Peer Review History
| Original SubmissionNovember 5, 2025 |
|---|
|
Dear Dr. Mishra, Thank you for submitting your manuscript to PLOS ONE. After careful consideration, we feel that it has merit but does not fully meet PLOS ONE’s publication criteria as it currently stands. Therefore, we invite you to submit a revised version of the manuscript that addresses the points raised during the review process. Please submit your revised manuscript by Jan 29 2026 11:59PM. If you will need more time than this to complete your revisions, please reply to this message or contact the journal office at plosone@plos.org. When you're ready to submit your revision, log on to https://www.editorialmanager.com/pone/ and select the 'Submissions Needing Revision' folder to locate your manuscript file.
If you would like to make changes to your financial disclosure, please include your updated statement in your cover letter. Guidelines for resubmitting your figure files are available below the reviewer comments at the end of this letter. If applicable, we recommend that you deposit your laboratory protocols in protocols.io to enhance the reproducibility of your results. Protocols.io assigns your protocol its own identifier (DOI) so that it can be cited independently in the future. For instructions see: https://journals.plos.org/plosone/s/submission-guidelines#loc-laboratory-protocols. Additionally, PLOS ONE offers an option for publishing peer-reviewed Lab Protocol articles, which describe protocols hosted on protocols.io. Read more information on sharing protocols at https://plos.org/protocols?utm_medium=editorial-email&utm_source=authorletters&utm_campaign=protocols. We look forward to receiving your revised manuscript. Kind regards, Muhammad Anwar, Ph.D. Academic Editor PLOS One Journal requirements: When submitting your revision, we need you to address these additional requirements. 1. Please ensure that your manuscript meets PLOS ONE's style requirements, including those for file naming. The PLOS ONE style templates can be found at https://journals.plos.org/plosone/s/file?id=wjVg/PLOSOne_formatting_sample_main_body.pdf and 2. Please note that PLOS One has specific guidelines on code sharing for submissions in which author-generated code underpins the findings in the manuscript. In these cases, we expect all author-generated code to be made available without restrictions upon publication of the work. Please review our guidelines at https://journals.plos.org/plosone/s/materials-and-software-sharing#loc-sharing-code and ensure that your code is shared in a way that follows best practice and facilitates reproducibility and reuse. 3. Thank you for stating the following in the Acknowledgments Section of your manuscript: “The authors extend their appreciation to the Deanship of Postgraduate Studies and Scientific Research at Majmaah University for funding this research work through the project number (R-2025-xxx ).” We note that you have provided funding information that is not currently declared in your Funding Statement. However, funding information should not appear in the Acknowledgments section or other areas of your manuscript. We will only publish funding information present in the Funding Statement section of the online submission form. Please remove any funding-related text from the manuscript and let us know how you would like to update your Funding Statement. Currently, your Funding Statement reads as follows: “The author(s) received no specific funding for this work.” Please include your amended statements within your cover letter; we will change the online submission form on your behalf. 4. When completing the data availability statement of the submission form, you indicated that you will make your data available on acceptance. We strongly recommend all authors decide on a data sharing plan before acceptance, as the process can be lengthy and hold up publication timelines. Please note that, though access restrictions are acceptable now, your entire data will need to be made freely accessible if your manuscript is accepted for publication. This policy applies to all data except where public deposition would breach compliance with the protocol approved by your research ethics board. If you are unable to adhere to our open data policy, please kindly revise your statement to explain your reasoning and we will seek the editor's input on an exemption. Please be assured that, once you have provided your new statement, the assessment of your exemption will not hold up the peer review process. 5. PLOS requires an ORCID iD for the corresponding author in Editorial Manager on papers submitted after December 6th, 2016. Please ensure that you have an ORCID iD and that it is validated in Editorial Manager. To do this, go to ‘Update my Information’ (in the upper left-hand corner of the main menu), and click on the Fetch/Validate link next to the ORCID field. This will take you to the ORCID site and allow you to create a new iD or authenticate a pre-existing iD in Editorial Manager. If the reviewer comments include a recommendation to cite specific previously published works, please review and evaluate these publications to determine whether they are relevant and should be cited. There is no requirement to cite these works unless the editor has indicated otherwise. [Note: HTML markup is below. Please do not edit.] Reviewers' comments: Reviewer's Responses to Questions Comments to the Author 1. Is the manuscript technically sound, and do the data support the conclusions? Reviewer #1: Yes Reviewer #2: Partly ********** 2. Has the statistical analysis been performed appropriately and rigorously? -->?> Reviewer #1: Yes Reviewer #2: No ********** 3. Have the authors made all data underlying the findings in their manuscript fully available??> The PLOS Data policy Reviewer #1: Yes Reviewer #2: Yes ********** 4. Is the manuscript presented in an intelligible fashion and written in standard English??