Skip to content
Open access

An Intelligent Cyber Threat Detection Framework Using a Hybrid Convolutional Neural Network-Long Short-Term Memory (CNN-LSTM) Machine Learning Mode

Jul 2026 · International Journal for Research in Applied Science and Engineering Technology · Vol 14, pp. 1562-1568 · 0 citations

TL;DR

An intelligent cyber threat detection framework based on a hybrid deep learning architecture that combines Long Short-Term Memory (LSTM) networks with Convolutional Neural Networks (CNN) in order to get around restrictions on conventional security solutions.

Abstract

The attack surface for contemporary cyber threats has greatly increased due to the growing reliance on networked digital systems and internet-driven services. Conventional security solutions that rely on static signatures and predetermined rules are no longer adequate as cyberattacks become more sophisticated and adaptable. Due to these conventional methods' inability to detect new and zero-day threats, network infrastructures are more vulnerable and detection is delayed. This paper offers an intelligent cyber threat detection framework based on a hybrid deep learning architecture that combines Long Short-Term Memory (LSTM) networks with Convolutional Neural Networks (CNN) in order to get around these restrictions. The suggested system does away with the requirement for human feature engineering by using the CNN module to automatically learn and extract significant spatial patterns from network traffic features. The detection of intricate and dynamic attack patterns is therefore made possible by using the LSTM module to represent the temporal linkages and sequential behaviors found in network traffic flows. Widely used intrusion detection datasets are used to verify the efficacy of the suggested model. Standard criteria, such as accuracy, precision, recall, F1-score, and false positive rate, are used to evaluate performance. According to experimental results, the hybrid CNN–LSTM architecture regularly outperforms both individual deep learning models and traditional machine learning techniques in terms of detection performance. The proposed approach demonstrates strong generalization capability and is well suited for real-time deployment in dynamic cybersecurity environments.

Read PDF

Similar papers

Open access Aug 2026

Deep Learning-Based Network Intrusion Detection Using Hybrid CNN and LSTM Architecture

The findings indicate that hybrid deep learning techniques can improve network security by enhancing intrusion detection capability while reducing false alarms.

A. O. Jimoh-Mahmud, Abubakar Dayyabu, Abubakar Sadiq Idris et al. · 0 citations
Open access Jul 2026

CyberNet-IDS: An AI-Driven Framework for Real-Time Cyber Attack Detection Using Deep Learning

Rising numbers of cyber threats require real-time, intelligent IDSs that are not only based on signatures or shallow ML models. Such systems often provide poor generalisation and high false alarms, especially in cases involving more complex temporal dependencies in network traffic. Although recent developments in deep learning offer new opportunities, many of these models struggle to capture the geographical and temporal characteristics of cyber threats, making them less applicable in real-time detection environments. In response to these concerns, this study presents CyberNet-IDS, an AI-based framework for detecting cyberattacks in real time, using a simulated deep-learning hybridisation approach. We integrate a 1-dimensional CNN to abstract spatial network data and BiLSTM networks to model temporal dependencies in network traffic in our framework. Stable preprocessing methods, such as normalisation, median imputation, and an XGBoost-based feature selection process, further enhance the model. CyberNet-IDS is deployed using Apache Kafka and TensorFlow Serving, supporting the streaming of real-time packet data and classification. Through extensive experimentation on the CIC-IDS2017 dataset, we demonstrate that CyberNet-IDS outperforms traditional and existing DL-based IDSs. A well-performing detection model with a reduced false alarm rate is obtained, achieving 97.30% classification accuracy, 96.80% precision, 96.20% recall, and 96.50% F1-score. Therefore, this proposed framework addresses the fundamental issues faced by current IDS solutions and provides a scalable, deployable architecture to secure modern networks against ever-evolving cyber threats instantly.

Ramu Moodu, R. B., S. K et al. · 0 citations
Open access Aug 2026

A Comparative Evaluation of Deep Learning Architectures for Binary Network Intrusion Detection Using the NSL-KDD Dataset

The rapid growth of digital communication technologies, cloud computing, and Internet of Things (IoT) devices has increased both the frequency and sophistication of cyber-attacks, making effective intrusion detection an essential component of modern cybersecurity systems. Traditional signature-based intrusion detection systems (IDS) are effective against known attacks but fail to detect previously unseen or evolving threats. This study investigates the application of deep learning models for binary network intrusion detection using the NSL-KDD benchmark dataset. Three standalone architectures, Convolutional Neural Networks (CNN), Long Short-Term Memory (LSTM) networks, and Deep Neural Networks (DNN), are implemented and evaluated, alongside a CNN-LSTM Hybrid model that integrates spatial and sequential learning, and a DNN-LSTM Ensemble model that combines independently trained DNN and LSTM predictions through weighted averaging. Following data cleaning, categorical encoding, normalization, and Random Forest-based feature selection (41 features reduced to 20), all models were trained and evaluated under identical conditions using Accuracy, Precision, Recall, F1-Score, ROC-AUC, training time, and inference time. The standalone DNN model achieved the best overall performance, with 80.98% accuracy, 97.08% precision, 68.66% recall, 80.43% F1-score, and 96.11% ROC-AUC, while also requiring the shortest training time (39.69 s). The CNNLSTM Hybrid model attained the highest precision (97.23%) but did not outperform the standalone architectures overall, and the DNN-LSTM Ensemble produced balanced but not superior results. These findings indicate that carefully designed standalone architectures can match or exceed the performance of more complex hybrid and ensemble models for binary intrusion detection, while incurring substantially lower computational cost. The study contributes a controlled, commonframework comparison of five deep learning architectures and provides practical guidance for selecting computationally efficient models for anomaly-based intrusion detection.

Ketki Naik, Sanjeev Ghosh · 0 citations
Open access Jul 2026

Hybrid Attention Convolutional Neural Network and Soft Sign Long Short-Term Memory Based Cyber-Attack Detection and Classification

The extensive use of smart devices and several security weaknesses of networks has intensively enhanced the number of cyber-attacks in Internet of Things (IoT) networks. The detection and classification of malicious traffic is a key to ensure the security of those systems. It aims to identify the behaviors and patterns that deviate significantly from the norm, indicating potential cyberattacks. This paper proposed a hybrid attention Convolutional Neural Network (CNN) and Soft sign Long Short-Term Memory (LSTM) for effective detection and classification. The min-max normalization is utilized in this experiment for data pre-processing and fed into Multi-Objective Sea Lion Optimization (MOSLO) based feature selection technique. Then, the selected features are given as input to the attention CNN and soft sign LSTM model. This model is estimated on NSL-KDD and ToN-IoT dataset and attains better results using accuracy, precision, recall, specificity, and F1-score. The obtained result shows that the proposed model achieves better accuracy of 99.45% on NSL-KDD dataset and 98.73% on ToN-IoT dataset which ensures accurate detection and classification compared to other existing methods like Feed Forward Neural Network (FFNN) and Improved Binary Golden Jackal Optimization-LSTM.

C. Venkata, Siva Rama Prasad, S. Krishna · 0 citations
Open access Aug 2026

AI-Driven Security: Detecting Cyber Attacks in IoT Networks

LSTM had good detection for frequent attacks and slow-changing patterns, which shows its capacity in learning long-lasting dependencies, which shows its capacity in learning long-lasting dependencies.

Jawad Hussain Awan, Misbah Safdar, Muhammad Ayaz Shirazi et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.