Skip to content
Open access

Hybrid Transformer–CNN–BiLSTM Model with Mahalanobis Embedding for Zero-Day Intrusion Detection

Jul 2026 · Journal of Intelligent Decision Making and Information Science · 0 citations · 37 references

TL;DR

A hybrid intrusion detection model that integrates a Feature Tokenization-based Transformer with a CNN–BiLSTM model to capture global feature interactions and local sequential dependencies in tabular network traffic data and indicates the strong zero-day detection capability with high family-wise true positive rates for Backdoor and Worms.

Abstract

Abstract: The increasing complexity of cyber threats and the limitations of signature-based intrusion detection systems have made the detection of zero-day attacks a critical challenge in network security. Although machine learning and deep learning methods have achieved high accuracy for known attacks, their ability to generalize to previously unseen attack families remain limited. This paper proposes a hybrid intrusion detection model that integrates a Feature Tokenization-based Transformer with a CNN–BiLSTM model to capture global feature interactions and local sequential dependencies in tabular network traffic data. The learned fusion embedding is further exploited using a Mahalanobis distance–based anomaly detector to identify zero-day intrusions in an open-set setting. Experiments were conducted on the UNSW-NB15 dataset using a strict held-out attack family protocol, where Analysis, Backdoor, and Worms were excluded from training and reserved for zero-day testing. The proposed model achieved 94.64% accuracy, 0.9610 F1-score, and 0.9902 AUC on the known test set, that indicate the strong zero-day detection capability with high family-wise true positive rates for Backdoor and Worms. Five-fold cross-validation, ablation study, and statistical significance analysis further confirmed the robustness and effectiveness of the proposed framework. The results indicate that the integration of transformer-based feature learning, sequential modeling, and covariance-aware embedding analysis provides a reliable and extensible solution for both known attack classification and zero-day intrusion detection.

Read PDF

Similar papers

Open access Jul 2026

A Hybrid CNN-BiLSTM Attention-Based Framework for Intelligent Intrusion Detection

A novel Hybrid CNN-BiLSTM Attention-based Ensemble Framework (CBAF) that unifies three complementary representations of network traffic and incorporates SMOTE-based oversampling to counter the severe class imbalance found in benchmark intrusion datasets.

Vishwaradhya K., Annappa S. S., L. C. · 0 citations
Open access Sep 2026

A Hybrid CNN–BiGRU Deep Learning Model for DDoS Attack Detection in Cybersecurity

Distributed Denial of Service (DDoS) attacks remain one of the most serious threats to modern network infrastructures, as they overwhelm systems with massive traffic and disrupt legitimate services. Traditional intrusion detection systems often struggle to detect complex and evolving attack patterns due to their reliance on manual feature engineering and limited learning capability. To address this issue, this study proposes a hybrid deep learning model that integrates Convolutional Neural Networks (CNN) and Bidirectional Gated Recurrent Units (BiGRU) for efficient DDoS attack detection. The CNN component is used to automatically extract important spatial features from network traffic data, while the BiGRU layer captures temporal dependencies and sequential patterns in the traffic flows. The proposed model is evaluated using the CICDDoS2019 dataset, which contains realistic benign and attack traffic across multiple DDoS categories. Experimental results demonstrate that the model achieves high performance in both binary and multiclass classification tasks, obtaining an accuracy of 99.82% for binary detection and 99.21% for multiclass classification. The results indicate that the hybrid CNN–BiGRU architecture effectively improves detection accuracy and provides a reliable approach for intelligent network intrusion detection systems.

S. V, D. S., N. Deepti et al. · 0 citations
Open access Aug 2026

HADS-Net: A Hybrid Attention-Based Deep Security Network for Network Intrusion Detection

The principal contribution of this work is architectural and diagnostic rather than a performance improvement: it documents that combining feature-wise attention with out-of-fold stacked generalization does not, in this setting, outperform a plain multi-layer perceptron, while incurring the highest memory footprint of the six models evaluated.

Mahima Khanna, V. Murthy, Siva Ramavarapu et al. · 0 citations
Open access Aug 2026

An Enhanced Hybrid Deep Learning Model for Anomaly-Based Intrusion Detection in the CICIDS2017 Web Attack Traffic

Anomaly-based intrusion detection systems (AIDS) are a critical line of defense against modern web attacks. Recent benchmarking studies on the CICIDS2017 dataset have shown that conventional machine learning and shallow deep learning baselines achieve high overall accuracy by exploiting the dataset’s severe class imbalance, while exhibiting poor recognition of rare attack categories. This paper proposes an enhanced hybrid deep learning architecture that combines one-dimensional convolutional layers, bidirectional long short-term memory units, and a multi-head self-attention mechanism for detecting web attacks in network-flow data. To address class imbalance, the framework integrates SMOTE-ENN hybrid resampling, a class-weighted focal loss, and a post-training threshold-optimization step based on the F-beta criterion. The model is evaluated on the Thursday Web Attack subset of CICIDS2017 using a stratified train–validation–test protocol, achieving 98.85 % test accuracy, 99.09 % weighted F1-score, and 74.72 % balanced accuracy. More importantly, it improves rare-class recall over the strongest deep learning baseline in the literature: cross-site scripting (XSS) recall increases from about 4 % to 78.46 %, with a corresponding F1-score of 0.4647, and the Brute Force F1-score reaches 0.5560 under the proposed precision-favored threshold tuning. The results demonstrate that architectural diversity, principled imbalance handling, and multi-criteria evaluation jointly produce a more balanced and security-relevant intrusion detector than overall accuracy alone would suggest.

Israa Shihab Ahmed, Wasan Alaa Hussain, Z. H. Rasool · 0 citations
Open access Aug 2026

Deep Learning-Based Network Intrusion Detection Using Hybrid CNN and LSTM Architecture

The findings indicate that hybrid deep learning techniques can improve network security by enhancing intrusion detection capability while reducing false alarms.

A. O. Jimoh-Mahmud, Abubakar Dayyabu, Abubakar Sadiq Idris et al. · 0 citations
Open access

Performance evaluation of deep learning models for intrusion detection using network traffic

This study examines a one-dimensional Convolutional Neural Network and a hybrid model, investigating how both architectures can detect network attacks in binary and multiclass classification settings, and provides actionable insights for practitioners choosing between deep learning and classical approaches under real-world NIDS deployment constraints.

Rachid Cheick Mohamed · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.