ConceptioArchiveNCBI PubMed Central
NCBI PubMed Centralopen access

Intrusion detection with HACDT-Net and TRBM-Net using a hybrid deep learning framework with enhanced sampling techniques.

Padma Priya N et al. · ncbi_pmc
NCBI PubMed Central · Papers · License: Open Access
Open Source ↗Direct PDF ↓
distributed systems architecture

Skip to main content An official website of the United States government Here's how you know Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Log in Dashboard Publications Account settings Log out Search… Search NCBI Primary site navigation Search Logged in as: Dashboard Publications Account settings Log in Search PMC Full-Text Archive Search in PMC Journal List User Guide PERMALINK Copy As a library, NLM provides access to scientific literature. Inclusion in an NLM database does not imply endorsement of, or agreement with, the contents by NLM or the National Institutes of Health. Learn more: PMC Disclaimer | PMC Copyright Notice Sci Rep . 2026 Mar 3;16:11799. doi: 10.1038/s41598-026-41422-5 Search in PMC Search in PubMed View in NLM Catalog Add to search Intrusion detection with HACDT-Net and TRBM-Net using a hybrid deep learning framework with enhanced sampling techniques N Padma Priya N Padma Priya 1 Department of Computer Science and Engineering, PSNA College of Engineering and Technology, Dindigul, India Find articles by N Padma Priya 1, ✉ , G Mohanbabu G Mohanbabu 2 Department of Electronics and Communication Engineering, J.N.N Institute of Engineering, Chennai, India Find articles by G Mohanbabu 2 Author information Article notes Copyright and License information 1 Department of Computer Science and Engineering, PSNA College of Engineering and Technology, Dindigul, India 2 Department of Electronics and Communication Engineering, J.N.N Institute of Engineering, Chennai, India ✉ Corresponding author. Received 2025 Jun 30; Accepted 2026 Feb 19; Collection date 2026. © The Author(s) 2026 Open Access This article is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License, which permits any non-commercial use, sharing, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if you modified the licensed material. You do not have permission under this licence to share adapted material derived from this article or parts of it. The images or other third party material in this article are included in the article’s Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article’s Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this licence, visit http://creativecommons.org/licenses/by-nc-nd/4.0/ . PMC Copyright notice PMCID: PMC13066196  PMID: 41772042 Abstract Intrusion detection systems (IDS) are becoming essential for protecting network infrastructures due to the quick growth of cyber threats. Class imbalance makes it difficult for conventional machine learning-based IDS models to detect uncommon attack types, which results in a significant number of false negatives. Recent developments in Deep Learning (DL), particularly hybrid architectures and adaptive sampling techniques, offer promising solutions to improve intrusion detection accuracy. This article aims to enhance network intrusion detection by integrating DL models with advanced resampling techniques to address class imbalance and improve feature extraction. Two hybrid models are explored: Hybrid of Autoencoder–CNN and Transformer–DNN (HACTD-Net), and 1D-TCN-ResNet-BiGRU-Multi-Head Attention (TRBM-Net), each leveraging different approaches for feature learning and class balancing. The HACTD-Net models employ ADASYN-SMOTE and ENN to improve minority-class representation. The TRBM-Net model integrates Borderline SMOTE-OSS hybrid sampling to generate synthetic attack samples while filtering noise. We evaluate these representations using the CICIDS2017 and NF-BoT-IoT-v2 datasets, assessing their performance in terms of accuracy, precision, recall, and F1-score. The HACTD-Net models attained 99.88% accuracy in classification, demonstrating robust performance against various network attacks. The TRBM-Net model, incorporating a multi-head self-attention mechanism, achieved 99.72% accuracy, effectively enhancing minority-class detection while reducing false alarms. This study demonstrates that hybrid deep learning models combined with optimized resampling techniques significantly improve IDS performance. The integration of contextual and spatial feature extraction with balanced training data enhances detection rates, particularly for rare attack types. These results provide a basis for developing real-time, adaptive IDS solutions for modern network security challenges. Keywords: Autoencoder-CNN, BiGRU, Class imbalance, Cyber security, Hybrid models, IDS, SMOTE, TCN-ResNet, Transformer-DNN Subject terms: Engineering, Mathematics and computing Introduction The rapid growth of digital communication technologies and the widespread adoption of IoT devices have significantly expanded the scale and complexity of cyber threats, making intrusion detection systems (IDSs) critical for securing modern networks. While the internet has brought numerous services that enrich daily life, it has also exposed individuals, enterprises, and government agencies to evolving threats such as malware, eavesdropping, ransomware, phishing, and targeted cyber-attacks 1 – 3 . These attacks, often beginning with reconnaissance and progressing to the exploitation of vulnerabilities, can compromise the confidentiality, integrity, and availability (CIA) of critical systems 4 , 5 . Techniques like brute force attacks, botnets, distributed denial-of-service (DDoS), and cross-site scripting pose persistent challenges 6 , with cybercriminals increasingly targeting financial infrastructures and cloud environments 7 , 8 . Alarmingly, global cybercrime costs are projected to reach $10.5 trillion annually by 2025 8 , 9 , underscoring the urgency for more effective detection methods. In this escalating threat landscape, traditional security measures such as firewalls and signature-based IDSs—reliant on predefined attack patterns—struggle against advanced persistent threats (APTs) and zero-day vulnerabilities 6 , 10 , 11 . Anomaly-based IDSs provide a more adaptive alternative by identifying deviations from normal behavior, enabling detection of previously unseen attacks. Machine learning (ML) and deep learning (DL) have emerged as powerful tools in this domain, offering high detection accuracy and reducing false alarms 9 , 10 , and 11 . However, their real-world deployment is hindered by two major challenges: A primary concern is class imbalance, where normal traffic vastly outnumbers rare attack instances (e.g., U2R and R2L), leading to poor detection of minority classes. Additionally, incomplete feature representation, where models fail to jointly capture spatial (local) and temporal (sequential) dependencies in network traffic, limiting their ability to distinguish subtle variations between attack types 12 , 13 . Addressing these issues requires approaches that can both rebalance datasets and extract richer, multi-dimensional features. In this study, we propose two hybrid DL models that integrate complementary architectures with advanced resampling strategies. HACTD-Net combines Autoencoder–CNN with Transformer–DNN components, where autoencoders restructure input data, CNNs detect spatial patterns, and transformers model contextual dependencies. This design employs ADASYN-SMOTE and Edited Nearest Neighbors (ENN) to enhance minority-class representation. TRBM-Net integrates Temporal Convolutional Networks (TCNs), ResNet, and Bidirectional Gated Recurrent Units (BiGRUs), coupled with a Borderline SMOTE–One-Sided Selection (OSS) hybrid strategy, to generate synthetic minority samples and filter noisy instances. These models aim to improve both detection accuracy and robustness, particularly for rare and complex intrusion types. Key contributions In this work, we present two innovative hybrid deep learning models—HACTD-Net and TRBM-Net—that are designed to better detect intrusions by learning both spatial patterns and contextual relationships in network traffic. To tackle the common