Network Intrusion Detection With Contrastive Learning and Transformer
Abstract
Network intrusion detection systems (NIDS) play a critical role in protecting modern communication networks against increasingly sophisticated cyber attacks. In this paper, we propose a Transformer-based network intrusion detection system (t-NIDS) that integrates a Transformer encoder with contrastive learning to learn discriminative and robust feature representations for network traffic classification. To improve representation learning under highly imbalanced data distributions, the proposed framework employs balanced sampling together with dropout-based view generation. Unlike conventional Transformer-based approaches that typically rely on high-dimensional embedding representations, the proposed framework achieves competitive detection performance using a compact embedding representation while maintaining a lightweight architecture. The proposed method was comprehensively evaluated on the CIC-IDS2017, CIC-DDoS2019, and NSL-KDD benchmark datasets. To improve the statistical reliability of the evaluation, all experiments were independently repeated ten times using randomly sampled training and testing datasets, and the average performance with standard deviation was reported. Experimental results demonstrate that the proposed framework consistently outperforms representative state-of-the-art methods, achieving average performance improvements of 6.63%, 5.06%, and 1.42% on the CIC-IDS2017, CIC-DDoS2019, and NSL-KDD datasets, respectively. In particular, the proposed method achieved a 112% improvement for the SQL Injection class on CIC-IDS2017 and a 17.43% improvement for the UDP class on CIC-DDoS2019. These results demonstrate that the proposed framework effectively captures complex traffic patterns while learning compact and discriminative feature representations with a lightweight Transformer architecture. Consequently, the proposed t-NIDS provides an effective balance between detection accuracy, computational efficiency, and robustness, making it suitable for practical deployment in real-world network intrusion detection environments.