential threats to a system. It was originally developed to enhance software security during the design phase but has since been adapted for Industrial Control Systems (ICSs). ICSs are complex and interconnected systems that control critical infrastructure, such as power plants, water treatment facilities, and manufacturing plants. As such, they are major targets for cyberattacks, which may lead to human casualties, severe national security impacts, and financial instability. This systematic literature review explores the existing threat modeling methodologies for ICSs and emphasizes the importance of employing methodical frameworks that cover safety, security, and privacy aspects with clear procedural guidelines. The review reveals that ICSs threat modeling often lacks validation to ensure that the used methodologies are effective in identifying and mitigating threats. This study emphasizes the need to develop and apply better validation metrics in case studies. The main goal of this review is to help cyber security researchers and practitioners in selecting a suitable threat modeling approach that facilitates the creation of ICSs with an acceptable level of security.
Shaymaa Mamdouh Khalil, Hayretdin Bahsi, Tarmo Korõtko
Comput. Secur.2
2024 Improving IoT Security With Explainable AI: Quantitative Evaluation of Explainability for IoT Botnet Detection
abstract
Detecting botnets is an essential task to ensure the security of IoT systems. Machine learning-based approaches have been widely used for this purpose, but the lack of interpretability and transparency of the models often limits their effectiveness. In this research paper, our aim is to improve the transparency and interpretability of high-performance machine learning models for IoT botnet detection by selecting higher-quality explanations using explainable artificial intelligence (XAI) techniques. We used three datasets to induce binary and multiclass classification models for IoT botnet detection, with Sequential Backward Selection employed as the feature selection technique. We then use two post hoc XAI techniques such as LIME and SHAP, to explain the behaviour of the models. To evaluate the quality of explanations generated by XAI methods, we employed faithfulness, monotonicity, complexity, and sensitivity metrics. ML models employed in this work achieve very high detection rates with a limited number of features. Our findings demonstrate the effectiveness of XAI methods in improving the interpretability and transparency of machine learning-based IoT botnet detection models. Specifically, explanations generated by applying LIME and SHAP to the XGBoost model yield high faithfulness, high Consistency, low complexity, and low sensitivity. Furthermore, SHAP outperforms LIME by achieving better results in these metrics.
Rajesh Kalakoti, Hayretdin Bahsi, Sven Nomm
IEEE Internet Things J.2
2023 Anomalous File System Activity Detection Through Temporal Association Rule Mining
abstract
International audience
Mohammad Reza Heidari Iman, Pavel Chikul, Gert Jervan, Hayretdin Bahsi, Tara Ghasempouri
ICISSP4
2023 Improving Transparency and Explainability of Deep Learning Based IoT Botnet Detection Using Explainable Artificial Intelligence (XAI)
abstract
Ensuring the utmost security of loT systems is imperative, and robust botnet detection plays a pivotal role in achieving this goal. Deep learning-based approaches have been widely employed for botnet detection. However, the lack of interpretability and transparency in these models can limit these models' effectiveness. In this research, we present a Deep Neural Network (DNN) model specifically designed for the detection of loT botnet attack types. Our model performs exceptionally, demonstrating outstanding performance of classification metrics with 99% accuracy, F1 score, recall, and precision. To gain deeper insights into our DNN model's behaviour, we employ seven different post hoc explanation techniques to provide local expla-nations. We evaluate the quality of Explainable AI (XAI) methods using metrics such as high faithfulness, monotonicity, complexity, and sensitivity. Our findings highlight the effectiveness of XAI techniques in enhancing the interpretability and transparency of the DNN model for loT botnet detection. Specifically, our results indicate that DeepLIFT yields high faithfulness, high consistency, low complexity, and low sensitivity among all the explainers.