> Reviewer #1: Yes Reviewer #2: No ********** Reviewer #1: The manuscript presents an ambitious hybrid IDS framework integrating supervised and unsupervised models with PCA, SMOTE, and a blockchain-based auditing layer. The overall concept is potentially innovative, especially in its attempt to unify multiple detection paradigms with tamper-proof logging. However, several methodological and interpretive issues need clarification. The supervised-only results showing nearly perfect accuracy (≈99.9%) strongly suggest possible data leakage or overfitting. The blockchain implementation is described inconsistently—referencing Ethereum, Hyperledger Fabric, and a private chain—and the reported performance metrics (e.g., 366 blocks/s, 0.09 s/tx, 0 KB storage overhead) do not align with typical blockchain behavior. Details on hyperparameters, PCA/SMOTE impact, ensemble weighting, statistical testing, and threshold selection are insufficient for reproducibility. Additionally, several figures are difficult to interpret, and the writing contains grammar and structural problems that hinder clarity. I recommend strengthening the methodological descriptions, adding ablation studies (e.g., PCA-only, SMOTE-only, ensemble vs. individual models), clarifying the blockchain architecture, and validating the supervised model results to rule out leakage. Improving the writing quality and reorganizing sections for smoother flow would also benefit the manuscript. Ethical and data availability statements appear acceptable, though the authors should ensure there is no overlap with their prior work. Overall, the paper has potential but requires significant revision to meet publication standards in terms of rigor, clarity, and reproducibility. Reviewer #2: Thank you for submitting your manuscript. The topic is important and timely, and the idea of integrating hybrid machine-learning models with blockchain-based logging is potentially valuable. However, several issues require substantial revision before the work can be considered further. Major Comments Technical Validity and Overfitting Concerns The reported results—particularly the near-perfect performance of the supervised models (e.g., 99.9% accuracy on CICIDS2017)—are unrealistic for these datasets and strongly suggest data leakage or methodological errors. Please verify and clearly document the preprocessing pipeline (especially the order of SMOTE, PCA, splitting, and scaling) to ensure no information from the test set influences training. Blockchain Evaluation Requires Clarification The blockchain component appears to be a simplified local logging mechanism rather than a true distributed blockchain system. Claims such as 0 KB memory growth, 24,000× faster than Ethereum, and strong tamper-proof guarantees are not supported. Please clarify: the actual consensus mechanism whether multiple nodes were used real ledger growth how tampering resistance was evaluated Without this, conclusions about blockchain security are overstated. Statistical Analysis Not Rigorous Although t-tests and p-values are mentioned, the methodology is not clearly described or justified. Please provide: statistical test details assumptions checks effect sizes and confidence intervals rationale for comparing “before” and “after” blockchain results At present, the statistical conclusions are not reliable. Mathematical Modeling Section Unrelated to Experiments The system of differential equations is theoretically interesting but not connected to any experimental results or validated through data. This section should either be removed or linked meaningfully to the system’s behavior. Manuscript Clarity and Structure The paper is lengthy, contains repetition, and includes several grammatical and syntactic issues. Some sections mix unrelated topics (e.g., blockchain details within ML model descriptions). A thorough English-language and structural revision is needed for clarity. Novelty Claims Are Overstated Several papers have already combined hybrid ML approaches with blockchain-based IDS designs. Please refine the novelty claim to highlight the specific technical contribution of your work without overstating uniqueness. Minor Comments Many figures lack clear titles, legends, and axis explanations. Several tables would benefit from more concise formatting. The implementation section mixes low-level details (e.g., Docker commands) with high-level descriptions; consider moving technical commands to supplementary material. Conclusion The manuscript proposes an interesting direction, but substantial methodological, experimental, and writing improvements are necessary. Addressing the issues above will significantly strengthen the scientific rigor and clarity of the work. ********** what does this mean?). If published, this will include your full peer review and any attached files. If you choose “no”, your identity will remain anonymous but your review may still be made public. Do you want your identity to be public for this peer review? For information about this choice, including consent withdrawal, please see our Privacy Policy Reviewer #1: Yes: Wenke Du Reviewer #2: No ********** [NOTE: If reviewer comments were submitted as an attachment file, they will be attached to this email and accessible via the submission site. Please log into your account, locate the manuscript record, and check for the action link "View Attachments". If this link does not appear, there are no attachment files.] To ensure your figures meet our technical requirements, please review our figure guidelines: https://journals.plos.org/plosone/s/figures You may also use PLOS’s free figure tool, NAAS, to help you prepare publication quality figures: https://journals.plos.org/plosone/s/figures#loc-tools-for-figure-preparation. NAAS will assess whether your figures meet our technical requirements by comparing each figure against our figure specifications. |
| Revision 1 |
|
Dear Dr. Mishra, Thank you for submitting your manuscript to PLOS ONE. After careful consideration, we feel that it has merit but does not fully meet PLOS ONE’s publication criteria as it currently stands. Therefore, we invite you to submit a revised version of the manuscript that addresses the points raised during the review process. Please submit your revised manuscript by Mar 15 2026 11:59PM. If you will need more time than this to complete your revisions, please reply to this message or contact the journal office at plosone@plos.org. When you're ready to submit your revision, log on to https://www.editorialmanager.com/pone/ and select the 'Submissions Needing Revision' folder to locate your manuscript file.
