Skip to content
Open access

A hybrid CNN-BiLSTM edge-cloud intrusion detection system with online incremental learning and SHAP explainability for smart city IoT

Aug 2026 · Discover Internet of Things · 0 citations

TL;DR

MI-IDS is presented, a hybrid Convolutional Neural Network–Bidirectional Long Short-Term Memory (CNN-BiLSTM) ensemble deployed on a two-tier edge-cloud framework that integrates reservoir-sampling-based incremental learning and SHAP explainability under a single experimentally validated pipeline.

Abstract

Smart city IoT deployments interconnect safety-critical infrastructure across millions of heterogeneous devices, creating an attack surface that signature-based intrusion detection systems (IDS) cannot defend against zero-day exploits, polymorphic malware, or concept drift. Prior deep-learning IDS proposals address the detection accuracy gap but typically evaluate on a single benchmark with a single random seed, omit structured ablation evidence, lack on-line adaptation, and provide no model-explanation interface for security analysts. This paper presents MI-IDS, a hybrid Convolutional Neural Network–Bidirectional Long Short-Term Memory (CNN-BiLSTM) ensemble deployed on a two-tier edge-cloud framework that integrates reservoir-sampling-based incremental learning and SHAP explainability under a single experimentally validated pipeline. The experimental results reveals that across five random seeds, MI-IDS achieves 96.7 ± 0.2% accuracy and 95.8 ± 0.2% F1-score on a 73,100-instance composite benchmark spanning seven traffic classes, one of which is a held-out group of synthetically mutated attack variants used as a partial-novelty proxy rather than a genuine zero-day family. A held-out UNSW-NB15 partition ( n  = 82,332) yields 97.4 ± 0.2% accuracy; because UNSW-NB15 also contributes to the composite, this figure reflects within-benchmark held-out performance rather than independent cross-dataset generalisation. A six-variant ablation study isolates the contribution of each architectural component. Under a 48-hour concept-drift simulation, reservoir sampling bounds accuracy loss to 1.2% points versus a 20.4-point degradation for the non-adaptive baseline. The hybrid edge-cloud deployment achieves 14.1 ms mean detection latency and 61.2% lower bandwidth than cloud-only deployment, and SHAP attributions lowered analyst mean time-to-decision by 57.1% in a small preliminary study with five experts, a result we treat as indicative rather than confirmatory. All improvements over six baselines are statistically significant at Bonferroni-corrected α = 0.0083. A central contribution is the integration and disciplined evaluation of multi-seed validation, structured ablation, on-line incremental learning, and model-agnostic explainability within a single smart city IoT pipeline, a combination that remains uncommon in the prior IDS literature rather than one we can demonstrate to be unprecedented.

Read PDF

Similar papers

Open access Aug 2026

XP-IDS: an explainable hybrid CNN–XGBoost framework for IoT intrusion detection

The proposed accurate and interpretable framework shows strong potential as an edge-deployable security solution for safeguarding IoT devices and improving cyber resilience.

Prabhav Jain, Aashima Sharma, A. Noonia et al. · 0 citations
Open access Sep 2026

A Deep Hybrid Recursive Model Combining 1D-CNN and BI-LSTM for Reliable Intrusion Detection in IoT Big Data Streams

Purpose: This study proposes a novel hybrid recursive deep learning-based Intrusion Detection System (IDS) for detecting sophisticated security threats in high-velocity IoT big data streams. Design/Methodology/Approach: The proposed framework integrates one-dimensional Convolutional Neural Networks (1D-CNNs) for lightw...

J. Alkenani, M. Nickray · 0 citations
Open access Sep 2026

A cross-attention CNN–LSTM fusion model for network traffic anomaly detection

Detecting cyber intrusions in modern IoT networks is challenging because of their large scale, heterogeneous device ecosystems, and high-volume traffic patterns. This paper presents a cross-attention CNN–LSTM fusion architecture that jointly learns the spatial and temporal characteristics of network traffic for bin...

Mohamed Fakri, A. Najid, Rachid Ben Said et al. · 0 citations
Open access Sep 2026

QuadFusion-IDS: Enhancing Intrusion Detection with Unified Hybrid Deep and Machine Learning Techniques in Cybersecurity Systems

As network traffic becomes increasingly complex and cyberattack behaviors continue to evolve, conventional intrusion detection approaches face challenges in accurately identifying malicious and legitimate network activities. This study proposes QuadFusion-IDS, a hybrid binary intrusion detection framework that integrat...

Janmejaya Mishra, Nilesh Dnyaneshwar Bhandarwar · 0 citations
Conference Aug 2026

An Intelligent Deep Learning-Based Intrusion Detection System for IoT Nodes using CNN- BiLSTM and Grasshopper Optimization

Recent networks have a remote larger attack surface owing to the quick spread of Internet of Things (IoT) strategies, which for effective and instantaneous Intrusion Detection Systems (IDS). Deep-IDS, a real-time Deep Learning (DL) IDS intended for IoT nodes with limited resources, is presented in this work. The raw ne...

D. Sameera, M. Sreenivasu, Aruna Kommu · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.