TAFS-Net: A Transformer Attention-Based Feature Selection and BiLSTM Framework for Intelligent Cloud DDoS Attack Detection Using the BCCC-Packet-2024 Dataset
Jul 2026· International Scientific Journal of Engineering and Management· Vol 05, pp. 1-9· 0 citations
TL;DR
TAFS-Net is proposed, an adaptive deep learning framework that integrates a Transformer-based attention mechanism for dynamic feature selection with a Bidirectional Long Short-Term Memory network for traffic classification that contributes an intelligent and scalable DDoS detection solution suitable for deployment in next-generation cloud security infrastructures.
Abstract
Abstract - Distributed Denial-of-Service (DDoS) attacks continue to pose a significant threat to modern cloud computing environments due to their increasing scale, diversity, and ability to evade conventional intrusion detection systems. Existing machine learning-based detection approaches often rely on static feature selection techniques that fail to adapt to dynamic traffic characteristics, resulting in reduced detection robustness and increased computational overhead. To address these limitations, this paper proposes TAFS-Net, an adaptive deep learning framework that integrates a Transformer-based attention mechanism for dynamic feature selection with a Bidirectional Long Short-Term Memory (BiLSTM) network for traffic classification. The attention module automatically learns the relative importance of network traffic features by exploiting global contextual relationships, thereby eliminating the dependence on manually engineered feature selection methods. The selected discriminative representations are subsequently processed by the BiLSTM classifier to capture temporal dependencies within packet sequences and accurately distinguish benign traffic from DDoS attacks. The proposed framework is evaluated exclusively on the BCCC-Packet-2024 dataset, a recent benchmark designed to represent contemporary cloud network traffic and attack behaviors. Experimental evaluation demonstrates that the proposed architecture achieves superior detection capability while maintaining efficient computational performance and strong generalization across network traffic patterns. The integration of adaptive attention-driven feature selection with temporal sequence learning significantly improves classification reliability compared with conventional deep learning architectures. The proposed framework contributes an intelligent and scalable DDoS detection solution suitable for deployment in next-generation cloud security infrastructures.
Key Words: Distributed Denial-of-Service (DDoS); Cloud Security; Transformer Attention; Feature Selection; Bidirectional Long Short-Term Memory (BiLSTM); Deep Learning; Intrusion Detection System (IDS); BCCC-Packet-2024 Dataset
A novel Hybrid CNN-BiLSTM Attention-based Ensemble Framework (CBAF) that unifies three complementary representations of network traffic and incorporates SMOTE-based oversampling to counter the severe class imbalance found in benchmark intrusion datasets.
Vishwaradhya K., Annappa S. S., L. C.· International Journal of Inn...· 0 citations
Network intrusion detection remains a fundamental cybersecurity challenge due to the increasing diversity and sophistication of malicious network traffic. Conventional signature-based approaches exhibit limited capability in detecting previously unseen attacks, while many machine learning methods suffer from class imbalance, high false-positive rates, and limited adaptability across heterogeneous network environments. To address these challenges, this paper proposes HADS-Net (Hybrid Attention-based Deep Security Network), which integrates a feature-wise multi-head self-attention module with a stacked ensemble consisting of Random Forest and Gradient Boosting base learners combined through out-of-fold stacking and a logistic regression meta-learner. The attention mechanism adaptively emphasizes informative network features to improve discriminative learning, while the stacking strategy enhances generalization and reduces overfitting. Experiments were conducted on a class-stratified 15,000-record subsample derived from the NSL-KDD KDDTrain+ corpus, in which the minority R2L and U2R categories were deliberately enriched to obtain usable test support; the subsample was divided into 70% training and 30% testing partitions, giving a held-out test partition of 4,500 records. Because this constructed distribution departs from the native NSL-KDD proportions, the results reported here are not directly comparable with published KDDTest+ figures, and no such comparison is claimed. The proposed model achieved 96.20% accuracy, 97.57% precision, 94.32% recall, 95.92% F1-score, and 98.83% AUC-ROC on the binary Normal-versus-Attack task. A multi-layer perceptron baseline attained higher accuracy (98.11%) and F1-score (97.99%) than the proposed model on the same partition, and the ablation deltas attributable to the attention and stacking components lie below 0.5%; these deltas are reported as single-run point estimates. The principal contribution of this work is consequently architectural and diagnostic rather than a performance improvement: it documents that combining feature-wise attention with out-of-fold stacked generalization does not, in this setting, outperform a plain multi-layer perceptron, while incurring the highest memory footprint of the six models evaluated.
Mahima Khanna, V. Murthy, Siva Ramavarapu et al.· International Journal for Gl...· 0 citations
A hybrid anomaly detection pipeline that combines deep learning for representation learning with gradient-boosted decision trees for multiclass classification on structured traffic features is proposed, designed with practical deployment in mind by leveraging a tree-based classifier on learned features.
Marliana Sari, Nanang Sadikin, A. Chan· International Journal of Adv...· 0 citations
Experimental results demonstrate that the proposed model achieves high detection accuracy, strong discriminative capability, and low false alarm rates across both datasets, confirming its effectiveness and scalability for next-generation cybersecurity applications.
Traditional Rule-Based Web Application firewalls (WAFs) are severely limited in defending against sophisticated attacks, such as zero-day exploits, polymorphic SQL injection, and advanced persistent threats, as they achieve less than 12% of detection on new attack variants. This research presents a Hybrid Deep Learning Framework (HDLF), which is a three-tier intelligent architecture that combines the use of Convolutional Neural Networks (CNNs) for extracting spatial payload features; Bidirectional Long Short-Term Memory (BiLSTM) networks for modeling temporal sequential attacks; and an isolation forest with adaptive dynamic thresholding for unsupervised anomaly detection. The framework employs a new cross modal multi-head attention fusion mechanism for aligning spatial and temporal feature representations and an automated 247-feature hierarchical extraction pipeline that eliminates manual feature engineering. Testing the HDLF framework using five benchmark datasets, such as CSIC 2010, UNSW-NB15, Enterprise Cloudflare Traffic Corpus (10 million requests), Zero-Day Simulation Set (15,000 variants), and API-Specific Dataset (30,000 REST requests). Demonstrates that HDLF achieves 99.2 ± 0.12% detection accuracy, 2.31 ± 0.18% false positive rate, 8.7 an average inference latency, and 114,000 requests per second throughput. The Wilcoxon signed-rank statistic test (p < 0.001) confirms that all baseline models were outperformed by the HDLF. HDLF successfully identified 847 synthetic generated zero-day attack variants and achieved 71-78% cost savings compared to commercial WAF solutions and demonstrated its feasibility for scalable enterprise cloud security deployments.
Kusumakumari Daram, P. S. Kumar· Scientific Reports· 0 citations
An intrusion detection framework integrating improved parrot optimization, latent denoising diffusion implicit models (DDIM) and a hybrid CNN-Transformer, which outperforms other mainstream intelligent algorithms in global optimal solution seeking with swifter convergence.
Huanchi Luo, Gen Li, Yong Tang· Discover Computing· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.