If applicable, we recommend that you deposit your laboratory protocols in protocols.io to enhance the reproducibility of your results. Protocols.io assigns your protocol its own identifier (DOI) so that it can be cited independently in the future. For instructions see: https://journals.plos.org/plosone/s/submission-guidelines#loc-laboratory-protocols. Additionally, PLOS ONE offers an option for publishing peer-reviewed Lab Protocol articles, which describe protocols hosted on protocols.io. Read more information on sharing protocols at https://plos.org/protocols?utm_medium=editorial-email&utm_source=authorletters&utm_campaign=protocols. We look forward to receiving your revised manuscript. Kind regards, Muhammad Anwar, Ph.D. Academic Editor PLOS One Journal Requirements: 1. If the reviewer comments include a recommendation to cite specific previously published works, please review and evaluate these publications to determine whether they are relevant and should be cited. There is no requirement to cite these works unless the editor has indicated otherwise. 2. Please review your reference list to ensure that it is complete and correct. If you have cited papers that have been retracted, please include the rationale for doing so in the manuscript text, or remove these references and replace them with relevant current references. Any changes to the reference list should be mentioned in the rebuttal letter that accompanies your revised manuscript. If you need to cite a retracted article, indicate the article’s retracted status in the References list and also include a citation and full reference for the retraction notice. [Note: HTML markup is below. Please do not edit.] Reviewers' comments: Reviewer's Responses to Questions Comments to the Author Reviewer #1: All comments have been addressed Reviewer #2: All comments have been addressed ********** 2. Is the manuscript technically sound, and do the data support the conclusions??> Reviewer #1: Yes Reviewer #2: Yes ********** 3. Has the statistical analysis been performed appropriately and rigorously? -->?> Reviewer #1: Yes Reviewer #2: Yes ********** 4. Have the authors made all data underlying the findings in their manuscript fully available??> The PLOS Data policy Reviewer #1: No Reviewer #2: Yes ********** 5. Is the manuscript presented in an intelligible fashion and written in standard English??> Reviewer #1: Yes Reviewer #2: Yes ********** Reviewer #1: Overall Review The revised manuscript entitled “A Lightweight Blockchain-Inspired Hybrid Intrusion Detection System with Ensemble Learning for Tamper-Proof Auditing” presents a technically sound and well-executed study addressing an important problem in modern cybersecurity. Following substantial revision, the authors have adequately addressed the major concerns raised in the previous round of review. The methodological framework is now clearly described and demonstrates appropriate rigor. In particular, the authors have convincingly clarified the preprocessing pipeline to rule out data leakage, provided detailed hyperparameter settings, and justified the use of PCA, SMOTE, and adaptive weighted ensemble voting. The inclusion of comprehensive ablation studies and cross-dataset validation strengthens confidence in the reported performance and demonstrates robustness beyond dataset-specific effects. The statistical analysis has been substantially improved, with clear descriptions of test design, assumption checks, effect sizes, and confidence intervals, making the conclusions well supported by the data. Importantly, the blockchain-inspired component has been appropriately reframed and clarified. The authors no longer overstate decentralization or consensus properties, instead positioning the mechanism as a lightweight, single-node, hash-chained audit ledger designed for tamper-evident forensic logging. The evaluation of overhead, storage growth, and tamper detection is now transparent, technically realistic, and aligned with the stated design goals. The manuscript has also benefited from significant improvements in structure, clarity, and language quality. Figures and tables are clearer, redundancy has been reduced, and novelty claims have been moderated to accurately reflect incremental but meaningful contributions relative to prior work. Data and code availability are clearly stated and meet PLOS ONE’s reproducibility requirements. Overall, the study now meets the journal’s standards for technical correctness, clarity, and transparency. The conclusions are supported by the experimental evidence, and the work makes a useful contribution to the literature on hybrid intrusion detection systems with auditable logging. I therefore consider the manuscript suitable for publication. Reviewer #2: he authors have performed a commendable and thorough revision of the manuscript. The most significant improvement is the transition from a broad "blockchain" claim to a precisely defined "lightweight blockchain-inspired audit ledger." This transparency, combined with the public release of the full codebase and datasets, significantly enhances the manuscript’s scientific integrity and reproducibility. The technical concerns regarding data leakage and statistical rigor have been addressed with new validation experiments and robust reporting. 2. Methodological Rigor and Technical Validity Data Leakage Mitigation: The implementation of a strict "leakage-proof" preprocessing pipeline—where splitting occurs before any data-dependent transformations like scaling, PCA, or SMOTE—effectively addresses the primary concern regarding over-optimistic performance. The updated Fig. 2 and the accompanying code references provide the necessary evidence for this correction. Ensemble Strategy: The use of seven supervised and unsupervised models fused via adaptive weighted voting based on cross-validation F1-scores is a sound approach for handling the high dimensionality of NSL-KDD and CIC-IDS2017 datasets. Ablation Study: The newly added Table 11 provides crucial insights, quantifying the performance gains from PCA (+0.57% accuracy) and SMOTE (~5% recall boost), justifying their inclusion in the pipeline. 