TY - JOUR AU - Seemela, Kago AU - Mphago, Banyatsang AU - Semong, Thabo AU - Methula, Phephisa PY - 2026 TI - Autoencoder-Based Intrusion Detection for ARP Poisoning in SDN Controllers JF - Journal of Computer Science VL - 22 IS - 7 DO - 10.3844/jcssp.2026.2266.2273 UR - https://thescipub.com/abstract/jcssp.2026.2266.2273 AB - Address Resolution Protocol (ARP) poisoning is still a critical control plane attack in Software Defined Networks (SDNs), and spoofing of ARP mappings can trick SDNs controller and accomplish man in the middle, eavesdropping and denial of service attacks. Current SDN intrusion detection systems of ARP attacks rely on supervised learning and labelled attack data which is rather expensive and not necessarily a good representation of evolving traffic. Hence, this paper presents an unsupervised IDS that uses autoencoder to detect ARP poisoning attacks on the SDN controller. The model is trained only on benign ARP data from the public ARP–SDN dataset and ARP poison/flood labels are used only for the evaluation. The method used is the reconstruction error and an anomaly score threshold is chosen from the 99th percentile of the reconstruction errors of benign training errors. The proposed model attains a binary-accuracy of 99.83%, a macro F1-score of 0.9978 and 0 false-negative on the test data which it did not trained. For tenfold cross-validation, mean accuracy of 0.9974 and macro F1-score of 0.9965 have been achieved. The results indicate that autoencoder based anomaly detection can yield a good ARP poisoning prediction accuracy with less need for labelled attack data, but more testing on real SDN deployments is still necessary.