Rajesh Kalakoti, Sven Nomm, Hayretdin Bahsi
ICMLA3
2023 Corrigendum to Concept drift and cross-device behavior: Challenges and implications for effective android malware detection Computers & Security, Volume 120, 102757
Alejandro Guerra-Manzanares, Marcin Luckner, Hayretdin Bahsi
Comput. Secur.3
2023 Threat Modeling of Cyber-Physical Systems - A Case Study of a Microgrid System
abstract
Cyber threat modeling is an analytical process that is used for identifying the potential threats against a system and supporting the selection of security requirements in the early stages of the system development life cycle. Thus, threat modeling is a vital instrument for the realization of the secure-by-design principle. Despite being a well-known practice in software development projects, its adaptation to cyber-physical systems still requires systematic elaboration. The complex interactions between cyber and physical spaces and their reflection on the cyber threat landscape constitute a significant challenge for the system development teams. This study proposes a detailed methodology to apply STRIDE to cyber-physical systems and demonstrates its applicability in a case study of a microgrid system. Our methodology provides a systematic threat elicitation procedure based on an attack taxonomy that was created for this research. This paper also shows how assets could be identified, data flow diagrams formed, trust boundaries determined, and threats prioritized, in the case of a cyber-physical system.
Shaymaa Mamdouh Khalil, Hayretdin Bahsi, Henry Ochieng' Dola, Tarmo Korõtko, Kieran McLaughlin, Vahur Kotkas
Comput. Secur.2
2023 On the application of active learning for efficient and effective IoT botnet detection
Alejandro Guerra-Manzanares, Hayretdin Bahsi
Future Gener. Comput. Syst.2
2022 On the Application of Active Learning to Handle Data Evolution in Android Malware Detection
Alejandro Guerra-Manzanares, Hayretdin Bahsi
ICDF2C2
2022 Deep Learning-Based Detection of Cyberattacks in Software-Defined Networks
Seyed Mohammad Hadi Mirsadeghi, Hayretdin Bahsi, Wissem Inbouli
ICDF2C2
2022 Concept drift and cross-device behavior: Challenges and implications for effective android malware detection
Alejandro Guerra-Manzanares, Marcin Luckner, Hayretdin Bahsi
Comput. Secur.3
2022 On the relativity of time: Implications and challenges of data drift on long-term effective android malware detection
Alejandro Guerra-Manzanares, Hayretdin Bahsi
Comput. Secur.2
2022 Android malware concept drift using system calls: Detection, characterization and challenges
Alejandro Guerra-Manzanares, Marcin Luckner, Hayretdin Bahsi
Expert Syst. Appl.3
2021 An Ontology Engineering Case Study for Advanced Digital Forensic Analysis
Pavel Chikul, Hayretdin Bahsi, Olaf Maennel
MEDI2
2021 KronoDroid: Time-based Hybrid-featured Dataset for Effective Android Malware Detection and Characterization
abstract
Android malware evolution has been neglected by the available data sets, thus providing a static snapshot of a non-stationary phenomenon. The impact of the time variable has not had the deserved attention by the Android malware research, omitting its degenerative impact on the performance of machine learning-based classifiers (i.e., concept drift). Besides, the sources of dynamic data and their particularities have been overlooked (i.e., real devices and emulators). Critical factors to take into account when aiming to build more effective, robust, and long-lasting Android malware detection systems. In this research, different sources of benign and malware data are merged, generating a data set encompassing a larger time frame and 489 static and dynamic features are collected. The particularities of the source of the dynamic features (i.e., system calls) are attended using an emulator and a real device, thus generating two equally featured sub-datasets. The main outcome of this research is a novel, labeled, and hybrid-featured Android dataset that provides timestamps for each data sample, covering all years of Android history, from 2008-2020, and considering the distinct dynamic data sources. The emulator data set is composed of 28,745 malicious apps from 209 malware families and 35,246 benign samples. The real device data set contains 41,382 malware, belonging to 240 malware families, and 36,755 benign apps. Made publicly available as KronoDroid, in a structured format, it is the largest hybrid-featured Android dataset and the only one providing timestamped data, considering dynamic sources’ particularities and including samples from over 209 Android malware families.