3. Audit Ledger (Blockchain Component) Refined Scope: The authors successfully clarified that the system uses a single-node, hash-chained ledger for forensic traceability rather than a decentralized consensus-based blockchain. This framing is much more realistic for a lightweight IDS. Performance Metrics: The reported average latency of ~0.09 s per transaction and the correction from "0 KB" to "negligible" (~1.2 MB for 10,000 entries) storage growth align with expected behavior for local cryptographic hashing. Tamper Resistance: The inclusion of a dedicated verify_chain() routine and the 100% detection rate of manual record modifications provides strong evidence for the ledger's efficacy in auditability. 4. Statistical Analysis Rigor: The transition to reporting p-values from paired t-tests, Cohen’s d effect sizes (0.42–0.46), and narrow 95% confidence intervals significantly strengthens the results section. Interpretation: The observation that the audit layer introduces only a minor, non-significant accuracy drop (from 98.85% to 98.15%) is now statistically substantiated. 5. Clarity and Presentation Structural Improvements: Removing the unrelated differential equations section and consolidating the "Research Gaps" has significantly improved the manuscript's focus and flow. Visual Aids: Figures have been updated with bold titles, descriptive legends, and labeled axes, addressing the previous concerns regarding interpretability. 6. Minor Suggestions for Final Polish Consistency Check: While the authors state in the "Response to Reviewers" that storage overhead is corrected to "negligible," they should ensure that any remaining "0 KB" or "zero persistent growth" phrases in old text blocks (if any) are purged during the final proofing stage. Novelty Positioning: Ensure the "softened" novelty claims (acknowledging similar hybrid models) are consistently applied in both the Introduction and Conclusion to avoid contradictions. Final Recommendation: Accept with Minor (Formatting) Revisions. The manuscript now meets PLOS ONE’s requirements for technical rigor, data availability, and reporting standards. ********** what does this mean?). If published, this will include your full peer review and any attached files. If you choose “no”, your identity will remain anonymous but your review may still be made public. Do you want your identity to be public for this peer review? For information about this choice, including consent withdrawal, please see our Privacy Policy Reviewer #1: Yes: Wenke Du Reviewer #2: No ********** [NOTE: If reviewer comments were submitted as an attachment file, they will be attached to this email and accessible via the submission site. Please log into your account, locate the manuscript record, and check for the action link "View Attachments". If this link does not appear, there are no attachment files.] To ensure your figures meet our technical requirements, please review our figure guidelines: https://journals.plos.org/plosone/s/figures You may also use PLOS’s free figure tool, NAAS, to help you prepare publication quality figures: https://journals.plos.org/plosone/s/figures#loc-tools-for-figure-preparation. NAAS will assess whether your figures meet our technical requirements by comparing each figure against our figure specifications. |
| Revision 2 |
|
Dear Dr. Mishra, Thank you for submitting your manuscript to PLOS ONE. After careful consideration, we feel that it has merit but does not fully meet PLOS ONE’s publication criteria as it currently stands. Therefore, we invite you to submit a revised version of the manuscript that addresses the points raised during the review process. Please submit your revised manuscript by Apr 12 2026 11:59PM. If you will need more time than this to complete your revisions, please reply to this message or contact the journal office at plosone@plos.org. When you're ready to submit your revision, log on to https://www.editorialmanager.com/pone/ and select the 'Submissions Needing Revision' folder to locate your manuscript file.
If applicable, we recommend that you deposit your laboratory protocols in protocols.io to enhance the reproducibility of your results. Protocols.io assigns your protocol its own identifier (DOI) so that it can be cited independently in the future. For instructions see: https://journals.plos.org/plosone/s/submission-guidelines#loc-laboratory-protocols. Additionally, PLOS ONE offers an option for publishing peer-reviewed Lab Protocol articles, which describe protocols hosted on protocols.io. Read more information on sharing protocols at https://plos.org/protocols?utm_medium=editorial-email&utm_source=authorletters&utm_campaign=protocols. We look forward to receiving your revised manuscript. Kind regards, Muhammad Anwar, Ph.D. Academic Editor PLOS One Journal Requirements: 1. If the reviewer comments include a recommendation to cite specific previously published works, please review and evaluate these publications to determine whether they are relevant and should be cited. There is no requirement to cite these works unless the editor has indicated otherwise. 2. Please review your reference list to ensure that it is complete and correct. If you have cited papers that have been retracted, please include the rationale for doing so in the manuscript text, or remove these references and replace them with relevant current references. Any changes to the reference list should be mentioned in the rebuttal letter that accompanies your revised manuscript. If you need to cite a retracted article, indicate the article’s retracted status in the References list and also include a citation and full reference for the retraction notice. [Note: HTML markup is below. Please do not edit.] Reviewers' comments: Reviewer's Responses to Questions Comments to the Author Reviewer #1: All comments have been addressed Reviewer #2: All comments have been addressed ********** 2. Is the manuscript technically sound, and do the data support the conclusions??