Robust multi-class DDoS and fraud detection using a Context-Adaptive Deep Evolutionary Game Framework with CNN–BiGRU
Abstract
Distributed Denial of Service (DDoS) attacks have become a serious threat in modern computer networks, which can commonly be integrated with other types of attacks to evade detection by conventional devices. Existing deep learning-based intrusion detection methods have high identification capability. However, they are also highly susceptible to adversarial attacks, in which even slight perturbations to features can fool the model into misclassification. To address these issues, this study introduced a hybrid deep learning framework. It integrates Convolutional Neural Networks (CNN) and Bidirectional Gated Recurrent Units (BiGRU) to detect diverse types of attacks in real time. CNN extracts spatial interactions to model traffic characteristics, while BiGRU, a recurrent neural network, models temporal dependencies in data flows. This combination enables the model to capture complex spatiotemporal behavioral patterns in network traffic. To address class imbalance, we propose a new Neuro-Evolutionary Resampling Algorithm (NERA). This method uses neural density estimation and evolutionary optimization to generate balanced, noise-filtered training samples. Additionally, a Context-Adaptive Deep Evolutionary Game Framework (CADEGF) is designed to improve resistance to attacks. It does this by simulating interactions between attackers and defenders. It also adjusts detection thresholds using game-theoretic ideas. Experimental results show that this approach achieves high classification accuracy, effectively detects minority classes, and highlights trade-offs between minority-class detection and adversarial robustness, indicating contexts where NERA benefits or harms resilience. The integrated synergy of NERA, CNN-BiGRU, and CADEGF establishes a context-aware, adaptive defense model that advances intelligent intrusion detection with balanced performance and adversarial robustness.