English

On the Impact of Entropy-based Features

Cryptography and Security 2026-07-16 v1 Machine Learning

Abstract

Network anomaly detection is increasingly challenging due to the growing diversity and variability of traffic patterns, which are not always well captured by traditional statistical features. In this work, we explore the use of entropy as an additional feature to support supervised network traffic classification. The main idea is to use entropy to represent variability in selected traffic attributes, complementing conventional descriptors rather than replacing them. We integrate the entropy-based feature into a standard machine learning pipeline and evaluate its impact through a direct comparison between models trained with and without this feature. Experiments conducted on a public intrusion detection dataset show consistent improvements in classification performance, while the additional computational cost remains low. The analysis of confusion matrices indicates a reduction in misclassifications, especially in traffic scenarios with higher variability. Overall, the results suggest that entropy-based features offer a simple and practical way to enhance existing anomaly detection pipelines. This approach is particularly attractive in settings where lightweight feature engineering and interpretability are important, making entropy a useful complement to commonly used traffic features.

Keywords

Cite

@article{arxiv.2607.15379,
  title  = {On the Impact of Entropy-based Features},
  author = {Iuri Mundstock and Abreu Quevedo and Jéferson Campos Nobre and Roben C. Lunardi and Thiago L. T. da Silveira and Bruno L. Dalmazo},
  journal= {arXiv preprint arXiv:2607.15379},
  year   = {2026}
}

Comments

This manuscript has been accepted for presentation at the IEEE International Symposium on Computers and Communications (ISCC 2026)