> Reviewer #1: Yes Reviewer #2: Partly ********** 3. Has the statistical analysis been performed appropriately and rigorously? -->?> Reviewer #1: Yes Reviewer #2: No ********** 4. Have the authors made all data underlying the findings in their manuscript fully available??> The PLOS Data policy Reviewer #1: Yes Reviewer #2: Yes ********** 5. Is the manuscript presented in an intelligible fashion and written in standard English??> Reviewer #1: Yes Reviewer #2: Yes ********** Reviewer #1: This manuscript presents a hybrid intrusion detection system (H-IDS) integrating supervised and unsupervised machine learning models within a weighted ensemble framework, combined with a lightweight blockchain-inspired immutable audit mechanism. The work addresses key challenges in IDS research, including class imbalance, dimensionality reduction, ensemble robustness, and tamper-evident logging. The manuscript is technically sound, methodologically detailed, and reproducible (code and datasets are publicly available). The authors clearly position their contribution as a refinement and integration of existing approaches rather than claiming entirely novel components, which strengthens the scientific integrity of the paper. Overall, the study is well-executed and suitable for publication after minor clarifications. Reviewer #2: I appreciate the substantial revisions made in response to the previous review round. The manuscript has improved significantly in clarity, methodological transparency, and positioning of its contributions. In particular, the clarification of the leakage-proof preprocessing pipeline (train–test split prior to scaling, PCA, and SMOTE), the softened novelty claims, and the explicit limitation of the blockchain-inspired component to a single-node hash-chained audit mechanism are positive and constructive improvements. The integration of supervised and unsupervised models within a weighted ensemble framework is clearly described, and the experimental setup is reproducible, with code and datasets made publicly available. The manuscript is generally well structured and intelligible. However, a few issues still require clarification before final acceptance: Statistical Rigor The paired t-test analysis appears to be conducted with a very small number of repetitions (n = 3, df = 2). While the computations are technically valid, such a small sample size limits statistical power and the robustness of inferential claims. The authors are encouraged either to: Provide clarification on what constitutes the three paired observations and justify the adequacy of this sample size, or Temper claims of statistical significance accordingly. Near-Perfect Supervised-Only Performance The reported 99.9%+ accuracy on benchmark datasets (NSL-KDD and CIC-IDS2017) is exceptionally high. Although the preprocessing pipeline is described as leakage-resilient, the authors should further clarify how cross-validation, validation splits, and ensemble weighting are strictly isolated from the final test set to eliminate any possibility of inadvertent information leakage. Blockchain Terminology Precision The manuscript correctly clarifies that the proposed mechanism is single-node and does not implement decentralized consensus. To avoid possible conceptual confusion, the authors may consider ensuring consistent terminology (e.g., “blockchain-inspired hash-chained audit log”) throughout the manuscript to accurately reflect the security guarantees provided. These issues are primarily clarification and rigor-related rather than structural flaws. Overall, the work is technically organized and contributes a practical integration of ensemble learning with tamper-evident logging for intrusion detection. With the above clarifications, the manuscript would be suitable for publication. ********** what does this mean?). If published, this will include your full peer review and any attached files. If you choose “no”, your identity will remain anonymous but your review may still be made public. Do you want your identity to be public for this peer review? For information about this choice, including consent withdrawal, please see our Privacy Policy Reviewer #1: Yes: Wenke Du Reviewer #2: No ********** [NOTE: If reviewer comments were submitted as an attachment file, they will be attached to this email and accessible via the submission site. Please log into your account, locate the manuscript record, and check for the action link "View Attachments". If this link does not appear, there are no attachment files.] To ensure your figures meet our technical requirements, please review our figure guidelines: https://journals.plos.org/plosone/s/figures You may also use PLOS’s free figure tool, NAAS, to help you prepare publication quality figures: https://journals.plos.org/plosone/s/figures#loc-tools-for-figure-preparation. NAAS will assess whether your figures meet our technical requirements by comparing each figure against our figure specifications. |
| Revision 3 |
|
Dear Dr. Mishra, Thank you for submitting your manuscript to PLOS ONE. After careful consideration, we feel that it has merit but does not fully meet PLOS ONE’s publication criteria as it currently stands. Therefore, we invite you to submit a revised version of the manuscript that addresses the points raised during the review process. Please submit your revised manuscript by Apr 30 2026 11:59PM. If you will need more time than this to complete your revisions, please reply to this message or contact the journal office at plosone@plos.org. When you're ready to submit your revision, log on to https://www.editorialmanager.com/pone/ and select the 'Submissions Needing Revision' folder to locate your manuscript file.
