Skip to content
Conference

Tackling extreme class imbalance in NIDS: a hybrid architecture integrating SMOTE and CNN-BiLSTM with focal loss

Jul 2026 · International Conference on Computer Vision, Al and Intelligent Automation · Vol 14260, pp. 142600Q - 142600Q-6 · 0 citations
Engineering

TL;DR

A hybrid NIDS framework integrating Synthetic Minority Over-sampling Technique (SMOTE), a CNN-BiLSTM architecture, and Focal Loss is proposed, which achieves a breakthrough in minority attack recognition.

Abstract

With the rapid development of network technologies, Network Intrusion Detection Systems (NIDS) play a critical role in securing networks against malicious attacks. However, existing machine learning and deep learning models often struggle to effectively identify minority class attacks, such as User-to-Root (U2R) and Remote-to-Local (R2L), when faced with highly imbalanced network traffic data. To tackle this extreme class imbalance challenge, this paper proposes a hybrid NIDS framework integrating Synthetic Minority Over-sampling Technique (SMOTE), a CNN-BiLSTM architecture, and Focal Loss. First, at the data level, the SMOTE algorithm is employed to synthetically oversample minority classes in the training set, establishing a balanced data distribution. Subsequently, at the algorithmic level, a Convolutional Neural Network-Bidirectional Long Short-Term Memory (CNN-BiLSTM) deep neural network is designed to jointly extract the local spatial topologies and global temporal features of network traffic. Finally, the Focal Loss function is introduced to further optimize the model by dynamically down-weighting easily classified majority samples, forcing the network to focus on hard-to-classify boundary samples. Extensive experiments on the benchmark NSL-KDD dataset demonstrate that the proposed method achieves a breakthrough in minority attack recognition. Specifically, the F1-Scores for R2L and U2R are elevated to 0.38 and 0.34, respectively, significantly outperforming traditional machine learning and standard deep learning baselines while maintaining robust detection capabilities for majority attacks.

View source

Similar papers

Open access Sep 2026

Attention-augmented CNN-BiLSTM with temporal-spatial attention for imbalanced multi-class network intrusion detection

The proposed Attention-Augmented CNN-BiLSTM architecture incorporating a lightweight Temporal-Spatial Attention Module (TSAM) achieves an effective balance between computational efficiency, robustness to severe class imbalance, and accurate multi-class intrusion detection for next-generation IoT security systems.

D. Bhosale, Avinash Dhole, P. B. Deshmukh et al. · 0 citations
Open access Jul 2026

A Hybrid CNN-BiLSTM Attention-Based Framework for Intelligent Intrusion Detection

A novel Hybrid CNN-BiLSTM Attention-based Ensemble Framework (CBAF) that unifies three complementary representations of network traffic and incorporates SMOTE-based oversampling to counter the severe class imbalance found in benchmark intrusion datasets.

Vishwaradhya K., Annappa S. S., L. C. · 0 citations
Conference Open access 2026

A Lightweight NLP-CNN Framework Based on Semantic Flow Representation for Network Intrusion Detection

One lesson emerges from the experiments: putting the effort into how traffic is written down, instead of making the classifier heavier, offers an economical and workable path to intrusion detection across heterogeneous network environments.

Asmaa Benchama, Khalid Zebbara · 0 citations
Open access Aug 2026

HADS-Net: A Hybrid Attention-Based Deep Security Network for Network Intrusion Detection

The principal contribution of this work is architectural and diagnostic rather than a performance improvement: it documents that combining feature-wise attention with out-of-fold stacked generalization does not, in this setting, outperform a plain multi-layer perceptron, while incurring the highest memory footprint of...

Mahima Khanna, V. Murthy, Siva Ramavarapu et al. · 0 citations
Open access Aug 2026

Deep learning intrusion detection for software-defined networking using synthetic minority oversampling

This article proposes an advanced method for network intrusion detection using a combination of recurrent neural networks (RNNs), specifically long short-term memory (LSTM), gated recurrent units (GRU), and bidirectional long short-term memory (BiLSTM) models, enhanced by synthetic minority oversampling technique (SMOT...

Prajwalasimha Sindugatta Nagaraja, Navya Rajashekara, Pushpa Bangalore Ramesh et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.