PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 10, 2026Computers, materials & continua/Computers, materials & continua (Print)3 citationsOpen Access

IntrusionNet: Deep Learning-Based Hybrid Model for Detection of Known and Zero-Day Attacks

SASarmad Dheyaa AzeezSASabbir AhmedMIMuhammad Ilyas

Key Points

  • The aim is to improve intrusion detection capabilities against both known and unknown cyber threats.
  • Developed a hybrid deep learning model combining CNN, RNN, and autoencoders.
  • Utilized a two-part design with supervised and unsupervised processes.
  • Tested on the UNSW-NB15 dataset, which features various attack types.
  • Assessed accuracy, F1-score, precision-recall, and false positive rates.
  • Achieved an accuracy of 98.80% and an F1-score of 0.985.
  • Outperformed other systems, particularly with lesser-known attack types.
  • Demonstrated effective handling of class imbalance in detection tasks.

Abstract

Traditional Intrusion Detection Systems (IDSs) that rely on fixed signatures or basic machine learning often struggle with sophisticated, multi-stage cyberattacks and previously unknown threats. To fix these problems, this paper introduces IntrusionNet, a mixed deep learning system that combines Convolutional Neural Networks (CNN), Recurrent Neural Networks (RNN), and Autoencoders in a two-part design. Differing from typical stacked models, IntrusionNet works on two levels at the same time. First, a supervised CNN-RNN process pulls spatial-temporal data from traffic flows to sort well-known attack patterns. Second, an unsupervised Autoencoder process spots new anomalies by looking at reconstruction error limits. This approach allows the automatic learning of threat traits as they change, without needing someone to do it by hand. The system was tested on the UNSW-NB15 data set, picked because it realistically includes many kinds of attacks, like Fuzzers, Shellcode, and Worms. Tests show that IntrusionNet gets an accuracy of 98.80% and an F1-score of 0.985, doing better than other systems, especially with less common attack types. Also, tests using Precision-Recall (PR) analysis and False Positive Rate (FPR) measurements prove that the model handles class imbalance well, which is key for real-world security. The suggested system can be scaled up easily and performs calculations fast, making it a possible key part of real-time detection in Security Information and Event Management (SIEM) systems.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Azeez et al. (2026) studied this question.

synapsesocial.com/papers/69d8968f6c1944d70ce0819ahttps://doi.org/10.32604/cmc.2026.076283
Ask AI
Helpful
Bookmark
Share
View Full Paper