Skip to content
Open access

Hybrid dynamic feature convolution with transformer fusion model for the detection of intrusion during manufacturing process

Aug 2026 · Discover Mechanical Engineering · Vol 5 · 0 citations · 34 references

TL;DR

The proposed hybrid framework offers a robust and efficient solution for real-time intrusion detection in manufacturing systems and demonstrates robust and repeatable intrusion detection performance rather than isolated success.

Abstract

Intrusion detection is essential in contemporary manufacturing systems. These are vulnerable to various cyber threats due to the integration of cyber-physical systems and continuous data exchange. Traditional intrusion detection systems include statistical models and standard machine learning (ML) approaches. They struggle with high-dimensional sensor data, imbalanced datasets, and fast-changing attack patterns. To overcome these challenges, we propose a hybrid intrusion detection model. It combines Dynamic Feature Convolution (DFC) with a Transformer-based temporal modelling structure. The DFC component uses gated convolutional layers with sigmoid and tanh activations to learn localized temporal features. The Transformer component applies self-attention mechanisms to capture long-term dependencies. This hybrid model learns both local feature dynamics and global temporal dependencies in industrial time series data. We evaluated the proposed model using the publicly available Water Distribution (WADI) dataset. This dataset simulates realistic industrial processes under both normal and attack scenarios. Experimental results demonstrate robust detection performance. Over five independent training runs and 5-fold cross-validation, the model achieved an average accuracy of 97.34% ± 0.23. It also reached a precision of 97.47% ± 0.24, a recall of 97.14% ± 0.22, and an F1-score of 97.30% ± 0.23. The close values of precision and recall, further supported by confusion matrix analysis and low variance across folds, indicate balanced class learning rather than precision inflation. These results demonstrate robust and repeatable intrusion detection performance rather than isolated success. Our findings suggest that the proposed hybrid framework offers a robust and efficient solution for real-time intrusion detection in manufacturing systems.

Read PDF

Similar papers

Conference Aug 2026

Intelligent Intrusion Detection System Using Hybrid Swin Transformer-RNN for Efficient Cyber Threat Mitigation

Due to the rising frequency as well as complexity of Cyber-attacks the real-time Intrusion Detection Systems (IDS) have a greater demand for reliable. Conventional IDS techniques frequently encounter performance limitations when dealing with high-dimensional data as well as temporal patterns. In order to efficiently detect and prevent cyber-attacks, this research offers a hybrid Swin Transformer and Recurrent Neural Network (RNN) model with Principal Component Analysis (PCA) for dimensionality reduction. To identify time-dependent patterns and spatial linkages in network traffic, spatial and temporal learning modules are used. To handle complicated data and retain high predicted accuracy, a hybrid model that combines the advantages of the Swin Transformer and RNN is used for training. Using Network Intrusion dataset (CIC-IDS-2017) from kaggle delivers accuracy, precision, F1-score, as well as AUC-ROC measures for the proposed method is of 99.9%. Method delivers an accessible as well as effective resolution for contemporary cyber security requirements by addressing the difficulties of real-time detection in high-dimensional datasets.

B. Deepthi, M. Sreenivasu, Chichari Rajesh · 0 citations
Open access Jul 2026

From Signature to Attention: Transformer-Powered Intrusion Detection Systems for Cybersecurity

Experimental results demonstrate that the proposed model achieves high detection accuracy, strong discriminative capability, and low false alarm rates across both datasets, confirming its effectiveness and scalability for next-generation cybersecurity applications.

