A Deep Hybrid Recursive Model Combining 1D-CNN and BI-LSTM for Reliable Intrusion Detection in IoT Big Data Streams
Abstract
Purpose: This study proposes a novel hybrid recursive deep learning-based Intrusion Detection System (IDS) for detecting sophisticated security threats in high-velocity IoT big data streams. Design/Methodology/Approach: The proposed framework integrates one-dimensional Convolutional Neural Networks (1D-CNNs) for lightweight spatial feature extraction with Bidirectional Long Short-Term Memory (Bi-LSTM) networks to capture complex temporal dependencies in network traffic. A recursive detection mechanism is incorporated to preserve temporal context and identify multi-stage and stealthy low-and-slow attacks that may be overlooked when network packets are treated as independent instances. The model is evaluated using the UNSW-NB15 and BoT-IoT datasets. Research Limitation: The evaluation is based on benchmark IoT intrusion datasets, which may not fully represent the diversity and complexity of continuously evolving real-world IoT environments. Findings: The proposed framework achieves a detection accuracy of 98.4% with a False Positive Rate (FPR) of only 0.72%. Moreover, it demonstrates an average inference latency of 0.45 ms per packet, indicating strong real-time detection capability. Practical Implication: The proposed system provides an efficient and scalable solution suitable for deployment in Edge AI-enabled environments, supporting real-time protection of next-generation IoT networks. Social Implication: Enhanced intrusion detection can improve the security and reliability of IoT services, helping protect connected devices, networks, and users from emerging cyber threats. Originality/Value: The study introduces a hybrid recursive 1D-CNN–Bi-LSTM architecture that combines lightweight spatial feature extraction with temporal dependency modelling, providing an effective approach for detecting complex and stealthy IoT attacks while maintaining low inference latency.