2026· EPJ Web of Conferences· 0 citations· 5 references
TL;DR
One lesson emerges from the experiments: putting the effort into how traffic is written down, instead of making the classifier heavier, offers an economical and workable path to intrusion detection across heterogeneous network environments.
Abstract
Attacks against networks keep changing form, and Intrusion Detection Systems (IDS) still stand among the first defenses expected to catch them. Deep learning brought real gains in detection accuracy, but a habit persists across most published models: traffic enters as flat tabular records, and whatever context ties one attribute to another is thrown away before training begins. This work follows a different route. Every network record is rewritten as a short piece of text - the protocol, the connection state, the ports, and a few traffic statistics, joined into what we call a semantic flow - after which the sequence is tokenized, embedded, and handed to a small Convolutional Neural Network (CNN). No transformer appears anywhere in the pipeline, and no recurrent stack either; the representation itself does the heavy lifting. Four benchmark datasets served for the evaluation (CIC-IDS-2017, KDDCup99, NSL-KDD, and Hogzilla), in binary as well as multiclass settings. Accuracy fell between 99.04% and 99.95%, F1-scores held above 0.99, and AUC values remained high - figures we read with prudence, since they come from benchmark data alone. Even so, one lesson emerges from the experiments: putting the effort into how traffic is written down, instead of making the classifier heavier, offers an economical and workable path to intrusion detection across heterogeneous network environments.
This paper proposes an explainable hybrid Convolutional Neural Network–Long Short-Term Memory (CNN–LSTM) model for binary intrusion detection in network traffic using flow-based data. The research problem addressed in this study is the need for a reliable intrusion detection model that preserves temporal traffic behavi...
A. Alsarayreh, A. Abu-Jassar· Engineering, Technology &...· 0 citations
Detecting cyber intrusions in modern IoT networks is challenging because of their large scale, heterogeneous device ecosystems, and high-volume traffic patterns. This paper presents a cross-attention CNN–LSTM fusion architecture that jointly learns the spatial and temporal characteristics of network traffic for bin...
Mohamed Fakri, A. Najid, Rachid Ben Said et al.· Scientific Reports· 0 citations
This work develops and compares traditional classifiers against a GNN-based IDS on the UNSW-NB15 dataset, for both binary and multiclass classification and reveals attack-specific structural patterns, confirming that temporally structured GNNs improve detection while providing interpretable predictions.
Alberto Caballero Ferrero, Shadi Motaali, Xavier Larriva-Novo et al.· Electronics· 0 citations
Web application security faces significant threats from SQL injection (SQLi) and Cross-Site Scripting (XSS) attacks, which are characterized by high variability and concealment. Traditional detection methods relying on rule matching or shallow machine learning features struggle to identify novel and obfuscated attacks....
Rong Liu· International Conference on...· 0 citations
These findings establish that ensemble methods, particularly hard voting, offer a practical pathway toward more reliable network intrusion detection systems.
Godspower Oraye· International Journal of Com...· 0 citations
The principal contribution of this work is architectural and diagnostic rather than a performance improvement: it documents that combining feature-wise attention with out-of-fold stacked generalization does not, in this setting, outperform a plain multi-layer perceptron, while incurring the highest memory footprint of...
Mahima Khanna, V. Murthy, Siva Ramavarapu et al.· International Journal for Gl...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.