If applicable, we recommend that you deposit your laboratory protocols in protocols.io to enhance the reproducibility of your results. Protocols.io assigns your protocol its own identifier (DOI) so that it can be cited independently in the future. For instructions see: https://journals.plos.org/plosone/s/submission-guidelines#loc-laboratory-protocols. Additionally, PLOS ONE offers an option for publishing peer-reviewed Lab Protocol articles, which describe protocols hosted on protocols.io. Read more information on sharing protocols at https://plos.org/protocols?utm_medium=editorial-email&utm_source=authorletters&utm_campaign=protocols. We look forward to receiving your revised manuscript. Kind regards, Muhammad Anwar, Ph.D. Academic Editor PLOS One Journal Requirements: 1. If the reviewer comments include a recommendation to cite specific previously published works, please review and evaluate these publications to determine whether they are relevant and should be cited. There is no requirement to cite these works unless the editor has indicated otherwise. 2. Please review your reference list to ensure that it is complete and correct. If you have cited papers that have been retracted, please include the rationale for doing so in the manuscript text, or remove these references and replace them with relevant current references. Any changes to the reference list should be mentioned in the rebuttal letter that accompanies your revised manuscript. If you need to cite a retracted article, indicate the article’s retracted status in the References list and also include a citation and full reference for the retraction notice. [Note: HTML markup is below. Please do not edit.] Reviewer's Responses to Questions Comments to the Author Reviewer #1: All comments have been addressed Reviewer #2: (No Response) ********** 2. Is the manuscript technically sound, and do the data support the conclusions??> Reviewer #1: Yes Reviewer #2: Partly ********** 3. Has the statistical analysis been performed appropriately and rigorously? -->?> Reviewer #1: Yes Reviewer #2: No ********** 4. Have the authors made all data underlying the findings in their manuscript fully available??> The PLOS Data policy Reviewer #1: Yes Reviewer #2: Yes ********** 5. Is the manuscript presented in an intelligible fashion and written in standard English??> Reviewer #1: Yes Reviewer #2: Yes ********** Reviewer #1: well writen compared with last time considering the rigorous template and the bullet point to prove the academic theis Reviewer #2: Thank you for the careful revision of the manuscript and the detailed responses to the reviewers’ comments. The revised version has improved in clarity and methodological transparency. In particular, the clarification of the leakage-safe preprocessing pipeline, the moderation of statistical claims, and the consistent terminology describing the blockchain-inspired hash-chained audit log have strengthened the manuscript. The methodology is clearly described, and the availability of the source code and datasets improves the reproducibility of the study. The explanation of the training–test separation and ensemble weighting procedure also addresses the earlier concerns regarding potential data leakage. While the statistical comparison is based on a limited number of repetitions, the authors appropriately acknowledge this limitation and present the results cautiously. Overall, the manuscript now provides a technically sound and clearly presented study. I believe the manuscript is suitable for publication in PLOS ONE. ********** what does this mean?). If published, this will include your full peer review and any attached files. If you choose “no”, your identity will remain anonymous but your review may still be made public. Do you want your identity to be public for this peer review? For information about this choice, including consent withdrawal, please see our Privacy Policy Reviewer #1: No Reviewer #2: No ********** [NOTE: If reviewer comments were submitted as an attachment file, they will be attached to this email and accessible via the submission site. Please log into your account, locate the manuscript record, and check for the action link "View Attachments". If this link does not appear, there are no attachment files.] To ensure your figures meet our technical requirements, please review our figure guidelines: https://journals.plos.org/plosone/s/figures You may also use PLOS’s free figure tool, NAAS, to help you prepare publication quality figures: https://journals.plos.org/plosone/s/figures#loc-tools-for-figure-preparation. NAAS will assess whether your figures meet our technical requirements by comparing each figure against our figure specifications. |
| Revision 4 |
|
Dear Dr. Mishra, Thank you for submitting your manuscript to PLOS ONE. After careful consideration, we feel that it has merit but does not fully meet PLOS ONE’s publication criteria as it currently stands. Therefore, we invite you to submit a revised version of the manuscript that addresses the points raised during the review process. Please submit your revised manuscript by Jul 11 2026 11:59PM. If you will need more time than this to complete your revisions, please reply to this message or contact the journal office at plosone@plos.org. When you're ready to submit your revision, log on to https://www.editorialmanager.com/pone/ and select the 'Submissions Needing Revision' folder to locate your manuscript file.
If you would like to make changes to your financial disclosure, please include your updated statement in your cover letter. Guidelines for resubmitting your figure files are available below the reviewer comments at the end of this letter. We look forward to receiving your revised manuscript. Kind regards, Rizik M. H. Al-Sayyed, Ph.D. Academic Editor PLOS One Journal Requirements: 1. If the reviewer comments include a recommendation to cite specific previously published works, please review and evaluate these publications to determine whether they are relevant and should be cited. There is no requirement to cite these works unless the editor has indicated otherwise. 2. Please review your reference list to ensure that it is complete and correct. If you have cited papers that have been retracted, please include the rationale for doing so in the manuscript text, or remove these references and replace them with relevant current references. Any changes to the reference list should be mentioned in the rebuttal letter that accompanies your revised manuscript. If you need to cite a retracted article, indicate the article’s retracted status in the References list and also include a citation and full reference for the retraction notice. Additional Editor Comments: The manuscript is technically sound, methodologically rigorous, and presents a valuable H-IDS framework combining high detection accuracy with blockchain-inspired auditability. The study is suitable for publication after minor revisions, mainly requiring brief clarification on scalability under high-volume attacks, handling of encrypted traffic, and provision of code/data availability details to support reproducibility. No major methodological or ethical concerns were identified. [Note: HTML markup is below. Please do not edit.] Reviewer's Responses to Questions Comments to the Author Reviewer #1: All comments have been addressed Reviewer #2: (No Response) ********** 2. Is the manuscript technically sound, and do the data support the conclusions??