DEEP LEARNING-BASED INTRUSION DETECTION SYSTEMS: ARCHITECTURES, IMPLEMENTATIONS, AND CHALLENGES IN MODERN NETWORK ANOMALY DETECTION
Abstract
The increasing complexity of cyber threats has strengthened the need for adaptive network intrusion detection systems (IDS). This systematic literature review (SLR) synthesizes nine peer-reviewed studies published from 2024 to 2026 on deep learning (DL)-based network anomaly detection. The review follows a PRISMA 2020-aligned process covering database selection, eligibility screening, quality assessment, and structured data extraction. Five research questions examine DL architectures, preprocessing and class-imbalance handling, comparative performance, deployment challenges, and the basis for a conceptual framework. The synthesis compares preprocessing, classification strategy, Accuracy, Precision, Recall, and F1-Score where reported. The evidence shows that hybrid architectures can achieve very high benchmark performance, but the results are dataset- and experimental-setting dependent; therefore, the claim that hybrid models universally exceed 95% is not supported. Across the included studies, the recurring technical pattern is: representative data collection, preprocessing and imbalance mitigation, architecture selection according to spatial or temporal characteristics, and multi-metric evaluation. The revised framework extends this four-layer pipeline by explicitly integrating Explainable AI (XAI) and edge-oriented deployment as cross-cutting operational requirements. The review also identifies limitations in dataset realism, cross-dataset validation, reporting consistency, computational efficiency, and explainability.