The revised framework extends this four-layer pipeline by explicitly integrating Explainable AI (XAI) and edge-oriented deployment as cross-cutting operational requirements by explicitly integrating Explainable AI (XAI) and edge-oriented deployment as cross-cutting operational requirements.
Abstract
The increasing complexity of cyber threats has strengthened the need for adaptive network intrusion detection systems (IDS). This systematic literature review (SLR) synthesizes nine peer-reviewed studies published from 2024 to 2026 on deep learning (DL)-based network anomaly detection. The review follows a PRISMA 2020-aligned process covering database selection, eligibility screening, quality assessment, and structured data extraction. Five research questions examine DL architectures, preprocessing and class-imbalance handling, comparative performance, deployment challenges, and the basis for a conceptual framework. The synthesis compares preprocessing, classification strategy, Accuracy, Precision, Recall, and F1-Score where reported. The evidence shows that hybrid architectures can achieve very high benchmark performance, but the results are dataset- and experimental-setting dependent; therefore, the claim that hybrid models universally exceed 95% is not supported. Across the included studies, the recurring technical pattern is: representative data collection, preprocessing and imbalance mitigation, architecture selection according to spatial or temporal characteristics, and multi-metric evaluation. The revised framework extends this four-layer pipeline by explicitly integrating Explainable AI (XAI) and edge-oriented deployment as cross-cutting operational requirements. The review also identifies limitations in dataset realism, cross-dataset validation, reporting consistency, computational efficiency, and explainability.
The rapid expansion of networked infrastructure, cloud computing, and IoT environments has significantly increased the attack surface, while traditional signature-based Network Intrusion Detection Systems (NIDS) remain limited in detecting zero-day attacks, polymorphic threats, and malicious activities within encrypted...
Y. Alnattaf, Hanaa Fathi Mahmoud· Neutrosophic Optimization an...· 1 citation
The paper concludes that no single model is universally best; rather, technique selection should depend on the type of attack, the quality of validation, the amount of latency, the scalability, privacy, and explainability, to determine the most appropriate approach.
Elijah Abayomi Olaniyi, T. Atoyebi, Ridwan Kolapo et al.· Iconic research and engineer...· 0 citations
Network intrusion detection systems (NIDS) play a critical role in protecting modern communication networks against increasingly sophisticated cyber attacks. In this paper, we propose a Transformer-based network intrusion detection system (t-NIDS) that integrates a Transformer encoder with contrastive learning to learn...
The findings support the adoption of hybrid IDS architectures as a balanced and practical solution that enhances detection capability, adaptability, and reliability in evolving cyber threat landscapes.
Bang-Chen Yu· Technologique: A Global Jour...· 0 citations
Security researchers rely heavily on Network Intrusion Detection Systems (NIDS) to keep an eye on network traffic and notify administrators of any suspicious activities. The purpose of this paper is to offer a comprehensive overview of intrusion detection systems (IDS), including the following topics: fundamentals, kin...
Madhav Sharma· International Journal of Cyb...· 0 citations
Machine learning (ML) and deep learning (DL) have dominated Intrusion Detection System (IDS) research in recent years. Unfortunately, many existing studies have produced inflated results and unreliable benchmarks due to critical oversights and mistakes in the ML and DL pipeline, from data collection and labeling to fea...