Publication Details
Keywords: Network Intrusion Detection System (NIDS), Deep Learning, Hybrid Architecture, Spatial–Temporal Feature Extraction, Explainable Artificial Intelligence (XAI), Cybersecurity
Abstract
In the present context where the threat of cyber-attack has increased in sophistication, the NIDS have emerged as an important component of the defense of modern communication infrastructure. Existing detection techniques are not able to capture the complicated space–time relationships between network flows, and thus detection accuracy decreases while false alarm rates increase. To overcome these limitations, a hybrid DL architecture which consists of Seq2Seq and ConvLSTM subnets is proposed and tested on three benchmark datasets: CIC-IDS2017, CIC-ToN-IoT and UNSW-NB15. The databases were consolidated from various data sources and the data were systematically preprocessed: label encoding, one hot encoding, Min Max normalization, feature selection (SelectKBest) and outlier removing. We have developed various machine learning and DL models such as RandomForest, DecisionTree, Naïve Bayes, XGBRF, CNN, ConvLSTM, Seq2Seq, LuNET, Voting Classifier and LSTM+GRU hybrid model. The performance was evaluated by accuracy, precision, recall and F1 score. Results from the experiments reveal that the Voting Classifier and LSTM+GRU models obtained 100% score on all metrics for CIC-IDS2017 and CIC-ToN-IoT whereas the RandomForest model achieved the best score on UNSW-NB15 with 91.5% accuracy and 91.6% F1-score. Additionally, instance level and global feature attribution are achieved using LIME and SHAP based explainable AI to enhance the interpretability of the model with increased transparency. A web interface with secure user driven real-time intrusion prediction and deployment is developed using flask and sqlite. Overall, the framework assures the accuracy, interpretability and deployability of the intrusion detection.
References
- [1] Ghosh, S., Goyal, R. K., & Chowdhury, K. (2026). Explainable AI-Driven Intrusion Detection System for DoS Attack Classification Using Deep Learning and Optimization Techniques. IEEE Access, 14, 5618-5642. [2] Sri Abhijit, C., Annie Jerusha, Y., Syed Ibrahim, S. P., & Varadharajan, V. (2025). Federated transfer learning for rare attack class detection in network intrusion detection systems. Scientific Reports, 15(1), 33797. [3] Velde, V., Prashanth, B., Krishna, B., Nagaraju, P., & Pogaku, R. (2025). Hybrid machine learning for AI-driven cyber threat intelligence and proactive intrusion detection. The European Physical Journal Plus, 140(12), 1214. [4] Baniya, S., Mahalal, E., & Hilal, A. (2025, December). A Review of Existing AI-Based IDSs in IoT: Challenges, Datasets, and Improvements. In 2025 TRON Symposium (TRONSHOW) (pp. 1-8). IEEE. [5] Gutiérrez-Galeano, L., Domínguez-Jiménez, J. J., Schäfer, J., & Medina-Bulo, I. (2025). Llm-based cyberattack detection using network flow statistics. Applied Sciences, 15(12), 6529. [6] Z. Ahmad, A. S. Khan, C. W. Shiang, J. Abdullah, and F. Ahmad, “Network intrusion detection system: A systematic study of machine learning and deep learning approaches,” Trans. Emerg. Telecommun. Technol., vol. 32, no. 1, pp. e4150, 2021. [7] H. Gwon, C. Lee, R. Keum, and H. Choi, “Network intrusion detection based on LSTM and feature embedding,” 2019, arXiv:1911.11552. [8] P. Mishra, V. Varadharajan, U. Tupakula, and E. S. Pilli, “A detailed investigation and analysis of using machine learning techniques for intrusion detection,” IEEE Commun. Surveys Tuts., vol. 21, no. 1, pp. 686–728, 1st Quart., 2019. [9] S. M. Erfani, S. Rajasegarar, S. Karunasekera, and C. Leckie, “High-dimensional and large-scale anomaly detection using a linear one-class SVM with deep learning,” Pattern Recognit., vol. 58, pp. 121–134, Oct. 2016. [10] N. Japkowicz, “The class imbalance problem: Significance and strategies,” in Proc. Int. Conf. Artif. Intell., vol. 56, 2000, pp. 111–117. [11] V. Chandola, A. Banerjee, and V. Kumar, “Anomaly detection,” ACM Comput. Surv., vol. 41, no. 3, pp. 1–58, Jul. 2009. [12] M. A. Al-Garadi, A. Mohamed, A. K. Al-Ali, X. Du, I. Ali, and M. Guizani, “A survey of machine and deep learning methods for Internet of Things (IoT) security,” IEEE Commun. Surveys Tuts., vol. 22, no. 3, pp. 1646–1685, 3rd Quart., 2020. [13] J. Hussain and V. Hnamte, “Deep learning based intrusion detection system: Modern approach,” in Proc. 2nd Global Conf. Advancement Technol. (GCAT), Oct. 2021, pp. 1–6. [14] A. H. Nasreen Fathima and S. P. S. Ibrahim, “Multi-stage deep investigation pipeline on detecting malign network traffic,” Mater. Today Proc., vol. 62, pp. 4726–4731, Jan. 2022. [15] Y. A. Jerusha, S. P. S. Ibrahim, and V. Varadharajan, “An effective network intrusion detection model for coarse-to-fine attack classification of imbalanced network