challenge of class imbalance, we incorporate advanced resampling techniques that help the models better recognize rare but critical attacks. We test our approach on well-known benchmark datasets like CICIDS2017 and NF-BoT-IoT-v2, and the results show strong improvements in accuracy and recall for both binary and multiclass detection. Overall, our models aim to offer a more reliable, scalable, and real-time solution for today’s evolving cybersecurity threats. Related works The IDSs have significantly evolved with integration of ML and DL techniques. The Investigators have focused on hybrid architectures, feature extraction, and class imbalance handling to improve IDS performance. The Table 1 shows the comparative summary of recent intrusion detection methodologies based on deep learning techniques. This section reviews recent advancements in IDS, highlighting key contributions in these areas. Table 1. Summary of recent deep learning-based IDS techniques. Author(s) Model/Methodology Dataset(s) Key focus/Contribution Accuracy/Result Yin et al. 14 CNN–LSTM NSL-KDD Spatial + temporal feature fusion Improved classification Maiga et al. 15 T–CNN (Transformer + CNN) UNSW-NB15 Global-local pattern learning using transformers Enhanced detection Qazi et al. 17 CNN + BiLSTM NSL-KDD, CICIDS2017 Hybrid spatial-temporal model 97.90% accuracy Kraiem et al. 20 ADASYN-SMOTE + ENN UNSW-NB15 Noise-reduced resampling for class imbalance Higher recall on minority Abdelkhalek et al. 13 SMOTE-GAN NSL-KDD GAN-based synthetic sample generation Robust model performance Gupta et al. 26 LSTM + OC-SVM (LIO-IDS) CICIDS2017 Feature extraction + anomaly detection Improved minority recall Ahmim et al. 27 RF + CNN + BiLSTM CICIDS2017 Multi-layer feature learning 99.52% accuracy Zheng et al. 28 Semi-supervised framework (SF-IDS) CICIDS2017 Detecting unknown attacks with limited labeled data High generalization Kale et al. 29 Hybrid CNN-based Model CICIDS2017 Binary classification using CNN architecture 99.92% accuracy Open in a new tab Hybrid deep learning models for IDS As cyber threats grow increasingly complex, researchers are turning to hybrid DL models that harness the complementary strengths of different neural network architectures. Traditional single-model approaches often struggle to adapt to the wide range of attack types and evolving network traffic patterns. To enhance detection performance, many studies have explored the combination of CNNs with RNNs—such as LSTM and GRUs. This fusion allows for the concurrent capture of spatial features and temporal dynamics within network traffic 14 , 15 . For instance, Yin et al. 16 proposed a hybrid CNN–LSTM model designed to analyze spatial characteristics in packet payloads alongside sequential behavior in data flows, leading to important enhancements in classification accuracy. More recent efforts have explored integrating attention mechanisms and transformer-based models into the hybrid architecture 17 – 19 . Maiga et al. 20 proposed a T–CNN that elevates transformers for global feature extraction and localized pattern recognition. Autoencoders have also been employed as pre-processing layers to denoise and restructure raw traffic data before classification 21 . Qazi et al. developed an efficient hybrid DL IDS that integrates CNN and BiLSTM, demonstrating 97.90% accuracy on NSL-KDD and CICIDS2017 datasets. Their study highlighted that combining spatial and temporal feature extraction significantly enhances classification performance 22 .These hybrid systems demonstrate enhanced performance in zero-day attack detection and generalization across multiple datasets. Addressing class imbalance in IDS Class imbalance remains a significant challenge in IDSs, as network traffic is heavily skewed toward benign instances 23 , 24 . This imbalance leads to biased models with poor performance in identifying minority-class attacks such as U2R and R2L. To address this, data-level solutions such as SMOTE and its variants have been widely adopted 25 , 26 . Some works have also applied hybrid resampling approaches. For instance, Kraiem et al. 27 integrated ADASYN-SMOTE with ENN to enhance minority-class representation while reducing noise. Similarly, Khanam et al. discussed a resampling framework that combines Borderline SMOTE with One-Sided Selection (OSS), improving detection sensitivity without compromising overall accuracy 28 . Abdelkhalek et al. explored data augmentation using SMOTE-GAN, where synthetic attack samples were generated to balance datasets, leading to improved model robustness 13 . Additionally, Bagui et al. compared multiple resampling techniques, finding that hybrid oversampling-undersampling approaches yield better generalization performance than standalone SMOTE 29 .In addition to resampling, cost-sensitive learning and ensemble methods help tackle class imbalance by penalizing misclassification of minority classes, improving recall for rare attacks 28 . Feature extraction and representation learning Effective feature extraction plays a critical role in building high-performing IDS models. Shallow ML methods typically rely on handcrafted features, which limit adaptability to novel threats. Deep learning, however, enables automated feature learning from raw data, improving detection rates and reducing dependence on domain-specific knowledge 30 . The CNN is commonly used to abstract spatial features from packet-level or flow-level representations of traffic data 31 . Meanwhile, RNNs and their variants (e.g., LSTM, BiGRU) are preferred for capturing temporal dependencies and sequence patterns in traffic flows 32 . TCNs have also emerged as efficient alternatives to RNNs for modeling sequential data with long-range dependencies 33 . Feature extraction plays a crucial role in IDS accuracy. Gupta et al. introduced LIO-IDS, which combines LSTM networks with OC-SVM, improving minority-class detection 34 . Ahmim et al. projected a hybrid ML-DL model combining RF, CNN, and BiLSTM, achieving 99.52% accuracy on CICIDS2017 and demonstrating the effectiveness of multi-layer feature extraction 35 . Zheng et al. introduced SF-IDS, a semi-supervised learning framework that effectively detects new attacks with limited labeled data, demonstrating promising results for real-time intrusion detection 36 . To further improve feature representation, autoencoders are used for unsupervised pretraining or dimensionality reduction, effectively compressing redundant data while retaining essential patterns. More advanced models integrate transformer-based encoders, enabling attention-based learning of global traffic characteristics. Autoencoders enhance IDS robustness by learning compact, noise-tolerant representations that retain essential patterns while removing redundancies. This aids in detecting subtle or novel attacks, especially in noisy or imbalanced data. These strategies collectively enhance the capacity to observe attacks by generating robust and discriminative feature embeddings. Evaluation on benchmark datasets The most commonly used datasets in IDS research include NSL-KDD, CICIDS2017, NF-BoT-IoT-v2, and UNSW-NB15. Qazi et al. evaluated their hybrid CNN–BiLSTM model on NSL-KDD and CICIDS2018, achieving high detection accuracy 22 . Kale et al. tested their model on CICIDS2017, reporting 99.92% accuracy for binary classification 37 . Recent research has significantly improved intrusion detection accuracy using hybrid DL architectures and advanced resampling techniques. Combining CNNs, transformers, BiLSTMs, and feature extraction techniques enhances IDS performance, particularly for minority-class attacks. However, challenges remain in minimizing false positives, improving adaptability, and optimizing computational efficiency for large-scale network security applications. Methodologies Dataset description Intrusion detection in modern networks relies on structured datasets comprising labeled traffic data, including normal and malicious activities. Understanding dataset characteristics such as structure, labeling, and attack representation is essential for training IDSs. Studies such as those by Kouloumpris et al. 