Jul 2026· International Journal of Drug Delivery Technology· Vol 16· 0 citations· 15 references
TL;DR
An AI-based, adaptable Network Intrusion Detection System (NIDS) which, using Generative Adversarial Networks (GANs) with XGBoost, will enhance the detection of known and novel cyberattacks.
Abstract
Background
The fast rate at which cyber threats are evolving brings a lot of challenges to the conventional signature-based intrusion
detection systems (IDS) that do not always identify new or zero-day attacks. The paper introduces an AI-based, adaptable
Network Intrusion Detection System (NIDS) which, using Generative Adversarial Networks (GANs) with XGBoost, will
enhance the detection of known and novel cyberattacks.
Objective
The suggested framework is designed to process network traffic data by preprocessing network traffic data, realistically
simulates the samples of synthetic attacks based on a feature-driven GAN, and uses XGBoost as a powerful feature selection
and classification tool. The system decreases the false positives and increases the detection of rare and previously unseen attacks
by managing class imbalance.
Results
Large-scale experiments, using benchmark network intrusion datasets, reveal the proposed approach to be much better than the
conventional machine learning and deep learning-based IDS models with regards to accuracy, precision, recall and F1-score.
In addition, the framework facilitates dynamic learning in changing patterns of network traffic to allow real-time monitoring in
dynamic environments.
Conclusion
Data augmentation using GAN and explainable XGBoost classification is a scalable, interpretable, and practical intelligent
network security solution. This research contributes to the work on the creation of active, AI-based intrusion detection systems
that can react to cybersecurity threats that change rapidly.
LSTM had good detection for frequent attacks and slow-changing patterns, which shows its capacity in learning long-lasting dependencies, which shows its capacity in learning long-lasting dependencies.
Jawad Hussain Awan, Misbah Safdar, Muhammad Ayaz Shirazi et al.· Italian National Conference...· 0 citations
Cloud computing has emerged as an important core to the contemporary digital services, facilitating scalable, on demand provisioning of resources across a variety of application fields. Nevertheless, this multi-tenant and dynamic environment of clouds and the amplified attack surface make the detection of intrusions through reliable methods a consistent issue that cloud security systems struggle with. The proposed work is a Generative Adversarial Network (GAN)-based hardening framework of cloud intrusion detection systems, targeting better resilience to changing and low-rate cyberattacks. The methodology combines a conditional generator which is used to generate realistic cloud-specific attack traffic, a discriminator used to refine the adversarial traffic, as well as a co-trained intrusion classifier trained on both clean and synthetic data in a closed-loop way. The feature-aware regularization is introduced to maintain the statistical consistency of network traffic, and optimize the attack diversity. The proposed approach is proved to yield better results in comparison with signature-based, machine learning, deep learning, and adversarial ML-based IDS models by experimental assessment. Significant gains in the accuracy of identifying, the ability to recall, stability, and minimizing errors are also noticed with quantifiable increases observed in all evaluation measures. These findings represent the usefulness of adversarial data-driven learning to develop robust, adaptive, and future-ready cloud intrusion detection systems.
T. Divya, Sheik Saidhbi, S. Umarani et al.· 2026 International Conferenc...· 0 citations
The findings confirm that the proposed IDSaaS framework provides an efficient, scalable, and adaptive solution for real-time cloud intrusion detection and significantly enhances the reliability and resilience of modern cloud and industrial cybersecurity infrastructures.
Unik B. Lokhande, Kavita Sonawane· Journal of Cloud Computing· 0 citations
An intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies is presented.
S. Singh, Alok Kumar· International Journal of Com...· 0 citations
Network intrusion detection remains a fundamental cybersecurity challenge due to the increasing diversity and sophistication of malicious network traffic. Conventional signature-based approaches exhibit limited capability in detecting previously unseen attacks, while many machine learning methods suffer from class imbalance, high false-positive rates, and limited adaptability across heterogeneous network environments. To address these challenges, this paper proposes HADS-Net (Hybrid Attention-based Deep Security Network), which integrates a feature-wise multi-head self-attention module with a stacked ensemble consisting of Random Forest and Gradient Boosting base learners combined through out-of-fold stacking and a logistic regression meta-learner. The attention mechanism adaptively emphasizes informative network features to improve discriminative learning, while the stacking strategy enhances generalization and reduces overfitting. Experiments were conducted on a class-stratified 15,000-record subsample derived from the NSL-KDD KDDTrain+ corpus, in which the minority R2L and U2R categories were deliberately enriched to obtain usable test support; the subsample was divided into 70% training and 30% testing partitions, giving a held-out test partition of 4,500 records. Because this constructed distribution departs from the native NSL-KDD proportions, the results reported here are not directly comparable with published KDDTest+ figures, and no such comparison is claimed. The proposed model achieved 96.20% accuracy, 97.57% precision, 94.32% recall, 95.92% F1-score, and 98.83% AUC-ROC on the binary Normal-versus-Attack task. A multi-layer perceptron baseline attained higher accuracy (98.11%) and F1-score (97.99%) than the proposed model on the same partition, and the ablation deltas attributable to the attention and stacking components lie below 0.5%; these deltas are reported as single-run point estimates. The principal contribution of this work is consequently architectural and diagnostic rather than a performance improvement: it documents that combining feature-wise attention with out-of-fold stacked generalization does not, in this setting, outperform a plain multi-layer perceptron, while incurring the highest memory footprint of the six models evaluated.
Mahima Khanna, V. Murthy, Siva Ramavarapu et al.· International Journal for Gl...· 0 citations
Network infrastructure has become more complex and the amount of cybersecurity challenges has grown with the introduction of cloud computing, the Internet of Things (IoT) and next-generation communication technologies. The known attack and known signatures are the reasons why traditional IDSs fail to detect sophisticated and new attacks; they are signature-based and programmed by hand. To overcome these drawbacks, this work presents a deep learning-based cybersecurity framework for proactively detecting the intrusion in CSE-CIC-IDS2018 benchmark dataset. The proposed system combines spatial and temporal features of network traffic using a hybrid Convolutional Neural Network (CNN) and Long Short-Term Memory (LSTM) network architecture with a systematic data preprocessing pipeline. In the preprocessing stage, data quality and learning efficiency are enhanced by data cleaning, handling missing data, removing duplicate data, encoding labels, normalizing features, and splitting the data into training and testing sets. The CNN part is used to automatically learn discriminative spatial features, and the LSTM was used to learn the sequential traffic dependencies to see the relation between the sequential sequence and attack detection capability was improved. Experiments were carried out on Python, TensorFlow, Keras and Google Colab with GPU support. The proposed framework was evaluated according to the accuracy, precision, recall, F1-score, and ROC-AUC and the results were found to be 98.64%, 98.41%, 98.18%, 98.29%, and 99.12%, respectively, which are considered to be excellent classification results and strong discrimination ability. Moreover, the framework demonstrated good computational efficiency with an average inference time of 2.8ms per network flow and a moderate use of GPU memory. Results of comparative analysis with the latest deep learning-based intrusion detection methods also validate the competitiveness and applicability of the proposed framework. The results highlight the efficiency, reliability, and effectiveness of the hybrid CNN-LSTM framework in proactively detecting network intrusions in contemporary cybersecurity settings.
Ali Rachini, M. K. Mahmood· SHIFRA· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.