> Reviewer #1: Yes Reviewer #2: Yes ********** 3. Has the statistical analysis been performed appropriately and rigorously? -->?> Reviewer #1: Yes Reviewer #2: Yes ********** 4. Have the authors made all data underlying the findings in their manuscript fully available??> The PLOS Data policy Reviewer #1: Yes Reviewer #2: No ********** 5. Is the manuscript presented in an intelligible fashion and written in standard English??> Reviewer #1: Yes Reviewer #2: Yes ********** Reviewer #1: The revised manuscript presents a substantial improvement over previous versions and now provides a clear, well-structured, and technically sound contribution. The authors have adequately addressed the concerns raised in earlier review rounds, particularly with respect to methodological transparency, data handling, and clarity of presentation. The proposed hybrid intrusion detection system (H-IDS), integrating supervised and unsupervised ensemble learning with a lightweight blockchain-inspired audit mechanism, is well-motivated and clearly described. The inclusion of a leakage-safe preprocessing pipeline, explicit training–test separation, and adaptive weighted ensemble design significantly strengthens the technical rigor of the work. The statistical analysis has also been improved. Although the number of experimental repetitions remains limited (n = 3), the authors have appropriately clarified assumptions, reported effect sizes, and moderated their claims. This transparent discussion of limitations is appropriate and aligns with good scientific practice. Data availability and reproducibility are well addressed, with datasets, preprocessing details, and source code made publicly accessible. The manuscript is written in clear and standard English, and the overall presentation is coherent and easy to follow. Overall, the study provides a technically sound and reproducible contribution with practical relevance to intrusion detection and auditability in cybersecurity systems. The combination of ensemble learning and tamper-evident logging is novel within the presented scope. Recommendation: Accept for publication. Reviewer #2: The manuscript presents a technically sound and well-executed study on a Hybrid Intrusion Detection System (H-IDS) that integrates machine learning ensembles with a blockchain-inspired auditing layer. The core strength of the work lies in its dual focus: achieving high detection accuracy (98%+) while providing a verifiable, tamper-proof forensic trail for network events. The methodology demonstrates high academic rigor, particularly in its handling of data preprocessing to prevent leakage. 1. Technical Rigor and MethodologyThe authors have established a robust pipeline for evaluating their H-IDS: Data Integrity: The use of Min-Max Scaling, PCA, and SMOTE is handled correctly by applying these transformations only after the train-test split. This ensures that the results are not artificially inflated by data leakage. Ensemble Design: The combination of seven diverse models—ranging from supervised learners like CatBoost and DNN to unsupervised anomaly detectors like Autoencoders—is well-justified for capturing both known and zero-day threats. Auditability: The integration of a SHA-256 hash-chaining mechanism for logging is a significant contribution. The "Tamper Evidence" analysis effectively proves the system's ability to identify unauthorized modifications to historical logs. 2. Statistical AnalysisThe statistical validation is appropriate for a study of this nature: The use of 5-fold cross-validation ensures that the performance metrics are stable and generalizable. The application of a paired t-test ($p < 0.05$) provides the necessary formal evidence that the hybrid ensemble's performance gains are statistically significant compared to individual base learners. 3. Areas for Improvement & RecommendationsWhile the manuscript is strong, addressing the following minor points would enhance its impact:Scalability Concerns: The throughput is reported at 210 blocks per second. The authors should include a brief discussion on how the system would behave under extreme traffic conditions, such as a volumetric DDoS attack, where log generation might exceed this rate. Encrypted Traffic: Given that the majority of modern network traffic is encrypted, it would be beneficial for the authors to clarify if the H-IDS operates on packet headers or if it requires decrypted payloads. Reproducibility: To align with PLOS ONE's commitment to open science, the authors are encouraged to provide a link to a public repository containing the custom weighting logic and the ledger implementation. 4. Ethics and Dual PublicationResearch Ethics: No ethical concerns were identified. The study utilizes public benchmarks (NSL-KDD and CIC-IDS2017) and does not involve human subjects or sensitive personal data. Publication Ethics: There are no indicators of dual publication or self-plagiarism. The work appears original and provides a distinct contribution to the intersection of cybersecurity and distributed ledger principles. Final Recommendation: Weak AcceptThe manuscript is a strong candidate for publication following minor clarifications regarding scalability and data availability ********** what does this mean?). If published, this will include your full peer review and any attached files. If you choose “no”, your identity will remain anonymous but your review may still be made public. Do you want your identity to be public for this peer review? For information about this choice, including consent withdrawal, please see our Privacy Policy Reviewer #1: Yes: Wenke Du Reviewer #2: No ********** [NOTE: If reviewer comments were submitted as an attachment file, they will be attached to this email and accessible via the submission site. Please log into your account, locate the manuscript record, and check for the action link "View Attachments". If this link does not appear, there are no attachment files.] To ensure your figures meet our technical requirements, please review our figure guidelines: https://journals.plos.org/plosone/s/figures You may also use PLOS’s free figure tool, NAAS, to help you prepare publication quality figures: https://journals.plos.org/plosone/s/figures#loc-tools-for-figure-preparation. NAAS will assess whether your figures meet our technical requirements by comparing each figure against our figure specifications. |
| Revision 5 |
|
