Skip to content
Open access

Two-layer long short-term memory with a hybrid feature selection method for intrusion detection in internet of things networks

Oct 2026 · PeerJ Computer Science · 0 citations · 61 references

Abstract

Recently, the intrusion detection systems (IDSs) gained a lot of popularity for detecting intrusions in the Internet of Things (IoT) environments. However, the IoT has many challenges; the most important is the weak security. Accordingly, the IDS is applied. The Long Short-Term Memory (LSTM) is a powerful type of recurrent neural network (RNN) that is used to identify the long-duration dependencies in network data and detect the complex attack patterns. However, it still achieved low accuracy; especially when processing large and high-dimensional datasets, its performance degrades. This article proposes two-layer bidirectional LSTM (Bi-LSTM), which achieves the best possible compromise between generalization performance, training efficiency, and model capacity. The first layer captures the short-term dependencies over the input feature sequences (treated as time steps) and local temporal patterns. While the second layer learns long-term dependencies and higher-level, abstract representations, which enables the model to detect complex, multi-stage attack behaviors. Furthermore, this article suggests a novel hybrid feature selection method that combines the Chi-square ( Chi 2 ) (for ranking the features by relevance to the target), the variance thresholding method (for eliminating the near-constant), and correlation-based filtering (for removing the highly redundant features). Accordingly, this feature selection method retains the most discriminative network traffic attributes. The proposed LSTM model effectively learns the complex patterns in the selected features, treating them as sequential input to capture intrinsic relationships. This model is evaluated by three datasets that are IoTID20, CICIDS2017, and UNSW-NB15 for multi-class and binary classification configurations. The results are evaluated using six key metrics, including accuracy, precision, recall, F1_score, Matthews Correlation Coefficient (MCC), and Area Under the Curve (AUC). The proposed model achieves an accuracy of 95.145%, 98.864%, and 85.74% for these datasets, respectively. The results prove the effectiveness of the proposed LSTM model to enhance the results compared to standard LSTM, multilayer perceptron (MLP), logistic regression (LR), decision tree (DT), and random forest (RF) machine learning models, in addition to outperforming many other previous models. These results suggest that the proposed model, which depends on the hybrid feature selection, provides a robust and generalizable solution for attack detection in IoT scenarios.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.