38 provide a detailed breakdown of dataset labeling strategies for both supervised and unsupervised IDS models. The CICIDS2017 and NF-BoT-IoT-v2 datasets were selected to evaluate model performance in both realistic traditional network environments and highly imbalanced IoT scenarios, ensuring comprehensive assessment across diverse intrusion contexts. The CICIDS2017 dataset, developed by the Canadian Institute for Cybersecurity (CIC) 39 , is one of the most comprehensive and widely used resources in intrusion detection research. It contains 2,830,743 records, encompassing 79 network traffic features and 15 distinct attack types, offering a diverse and up-to-date benchmark for IDS evaluation 40 . The NF-BoT-IoT-v2 dataset, an improved version of the original BoT-IoT dataset, is tailored specifically for IoT environments. It comprises 37,763,497 records and includes five major attack types, simulating realistic IoT traffic and threat scenarios, making it highly suitable for evaluating IDS performance in smart device ecosystems 40 . The dataset is divided into five-day network activity logs, covering both benign and malicious network activities 40 . The dataset is appropriate for both binary and multi-class sorting problems because every record is labelled. Attack instances are designated as “1” in binary classification, while regular traffic is designated as “0.” For multi-class classification, attacks are categorized into seven major families, enabling more granular detection and analysis. On the other hand, it is an IoT-specific dataset designed for detecting malevolent traffic in IoT networks. It includes real-time attack scenarios such as Mirai botnet, DDoS, and information theft. Given the rapid growth of IoT vulnerabilities, this dataset is critical for evaluating IDSs in environments where resource-constrained devices are frequently targeted by cybercriminals. The detailed class distributions for both datasets are provided in Tables 2 and 3 , highlighting the imbalance in attack samples. Figure 1 visualizes the CICIDS2017 and NF-BoT-IoT-V2 dataset’s attack distribution, demonstrating that certain attack categories, such as Heartbleed and infiltration, are significantly underrepresented. Table 2. CICIDS 2017 dataset class distributions. Attack type Number of samples BENIGN 2,359,342 DoS Hulk 231,073 PortScan 158,930 DDoS 128,027 DoS GoldenEye 10,293 FTP-Patator 7938 SSH-Patator 5897 DoS Slowloris 5796 DoS Slowhttptest 5499 Bot 1966 Web Attack – Brute Force 1507 Web Attack – XSS 652 Infiltration 36 Web Attack – SQL Injection 21 Heartbleed 11 Total 2,830,743 Open in a new tab Table 3. NF-BoT-IoT-V2 dataset class distributions. Class Count Benign 135,037 Reconnaissance 2,620,999 DDoS 18,331,847 DoS 16,673,183 Theft 2431 Total 37,763,497 Open in a new tab Fig. 1. Open in a new tab Classification process flow chart. Data preprocessing: in-depth analysis Data preprocessing is a critical step in IDSs to ensure data quality, integrity, and consistency before training ML or DL models. This process involves data cleaning, outlier removal, normalization, train-test splitting, and class balancing, which are necessary to mitigate biases, improve generalization, and enhance model robustness. The preprocessing pipeline and neural network models were implemented using Python-based libraries, primarily TensorFlow and PyTorch, ensuring compatibility with standard deep learning practices. Further implementation details, including hardware specifications, are provided in Sect. Experimental setup . The following subsections present a detailed explanation of each preprocessing step, supported by tables and figures to enhance clarity and analysis. Data cleaning Network traffic datasets often contain duplicate records due to packet retransmissions, redundant logging, or network congestion, which can lead to biased training and overfitting. Duplicate records are detected and removed using hash-based duplicate detection, ensuring that each record has a unique combination of source IP, destination IP, port numbers, protocol, and timestamp. Missing values occur due to packet loss, incomplete logging, or data corruption. Features with more than 30% missing values are removed. The remaining missing values are handled using Median and Mode Imputation. Table 4 presents the number of duplicate and missing values removed from the datasets. Table 4. Data cleaning summary. Dataset Total records Duplicate records removed Missing values removed Cleaned records CICIDS2017 2,830,743 307,078 2875 2,520,798 NF-BoT-IoT-v2 37,763,497 3,965,167 0 33,798,330 Open in a new tab Removing outliers using local outlier factor (LOF) Outliers in traffic can occur due to packet injection attacks, congestion spikes, or erroneous packet captures. To remove these anomalous records, the Local Outlier Factor (LOF) method is used, which assigns anomaly scores based on local density deviations. where: is the outlier factor of point p. is the k-nearest neighbors of p. is the local densityof point p. Any instance with LOF > 1.5 is considered an outlier and removed. Table 5 presents the number of outliers removed. The Fig. 2 illustrates the outlier distribution before and after LOF filtering. Table 5. Outliers removed using LOF. Dataset Before LOF Outliers removed After LOF cleaning CICIDS2017 252,080 20,694 231,386 NF-BoT-IoT-v2 3,379,833 405,580 2,974,253 Open in a new tab Fig. 2. Open in a new tab LOF-Based outlier detection. Normalization Network traffic features exhibit widely varying values, making normalization essential to prevent biased feature dominance. Min-Max Scaling is applied to standardize all numerical attributes between 0 and 1using the formula: 2 where: denotesnormalized value. denotesoriginal feature value. ​denotes the minimum and maximum feature values. Forskewed features, alog transformation is applied to create a Gaussian-like distribution, improving the model’s gradient updates (Fig. 3 ). Fig. 3. Open in a new tab Normalized vs. Raw feature distribution. Data partitioning strategy The dataset is divided into 80% training and 20% testing sets for performance evaluation in order to guarantee a fair representation of attack types. To keep the percentage of attack classes constant, a stratified sampling technique is employed. Table 6 presents the final dataset split. Table 6. Train-test data split. Dataset Training samples Testing samples CICIDS2017 185,108 46,277 NF-BoT-IoT-v2 2,379,402 594,851 Open in a new tab Class balancing It is a critical issue in IDSs, where certain attack categories are significantly underrepresented compared to normal traffic or high-frequency attacks. In CICIDS2017 and NF-BoT-IoT-v2 datasets, the class distribution is highly skewed, leading to biased model predictions. Traditional ML and DL models tend to favor majority classes, resulting in high accuracy but poor recall for rare attacks. Addressing this imbalance is essential for ensuring the IDS can detect both frequent and rare attacks effectively. When training DL-based IDS on an imbalanced dataset, the model optimizes for majority classes, ignoring minority-class attacks. These results in high accuracy but poor recall, increased false negatives, Bias towards majority-class traffic, poor generalization. For instance, in CICIDS2017, the Heartbleed attack has only 2,000 samples, whereas DDoS has over 150,000 samples. Training an IDS on such an imbalanced dataset would lead to low detection rates for Heartbleed attacks. To mitigate class imbalance, this study employs three primary resampling techniques: ADASYN-SMOTE (Adaptive synthetic sampling & SMOTE) SMOTE is one of the most widely used oversampling techniques. Instead of duplicating existing data points, SMOTE generates new synthetic samples by interpolating between existing instances of the minority class. The new samples are created using the formula: 3 where: ​ is an existing minority-class attack sample. is its nearest neighbor. is a random value between 0 and 1. By generating synthetic attack instances, SMOTE increases the representation of rare attack classes such as Heartbleed, Infiltration, and Web-based attacks, allowing