Alejandro Guerra-Manzanares, Hayretdin Bahsi, Sven Nomm
Comput. Secur.2
2020 MedBIoT: Generation of an IoT Botnet Dataset in a Medium-sized IoT Network
Alejandro Guerra-Manzanares, Jorge Medina-Galindo, Hayretdin Bahsi, Sven Nomm
ICISSP3
2020 The cyber-insurance market in Norway
abstract
Purpose This paper aims to describe the cyber-insurance market in Norway but offers conclusions that are interesting to a wider audience. Design/methodology/approach The study is based on semi-structured interviews with supply-side actors: six general insurance companies, one marine insurance company and two insurance intermediaries. Findings The Norwegian cyber-insurance market supply-side has grown significantly in the past two years. The General Data Protection Regulation (GDPR) is found to have had a modest effect on the market so far but has been used by the supply-side as an icebreaker to discuss cyber-insurance with customers. The NIS Directive has had little or no impact on the Norwegian cyber-insurance market until now. Informants also indicate that Norway is still the least mature of the four Nordic markets. Practical implications Some policy lessons for different stakeholders are identified. Originality/value Empirical investigation of cyber-insurance is still rare, and the paper offers original insights on market composition and actor motivations, ambiguity of coverage, the NIS Directive and GDPR.
Hayretdin Bahsi, Ulrik Franke, Even Langfeldt Friberg
Inf. Comput. Secur.1
2019 Hybrid Feature Selection Models for Machine Learning Based Botnet Detection in IoT Networks
abstract
Timely detection of intrusions is essential in IoT networks, considering the massive attacks launched by the huge-sized botnets which are composed of insecure devices. Machine learning methods have demonstrated promising results for the detection of such attacks. However, the effectiveness of such methods may greatly benefit from the reduction of feature set size as this may prevent the impeding impact of unnecessary features and minimize the computational resources required for intrusion detection in such networks having several limitations. This paper elaborates on feature selection methods applied to machine learning models which are induced for botnet detection in IoT networks. A particular attention is devoted to the use of wrapper methods and their combination with filter methods. While filter-based feature selection methods provide a computationally light approach to select the most informative features, it is shown that their utilization in combination with wrapper methods boosts up the detection accuracy.
Alejandro Guerra-Manzanares, Hayretdin Bahsi, Sven Nomm
CW2
2019 In-depth Feature Selection and Ranking for Automated Detection of Mobile Malware
abstract
New malware detection techniques are highly needed due to the increasing threat posed by mobile malware. Machine learning techniques have provided promising results in this problem domain. However, feature selection, which is an essential instrument to overcome the curse of dimensionality, presenting higher interpretable results and optimizing the utilization of computational resources, requires more attention in order to induce better learning models for mobile malware detection. In this paper, in order to find out the minimum feature set that provides higher accuracy and analyze the discriminatory powers of different features, we employed feature selection and ranking methods to datasets characterized by system calls and permissions. These features were extracted from malware application samples belonging to two different time-frames (2010-2012 and 2017-2018) and benign applications. We demonstrated that selected feature sets with small sizes, in both feature categories, are able to provide high accuracy results. However, we identified a decline in the discriminatory power of the selected features in both categories when the dataset is induced by the recent malware samples instead of old ones, indicating a concept drift. Although we plan to model the concept drift in our future studies, the feature selection results presented in this study give a valuable insight regarding the change occurred in the best discriminating features during the evolvement of mobile malware over time.
