Skip to content
Conference

A Deep Learning-Based Intrusion Detection System using Multi-Granularity Attention for Minimizing False Positives in Industrial Internet of Things Networks

Jul 2026 · 2026 5th International Conference on Distributed Computing and Electrical Circuits and Electronics (ICDCECE) · pp. 1-8 · 0 citations · 25 references

Abstract

The rapid expansion of the Internet of Things (IoT) has transformed modern industrial communication. However, this massive growth has introduced critical security vulnerabilities into network environments. Current intrusion detection systems struggle to address these threats effectively due to high false alarm rates. To overcome these challenges, this study introduces the Multi-Granularity Attention-based Graph Attention Network Bidirectional Long Short-Term Memory (MGA-GBiLSTM) framework for accurate multi-class traffic categorisation. The proposed MGA-GBiLSTM functions by mapping network connections into dynamic graphs and utilises a gated attention mechanism to cross-verify individual anomalies against peer-group and organisational baselines. By combining Graph Attention Networks for spatial mapping with a BiLSTM for deep temporal analysis, the system simultaneously validates the structural intent and sequential patterns of network actions. The MGA-GBiLSTM model was evaluated using the CIC IoT-DIAD 2024, CICDDoS2019, and UNSW-NB15 datasets. Experimental results demonstrate that the framework achieves impressive classification accuracy of 99.16% on the CIC IoT-DIAD 2024 dataset, 99.78% on the CICDDoS2019 dataset and 98.91% on the UNSWNB-15 dataset, respectively. Ultimately, this MGA-GBiLSTM approach improves system reliability in automated monitoring by significantly reducing alert fatigue while maintaining a robust defence against complex cyber threats.

View source

Similar papers

Conference Jul 2026

An Attention-based Transformer Encoder for Efficient Intrusion Detection in High-Volume Network Traffic

The rapid growth in cloud computing and the emergence of the new Internet of Things (IoT) environment, there has also been a corresponding increase in long-term and high-volume network traffic and ever-growing complexity of cyber-attacks. This growth creates a significant challenge in achieving accurate and timely intrusion detection. Traditional Intrusion Detection Systems (IDS) and Long Short-Term Memory (LSTM) models are detecting malicious activity with limited scalability; process information sequentially, causing increased overhead; and inefficiently model long time-frame dependencies (i.e., long-term detection). Given this need for scalable and low-latency IDS with the ability to detect complex and zero-day attacks, this research work provides an Attention Based (self-attention-based) intrusion detection system (AB-IDS). The proposed AB-IDS uses transformer encoders based on self-attention rather than recurrent models. It models network traffic as time-sequenced flows and uses a multi-head self-attention mechanism to capture all long-term dependencies in parallel. Results from extensive evaluations using the CIC-IDS 2017, UNSW-NB15, and NSL-KDD benchmark datasets show that the AB-IDS consistently offers performance improvements of up to 2.6% (increased accuracy) and up to 46.2% reduction (in reduced false alarm rates) over BiLSTM Based IDS. In addition, the proposed method reduces the amount of time required to train the network by 44.6% and the amount of time needed to make the inferences from the network by 52.9%. Based on these findings, the proposed approach has demonstrated its capability to be effectively used for real-time intrusion detection in large Cloud Computing (CC) and IoT networks.

K.S.Kamalam, L.Sheeba · 0 citations
Conference Jul 2026

Knowledge-Distilled Multi-Model Intrusion Detection and Prevention System for IoT Networks

The growth of Internet of Things devices has expanded the number of attackable targets of advanced cyber threats by orders of magnitude, and the limited computational capabilities of IoT devices have made more traditional intrusion detection systems infeasible to execute at the edge. A Knowledge-Distilled Multi-Model Intrusion Detection and Prevention System is presented, which combines a Residual Graph Convolutional Network, Long Short-Term Memory classifier, and a Conditional Tabular Generative Adversarial Network enhanced with the student-only autoencoders through multi-loss knowledge distillation to create a high-performing Teacher ensemble and compresses its intelligence into an edge-deployed system. The system is evaluated using the IoT-23 benchmark of 325 million network flow records and attains 98.2% Teacher-Student fidelity, 0.94 Knowledge Retention Score, and 4.4x throughput increase with 82.7% reduction in the parameter and provides per-packet SHapely Additive exPlanation forensic explainability.

S. K, Menaka T K, N. R · 0 citations
Aug 2026

Cyber Security Intrusion Detection Based on Deep Learning

The Hybrid Autoencoder–TabTransformer framework provides an effective intrusion detection solution that demonstrates strong performance under the evaluated experimental conditions and comparative analysis with existing deep learning‐based intrusion detection approaches confirms the superior and balanced performance of the proposed method.

Rui Guo, Guangjun Wen · 0 citations
Open access Jul 2026

From Signature to Attention: Transformer-Powered Intrusion Detection Systems for Cybersecurity

Experimental results demonstrate that the proposed model achieves high detection accuracy, strong discriminative capability, and low false alarm rates across both datasets, confirming its effectiveness and scalability for next-generation cybersecurity applications.

Arun Pandey, Ayush Kumar Agrawal, Abhinav Shukla et al. · 0 citations
Open access Sep 2026

Traffic-Aware Imbalance Learning Network for Lightweight IoT Intrusion Detection

The rapid growth of internet of things (IoT) networks has significantly increased cybersecurity risks due to heterogeneous traffic characteristics, large-scale connectivity, and highly imbalanced attack distributions. Existing intrusion detection approaches primarily focus on improving overall detection performance through computationally expensive deep learning architectures or synthetic oversampling techniques. However, such methods often overlook semantic relationships among traffic features, increase computational complexity, and exhibit a limited capability to learn minority attack patterns. This paper presents a Traffic-Aware Imbalance Learning Network (TAIL-Net) for lightweight and imbalance-aware IoT intrusion detection. The proposed framework introduces a traffic-aware semantic feature mapping mechanism that reorganizes network traffic attributes according to their semantic relationships to improve feature representation learning. The mapped features are processed through a lightweight convolutional neural network (CNN)-GRU architecture integrated with a minority-aware attention and an Adaptive Class-Balanced Focal Loss (ACB-FL) function to enhance minority attack discrimination without relying on synthetic oversampling. Experimental evaluation on the Botnet-internet of things (BoT-IoT) dataset demonstrates that the proposed framework achieved 99% detection accuracy and 99% weighted F1-score. Furthermore, TAIL-Net requires only 81,866 trainable parameters with a model size of 0.3122 MB and achieves an average inference latency of 0.0041 ms/sample.

Sowmya Somanath, Usha Banavikal Ajay · 0 citations
Open access Jul 2026

Adaptive intrusion detection system for cloud security using deep learning

The findings confirm that the proposed IDSaaS framework provides an efficient, scalable, and adaptive solution for real-time cloud intrusion detection and significantly enhances the reliability and resilience of modern cloud and industrial cybersecurity infrastructures.

Unik B. Lokhande, Kavita Sonawane · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.