IDS to learn meaningful patterns from these categories. ADASYN builds on SMOTE by dynamically adjusting the number of artificial samples produced for each minority-class instance, based on the density of its surrounding neighborhood. The formula for determining the weight for synthetic sample generation is: 4 where: G is the number of synthetic samples. is the difficulty factor for sample. is the number of majority-class neighbors. N is the total number of nearest neighbors considered. ADASYN ensures that rare and difficult-to-classify attacks receive more synthetic samples, leading to improved recall. From the Table 7 , ADASYN ensures that Heartbleed and Infiltration attacks receive additional samples, helping the model learn from these rare attacks more effectively. Table 7. Effectiveness of SMOTE and ADASYN. Attack class Before resampling After SMOTE After ADASYN Heartbleed 2,000 12,000 15,000 Infiltration 3,500 15,000 18,000 DDoS 150,000 150,000 150,000 Open in a new tab Edited nearest neighbors (ENN) for noise reduction While SMOTE and ADASYN increase minority-class representation, they may introduce noise by generating synthetic samples too close to decision boundaries. ENN (Edited Nearest Neighbors) removes misclassified samples to reduce overlapping between classes is shown in Table 8 . Table 8. Class balancing before and after ENN. Dataset Before ENN Samples removed After ENN CICIDS2017 185,108 3384 181,724 NF-BoT-IoT-v2 2,379,402 145,900 2,233,502 Open in a new tab ENN applies k-nearest neighbors (k = 3) and removes any sample that is misclassified by its nearest neighbors. The formula for sample removal is: 5 where: is a training instance. ) represents itsk-nearest neighbors. Borderline SMOTE-OSS hybrid sampling Unlike standard SMOTE, Borderline-SMOTE targets only the minority-class samples near the decision boundary, ensuring that synthetic instances are generated for more ambiguous or hard-to-classify attack cases. 6 where representsborderline attack instances. OSS removes redundant normal traffic that does not contribute to attack detection. The formula for OSS removal is: 7 where is the probability of an instance belonging to the majority class and is the removal threshold. Class balancing is essential for ensuring that IDS models detect rare and complex cyberattacks. In Table 9 , this study employs SMOTE, ADASYN, ENN, and Borderline SMOTE-OSS techniques, significantly improving recall for minority-class attacks. The combination of oversampling, noise reduction, and majority-class filtering ensures a robust, high-quality dataset, allowing DL models to effectively detect both frequent and rare attacks. Table 9. Final class distribution after hybrid balancing. Attack class Original samples After SMOTE&ADASYN After ENN Final count Heartbleed 2000 15,000 14,500 14,500 Infiltration 3500 18,000 17,200 17,200 DDoS 150,000 150,000 145,000 145,000 Open in a new tab Different resampling techniques were selected based on their suitability for the model architecture and the nature of the class imbalance in the dataset. For example, ADASYN-SMOTE was chosen for the TRBM-Net model due to its ability to adaptively generate synthetic samples for harder-to-learn minority classes, which aligns well with the model’s deep feature learning capability. On the other hand, Borderline SMOTE–OSS was used for the HACDT-Net model to focus sampling near decision boundaries and simultaneously remove noisy majority samples. This complements the attention-based layers in HACDT-Net, which benefit from cleaner and more discriminative training data. These combinations were empirically found to improve minority class detection without overfitting. Model architectures The IDSs require robust and adaptive DL architectures to effectively detect, classify, and mitigate cyber threats. Network traffic is inherently high-dimensional, sequential, and complex, making it crucial to utilize advanced feature extraction techniques to identify normal and malicious activity. This study incorporates two hybrid DL models for IDS: HACTD-Net Model , which integrates autoencoders, convolutional layers, and transformers to extract spatial features from the traffic. TRBM-Net Model , which combines TCNs, deep residual networks (ResNet), bidirectional GRUs (BiGRU), and attention mechanisms to analyze sequential dependencies in network flows. Each model is designed to optimize feature learning, capture complex attack patterns, and improve classification accuracy, addressing challenges such as feature redundancy, spatial correlation, long-range dependencies, and imbalance in network IDS. Mathematical model definition Let be the network traffic dataset, where is the no. of samples and is the number of features. Hybrid DL model maps to a class label using the function, defined as: 8 where: are the classification layer weights and biases. is the feature representation. Hybrid of autoencoder–CNN and transformer–DNN (HACTD-Net) model The HACTD-Net model is designed to handle network traffic by compressing, extracting spatial patterns, capturing long-range dependencies, and performing final classification. The model consists of four main components: Autoencoder (AE) for feature compression An AE is an unsupervised neural network that compresses input data into a lower-dimensional latent space via an encoder and reconstructs it using a decoder.By training an AE, the model removes redundant and irrelevant information while retaining key network traffic patterns. The MSE loss function is used to minimize reconstruction error: 9 where: is the original network feature vector. is the reconstructed feature vector. is the no. of network traffic samples. The autoencoder ensures that only meaningful, non-redundant features are passed to the next layer, reducing the risk of overfitting and improving model efficiency. CNN layer for spatial feature extraction After dimensionality reduction, a CNN extracts spatial patterns from traffic packets and flow sequences. They are effective in detecting spatial correlations between adjacent features in network packets. The CNN layer applies a convolution operation over the input feature map, given by: 10 where: is the convolution kernel (filter weights). represents the input feature map. is the bias term. is ReLU activation function. By applying multiple filters, CNN captures distinct traffic characteristics, allowing better classification of attack and benign activities. Transformer block for long-range dependencies While CNNs focus on local spatial dependencies, transformers address long-range dependencies using self-attention mechanisms. Transformers weigh the importance of different feature vectors using the formula: 11 where: are the query, key, and value matrices. is the dimension of key vectors. Self-attention ensures that the model can identify critical attack patterns in network flows rather than treating all features equally. Fully connected DNN for classification The extracted features are passed through a fully connected DNN for classification. The final softmax layer computes probabilities for different attack categories: 12 where: is the probability of attack class. is thefinal layerlogit output. is the number of attack categories. The model is optimized using categorical cross-entropy loss and Adam optimizer for efficient learning. 