Skip to content
Open access

An Enhanced Hybrid Deep Learning Model for Anomaly-Based Intrusion Detection in the CICIDS2017 Web Attack Traffic

Aug 2026 · International Journal on Advanced Science, Engineering and Information Technology · 0 citations

TL;DR

An enhanced hybrid deep learning architecture that combines one-dimensional convolutional layers, bidirectional long short-term memory units, and a multi-head self-attention mechanism for detecting web attacks in network-flow data is proposed.

Abstract

Anomaly-based intrusion detection systems (AIDS) are a critical line of defense against modern web attacks. Recent benchmarking studies on the CICIDS2017 dataset have shown that conventional machine learning and shallow deep learning baselines achieve high overall accuracy by exploiting the dataset’s severe class imbalance, while exhibiting poor recognition of rare attack categories. This paper proposes an enhanced hybrid deep learning architecture that combines one-dimensional convolutional layers, bidirectional long short-term memory units, and a multi-head self-attention mechanism for detecting web attacks in network-flow data. To address class imbalance, the framework integrates SMOTE-ENN hybrid resampling, a class-weighted focal loss, and a post-training threshold-optimization step based on the F-beta criterion. The model is evaluated on the Thursday Web Attack subset of CICIDS2017 using a stratified train–validation–test protocol, achieving 98.85 % test accuracy, 99.09 % weighted F1-score, and 74.72 % balanced accuracy. More importantly, it improves rare-class recall over the strongest deep learning baseline in the literature: cross-site scripting (XSS) recall increases from about 4 % to 78.46 %, with a corresponding F1-score of 0.4647, and the Brute Force F1-score reaches 0.5560 under the proposed precision-favored threshold tuning. The results demonstrate that architectural diversity, principled imbalance handling, and multi-criteria evaluation jointly produce a more balanced and security-relevant intrusion detector than overall accuracy alone would suggest.

Read PDF

Similar papers

Open access Aug 2026

HADS-Net: A Hybrid Attention-Based Deep Security Network for Network Intrusion Detection

The principal contribution of this work is architectural and diagnostic rather than a performance improvement: it documents that combining feature-wise attention with out-of-fold stacked generalization does not, in this setting, outperform a plain multi-layer perceptron, while incurring the highest memory footprint of...

Mahima Khanna, V. Murthy, Siva Ramavarapu et al. · 0 citations
Open access Aug 2026

Deep Learning-Based Network Intrusion Detection Using Hybrid CNN and LSTM Architecture

The findings indicate that hybrid deep learning techniques can improve network security by enhancing intrusion detection capability while reducing false alarms.

A. O. Jimoh-Mahmud, Abubakar Dayyabu, Abubakar Sadiq Idris et al. · 0 citations
Open access Aug 2026

An enhanced multi-model ensemble learning architecture for robust network intrusion detection

An Enhanced Multi-Model Ensemble Network Intrusion Detection System (EME-NIDS), a deep meta-learning system that combines five different heterogeneous learning paradigms, including Convolutional Neural Networks, Dense Neural Networks, Transformers, XGBoost, and Random Forests is introduced.

Dwarsala Sireesha, Kakelli Anil Kumar · 0 citations
Open access Aug 2026

A Comparative Evaluation of Deep Learning Architectures for Binary Network Intrusion Detection Using the NSL-KDD Dataset

Investigation of deep learning models for binary network intrusion detection using the NSL-KDD benchmark dataset indicates that carefully designed standalone architectures can match or exceed the performance of more complex hybrid and ensemble models for binary intrusion detection, while incurring substantially lower c...

Ketki Naik, Sanjeev Ghosh · 0 citations
Open access Aug 2026

A hybrid deep reinforcement learning framework for proactive cloud network intrusion detection using spatiotemporal feature learning

ShieldDRLNet is a hybrid deep reinforcement learning framework for proactive cloud-network intrusion detection that employs a convolutional neural network and a long short-term memory encoder to obtain a spatiotemporal traffic representation and uses a Double Deep Q-Network agent for adaptive sequential decision-making...

S. Venkatramulu, Anitha Patil, K. Pradeep et al. · 0 citations
Open access Sep 2026

A Hybrid CNN–BiGRU Deep Learning Model for DDoS Attack Detection in Cybersecurity

This study proposes a hybrid deep learning model that integrates Convolutional Neural Networks (CNN) and Bidirectional Gated Recurrent Units (BiGRU) for efficient DDoS attack detection and demonstrates that the hybrid CNN–BiGRU architecture effectively improves detection accuracy and provides a reliable approach for in...

S. V, D. S., N. Deepti et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.