<p>A Lightweight Blockchain-Inspired Hybrid Intrusion Detection System with Ensemble Learning for Tamper-Proof Auditing PONE-D-25-59640R5 Dear Dr. Mishra, We’re pleased to inform you that your manuscript has been judged scientifically suitable for publication and will be formally accepted for publication once it meets all outstanding technical requirements. Within one week, you’ll receive an e-mail detailing the required amendments. When these have been addressed, you’ll receive a formal acceptance letter and your manuscript will be scheduled for publication. An invoice will be generated when your article is formally accepted. Please note, if your institution has a publishing partnership with PLOS and your article meets the relevant criteria, all or part of your publication costs will be covered. Please make sure your user information is up-to-date by logging into Editorial Manager at Editorial Manager® and clicking the ‘Update My Information' link at the top of the page. For questions related to billing, please contact billing support. If your institution or institutions have a press office, please notify them about your upcoming paper to help maximize its impact. If they’ll be preparing press materials, please inform our press team as soon as possible -- no later than 48 hours after receiving the formal acceptance. Your manuscript will remain under strict press embargo until 2 pm Eastern Time on the date of publication. For more information, please contact onepress@plos.org. Kind regards, Sohail Saif, Ph.D Academic Editor PLOS One Additional Editor Comments (optional): Reviewers' comments: Reviewer's Responses to Questions Comments to the Author Reviewer #1: All comments have been addressed ********** 2. Is the manuscript technically sound, and do the data support the conclusions??> Reviewer #1: Yes ********** 3. Has the statistical analysis been performed appropriately and rigorously? -->?> Reviewer #1: Yes ********** 4. Have the authors made all data underlying the findings in their manuscript fully available??> The PLOS Data policy Reviewer #1: Yes ********** 5. Is the manuscript presented in an intelligible fashion and written in standard English??> Reviewer #1: Yes ********** Reviewer #1: The revised manuscript has been substantially improved and addresses the concerns raised during the previous review rounds. The authors have provided clear and satisfactory responses to the comments regarding scalability under high-volume attack scenarios, compatibility with encrypted traffic, and reproducibility through public release of the implementation and experimental resources. The additional discussions improve both the practical relevance and transparency of the work. PONE-D-25-59640_R5.pdf The proposed hybrid intrusion detection system combines supervised and unsupervised learning with a lightweight blockchain-inspired audit mechanism in a well-motivated and technically sound framework. The experimental methodology follows appropriate machine learning practices, including leakage-free preprocessing, cross-validation, statistical significance testing, and evaluation on two widely used benchmark datasets. The reported performance demonstrates strong detection capability while maintaining a lightweight tamper-evident auditing mechanism. PONE-D-25-59640_R5.pdf The authors have also strengthened the manuscript by clarifying that the audit ledger is intentionally implemented as a lightweight single-node hash-chain mechanism rather than a decentralized blockchain, discussing its scalability limitations and future extensions, and explaining that the proposed IDS operates on flow-level statistical and metadata features, making it applicable to encrypted network traffic without requiring payload inspection. Furthermore, the availability of the complete source code and datasets significantly enhances reproducibility and aligns with the journal’s open science requirements. PONE-D-25-59640_R5.pdf Overall, I believe the manuscript is technically rigorous, clearly presented, and provides a meaningful contribution to the field of intrusion detection systems by integrating ensemble learning with tamper-evident auditing. I have no further major concerns and recommend the manuscript for publication in its current form. ********** what does this mean?). If published, this will include your full peer review and any attached files. If you choose “no”, your identity will remain anonymous but your review may still be made public. Do you want your identity to be public for this peer review? For information about this choice, including consent withdrawal, please see our Privacy Policy Reviewer #1: Yes: Wenke Du ********** |
| Formally Accepted |
|
PONE-D-25-59640R5 PLOS One Dear Dr. Mishra, I'm pleased to inform you that your manuscript has been deemed suitable for publication in PLOS One. Congratulations! Your manuscript is now being handed over to our production team. At this stage, our production department will prepare your paper for publication. This includes ensuring the following: * All references, tables, and figures are properly cited * All relevant supporting information is included in the manuscript submission, * There are no issues that prevent the paper from being properly typeset You will receive further instructions from the production team, including instructions on how to review your proof when it is ready. Please keep in mind that we are working through a large volume of accepted articles, so please give us a few days to review your paper and let you know the next and final steps. Lastly, if your institution or institutions have a press office, please let them know about your upcoming paper now to help maximize its impact. If they'll be preparing press materials, please inform our press team within the next 48 hours. Your manuscript will remain under strict press embargo until 2 pm Eastern Time on the date of publication. For more information, please contact onepress@plos.org. You will receive an invoice from PLOS for your publication fee after your manuscript has reached the completed accept phase. If you receive an email requesting payment before acceptance or for any other service, this may be a phishing scheme. Learn how to identify phishing emails and protect your accounts at https://explore.plos.org/phishing. If we can help with anything else, please email us at customercare@plos.org. Thank you for submitting your work to PLOS One and supporting open access. Kind regards, PLOS One Editorial Office Staff on behalf of Dr. Sohail Saif Academic Editor PLOS One |
Open letter on the publication of peer review reports
PLOS recognizes the benefits of transparency in the peer review process. Therefore, we enable the publication of all of the content of peer review and author responses alongside final, published articles. Reviewers remain anonymous, unless they choose to reveal their names.
We encourage other journals to join us in this initiative. We hope that our action inspires the community, including researchers, research funders, and research institutions, to recognize the benefits of published peer review reports for all parts of the research system.
Learn more at ASAPbio .