Lightweight AI Models for Cyber Threat Detection: An Evaluation of MobileNetV2, Random Forest, and CNN-LSTM for Phishing and Network Anomaly Detection
TL;DR
This work contributes a comparative evaluation of lightweight detection models, consistent attention to security-critical metrics, and interpretable insights to support practical cybersecurity deployment.
Abstract
The rising sophistication of cyber threats - including phishing, malware, and network anomalies - demands detection mechanisms beyond traditional rule-based systems. This study defines real-time detection as low-latency inference suitable for continuous monitoring in edge or cloud environments, enabling per-sample or per-flow predictions without offline batch processing. Within this framework, we evaluate lightweight models - MobileNetV2, Random Forest, and CNN-LSTM - using the UNSW-NB15 and CICIDS2017 network datasets, along with a public phishing image dataset of over 5,000 labeled samples. This heterogeneous data mix ensures exposure to diverse attack patterns and realistic deployment conditions. Given resource constraints in IoT and small-scale settings, our analysis emphasizes scalability, interpretability, and computational efficiency alongside detection performance. MobileNetV2 (2.3 million parameters, 300 million FLOPs) achieved 85.4% accuracy, Precision 0.84, Recall 0.82, F1-Score 0.83, and AUC 0.87, supporting its use as a first-stage phishing filter in low-resource environments. Random Forest initially showed reduced sensitivity to minority classes; however, SMOTE and cost-sensitive learning improved Recall to 83.2%, F1-Score to 0.81, and AUC to 0.88, yielding balanced anomaly detection. The optimized CNN-LSTM, with regularization and early stopping, achieved Precision 0.80, Recall 0.77, F1-Score 0.79, and AUC 0.84, demonstrating improved generalization. For transparency, SHAP analysis identified Packet Header Length, Domain Entropy, and Connection Duration as dominant predictive features. This work contributes a comparative evaluation of lightweight detection models, consistent attention to security-critical metrics, and interpretable insights to support practical cybersecurity deployment.