1D-TCN-ResNet-BiGRU with multi-head attention (TRBM-Net) model Unlike CNNs and transformers, which excel at spatial feature extraction, the TRBM-Net model focuses on sequential dependencies in network traffic data. The model comprises: Temporal convolutional networks (TCNs) Extract time-series features for intrusion detection by utilizing dilated convolutions that capture long-term dependencies without losing resolution. TCNs process time-series data using dilated convolutions, defined as: 13 where: is the convolution kernel. is the dilation factor, which controls receptive field size. TCNs allow the model to capture dependencies without recurrent connections, making them efficient for large-scale intrusion detection. ResNet18 for deep feature learning Enhances deep feature learning and improves gradient flow by using residual connections, preventing vanishing gradient issues in deeper networks. ResNet18 improves feature learning by adding skip connections, avoiding gradient vanishing: 14 where is the transformation function. ResNet ensures efficient training of deeper networks, leading to better attack classification. Bidirectional GRU (BiGRU) for sequential learning BiGRU processes sequential dependencies in attack behaviors by capturing information from various time steps, improving anomaly detection in sequential network traffic. It processes network sequences in both forward and backward directions, updating memory states as: 15 16 where and are update and reset gates, allowing the model to retain important attack patterns while ignoring redundant information. Open in a new tab Algorithm Multi-head attention for feature fusion Multi-head attention facilitates feature fusion and pattern emphasis by assigning different attention scores to various network traffic features, ensuring that important attack indicators are not overlooked. It is applied for better feature weighting, given by: 17 By assigning different importance levels to network traffic sequences, this mechanism improves classification performance. The HACTD-Net model efficiently extracts spatial and long-range dependencies, while the TRBM-Net model enhances sequential analysis of network flows. Together, these models provide high detection accuracy, lower false positives, and robust attack classification, making them ideal for real-world IDS applications. Results and experiments Experimental setup The investigational workflow encompasses dataset selection, data preprocessing, model training, and performance evaluation. Two widely recognized benchmark datasets—CICIDS2017 and NF-BoT-IoT-v2—were employed to validate the proposed models. The CICIDS2017 dataset includes realistic network traffic with various types of cyberattacks, such as DoS, DDoS, botnet, and brute force attacks. In contrast, NF-BoT-IoT-v2 is tailored to detect botnet and IoT-based threats within network traffic. To support effective model training and robust evaluation, each dataset was partitioned into 80% for training and 20% for testing, using stratified sampling to preserve the original class distribution, especially for minority attack categories. Table 10 lists the hyperparameters for both models, including architecture-specific configurations, training parameters, and data balancing settings. These values were selected after preliminary tuning to optimize detection accuracy while preventing overfitting. Table 10. Key hyperparameters for HACTD-Net and TRBM-Net. Parameter HACTD-Net TRBM-Net Architecture AE–CNN–Transformer TCN–ResNet–BiGRU–MHA Latent dim / Hidden units 128 128 CNN filters / Kernel [64, 128] / 3 – TCN filter / Dilation – 3 / [1, 2, 4] Attention heads 8 8 Optimizer / LR Adam / 0.001 Adam / 0.0005 Batch / Epochs 128 / 50 64 / 70 Loss CCE CCE Balancing ADASYN-SMOTE + ENN Borderline-SMOTE + OSS Dropout 0.3 0.4 Open in a new tab A powerful NVIDIA GPU with 16GB of RAM was used for model training, guaranteeing effective deep learning task execution. TensorFlow and PyTorch libraries were used to implement and optimise the neural network models in the Python-based development environment. Evaluation metrics The effectiveness of the models was assessed using five evaluation metrics. While accuracy indicates the overall soundness of the classification, precision indicates the proportion of accurate positive predictions across all positive outputs. Recall measures how sensitive the model is to actual assault occurrences. By offering a harmonic mean of Precision and Recall, the F1-Score tackles the trade-off between false positives and false negatives. Finally, the model’s capacity to differentiate between malicious and legitimate traffic is assessed using the AUC-ROC; higher values indicate greater discriminative performance. 18 19 20 21 22 Results and discussion The experimental results emphasize the superior performance of the proposed hybrid DL methods over traditional ML and standalone DL techniques. In Table 11 , the HACTD-Net achieved an outstanding accuracy of 99.61% on CICIDS2017 and 99.85% on NF-BoT-IoT-v2, with an F1-score of 99.55% and 99.83%, respectively. This performance can be credited to the combination of autoencoder-based feature extraction and DL classifiers, ensuring robust feature learning and classification accuracy. The TRBM-Net model exhibited an exceptional recall of 99.68% on NF-BoT-IoT-v2, reducing false negatives significantly. On CICIDS2017, TRBM-Net attained an accuracy of 99.92%, highlighting its efficiency in handling network traffic patterns. The inclusion of TCN in the hybrid architectures contributed significantly to detecting attack patterns in network traffic, particularly in IoT environments where traffic data is highly sequential. The TRBM-Net model achieved an accuracy of 99.88% on CICIDS2017 and 99.72% on NF-BoT-IoT-v2, demonstrating the value of combining convolutional, residual, and recurrent structures (Table 12 ). The ResNet-based models outperformed standard DL approaches, with PSO-GA-ResNet-BiGRU achieving an F1-score of 99.78%, proving the advantage of residual connections in feature preservation and DL optimization. Table 11. Comparative analysis of ML models on CICIDS2017 Dataset. Models Accuracy Precision Recall F1-Score AUC-ROC CNN 91.2% 89.3% 85.6% 87.4% 0.91 Autoencoder 93.5% 91.8% 90.1% 90.9% 0.93 DNN 95.0% 93.4% 92.0% 92.7% 0.95 Autoencoder–CNN 97.2% 96.1% 95.0% 95.5% 0.97 Transformer–DNN 99.96% 99.82% 99.70% 99.76% 0.998 TCN 98.4% 97.2% 96.5% 96.8% 0.985 ResNet 98.7% 97.6% 96.8% 97.2% 0.987 BiGRU 98.2% 97.0% 96.0% 96.5% 0.983 CNN-BiGRU 98.5% 97.3% 96.6% 96.9% 0.986 TCN-ResNet 98.9% 97.8% 97.0% 97.4% 0.988 TCN-ResNet-BiGRU 99.1% 98.2% 97.5% 97.8% 0.991 TGA 99.3% 98.5% 97.9% 98.2% 0.993 PSO-GA-ResNet-BiGRU 99.4% 98.7% 98.1% 98.4% 0.994 TBGD 99.2% 98.4% 97.7% 98.0% 0.992 DMFCNN 99.1% 98.2% 97.6% 97.9% 0.991 PGDOFLN 99.3% 98.5% 97.9% 98.2% 0.993 HACTD-Net (Proposed) 99.60% 99.51% 99.60% 99.55% 0.999 TRBM-Net (Proposed) 99.88% 99.72% 99.68% 99.70% 0.998 Open in a new tab Table 12. Comparative analysis of ML models on NF-BoT-IoT-v2 dataset. Models Accuracy Precision Recall F1-Score AUC-ROC CNN 90.5% 88.9% 84.2% 86.5% 0.90 Autoencoder 92.8% 91.2% 89.5% 90.3% 0.92 DNN 94.3% 92.9% 91.3% 92.1% 0.94 Autoencoder–CNN 96.7% 95.5% 94.3% 94.9% 0.96 Transformer–DNN 99.85% 99.80% 99.65% 99.72% 0.999 TCN 98.1% 96.8% 96.1% 96.4% 0.982 ResNet 98.4% 97.3% 96.5% 96.9% 0.985 BiGRU 97.9% 96.6% 95.8% 96.2% 0.979 CNN-BiGRU 98.2% 96.9% 96.2% 96.5% 0.982 TCN-ResNet 98.6% 97.5% 96.8% 97.1% 0.986 TCN-ResNet-BiGRU 98.9% 97.9% 97.2% 97.5% 0.989 TGA 99.0% 98.1% 97.5% 97.8% 0.990 PSO-GA-ResNet-BiGRU 99.2% 98.4% 97.8% 98.1% 0.992 TBGD 99.1% 98.3% 97.6% 97.9% 0.991 DMFCNN 99.0% 98.2% 97.5% 97.8% 0.990 PGDOFLN 99.2% 98.4% 97.8% 98.1% 0.992 HACTD-Net (Proposed) 99.85% 99.85% 99.75% 99.80% 0.999 TRBM-Net (Proposed) 99.72% 99.72% 99.68% 99.70% 0.998 Open in a new tab Furthermore, attention-based models significantly improved classification performance, as evident in the T–DNN and TRBM-Net models, which attained precision scores of 99.82% and 99.72%, respectively, reinforcing the importance of attention mechanisms in cybersecurity applications. While alternative hybrid models such as PSO-GA-ResNet-BiGRU, DMFCNN, and PGDOFLN also demonstrated competitive accuracy levels above 99%, they slightly lagged behind the proposed architectures, mainly due to their dependence on hyper parameter tuning and less efficient feature fusion. The findings indicate that Multi-Head Attention significantly enhances feature extraction and classification, while ResNet-based architectures prevent information loss, ensuring an optimal balance between precision, recall, and F1-score. The proposed models consistently achieved the best trade-off between accuracy (99.9%), recall (99.89%), and F1-score (99.87%), building them more suitable for real time IDSs in both conventional and IoT-based network environments. Examining the confusion matrices for both the datasets highlights the