traffic,” Int. Res. J. Adv. Sci. Hub, vol. 5, pp. 531–540, May 2023. [16] Y. Yang, K. Zheng, B. Wu, Y. Yang, and X. Wang, “Network intrusion detection based on supervised adversarial variational auto-encoder with regularization,” IEEE Access, vol. 8, pp. 42169–42184, 2020. [17] B. Yan and G. Han, “Effective feature extraction via stacked sparse autoencoder to improve intrusion detection system,” IEEE Access, vol. 6, pp. 41238–41248, 2018. [18] X. Shi, Z. Chen, H. Wang, D. Yeung, W. K. Wong, and W. Woo, “Convolutional LSTM network: A machine learning approach for precipitation nowcasting,” in Proc. Adv. Neural Inf. Process. Syst., Jan. 2015, pp. 1792–1806. [19] G. Andresini, A. Appice, N. Di Mauro, C. Loglisci, and D. Malerba, “Multi-channel deep feature learning for intrusion detection,” IEEE Access, vol. 8, pp. 45346–45359, 2020. [20] H. Nizam, S. Zafar, Z. Lv, F. Wang, and X. Hu, “Real-time deep anomaly detection framework for multivariate time-series data in industrial IoT,” IEEE Sensors J., vol. 22, no. 23, pp. 22836–22849, Dec. 2022. [21] W. Khan, M. Haroon, A. N. Khan, M. K. Hasan, A. Khan, U. A. Mokhtar, and S. Islam, “DVAEGMM: Dual variational autoencoder with Gaussian mixture model for anomaly detection on attributed networks,” IEEE Access, vol. 10, pp. 91160–91176, 2022. [22] S. M. Kasongo and Y. Sun, “A deep gated recurrent unit based model for wireless intrusion detection system,” ICT Exp., vol. 7, no. 1, pp. 81–87, Mar. 2021. [23] P. Wu and H. Guo, “LuNet: A deep neural network for network intrusion detection,” in Proc. IEEE Symp. Ser. Comput. Intell. (SSCI), Xiamen, China, Dec. 2019, pp. 617–624. [24] V. Hnamte and J. Hussain, “DCNNBiLSTM: An efficient hybrid deep learning-based intrusion detection system,” Telematics Informat. Rep., vol. 10, Jun. 2023, Art. no. 100053. [25] W. Khan and M. Haroon, “An unsupervised deep learning ensemble model for anomaly detection in static attributed social networks,” Int. J. Cognit. Comput. Eng., vol. 3, pp. 153–160, Jun. 2022. [26] A. Corsini, S. J. Yang, and G. Apruzzese, “On the evaluation of sequential machine learning for network intrusion detection,” in Proc. 16th Int. Conf. Availability, Rel. Secur., vol. 3, Aug. 2021, pp. 1–10. [27] K. Jiang, W. Wang, A. Wang, and H. Wu, “Network intrusion detection combined hybrid sampling with deep hierarchical network,” IEEE Access, vol. 8, pp. 32464–32476, 2020. [28] R. K. Malaiya, D. Kwon, S. C. Suh, H. Kim, I. Kim, and J. Kim, “An empirical evaluation of deep learning for network anomaly detection,” IEEE Access, vol. 7, pp. 140806–140817, 2019. [29] Y. Yao, L. Su, Z. Lu, and B. Liu, “STDeepGraph: Spatial–temporal deep learning on communication graphs for long-term network attack detection,” in Proc. 18th IEEE Int. Conf. Trust, Secur. Privacy Comput. Commun./13th IEEE Int. Conf. Big Data Sci. Eng. (TrustCom/BigDataSE), Aug. 2019, pp. 120–127. [30] D. Gaspar, P. Silva, and C. Silva, “Explainable AI for intrusion detection systems: LIME and SHAP applicability on multi-layer perceptron,” IEEE Access, vol. 12, pp. 30164–30175, 2024. [31] J. Gera, A. R. Palakayala, V. K. K. Rejeti, and T. Anusha, “ Blockchain Technology for Fraudulent Practices in Insurance Claim Process,” in 2020 5th International Conference on Communication and Electronics Systems (ICCES) (IEEE, 2020), 1068–1075. [32] Rejeti, Kishore, G. Murali, and B. Suresh Kumar. “An Accurate Methodology to Identify the Explosives Using Wireless Sensor Networks.” In Proceedings of International Conference on Sustainable Computing in Science, Technology and Management (SUSCOM), Amity University Rajasthan, Jaipur-India. 2019. [33] V. K. K. Rejeti, S. Abdul, P. H. Prasanth, S. Ashok, and S. M. Sameer, “Virtual fit using computer vision and trimesh,” in 2023 Second International Conference on Electronics and Renewable Systems (ICEARS). IEEE, 2023, pp. 1590–1595. [34] Kishore, N. G. Manthru, and Gudipati, “Wireless nano senor Network (WNSN) for trace detection of explosives: The case of RDX and TNT,” Instrum. Mes. Metrol., vol. 18, no. 2, pp. 153 - 158, 2019, doi: 10.18280/i2m.180209. [35] Krishnaiah, V. J. R., Prakash, V. S., Chandra, G. R., Sirisha, P. G. K., Mohan, K. J., Rejeti, V. K. K., & Sundari, P. N. (2024). Optimizing ZnO/CdS/CdTe bilayer structures for enhanced CdTe solar cell efficiency: A machine learning approach: VVJR Krishnaiah et al. MRS Advances, 9(9), 640-645. [36] Sai M S, Rejeti V K K, Gera J and Raju M N 2021 Effective routing protocol in mobile ad-hoc network using individual node energy. Int. J. Adv. Res. Eng. Tech. 12: 445–453. [37] Rejeti, Kishore, G. Murali, and B. Suresh Kumar. “An Accurate Methodology to Identify the Explosives Using Wireless Sensor Networks.” In Proceedings of International Conference on Sustainable Computing in Science, Technology and Management (SUSCOM), Amity University Rajasthan, Jaipur-India. 2019.