Skip to content
Review Open access

DEEP LEARNING-BASED INTRUSION DETECTION IN COMPUTER SYSTEMS AND NETWORKS: ADVANCES, HYBRIDS, AND CHALLENGES 2022–2026

Jul 2026 · Advanced Information Systems · Vol 10, pp. 80-96 · 0 citations · 128 references

TL;DR

It was found that hybrid and ensemble models provide the highest accuracy in complex environments (over 99%), while the combination of convolutional neural networks with recurrent networks or Transformers is the most effective solution for detecting multi-stage attacks.

Abstract

The work is devoted to a comprehensive systematic review of advances in identifying the state of computer systems and networks in the context of cybersecurity for the period 2022–2026. The study analyzes the evolution of intrusion detection systems (IDS), provides categorization and synthesis of key approaches, including supervised, unsupervised, and semi-supervised learning, as well as statistical and temporal analysis methods. Particular attention is paid to deep learning models (CNN, RNN/LSTM, Transformers, GNN) and their hybrid combinations, which demonstrate accuracy above 95% in detecting complex multi-stage attacks and zero-day threats. The experience of implementing identification methods in specific domains such as IoT, SCADA, automotive networks, and maritime transportation systems is summarized. Critical challenges for the scientific community are identified, including the problem of explainable artificial intelligence (XAI), resilience to adversarial attacks, and optimization for real-time operation on resource-constrained devices. Conclusions. The study revealed a trend of transition from classical static signature-based methods to dynamic intelligent algorithms. The analysis of available sources made it possible to classify the considered approaches according to their mathematical foundations and operational characteristics. For each group of methods, their main advantages, disadvantages, and key prospects for application were identified. It was found that hybrid and ensemble models provide the highest accuracy in complex environments (over 99%), while the combination of convolutional neural networks with recurrent networks or Transformers is the most effective solution for detecting multi-stage attacks. In addition, the growing role of federated learning in the development and implementation of intrusion detection systems was emphasized.

Read PDF

Similar papers

Review 2026

Deep Learning-Driven Intrusion Detection Systems: A Comprehensive Survey of Architectures, Performance Evaluation, and Research Challenges

A taxonomy of IDS architectures and a survey of recently proposed networks, such as Convolutional Neural Networks (CNNs), Recurrent Neural Networks (RNNs), LSTMs, GRUs, Autoencoders, GANs, Transformer-based, as well as hybrids are developed.

Sajith K. V., Gripsy Paul, Bhagavant Deshpande et al. · 0 citations
Open access Aug 2026

AI-Driven Security: Detecting Cyber Attacks in IoT Networks

LSTM had good detection for frequent attacks and slow-changing patterns, which shows its capacity in learning long-lasting dependencies, which shows its capacity in learning long-lasting dependencies.

Jawad Hussain Awan, Misbah Safdar, Muhammad Ayaz Shirazi et al. · 0 citations
Review Open access 2026

Deep Reinforcement Learning-Based Intrusion Detection in IoT Networks: A Systematic Mapping and Literature Review

The review reveals that the most used algorithm for DRL-based IDS is Deep Q-Network (DQN), appearing in 8 studies (30.8%), and the most frequently targeted attacks are DoS, DDoS, Backdoors, Mirai, Reconnaissance, Scan, and Torii.

Maryam Omar Abdullah Sawad, S. Abdulkadir, H. Alhussian et al. · 0 citations
Review Open access Jul 2026

A Systematic Review of AI-Driven Intrusion Detection and Performance Optimization in Wireless Sensor Networks

The study analyzes the most recent progress in ML and DL methods used to develop IDS that operate in WSNs through analysis of their primary algorithms and algorithmic combinations and concludes that the DL and hybrid approaches are superior to conventional ML algorithms in handling complicated and imbalanced datasets.

Priyanka Sharma, Mohd. Suhaib Kidwai, Piyush Charan · 0 citations
Open access Aug 2026

HybridML CyberShield for explainable proactive intrusion detection in enterprise and IoT networks

The framework introduces CNN–BiLSTM deep learning networks to represent traffic in a spatiotemporal manner and adopts ensemble machine learning classifiers to enhance the robustness of traffic detection and its interpretability, to enhance the robustness of traffic detection and its interpretability.

Ramesh N. S. V. S. C. Sripada, A. Bhavani, Kiran B. Malagi et al. · 0 citations
Review Open access Aug 2026

Advancing Intrusion Detection Systems: A Comprehensive Review of Deep Learning and Hyperparameter Optimization Techniques

In the suddenly changing realm of cyber security, Intrusion Detection Systems (IDS) are essential for protecting computer networks from harmful actions.  This survey paper offers an extensive examination of sophisticated approaches and procedures utilised in IDS, emphasising the amalgamation of deep learning (DL) and hyper parameter optimisation.  We examine many categories of cyber-attacks that confront conventional IDS, including phishing, malware, ransom ware, and advanced evasion strategies.  The study explores the intricacies of hyper parameter tuning in DL algorithms, emphasising major methods such grid search (GS), random search (RS), Bayesian optimisation (BO), and genetic algorithms (GA).  This paper examines recent progress in DL applications for IDS, highlighting the efficacy of models such as Convolutional Neural Networks (CNNs), Recurrent Neural Networks (RNNs), and auto encoders in identifying both established and emerging threats.  Case studies and contemporary research illustrate the effects of these tactics on enhancing IDS accuracy, minimising false positives, and responding to novel attack strategies.  This survey highlights the necessity for on-going advancement in IDS to tackle the evolving nature of cyber threats and improve the overall security stance of networked systems.

H. K. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.