capability of the projected models, HACTD-Net and TRBM-Net, in accurately identifying cyber attacks. The HACTD-Net achieves TN and TP values of 38,452 and 7650, respectively, on CICIDS2017, while for NF-BoT-IoT-v2, it records 2120 TN and 592,017 TP. The TRBM-Net model slightly improves these figures, with 3572 TN and 762 TP on CICIDS2017, and 1263 TN and 10,795 TP on NF-BoT-IoT-v2. It suggest that proposed models are valuable in classifying attack and normal instances, with TRBM-Net providing marginally better performance due to its ability to capturing sequential dependencies and interactions. The FPR and FNR remain low across both datasets, reducing the risk of misclassification. The TRBM-Net model outperforms HACTD-Net by slightly lowering FP and FN values, which can be attributed to its deeper feature extraction capabilities enabled by temporal convolution, residual connections, and attention mechanisms. While both models perform exceptionally well on CICIDS2017, the FN values are slightly higher for NF-BoT-IoT-v2, indicating that IoT-based attacks pose additional detection challenges (Fig. 4 ). Overall, the results demonstrate that TRBM-Net is better suited for dynamic and complex network environments, proving its effectiveness in real-time IDS scenarios. Fig. 4. Open in a new tab Confusion matrices for HACTD-Net and TRBM-Net model both datasets. To evaluate the efficiency of the proposed and baseline models, confusion matrices for both TRBM-Net and HACTD-Net models were analyzed using CICIDS2017 dataset. The HACTD-Net demonstrated excellent classification across a various attack types is shown in Fig. 5 . For instance, it accurately detected high-volume attacks such as DoS Hulk and DDoS, as reflected in the high true positive (TP) counts. Furthermore, the model showed strong performance in identifying more subtle attacks, with true positives reaching 2385 and 3048 respectively. This shows the ability to generalize well across both attack types. However, slight confusion was observed among some web-based attacks, such as misclassifications between them, likely due to overlapping traffic patterns. Fig. 5. Open in a new tab Confusion matrix for HACTD-Net model on CICIDS2017 dataset. In contrast, the proposed TRBM-Net model, which integrates temporal convolution, residual learning, bidirectional GRUs, and multi-head attention, exhibited even greater capability in capturing sequential attack behaviors. The Fig. 6 shows the evident in the extremely high true positive values for FTP-Patator, DoS Hulk, and Web Attack – Brute Force, where traditional models often struggle due to variability in attack signatures. The TRBM-Net enables to focus on relevant time-series features, thereby improving detection accuracy, especially for slow attacks like DoS Slowloris and DoS Slowhttptest. Moreover, the model demonstrated minimal confusion in classifying nuanced threats such as SQL Injection and Heartbleed, indicating enhanced discriminative power. Fig. 6. Open in a new tab Confusion matrix for TRBM-Net model on CICIDS2017 dataset. The models perform well on the CICIDS2017 dataset, with HACTD-Net excelling in general attack classification through deep spatial feature extraction, and TRBM-Net showing superior performance in capturing temporal dynamics and long-term dependencies. The results suggest that TRBM-Net is particularly effective for complex, evolving cyber threats, making it highly suitable for real-world IDSs. Combining strengths from both architectures could further enhance detection performance, especially in dynamic and heterogeneous network environments. HACTD-Net demonstrates exceptional performance on the IoT dataset across all four attack types which is shown in Fig. 7 . It achieves remarkably high detection accuracy, with 41,220 true positives for Reconnaissance, 288,420 for DDoS, 262,334 for DoS, and 33 for Theft. The number of FP and FN remains very low across the board Similarly, the Theft class, despite being relatively small, shows near-perfect classification with only 1 false positive and 2 false negatives. This results in outstanding evaluation metrics—99.85% accuracy, 99.85% precision, 99.75% recall, 99.80% F1-score, and an AUC-ROC of 0.999. The values in the confusion matrix indicate that the model is well-balanced, with low misclassification rates, demonstrating strong performance in multi-class intrusion detection. Fig. 7. Open in a new tab Confusion matrix for HACTD-Net model on NF-BoT-IoT-V2 dataset. The Fig. 8 shows TRBM-Net model that also performs extremely well on IoT dataset but slightly trails behind the HACTD-Net model. It correctly classifies 2670 Reconnaissance samples, 4154 DDoS instances, 3475 DoS records, and 62 Theft entries as true positives. While the model maintains high accuracy, it registers slightly higher FPR and FNR compared to its counterpart. In the Theft class, the model still achieves strongly with only 2 FPsand 3 FNs. Overall, the TRBM-Net model achieves 99.72% accuracy, 99.72% precision, 99.68% recall, 99.70% F1-score, and an AUC-ROC of 0.998. While marginally less precise, the model remains highly reliable and efficient, particularly considering the complexity and imbalance of the dataset. Fig. 8. Open in a new tab Confusion matrix for TRBM-Net model on NF-BoT-IoT-V2 dataset. The analysis of the confusion matrices for the HACTD-Net and TRBM-Net models across the both datasets highlights critical performance insights. The HACTD-Net model performed well across both datasets, demonstrating strong classification accuracy, particularly for high-frequency attacks such as PortScan, DDoS, and DoS Hulk. However, it exhibited relatively higher misclassification rates for Heartbleed and Infiltration, which suggests that these attack types require further feature enhancement or additional training data. In contrast, the TRBM-Net model showcased superior classification performance, in the NF-BoT-IoT-v2 dataset, where it efficiently captured sequential attack patterns due to the combined use of temporal convolution, residual learning, and attention mechanisms. For the CICIDS2017 dataset, achieved the accuracy of ~ 99.9% for major attack categories, but TRBM-Net improved recall rates by 15–20% compared to HACTD-Net, leading to a significant reduction in false negatives. The NF-BoT-IoT-v2 dataset posed a greater challenge due to the presence of botnet-based cyber threats, which require robust sequential analysis. Here, TRBM-Net significantly outperformed HACTD-Net, achieving a recall rate of ~ 99.8% for DoS Slowloris and SSH-Patator, which indicates its capability in identifying IoT-specific threats. The HACTD-Net model struggled slightly with time-dependent attack patterns, reinforcing the importance of architectures that integrate recurrent learning mechanisms for intrusion detection. Although feature extraction techniques improved overall detection, a higher false positive rate was observed. This is likely due to the similarity between normal and certain attack traffic, residual class imbalance despite resampling, and threshold sensitivity favoring recall. Further tuning and filtering methods are needed to reduce false alarms. Despite the overall high classification performance, minority attack classes still exhibited misclassification rates of 4–5%, mainly due to lower representation in training data. While TRBM-Net significantly improved recall for these cases, additional techniques such as cost-sensitive learning and data augmentation could further enhance detection rates. In general, HACTD-Net provided reliable detection for high-frequency attack types, whereas TRBM-Net delivered a more balanced classification across all attack categories, making it the superior model for both conventional and IoT-based cyber threat detection. Computational cost analysis The proposed HACTD-Net and TRBM-Net achieve the highest detection accuracy across both CICIDS2017 and NF-BoT-IoT-v2 datasets (Tables 11 and 12 ), while maintaining computational costs that are competitive with other high-performing deep learning models (Table 13 ). Although the proposed models have more parameters than simpler