Alejandro Guerra-Manzanares, Sven Nomm, Hayretdin Bahsi
ICISSP3
2019 Towards the Integration of a Post-Hoc Interpretation Step into the Machine Learning Workflow for IoT Botnet Detection
abstract
The analysis of the interplay between the feature selection and the post-hoc local interpretation steps in a machine learning workflow followed for IoT botnet detection constitutes the research scope of the present paper. While the application of machine learning-based techniques has become a trend in cyber security, the main focus has been almost on detection accuracy. However, providing the relevant explanation for a detection decision is a vital requirement in a tiered incident handling processes of the contemporary security operations centers. Moreover, the design of intrusion detection systems in IoT networks has to take the limitations of the computational resources into consideration. Therefore, resource limitations in addition to human element of incident handling necessitate considering feature selection and interpretability at the same time in machine learning workflows. In this paper, first, we analyzed the selection of features and its implication on the data accuracy. Second, we investigated the impact of feature selection on the explanations generated at the post-hoc interpretation phase. We utilized a filter method, Fisher's Score and Local Interpretable Model-Agnostic Explanation (LIME) at feature selection and post-hoc interpretation phases, respectively. To evaluate the quality of explanations, we proposed a metric that reflects the need of the security analysts. It is demonstrated that the application of both steps for the particular case of IoT botnet detection may result in highly accurate and interpretable learning models induced by fewer features. Our metric enables us to evaluate the detection accuracy and interpretability in an integrated way.
Sven Nomm, Alejandro Guerra-Manzanares, Hayretdin Bahsi
ICMLA3
2018 Dimensionality Reduction for Machine Learning Based IoT Botnet Detection
abstract
The rapid development of the internet of things caused severe security problems such as the cyber attacks launched by extremely huge botnets comprised of IoT devices. The detection of these devices is essential for protecting the networks. Recently, some of the studies have demonstrated the high accuracy of machine learning methods, including deep learning, in detecting IoT botnets. However, the minimizing of the required features for classification is highly needed for overcoming scalability and computation resource problems in IoT environments. Having results which can be readily interpretable by cyber security analysts and producing signatures for the contemporary intrusion detection or network monitoring systems are other significant factors in this area in which quick and widespread security adaption is highly required. In this study, we applied feature selection to minimize the number of features in detecting the IoT bots. It is shown that fewer features can achieve very high accuracy rates and afford interpretable results with a multi-class classifier based on a shallow method, decision tree.
Hayretdin Bahsi, Sven Nomm, Fabio Benedetto La Torre
ICARCV1
2018 Forensics Analysis of an On-line Game over Steam Platform
Raquel Tabuyo-Benito, Hayretdin Bahsi, Pedro Peris-Lopez
ICDF2C2
2018 Unsupervised Anomaly Based Botnet Detection in IoT Networks
abstract
Anomaly-based detection of the IoT botnets with emphasis on feature selection is elaborated in this paper. Due to the rapid growth of the Internet of Things technology, the number of vulnerable devices that become a part of a botnet has grown significantly. The detection of such malicious traffic is essential for taking timely countermeasures. While the idea of anomaly-based attack detection is not new and has been extensively studied, much less attention has been paid to dimensionality reduction in learning models induced for IoT networks. In this paper, we showed that it is possible to induce high accurate unsupervised learning models with reduced feature set sizes, which enables to decrease the required computational resources. Training one common model for all IoT devices, instead of dedicated model for each device, is another design option that is evaluated for resource optimization.
Sven Nomm, Hayretdin Bahsi
ICMLA2
2013 Security-level classification for confidential documents by using adaptive neuro-fuzzy inference systems
abstract
Abstract The security‐level detection of a confidential document is a vital task for organizations to protect their confidential information. Diverse classification rules and techniques are being applied by human experts. Increasing number of confidential information in organizations is making difficult to classify all the documents carefully with human effort. The recommended frameworks in this study classify the internal documents of TUBITAK UEKAE (National Research Institute of Electronics and Cryptology of Turkey) by using classification algorithms naïve Bayes, support vector machines (SVMs) and adaptive neuro‐fuzzy inference systems (ANFISs). A hybrid approach involving support vector classifiers and adaptive neuro‐fuzzy classifiers exposes the most successful accuracy rates of expert system classification. This study also states preprocessing tasks required for document classification with natural language processing. To represent term–document relations, a recommended metric TF‐IDF was chosen to construct a weight matrix. Agglutinative nature of Turkish documents is handled by Turkish stemming algorithms. At the end of the article, some experimental results and success metrics are projected with accuracy rates and receiver operating characteristic (ROC) curves.
Erdem Alparslan, Adem Karahoca, Hayretdin Bahsi
Expert Syst. J. Knowl. Eng.3