Authors :
Vishwaradhya K.; Annappa S. S.; Lohith C.
Volume/Issue :
Volume 11 - 2026, Issue 7 - July
Google Scholar :
https://tinyurl.com/ydwx2r5b
Scribd :
https://tinyurl.com/463z6kre
DOI :
https://doi.org/10.38124/ijisrt/26jul1444
Note : A published paper may take 4-5
working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and
ResearchGate.
Abstract :
The rapid growth of networked and cloud-connected infrastructure has widened the attack surface available to
adversaries, exposing enterprise and IoT environments to increasingly stealthy and evolving intrusions. Signature-based
and shallow machine-learning intrusion detection systems (IDS) generalize poorly to zero-day and low-frequency attack
classes and typically treat traffic features independently, ignoring both the spatial correlation among flow attributes and the
temporal evolution of a connection. This paper proposes a novel Hybrid CNN-BiLSTM Attention-based Ensemble
Framework (CBAF) that unifies three complementary representations of network traffic. A one-dimensional feature vector
is first reshaped into a two-dimensional matrix and passed through convolutional layers that learn local spatial correlations
among protocol, packet, and byte-level attributes. The resulting feature maps are fed into a Bidirectional Long Short-Term
Memory (BiLSTM) network that models the forward and backward temporal dependencies characteristic of multi-stage
attacks. A self-attention layer then assigns adaptive importance weights to the most discriminative time steps and features,
improving both detection accuracy and interpretability. The attention-weighted representation is finally passed to a stacked
Random Forest meta-classifier that consolidates the deep and shallow decision boundaries to reduce false positives. The
framework further incorporates SMOTE-based oversampling to counter the severe class imbalance found in benchmark
intrusion datasets. Experiments on NSL-KDD, CICIDS2017, and UNSW-NB15 show that the proposed CBAF achieves
97.6% accuracy and a 0.96 F1-score, outperforming Logistic Regression, Support Vector Machine, Random Forest, and a
plain CNN-LSTM baseline, while maintaining real-time inference latency suitable for deployment in security operations
centers (SOCs).
Keywords :
Intrusion Detection System (IDS), Deep Learning, Convolutional Neural Network (CNN), Bidirectional LSTM, SelfAttention, Ensemble Learning, Class Imbalance, SMOTE, Cybersecurity, Network Traffic Analysis.
References :
- C. Yin, Y. Zhu, J. Fei, and X. He, “A deep learning approach for intrusion detection using recurrent neural networks,” IEEE Access, vol. 5, pp. 21954-21961, 2017.
- R. Vinayakumar, M. Alazab, K. P. Soman, P. Poornachandran, A. Al-Nemrat, and S. Venkatraman, “Deep learning approach for intelligent intrusion detection system,” IEEE Access, vol. 7, pp. 41525-41550, 2019.
- J. Kim, J. Kim, H. L. T. Thu, and H. Kim, “Long short term memory recurrent neural network classifier for intrusion detection,” in Proc. Int. Conf. Platform Technol. Service (PlatCon), 2016, pp. 1-5.
- N. Shone, T. N. Ngoc, V. D. Phai, and Q. Shi, “A deep learning approach to network intrusion detection,” IEEE Trans. Emerg. Topics Comput. Intell., vol. 2, no. 1, pp. 41-50, Feb. 2018.
- S. M. Kasongo and Y. Sun, “A deep learning method with wrapper based feature extraction for wireless intrusion detection system,” Comput. Secur., vol. 92, Art. no. 101752, 2020.
- A. Vaswani et al., “Attention is all you need,” in Proc. Adv. Neural Inf. Process. Syst. (NeurIPS), 2017, pp. 5998-6008.
- V. K. Mishra, M. Mishra, A. K. Tamrakar, T. Srikanth, T. Ram Kumar, and K. Anoop, “Pneumonia detection through deep learning: A comparative exploration of classification and segmentation strategies,” Int. J. Eng. Res. Rev., vol. 40, Spl. vol., 2024.