architectures such as CNN or DNN, they require less runtime and memory than other top-performing hybrids like Transformer–DNN or TCN–ResNet–BiGRU. This efficiency stems from our optimized feature fusion strategy and architectural design, which allow us to balance performance and computational demands. Consequently, our models are suitable for real-time IDS deployment with minor hardware acceleration or pruning. Table 13. Computational efficiency comparison of models. Models Runtime (s) Memory usage (MB) Parameters (Millions) CNN 42 850 4.8 Autoencoder 58 920 6.2 DNN 37 780 3.9 Autoencoder–CNN 65 980 7.1 Transformer–DNN 92 1320 12.4 TCN 55 890 6.7 ResNet 63 1050 11.2 BiGRU 68 1080 10.5 CNN–BiGRU 74 1150 11.6 TCN–ResNet 81 1210 12.0 TCN–ResNet–BiGRU 94 1320 14.3 HACTD-Net (Proposed) 88 1200 11.8 TRBM-Net (Proposed) 91 1250 12.1 Open in a new tab Real-time and edge deployment considerations Although our deep learning-based IDS models (including TRBM-Net) show strong performance in experimental settings, real-time or edge deployment introduces practical constraints such as latency and limited computational resources. Preprocessing steps like LOF and synthetic oversampling also require efficient handling in streaming scenarios. To bridge this gap, future efforts will explore model optimization techniques—such as pruning, quantization, and conversion using tools like ONNX or TensorRT—to enable faster inference on edge devices. These steps will help ensure that the models remain effective and responsive when deployed in resource-constrained or time-sensitive environments. Conclusions In this study, HACTD-Net and TRBM-Net models are widely studied and compared for intrusion detection, with the help of the NF-BoT-IoT-v2 and CICIDS2017 datasets. According to the analysis, the TRBM-Net did better than HACTD-Net on all types of measures and attacks. On the NF-BoT-IoT-v2 data, TRBM-Net achieved high accuracy, precision, recall and an F1-score of 99.72%, 99.72%, 99.68% and 99.70%, respectively, with an AUC of 0.998. It also confirmed that the model could predict well all kinds of attacks, whether common or rare. These outcomes underscore TRBM-Net’s robustness and suitability for real-world IDS deployments. Compared to this, the HACTD-Net model also provided competitive results with similar TP counts but slightly higher FP and FN values in some cases, indicating comparatively less precision. On the CICIDS2017 dataset, the confusion matrix heatmaps for each model further emphasized the superiority of TRBM-Net. For instance, TRBM-Net achieved highly accurate classification for Heartbleed attacks and PortScan, with significantly fewer misclassifications across other classes. In contrast, HACTD-Net, while still effective, exhibited more noticeable misclassifications in certain complex categories like Web Attacks and Infiltration. The multi-headed attention in TRBM-Net allowed for better temporal and contextual focus across sequential data, enhancing detection capabilities especially for time-dependent attack patterns. While the proposed TRBM-Net model demonstrates strong performance in detecting intrusions across both binary and multiclass tasks, it is not without limitations. The model’s deep architecture and ensemble complexity result in increased training time and computational demands, which may impact scalability and deployment on low-resource or real-time systems. Looking forward, key directions to enhance this work include deploying the TRBM-Net model in real-time IDSs to evaluate its performance under live traffic conditions. However, such deployment may face challenges like latency constraints, memory limitations, and hardware dependencies—especially on edge or resource-limited devices. Addressing these challenges through model optimization and hardware-aware tuning will be critical. Additional future work includes incorporating federated learning for privacy-preserving decentralized detection and integrating XAI techniques to improve the transparency and explicability of model decisions. These focused advancements will support practical deployment and broader trust in AI-driven IDSs. Lastly, validating the model’s generalizability on datasets like UNSW-NB15, NSL-KDD, and TON_IoT will further confirm its adaptability across varied network environments. Author contributions NPP contributed to the conceptualization of the research problem, design of the methodology, and development of the algorithm. NPP also played a key role in analyzing the simulation results and drafting the initial manuscript. GMB was responsible for the implementation and testing of the algorithm, conducting simulations, and interpreting the outcomes. GMB also contributed significantly to refining the manuscript through critical revisions and suggestions. All authors have read and approved the final version of the manuscript. Funding No funding. Data availability The datasets used and analyzed in our study, CICIDS2017 and NF-BoT-IoT-v2, are publicly available at https://www.unb.ca/cic/datasets/ids-2017.html (accessed on 23 March 2025) and https://staff.itee.uq.edu.au/marius/NIDS_datasets/ (accessed on 4 April 2025). The full implementation code used to generate the results reported in this study has been made publicly available via Zenodo and is archived with a permanent DOI. The code repository can be accessed at DOI: https://doi.org/10.5281/zenodo.18668621. Declarations Competing interests The authors declare no competing interests. Footnotes Publisher’s note Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations. References 1. Roesch, M. Snort - Lightweight intrusion detection for networks, in Proceedings of the 13th Conference on Systems Administration, LISA 1999, (1999). 2. Vashishtha, L. K., Singh, A. P. & Chatterjee, K. A Hybrid intrusion detection model for cloud based systems. Wirel. Pers. Commun. 128 (4). 10.1007/s11277-022-10063-y (2023). 3. Padhiar, S. & Patel, R. Outside the Closed World: On Using Machine Learning for Network Intrusion Detection. Smart Innov. Syst. Technol. 10.1007/978-981-99-3982-4_23 (2023). [ Google Scholar ] 4. Parker, C. Firewalls don’t stop dragons: A step-by-step guide to computer security and privacy for non-techies, Fourth Edition. 10.1007/978-1-4842-6189-7 (2020) 5. Alsahli, M. S., Almasri, M. M., Al-Akhras, M., Al-Issa, A. I. & Alawairdhi, M. Evaluation of Machine Learning Algorithms for Intrusion Detection System in WSN. Int. J. Adv. Comput. Sci. Appl. 12 (5). 10.14569/IJACSA.2021.0120574 (2021). 6. Oluoha, O. U., Yange, T. S., Okereke, G. E. & Bakpo, F. S. Cutting edge trends in deception based intrusion detection systems—a survey. J. Inf. Secur. 12 (04). 10.4236/jis.2021.124014 (2021). 7. Crandal, J. Cybersecurity and offshore oil: The next big threat. ONE J. , 4 , (2018). 8. Saheed, Y. K. Performance improvement of intrusion detection system for detecting attacks on internet of things and edge of things, in artificial intelligence for cloud and edge computing, A. and P. V. and G. L. Misra Sanjayand Kumar Tyagi, Ed., Cham: Springer International Publishing, 321–339. doi: 10.1007/978-3-030-80821-1_15. (2022). [ Google Scholar ] 9. Morgan, S. Cybercrime to cost the world $10.5 Trillion Annually By 2025, (2020). 10. Ji, R., Padha, D., Singh, Y. & Sharma, S. Review of intrusion detection system in cyber-physical system based networks: Characteristics, industrial protocols, attacks, data sets and challenges. Trans. Emerg. Telecommun Technol. 35 (9), e5029. 10.1002/ett.5029 (2024). [ Google Scholar ] 11. Ji, R., Selwal, A., Kumar, N. & Padha, D. Cascading bagging and boosting ensemble methods for intrusion detection in cyber-physical systems. Secur. Priv. 8 (1), e497. 10.1002/spy2.497 (2025). [ Google Scholar ] 12. Al-Turaiki, I. & Altwaijry, N. A Convolutional neural network for improved anomaly-based network intrusion detection. Big Data . 9 (3). 10.1089/big.2020.0263 (2021). [ DOI ] [ PMC free article ] [ PubMed ] 13. Abdelkhalek, A. & Mashaly, M. Addressing the class imbalance problem in network intrusion detection systems using data resampling and deep learning. J. Supercomput . 79 (10). 10.1007/s11227-023-05073-x (2023). 