Skip to content
Conference Open access

A Lightweight NLP-CNN Framework Based on Semantic Flow Representation for Network Intrusion Detection

2026 · EPJ Web of Conferences · 0 citations · 5 references

TL;DR

One lesson emerges from the experiments: putting the effort into how traffic is written down, instead of making the classifier heavier, offers an economical and workable path to intrusion detection across heterogeneous network environments.

Abstract

Attacks against networks keep changing form, and Intrusion Detection Systems (IDS) still stand among the first defenses expected to catch them. Deep learning brought real gains in detection accuracy, but a habit persists across most published models: traffic enters as flat tabular records, and whatever context ties one attribute to another is thrown away before training begins. This work follows a different route. Every network record is rewritten as a short piece of text - the protocol, the connection state, the ports, and a few traffic statistics, joined into what we call a semantic flow - after which the sequence is tokenized, embedded, and handed to a small Convolutional Neural Network (CNN). No transformer appears anywhere in the pipeline, and no recurrent stack either; the representation itself does the heavy lifting. Four benchmark datasets served for the evaluation (CIC-IDS-2017, KDDCup99, NSL-KDD, and Hogzilla), in binary as well as multiclass settings. Accuracy fell between 99.04% and 99.95%, F1-scores held above 0.99, and AUC values remained high - figures we read with prudence, since they come from benchmark data alone. Even so, one lesson emerges from the experiments: putting the effort into how traffic is written down, instead of making the classifier heavier, offers an economical and workable path to intrusion detection across heterogeneous network environments.

Read PDF

Similar papers

Open access Aug 2026

An Improved Explainable Hybrid CNN–LSTM Framework with Leakage-Aware Evaluation for Network Traffic Intrusion Detection

This paper proposes an explainable hybrid Convolutional Neural Network–Long Short-Term Memory (CNN–LSTM) model for binary intrusion detection in network traffic using flow-based data. The research problem addressed in this study is the need for a reliable intrusion detection model that preserves temporal traffic behavi...

A. Alsarayreh, A. Abu-Jassar · 0 citations
Open access Sep 2026

A cross-attention CNN–LSTM fusion model for network traffic anomaly detection

Detecting cyber intrusions in modern IoT networks is challenging because of their large scale, heterogeneous device ecosystems, and high-volume traffic patterns. This paper presents a cross-attention CNN–LSTM fusion architecture that jointly learns the spatial and temporal characteristics of network traffic for bin...

Mohamed Fakri, A. Najid, Rachid Ben Said et al. · 0 citations
Open access Aug 2026

An Explainable and Interpretable GNN Based on Temporal Time Series: An IDS Approach

This work develops and compares traditional classifiers against a GNN-based IDS on the UNSW-NB15 dataset, for both binary and multiclass classification and reveals attack-specific structural patterns, confirming that temporally structured GNNs improve detection while providing interpretable predictions.

Alberto Caballero Ferrero, Shadi Motaali, Xavier Larriva-Novo et al. · 0 citations
Conference Sep 2026

Deep detection method for web attacks based on spatial attention and CNN-GRU

Web application security faces significant threats from SQL injection (SQLi) and Cross-Site Scripting (XSS) attacks, which are characterized by high variability and concealment. Traditional detection methods relying on rule matching or shallow machine learning features struggle to identify novel and obfuscated attacks....

Rong Liu · 0 citations
Open access Aug 2026

HADS-Net: A Hybrid Attention-Based Deep Security Network for Network Intrusion Detection

The principal contribution of this work is architectural and diagnostic rather than a performance improvement: it documents that combining feature-wise attention with out-of-fold stacked generalization does not, in this setting, outperform a plain multi-layer perceptron, while incurring the highest memory footprint of...

Mahima Khanna, V. Murthy, Siva Ramavarapu et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.