Skip to content
Conference

A Lightweight Hybrid CNN–Gradient Boosting Framework for Real-Time Network Intrusion Detection

Aug 2026 · 2026 International Conference on Secure Information Systems and Technologies (ICSIST) · pp. 410-415 · 0 citations · 15 references

Abstract

Network intrusion detection systems must distinguish malicious from benign traffic under realistic conditions where attack types seen at deployment time may not have appeared during training. This paper presents a lightweight hybrid framework combining a compact one-dimensional convolutional neural network (CNN), used as a feature extractor over the ordered feature vector of a network connection record, with a gradient boosting classifier that combines the CNN-extracted representation with the original engineered features. Both the CNN and a from-scratch leaf-wise, histogram-binned gradient booster are implemented and gradient-checked before use. The framework is evaluated on the real, official NSL-KDD benchmark (KDDTrain+_20Percent for training, the official KDDTest+ for testing), which deliberately contains 17 attack types absent from training, over ten random seeds with paired statistical testing. Gradient boosting alone achieved the strongest single-branch result (accuracy 0.790 ± 0.008, F1 0.779 ± 0.010), and the proposed hybrid matched it (accuracy 0.790 ± 0.011, F1 0.780 ± 0.014, p = 0.76, not significant) while significantly outperforming logistic regression, random forest, and the CNN alone (p < 0.02 in each case). A formal proposition establishes that augmenting features cannot increase Bayes-optimal risk in population, explaining why the hybrid is never worse in expectation, and a companion remark explains, via finite-sample estimation variance, why this population guarantee does not translate into a significant empirical gain here. Results are compared against real published NSL-KDD studies, with an explicit discussion of the protocol differences (in-distribution random splits versus the official train/test generalisation split used here) that materially affect reported accuracy across the literature. All results are genuine outputs of code executed for this paper on the real, downloaded dataset; no results are estimated or fabricated.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.