- V. K. Mishra, M. Mishra, D. J. B. Saini, S. D. Pande, S. Bharany, and A. Ur Rehman, “Exploiting machine learning for vulnerable road users’ protection of moving objects on trajectory motion,” Arabian J. Sci. Eng., 2025, doi: 10.1007/s13369-025-10346-z.
- R. C. Staudemeyer, “Applying long short-term memory recurrent neural networks to intrusion detection,” South African Comput. J., vol. 56, no. 1, pp. 136-154, 2015.
- A. Halbouni, T. S. Gunawan, M. H. Habaebi, M. Halbouni, M. Kartiwi, and R. Ahmad, “Machine learning and deep learning approaches for cybersecurity: A review,” IEEE Access, vol. 10, pp. 19572-19585, 2022.
- M. Al-Qatf, Y. Lasheng, M. Al-Habib, and K. Al-Sabahi, “Deep learning approach combining sparse autoencoder with SVM for network intrusion detection,” IEEE Access, vol. 6, pp. 52843-52856, 2018.
- Y. Zhang, X. Chen, L. Jin, X. Wang, and D. Guo, “Network intrusion detection: Based on deep hierarchical network and original flow data,” IEEE Access, vol. 7, pp. 37004-37016, 2019.
- P. Panwar, A. Kumar, and R. Sharma, “Attention-based hybrid CNN-LSTM model for network intrusion detection,” in Proc. IEEE Int. Conf. Comput. Commun. Informat. (ICCCI), 2023, pp. 1-6.
- T.-T.-H. Le, H. Kim, H. Kang, and H. Kim, “Classification and explanation for intrusion detection system based on ensemble trees and SHAP method,” Sensors, vol. 22, no. 3, p. 1154, Feb. 2022.
- N. Moustafa and J. Slay, “UNSW-NB15: A comprehensive data set for network intrusion detection systems,” in Proc. Mil. Commun. Inf. Syst. Conf. (MilCIS), 2015, pp. 1-6.
- I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, “Toward generating a new intrusion detection dataset and intrusion traffic characterization,” in Proc. Int. Conf. Inf. Syst. Secur. Privacy (ICISSP), 2018, pp. 108-116.
- C. Anthony, W. Elgenaidi, and M. Rao, “Intrusion detection system for autonomous vehicles using non-tree-based machine learning algorithms,” Electronics, vol. 13, no. 5, p. 809, Feb. 2024.
The rapid growth of networked and cloud-connected infrastructure has widened the attack surface available to
adversaries, exposing enterprise and IoT environments to increasingly stealthy and evolving intrusions. Signature-based
and shallow machine-learning intrusion detection systems (IDS) generalize poorly to zero-day and low-frequency attack
classes and typically treat traffic features independently, ignoring both the spatial correlation among flow attributes and the
temporal evolution of a connection. This paper proposes a novel Hybrid CNN-BiLSTM Attention-based Ensemble
Framework (CBAF) that unifies three complementary representations of network traffic. A one-dimensional feature vector
is first reshaped into a two-dimensional matrix and passed through convolutional layers that learn local spatial correlations
among protocol, packet, and byte-level attributes. The resulting feature maps are fed into a Bidirectional Long Short-Term
Memory (BiLSTM) network that models the forward and backward temporal dependencies characteristic of multi-stage
attacks. A self-attention layer then assigns adaptive importance weights to the most discriminative time steps and features,
improving both detection accuracy and interpretability. The attention-weighted representation is finally passed to a stacked
Random Forest meta-classifier that consolidates the deep and shallow decision boundaries to reduce false positives. The
framework further incorporates SMOTE-based oversampling to counter the severe class imbalance found in benchmark
intrusion datasets. Experiments on NSL-KDD, CICIDS2017, and UNSW-NB15 show that the proposed CBAF achieves
97.6% accuracy and a 0.96 F1-score, outperforming Logistic Regression, Support Vector Machine, Random Forest, and a
plain CNN-LSTM baseline, while maintaining real-time inference latency suitable for deployment in security operations
centers (SOCs).
Keywords :
Intrusion Detection System (IDS), Deep Learning, Convolutional Neural Network (CNN), Bidirectional LSTM, SelfAttention, Ensemble Learning, Class Imbalance, SMOTE, Cybersecurity, Network Traffic Analysis.