Arun Pandey, Ayush Kumar Agrawal, Abhinav Shukla et al. · 0 citations
Open access Jul 2026

Hybrid CNN–LSTM Intrusion Detection Framework for Industrial IoT Security

Introduction: The rapid adoption of the Industrial Internet of Things (IIoT) has increased the exposure of safety-critical industrial systems to sophisticated cyberattacks, requiring intrusion detection mechanisms that are accurate, computationally efficient, and operationally reliable. Traditional intrusion detection systems often struggle with correlated traffic descriptors, temporal attack evolution, false alarm control, and deployment-level reliability in resource-constrained industrial environments. Methodology: This study proposes a lightweight hybrid CNN–LSTM intrusion detection framework for binary IIoT attack detection. Convolutional layers learn compact representations from high-dimensional statistical traffic descriptors, while an LSTM layer captures short-term temporal dependencies associated with multi-stage and slow-rate attacks. The model was evaluated on the BoTNeTIoT-L01 Industrial IoT benchmark using a leakage-controlled split, imbalance-aware metrics, threshold-specific false alarm analysis, probability calibration, temporal robustness assessment, and CPU-only inference benchmarking. Results: The proposed CNN–LSTM achieved accuracy = 0.99875, precision = 0.99930, recall/sensitivity = 0.99820, F1-score = 0.99875, and FAR = 0.00070 on the held-out test set. At the selected deployment threshold, the model produced a ROC operating point with TPR = 0.99820 and FPR = 0.00070. Same-split baseline and ablation comparisons further demonstrated that the proposed model provided a strong balance between detection performance, false-alarm control, calibration reliability, and CPU inference efficiency. Conclusion: The results indicate that the proposed CNN–LSTM framework is suitable for near-real-time IIoT intrusion detection where low false alarms, calibrated confidence, temporal stability, and lightweight deployment are critical.

Mushtaq Ali, Imad Ullah · 3 citations · ⚡1
Open access Aug 2026

An enhanced multi-model ensemble learning architecture for robust network intrusion detection

An Enhanced Multi-Model Ensemble Network Intrusion Detection System (EME-NIDS), a deep meta-learning system that combines five different heterogeneous learning paradigms, including Convolutional Neural Networks, Dense Neural Networks, Transformers, XGBoost, and Random Forests is introduced.

Dwarsala Sireesha, Kakelli Anil Kumar · 0 citations
Open access Aug 2026

Deep Learning-Based Network Intrusion Detection Using Hybrid CNN and LSTM Architecture

The findings indicate that hybrid deep learning techniques can improve network security by enhancing intrusion detection capability while reducing false alarms.

A. O. Jimoh-Mahmud, Abubakar Dayyabu, Abubakar Sadiq Idris et al. · 0 citations
Conference Jul 2026

Transformer-based Network Anomaly Detection System for Intelligent Cyber Security Monitoring

As MNI becomes increasingly vulnerable to new kinds of attacks from the cyber world, accurate and timely detection of intrusions becomes a primary key to the power of cybersecurity. More complex attack patterns, complex traffic interactions within large scales are not very collaborable with the typical signature-based detection methods. A Transformer Based Network Anomaly Detection System for intelligent cyber security monitoring based on network flow analysis (NFAs) is proposed in the paper. This framework is derived from the CICIDS2017 data-set and proposes 78 of the statistical flow characteristics, where each flow characteristic impacts the behaviour of a packet, protocol, volume of traffic and temporal communication pattern. The model uses a Transformer Encoder network architecture along with multiple heads of self-attention, which provides greater understanding to deal with complex relationships between features from network traffic. LabelEncoder and StandardScaler have been applied to the columns with values that need to be encoded for categorical variables and scaled to fit the values for models training. A trained model is then applied to progress multiple different categories of cyberattacks including DDoS attacks, PortScan, Brute Force, Botnet, Web Based, etc. and different kinds of traffic, all traffic is considered benign traffic. For providing real-time predictions, confidence interval, prediction of class severity and alerts using trained model an API developed on flask to connect the trained model to a dashboard was built. The experimental results show that the Transformer-based learning could be very effective in achieving successful capturing of the network behavior and conducting realistic detection. The overall proposed system offers an intelligent, scalable and deployment-centric approach to improve the monitoring and proactive detection of threats in contemporary networks in the field of cybersecurity.

S. Nagendrudu, Shaik Mohammed Anays, F. Mahammad et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.