Skip to content
Review Open access

Cognitive Detection at Big-Data Scale: A CNN-LSTM-DQN Framework with Prioritized Experience Replay for Cross-Attack-Family Generalization and Multi-Seed Initialization Sensitivity Analysis

Jul 2026 · Big Data and Cognitive Computing · Vol 10, pp. 239 · 1 citation · 35 references

TL;DR

A cognitive computing framework for network intrusion detection: a CNN–LSTM–DQN architecture with Prioritized Experience Replay (PER) evaluated on a 5,000,000-flow naturalistic sample of the TON_IoT Processed_Network dataset.

Abstract

Real-world IoT network security generates traffic at big-data scale with extreme class imbalance, temporal non-stationarity, and continuously evolving attack strategies that overwhelm static supervised classifiers. This paper presents a cognitive computing framework for network intrusion detection: a CNN–LSTM–DQN architecture with Prioritized Experience Replay (PER) evaluated on a 5,000,000-flow naturalistic sample of the TON_IoT Processed_Network dataset (4,000,000 training/1,000,000 temporally held-out test flows; 94.5% attack ratio) under a strict temporal split. The cognitive agent optimizes detection decisions using an Alerts per Million Flows (ARMF)-aware reward function that encodes both alert-fatigue cost and missed-attack penalty. We conduct a cross-attack-family generalization study: the methodology—architecture template, reward design, and hyperparameter calibration—is inherited from a framework previously validated on CSE-CIC-IDS2018, re-instantiated and retrained on the structurally different TON_IoT environment, and compared against the previously published benchmark. Initialization sensitivity is characterized across five independent random seeds using paired Wilcoxon signed-rank and t-tests. Across the five seeds, the proposed X2 model attains recall 0.833 ± 0.306 and F1 0.874 ± 0.241 (mean ± sample SD), versus the supervised X1 baseline at 0.858 ± 0.178 and 0.912 ± 0.116; the best-performing seed (42) achieves 97.52% accuracy, 98.02% attack recall, 99.46% precision, and 98.73% F1-score on 1,000,000 held-out XSS flows—an attack family entirely absent from training—with temporal stability variances of 4.63 × 10−7 (recall) and 1.38 × 10−7 (F1). The X2 advantage observed among the four stable seeds is not statistically demonstrated at n = 5 (statistical power ≈ 5.1%); the initialization-sensitivity finding itself, including one degenerate alert-suppression seed, is reported as a primary contribution. A formal, exactly additive ARMF decomposition distinguishes the detected-attack (structural) component (99.46%) from the model-induced false-positive component (0.54%), and we report a multi-seed, ARMF-aware cognitive IDS evaluation on naturalistic TON_IoT traffic under an unseen-attack-family test condition that, to the best of our knowledge, has not been reported in the surveyed RL-based NIDS literature.

Read PDF

Similar papers

Open access Sep 2026

Lightweight AI Models for Cyber Threat Detection: An Evaluation of MobileNetV2, Random Forest, and CNN-LSTM for Phishing and Network Anomaly Detection

This work contributes a comparative evaluation of lightweight detection models, consistent attention to security-critical metrics, and interpretable insights to support practical cybersecurity deployment.

Nwagbara Chisom Telvin, Gilbert Imuetin Osaze Aimufua, Raymond Ternenge Igbudu · 0 citations
Open access Sep 2026

A cross-attention CNN–LSTM fusion model for network traffic anomaly detection

Detecting cyber intrusions in modern IoT networks is challenging because of their large scale, heterogeneous device ecosystems, and high-volume traffic patterns. This paper presents a cross-attention CNN–LSTM fusion architecture that jointly learns the spatial and temporal characteristics of network traffic for bin...

Mohamed Fakri, A. Najid, Rachid Ben Said et al. · 0 citations
Open access Sep 2026

Explainable Sequence-Aware Deep Learning Framework for Potential Zero-Day Attack Detection and Cross-Domain Generalization in Enterprise Network Intrusion Detection

Zero-day attacks remain a significant challenge in enterprise network security because their previously unseen characteristics can reduce the effectiveness of conventional signature-based intrusion detection systems. Although machine learning and deep learning have improved intrusion detection, many existing approaches...

Uchechukwu Nwankwo, O. Nwokonkwo, C. Ikerionwu et al. · 0 citations
Open access Aug 2026

Comparative Evaluation of LSTM, BiLSTM, CNN-LSTM, Random Forest, and XGBoost for Detection of Distributed Denial of Service (DDoS) Attacks Using the CICDDoS2019 Dataset

Distributed Denial of Service (DDoS) attacks continue to pose a severe and escalating threat to networked digital infrastructure, with global attack volumes rising by over 53% in 2024 alone. While machine learning approaches have demonstrated improved detection performance over traditional rule-based systems, many exis...

Godson Samwel, I. Tende, Gustaph Sanga · 0 citations
Open access Aug 2026

A Systematic Multi-Paradigm Evaluation Framework for Network Intrusion Detection in Fog-IoT Environments: Deep Learning, Transformer, and Ensemble Methods Across Deployment Tiers

The Adaptive Confidence-Gated Ensemble framework for Network Intrusion Detection Systems (NIDSs) in resource-heterogeneous fog-IoT deployments is presented and targeted data collection, few-shot adaptation, and federated learning are recommended as the most critical future directions.

Khalil M. Abdelnaby · 0 citations
Open access Sep 2026

X-THREAT framework for adaptive and explainable deep learning-based minority-class and zero-day cyber threat detection

The dynamic nature of cyber threats—particularly minority-class and zero-day attacks—poses significant challenges to existing intrusion detection systems (IDS), which often lack adaptability, interpretability, and robustness. This paper presents X-THREAT, an adaptive and explainable deep learning framework designed to...

Samina Naz Qaisarani, Sahar K. Badri, A. Khattak et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.