14. Abdulganiyu, O. H., Tchakoucht, T. A., Saheed, Y. K., Mouhtadi, M. E. & Alaoui, A. E. H. Modified variational autoencoder and attention mechanism-based long short-term memory for detecting intrusions in imbalanced network traffic. Secur. Priv. 8 (3), e70044. 10.1002/spy2.70044 (2025). [ Google Scholar ] 15. Saheed, Y. K., Abdulganiyu, O. H. & Tchakoucht, T. A. Modified genetic algorithm and fine-tuned long short-term memory network for intrusion detection in the internet of things networks with edge capabilities. Appl. Soft Comput. 155 10.1016/j.asoc.2024.111434 (2024). 16. Yin, C., Zhu, Y., Fei, J. & He, X. A Deep Learning Approach for Intrusion Detection Using Recurrent Neural Networks. IEEE Access. 5 10.1109/ACCESS.2017.2762418 (2017). 17. Talukder, M. A., Khalid, M. & Uddin, M. A. An integrated multistage ensemble machine learning model for fraudulent transaction detection. J. Big Data . 11 (1), 168. 10.1186/s40537-024-00996-5 (2024). [ Google Scholar ] 18. Uddin, M. A., Aryal, S., Bouadjenek, M. R., Al-Hawawreh, M. & Talukder, M. A. usfAD based effective unknown attack detection focused IDS framework. Sci. Rep. 14 (1), 29103. 10.1038/s41598-024-80021-0 (2024). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 19. Ji, R., Kumar, N. & Padha, D. CNN-GWO-voting & hybrid: ensemble learning inspired intrusion detection approaches for cyber-physical systems, Proc. Indian Natl. Sci. Acad., (2024). 10.1007/s43538-024-00372-0 20. Maiga, A. A., Ataro, E. & Githinji, S. Intrusion detection with deep learning classifiers: A synergistic approach of probabilistic clustering and human expertise to reduce false alarms. IEEE Access. 12 10.1109/ACCESS.2024.3359595 (2024). 21. Alaghbari, K. A., Lim, H. S., Saad, M. H. M. & Yong, Y. S. Deep autoencoder-based integrated model for anomaly detection and efficient feature extraction in IoT networks. Internet Things . 4 (3). 10.3390/iot4030016 (2023). 22. Qazi, E. U. H., Faheem, M. H. & Zia, T. Hybrid deep-learning-based network intrusion detection system. Appl. Sci. 13 (8). 10.3390/app13084921 (2023). 23. Talukder, M. A., Khalid, M. & Sultana, N. A hybrid machine learning model for intrusion detection in wireless sensor networks leveraging data balancing and dimensionality reduction. Sci. Rep. 15 (1), 4617. 10.1038/s41598-025-87028-1 (2025). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 24. Talukder, M. A. et al. Machine learning-based network intrusion detection for big and imbalanced data using oversampling, stacking feature embedding and feature extraction. J. Big Data . 11 (1), 33. 10.1186/s40537-024-00886-w (2024). [ Google Scholar ] 25. Chawla, N. V., Bowyer, K. W., Hall, L. O. & Kegelmeyer, W. P. SMOTE: Synthetic minority over-sampling technique, J. Artif. Intell. Res., vol. 16, (2002). 10.1613/jair.953 26. Borno, S. Z., Moniruzzaman, M. & Technologies, N. 14th International Conference on Computing Communication and A hybrid intrusion detection system for an imbalanced dataset using deep learning, in, ICCCNT 2023, 2023. (2023). 10.1109/ICCCNT56998.2023.10308169 27. Kraiem, M. S., Sánchez-Hernández, F. & Moreno-García, M. N. An approach based on association models. Appl. Sci. 11 (18). 10.3390/app11188546 (2021). Selecting the suitable resampling strategy for imbalanced data classification regarding dataset properties. 28. Khanam, S., Ahmedy, I., Idris, M. Y. I. & Jaward, M. H. Towards an Effective Intrusion Detection Model Using Focal Loss Variational Autoencoder for Internet of Things (IoT). Sensors 22 (15). 10.3390/s22155822 (2022). [ DOI ] [ PMC free article ] [ PubMed ] 29. Bagui, S. & Li, K. Resampling imbalanced data for network intrusion detection datasets. J. Big Data . 8 (1). 10.1186/s40537-020-00390-x (2021). 30. Saheed, Y. K. & Firefly algorithm based feature selection method on high dimensional intrusion detection data, in Illumination of Artificial Intelligence in Cybersecurity and Forensics . 273–288 (eds Misra Sanjayand, C. & Arumugam) (Springer International Publishing, 2022). 10.1007/978-3-030-93453-8_12 31. Niyaz, Q., Sun, W., Javaid, A. Y. & Alam, M. A deep learning approach for network intrusion detection system, in EAI International Conference on Bio-inspired Information and Communications Technologies (BICT), (2015). 10.4108/eai.3-12-2015.2262516 32. Zhou, Z. & Ou, Y. Research on network anomaly traffic detection based on ODCAE and BiGRU, in Proceedings of the IEEE International Conference on Software Engineering and Service Sciences, ICSESS, (2023). 10.1109/ICSESS58500.2023.10293048 33. Zhao, P., Fan, Z., Cao, Z. & Li, X. Intrusion detection model using temporal convolutional network blend into attention mechanism. Int. J. Inf. Secur. Priv. 16 (1). 10.4018/IJISP.290832 (2022). 34. Gupta, N., Jindal, V., Bedi, P., LIO-IDS. & Handling class imbalance using LSTM and improved one-vs-one technique in intrusion detection system. Comput. Networks . 192 10.1016/j.comnet.2021.108076 (2021). 35. Ahmim, A., Maazouzi, F., Ahmim, M., Namane, S. & Ben Dhaou, I. Distributed denial of service attack detection for the internet of things using hybrid deep learning model. IEEE Access. 11 10.1109/ACCESS.2023.3327620 (2023). 36. Zheng, X., Yang, S. & Wang, X. SF-IDS: An Imbalanced semi-supervised learning framework for fine-grained intrusion detection, in IEEE International Conference on Communications, (2023). 10.1109/ICC45041.2023.10279032 37. Kale, R. et al. A Hybrid deep learning anomaly detection framework for intrusion detection, in proceedings – 2022 and BigDataSecurity/HPSC/IDS 2022. (2022). 10.1109/BigDataSecurityHPSCIDS54978.2022.00034 38. Kouloumpris, A., Stavrinides, G. L., Michael, M. K. & Theocharides, T. An optimization framework for task allocation in the edge/hub/cloud paradigm. Future Generation Comput. Syst. 10.1016/j.future.2024.02.005 (2024). [ Google Scholar ] 39. Kurniabudi, D., Stiawan, Darmawijoyo, M. Y., Bin Bin Idris, A. M., Bamhdi & Budiarto, R. CICIDS-2017 dataset feature analysis with information gain for anomaly detection. IEEE Access. 8 10.1109/ACCESS.2020.3009843 (2020). 40. B. Dong, A. S. Varde, D. Li, B. K. Samanthula, W. Sun, and L. Zhao, Cyber intrusion detection by using deep neural networks with attack-sharing loss cyber attacks, arXiv Prepr (2019). Associated Data This section collects any data citations, data availability statements, or supplementary materials included in this article. Data Citations Kraiem, M. S., Sánchez-Hernández, F. & Moreno-García, M. N. An approach based on association models. Appl. Sci. 11 (18). 10.3390/app11188546 (2021). Selecting the suitable resampling strategy for imbalanced data classification regarding dataset properties. Data Availability Statement The datasets used and analyzed in our study, CICIDS2017 and NF-BoT-IoT-v2, are publicly available at https://www.unb.ca/cic/datasets/ids-2017.html (accessed on 23 March 2025) and https://staff.itee.uq.edu.au/marius/NIDS_datasets/ (accessed on 4 April 2025). The full implementation code used to generate the results reported in this study has been made publicly available via Zenodo and is archived with a permanent DOI. The code repository can be accessed at DOI: https://doi.org/10.5281/zenodo.18668621. Articles from Scientific Reports are provided here courtesy of Nature Publishing Group ACTIONS View on publisher site PDF (4.3 MB) Cite Collections Permalink PERMALINK Copy RESOURCES Similar articles Cited by other articles Links to NCBI Databases Cite Copy Download .nbib .nbib Format: AMA APA MLA NLM Add to Collections Create a new collection Add to an existing collection Name your collection * Choose a collection Unable to load your collection due to an error Please try again Add Cancel Follow NCBI NCBI on X (formerly known as Twitter) NCBI on Facebook NCBI on LinkedIn NCBI on GitHub NCBI RSS feed Connect with NLM NLM on X (formerly known as Twitter) NLM on Facebook NLM on YouTube National Library of Medicine 8600 Rockville Pike Bethesda, MD 20894 Web Policies FOIA HHS Vulnerability Disclosure Help Accessibility Careers NLM NIH HHS USA.gov Back to Top

Record · ID 1029 · SHA-256 ea571ccd36338c26
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.