A Deep Learning-Based Intrusion Detection System using Multi-Granularity Attention for Minimizing False Positives in Industrial Internet of Things Networks
The rapid expansion of the Internet of Things (IoT) has transformed modern industrial communication. However, this massive growth has introduced critical security vulnerabilities into network environments. Current intrusion detection systems struggle to address these threats effectively due to high false alarm rates. To overcome these challenges, this study introduces the Multi-Granularity Attention-based Graph Attention Network Bidirectional Long Short-Term Memory (MGA-GBiLSTM) framework for accurate multi-class traffic categorisation. The proposed MGA-GBiLSTM functions by mapping network connections into dynamic graphs and utilises a gated attention mechanism to cross-verify individual anomalies against peer-group and organisational baselines. By combining Graph Attention Networks for spatial mapping with a BiLSTM for deep temporal analysis, the system simultaneously validates the structural intent and sequential patterns of network actions. The MGA-GBiLSTM model was evaluated using the CIC IoT-DIAD 2024, CICDDoS2019, and UNSW-NB15 datasets. Experimental results demonstrate that the framework achieves impressive classification accuracy of 99.16% on the CIC IoT-DIAD 2024 dataset, 99.78% on the CICDDoS2019 dataset and 98.91% on the UNSWNB-15 dataset, respectively. Ultimately, this MGA-GBiLSTM approach improves system reliability in automated monitoring by significantly reducing alert fatigue while maintaining a robust defence against complex cyber threats.