A Hybrid CNN-BiLSTM Model with Self-Attention for Network Intrusion Detection: Comparative Evaluation on the NSL-KDD Dataset
Author(s):Dr. K. Sujatha
Affiliation: Independent Researcher
Page No: 33-40
Volume issue & Publishing Year: Volume 2, Issue 8, 2026/08/29
Journal: International Journal of Advanced Engineering Application (IJAEA)
ISSN NO: 3048-6807
DOI: https://doi.org/10.5281/zenodo.20051149
Download PDF Cite this article
Abstract:
Network intrusion detection systems (NIDS) represent a critical line of defence in modern cybersecurity infrastructure, tasked with identifying malicious network activity from high-dimensional, high-velocity traffic data in real time. Conventional signature-based and statistical anomaly detection approaches have demonstrated limited efficacy against zero-day attacks, low-rate flooding attacks, and obfuscated intrusion patterns that exploit temporal dependencies in packet sequences. This paper proposes a hybrid deep learning architecture that combines one-dimensional convolutional neural networks (1D-CNN) for local spatial feature extraction with bidirectional long short-term memory networks (BiLSTM) for sequential temporal modelling, augmented by a self-attention mechanism that dynamically weights the contribution of each time step to the final classification decision. The proposed CNN-BiLSTM-Attention model is trained and evaluated on the NSL-KDD benchmark dataset, a widely used standard for NIDS research that addresses the class imbalance and redundancy limitations of the original KDD Cup 1999 dataset. The model is benchmarked against four baseline classifiers — logistic regression, support vector machine (SVM), random forest, and XGBoost — across four attack categories: Denial of Service (DoS), Probe, Remote-to-Local (R2L), and the benign traffic class. The proposed model achieves an overall classification accuracy of 94.7%, macro-averaged F1-score of 93.8%, and area under the ROC curve (AUC) of 0.987, outperforming all baseline models across all evaluation metrics. Ablation studies confirm that both the BiLSTM and attention components make statistically significant independent contributions to classification performance beyond the CNN baseline alone. The results demonstrate that the CNN-BiLSTM-Attention architecture provides a robust, generalisable framework for multi-class network intrusion detection that is well-suited for deployment in real-time network security monitoring systems.
Keywords: network intrusion detection, deep learning, CNN, BiLSTM, self-attention, NSL-KDD, cybersecurity, anomaly detection, classification, XGBoost
Reference:
- [1] Tavallaee, M., Bagheri, E., Lu, W., & Ghorbani, A. A. (2009). A detailed analysis of the KDD CUP 99 data set. Proceedings of the 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications (CISDA), pp. 1–6.
- [2] Yin, C., Zhu, Y., Fei, J., & He, X. (2017). A deep learning approach for intrusion detection using recurrent neural networks. IEEE Access, 5, 21954–21961.
- [3] Vinayakumar, R., Alazab, M., Soman, K. P., Poornachandran, P., Al-Nemrat, A., & Venkatraman, S. (2019). Deep learning approach for intelligent intrusion detection system. IEEE Access, 7, 41525–41550.
- [4] Goodfellow, I., Bengio, Y., & Courville, A. (2016). Deep Learning. MIT Press, Cambridge, Massachusetts.
- [5] Hochreiter, S., & Schmidhuber, J. (1997). Long short-term memory. Neural Computation, 9(8), 1735–1780.
- [6] Vaswani, A., Shazeer, N., Parmar, N., Uszkoreit, J., Jones, L., Gomez, A. N., Kaiser, L., & Polosukhin, I. (2017). Attention is all you need. Advances in Neural Information Processing Systems, 30, 5998–6008.
- [7] Chen, T., & Guestrin, C. (2016). XGBoost: A scalable tree boosting system. Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 785–794.
- [8] Schapire, R. E., & Freund, Y. (2012). Boosting: Foundations and Algorithms. MIT Press, Cambridge.
- [9] Chawla, N. V., Bowyer, K. W., Hall, L. O., & Kegelmeyer, W. P. (2002). SMOTE: Synthetic minority over-sampling technique. Journal of Artificial Intelligence Research, 16, 321–357.
- [10] Breiman, L. (2001). Random forests. Machine Learning, 45(1), 5–32.
- [11] Cortes, C., & Vapnik, V. (1995). Support-vector networks. Machine Learning, 20(3), 273–297.
- [12] Kim, J., Kim, J., Thu, H. L. T., & Kim, H. (2016). Long short term memory recurrent neural network classifier for intrusion detection. International Conference on Platform Technology and Service (PlatCon), pp. 1–5.
- [13] Kingma, D. P., & Ba, J. (2015). Adam: A method for stochastic optimization. International Conference on Learning Representations (ICLR 2015).
- [14] Srivastava, N., Hinton, G., Krizhevsky, A., Sutskever, I., & Salakhutdinov, R. (2014). Dropout: A simple way to prevent neural networks from overfitting. Journal of Machine Learning Research, 15(1), 1929–1958.
- [15] Sherstinsky, A. (2020). Fundamentals of recurrent neural network (RNN) and long short-term memory (LSTM) network. Physica D: Nonlinear Phenomena, 404, 132306.
📚 Explore Our Related Journals
Looking for the right journal for your next manuscript? Explore our international peer-reviewed journals covering multidisciplinary research, engineering, management, computer science and artificial intelligence.
IJAMA
International Journal of Advanced Multidisciplinary Application
Publishes peer-reviewed research articles in Engineering, Management, Computer Science, Artificial Intelligence, Science, Humanities, Social Sciences and multidisciplinary research.
IJMEM
International Journal of Modern Engineering and Management
Publishes peer-reviewed research articles in Engineering, Management, Computer Science, Artificial Intelligence, Technology and multidisciplinary research.