Skip to content
Open access

Hybrid CNN–LSTM Intrusion Detection Framework for Industrial IoT Security

Jul 2026 · Majestic International Journal of AI Innovations · Vol 1, pp. 1 · 3 citations · ⚡ 1 influential

TL;DR

The results indicate that the proposed CNN–LSTM framework is suitable for near-real-time IIoT intrusion detection where low false alarms, calibrated confidence, temporal stability, and lightweight deployment are critical.

Abstract

Introduction: The rapid adoption of the Industrial Internet of Things (IIoT) has increased the exposure of safety-critical industrial systems to sophisticated cyberattacks, requiring intrusion detection mechanisms that are accurate, computationally efficient, and operationally reliable. Traditional intrusion detection systems often struggle with correlated traffic descriptors, temporal attack evolution, false alarm control, and deployment-level reliability in resource-constrained industrial environments. Methodology: This study proposes a lightweight hybrid CNN–LSTM intrusion detection framework for binary IIoT attack detection. Convolutional layers learn compact representations from high-dimensional statistical traffic descriptors, while an LSTM layer captures short-term temporal dependencies associated with multi-stage and slow-rate attacks. The model was evaluated on the BoTNeTIoT-L01 Industrial IoT benchmark using a leakage-controlled split, imbalance-aware metrics, threshold-specific false alarm analysis, probability calibration, temporal robustness assessment, and CPU-only inference benchmarking. Results: The proposed CNN–LSTM achieved accuracy = 0.99875, precision = 0.99930, recall/sensitivity = 0.99820, F1-score = 0.99875, and FAR = 0.00070 on the held-out test set. At the selected deployment threshold, the model produced a ROC operating point with TPR = 0.99820 and FPR = 0.00070. Same-split baseline and ablation comparisons further demonstrated that the proposed model provided a strong balance between detection performance, false-alarm control, calibration reliability, and CPU inference efficiency. Conclusion: The results indicate that the proposed CNN–LSTM framework is suitable for near-real-time IIoT intrusion detection where low false alarms, calibrated confidence, temporal stability, and lightweight deployment are critical.

Read PDF

Similar papers

Open access Aug 2026

XP-IDS: an explainable hybrid CNN–XGBoost framework for IoT intrusion detection

The proposed accurate and interpretable framework shows strong potential as an edge-deployable security solution for safeguarding IoT devices and improving cyber resilience.

Prabhav Jain, Aashima Sharma, A. Noonia et al. · 0 citations
Open access Aug 2026

AI-Driven Security: Detecting Cyber Attacks in IoT Networks

LSTM had good detection for frequent attacks and slow-changing patterns, which shows its capacity in learning long-lasting dependencies, which shows its capacity in learning long-lasting dependencies.

Jawad Hussain Awan, Misbah Safdar, Muhammad Ayaz Shirazi et al. · 0 citations
Aug 2026

A Scalable Deep Learning-Based Intrusion Detection System for Real-Time Cybersecurity in IoT Networks of the Sugar Industry

The increasing integration of IoT-enabled systems in the sugar industry has enhanced operational efficiency but also exposed critical infrastructures to cyber threats. This paper presents the design and implementation of a scalable, real-time Intrusion Detection System (IDS) using deep learning-based Stacked Ensemble m...

Ramalakshmi Alagarsamy, A. S · 0 citations
Open access Sep 2026

A Deep Hybrid Recursive Model Combining 1D-CNN and BI-LSTM for Reliable Intrusion Detection in IoT Big Data Streams

Purpose: This study proposes a novel hybrid recursive deep learning-based Intrusion Detection System (IDS) for detecting sophisticated security threats in high-velocity IoT big data streams. Design/Methodology/Approach: The proposed framework integrates one-dimensional Convolutional Neural Networks (1D-CNNs) for lightw...

J. Alkenani, M. Nickray · 0 citations
Open access Aug 2026

A hybrid CNN-BiLSTM edge-cloud intrusion detection system with online incremental learning and SHAP explainability for smart city IoT

MI-IDS is presented, a hybrid Convolutional Neural Network–Bidirectional Long Short-Term Memory (CNN-BiLSTM) ensemble deployed on a two-tier edge-cloud framework that integrates reservoir-sampling-based incremental learning and SHAP explainability under a single experimentally validated pipeline.

Manjot Kaur, Kedar Nath Singh, Alpana Suman et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.