Skip to content
Open access

Lightweight AI Models for Cyber Threat Detection: An Evaluation of MobileNetV2, Random Forest, and CNN-LSTM for Phishing and Network Anomaly Detection

Sep 2026 · FUDMA Journal of Sciences · 0 citations · 2 references

TL;DR

This work contributes a comparative evaluation of lightweight detection models, consistent attention to security-critical metrics, and interpretable insights to support practical cybersecurity deployment.

Abstract

The rising sophistication of cyber threats - including phishing, malware, and network anomalies - demands detection mechanisms beyond traditional rule-based systems. This study defines real-time detection as low-latency inference suitable for continuous monitoring in edge or cloud environments, enabling per-sample or per-flow predictions without offline batch processing. Within this framework, we evaluate lightweight models - MobileNetV2, Random Forest, and CNN-LSTM - using the UNSW-NB15 and CICIDS2017 network datasets, along with a public phishing image dataset of over 5,000 labeled samples. This heterogeneous data mix ensures exposure to diverse attack patterns and realistic deployment conditions. Given resource constraints in IoT and small-scale settings, our analysis emphasizes scalability, interpretability, and computational efficiency alongside detection performance. MobileNetV2 (2.3 million parameters, 300 million FLOPs) achieved 85.4% accuracy, Precision 0.84, Recall 0.82, F1-Score 0.83, and AUC 0.87, supporting its use as a first-stage phishing filter in low-resource environments. Random Forest initially showed reduced sensitivity to minority classes; however, SMOTE and cost-sensitive learning improved Recall to 83.2%, F1-Score to 0.81, and AUC to 0.88, yielding balanced anomaly detection. The optimized CNN-LSTM, with regularization and early stopping, achieved Precision 0.80, Recall 0.77, F1-Score 0.79, and AUC 0.84, demonstrating improved generalization. For transparency, SHAP analysis identified Packet Header Length, Domain Entropy, and Connection Duration as dominant predictive features. This work contributes a comparative evaluation of lightweight detection models, consistent attention to security-critical metrics, and interpretable insights to support practical cybersecurity deployment.

Read PDF

Similar papers

Open access Oct 2026

Protocol-Conditioned Feature Analysis, Multi-Dataset Intrusion Detection, and Context-Aware Alert Prioritization for IoT Network Security

Internet of Things (IoT) malware and intrusions generate network-observable flow patterns, but high benchmark accuracy does not by itself establish transfer to new environments. This study presents Protocol-conditioned Analysis with Behavioral Threat Identification (PA-BTI) as an evidence-bounded framework combining da...

Abdullah Abbasi, D. Hakro, Akhtar Hussain et al. · 0 citations
Open access Aug 2026

AI-Driven Security: Detecting Cyber Attacks in IoT Networks

LSTM had good detection for frequent attacks and slow-changing patterns, which shows its capacity in learning long-lasting dependencies, which shows its capacity in learning long-lasting dependencies.

Jawad Hussain Awan, Misbah Safdar, Muhammad Ayaz Shirazi et al. · 0 citations
Open access Aug 2026

Unsupervised deep learning for IoT botnet detection in a surveillance VLAN via multi-source traffic, threat intelligence and honeypot corroboration

The increase in internet of thing devices, especially within VLANs in corporate networks, introduces significant security risks from advanced botnet attacks. Traditional signature-based detection methods struggle to identify encrypted, stealthy command-and-control traffic, while high false-positive rates overwhelm secu...

Özkan Zeybek, Hasan Güler · 0 citations
Open access Aug 2026

Intelligent DDOS Attack Detection and Mitigation Using Machine Learning Techniques

An intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies is presented.

S. Singh, Alok Kumar · 0 citations
Open access Aug 2026

Comparative Evaluation of LSTM, BiLSTM, CNN-LSTM, Random Forest, and XGBoost for Detection of Distributed Denial of Service (DDoS) Attacks Using the CICDDoS2019 Dataset

Distributed Denial of Service (DDoS) attacks continue to pose a severe and escalating threat to networked digital infrastructure, with global attack volumes rising by over 53% in 2024 alone. While machine learning approaches have demonstrated improved detection performance over traditional rule-based systems, many exis...

Godson Samwel, I. Tende, Gustaph Sanga · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.