Stacked LSTM with Multi Head Attention Based Model for Intrusion Detection

S Phani Praveen, Padmavathi Panguluri, Uddagiri Sirisha, Deshinta Arrova Dewi, Tri Basuki Kurniawan, Lusiana Efrizoni

Abstract


The rapid advancement of digital technologies, including the Internet of Things (IoT), cloud computing, and mobile communications, has intensified reliance on interconnected networks, thereby increasing exposure to diverse cyber threats. Intrusion Detection Systems (IDS) are essential for identifying and mitigating these threats; however, traditional signature-based and rule-based methods fail to detect unknown or complex attacks and often generate high false positive rates. Recent studies have explored machine learning (ML) and deep learning (DL) approaches for IDS development, yet many suffer from poor generalization, limited scalability, and an inability to capture both spatial and temporal dependencies in network traffic. To overcome these challenges, this study proposes a hybrid deep learning framework integrating Convolutional Neural Networks (CNN), Stacked Long Short-Term Memory (LSTM) networks, and a Multi-Head Self-Attention (MHSA) mechanism. CNN layers extract spatial features, stacked LSTM layers capture long-term temporal dependencies, and MHSA enhances focus on the most relevant time steps, improving accuracy and reducing false alarms. The proposed model was trained and evaluated on the UNSW-NB15 dataset, which represents modern attack vectors and realistic network behavior. Experimental results show that the model achieves state-of-the-art performance, attaining 99.99% accuracy and outperforming existing ML and DL-based intrusion detection systems in both precision and generalization capability.

Keywords


Stacked LSTM; Social Protection; Intrusion Detection; Multi Head Attention; UNSW-NB15 Dataset; Adam Optimizer; Process Innovation

Full Text:

PDF

References


Takkar, A. & Lohiya, R. A survey on intrusion detection system: Feature selection, model, performance measures, application perspective, challenges, and future research directions. Artif. Intell. Rev. 55(1), 453–563 (2022).

Khare, N. et al. Smo-dnn: Spider monkey optimization and deep neural network hybrid classifer model for intrusion detection. Electronics 9(4), 692 (2020).

Vijayalakshmi, P. & Karthika, D. "Hybrid dual-channel convolution neural network (DCCNN) with spider monkey optimization (SMO) for cyber security threats detection in internet of things. Meas. Sens. 27, 100783 (2023).

Shenfeld, A., Day, D. & Ayesh, A. Intelligent intrusion detection systems using artifcial neural networks. Ict Express 4(2), 95–99 (2018).

Agrawal, A., Garg, D., Sethi, R. & Shrivastava, A. K. Optimum redundancy allocation using spider monkey optimization. Sof Comput. 27(21), 15595–15608 (2023).

Agrawal, V., Ratika, R. & Tiwari, D. C. Spider monkey optimization: A survey. Int. J. Syst. Assurance Eng. Manag. 9(4), 929–941. https://doi.org/10.1007/s13198-017-0685-6 (2018).

Pothumani, P. & Reddy, E. S. Original research article network intrusion detection using ensemble weighted voting classifer based honeypot framework. J. Autonomous Intell. https://doi.org/10.32629/jai.v7i3.1081 (2024).

Ramu, C. K., Rao, T. S. & Rao, E. U. S. Attack classifcation in network intrusion detection system based on optimization strategy and deep learning methodology. Multimed. Tools Appl. https://doi.org/10.1007/s11042-024-18558-5 (2024).

Jayalatchumy, D., Ramalingam, R., Balakrishnan, A., Safran, M. & Alfarhood, S. Improved crow search-based feature selection and ensemble learning for IoT intrusion detection. IEEE Access 12, 33218–33235. https://doi.org/10.1109/ACCESS.2024.33728 59 (2024).

Vinayakumar, R. et al. Deep learning approach for intelligent intrusion detection system. Ieee Access 7, 41525–41550 (2019).

Alwahedi, F., Aldhaheri, A., Ferrag, M. A., Battah, A. & Tihanyi, N. Machine learning techniques for IoT security: Current research and future vision with generative AI and large language models. Internet of Tings Cyber-Phys. Syst. 4, 167–185. https://doi.org/ 10.1016/j.iotcps.2023.12.003 (2024).

Keskin, S. & Okatan, E. Machine learning methods for intrusion detection in computer networks: A comparative analysis. Int. J. Eng. Innovat. Res. 5(3), 268–279 (2023).

Ikram, S. T. & Cherukuri, A. K. Improving accuracy of intrusion detection model using PCA and optimized SVM. J. Comput. Inform. Technol. 24(2), 133–148. https://doi.org/10.20532/cit.2016.1002701 (2016).

Bebortta, S., Das, S. K., & Chakravarty, S. “Fog-enabled intelligent network intrusion detection framework for internet of things applications,” Jan. https://doi.org/10.1109/confluence56041.2023.10048841 (2023)

Tang, T. A., Mhamdi, L., McLernon, D., Zaidi, S. A., & Ghogho, M. “Deep Learning Approach for network intrusion detection in software defined networking,” in 2016 International Conference on Wireless Networks and Mobile Communications (WINCOM), pp. 258–263, Oct. https://doi.org/10.1109/wincom.2016.7777224 (2016).

Kim, J., Kim, J., Thi Thu, H. L., & Kim, H. Long short term memory recurrent neural network classifier for intrusion detection 2016 International Conference on Platform Technology and Service (PlatCon), pp. 258–263, Feb. https://doi.org/10.1109/platcon.2016.74 56805 (2016).

Ma, T., Wang, F., Cheng, J., Yu, Y. & Chen, X. A hybrid spectral clustering and deep neural network ensemble algorithm for intrusion detection in Sensor Networks. Sensors 16(10), 1701. https://doi.org/10.3390/s16101701 (2016).

Le, T.-T.-H., Kim, J. & Kim, H. “An effective intrusion detection classifier using long short-term memory with gradient descent optimization,” in 2017 International Conference on Platform Technology and Service (PlatCon), pp. 1–6, Feb. https://doi.org/10.110 9/platcon.2017.7883684 (2017).

Yin, C., Zhu, Y., Fei, J. & He, X. A deep learning approach for intrusion detection using recurrent neural networks. IEEE Access 5, 21954–21961. https://doi.org/10.1109/access.2017.2762418 (2017).

Fu, Y., et al. An intelligent network attack detection method based on RNN, 2018 IEEE Third International Conference on Data Science in Cyberspace (DSC), pp. 483–489, Jun. 2018. https://doi.org/10.1109/dsc.2018.00078

He, H. et al. A novel multimodal-sequential approach based on Multi-view features for network intrusion detection. IEEE Access 7, 183207–183221. https://doi.org/10.1109/access.2019.2959131 (2019).

Wu, P. & Guo, H. LuNet: A deep neural network for network intrusion detection,” 2019 IEEE Symposium Series on Computational Intelligence (SSCI), pp. 617–624, https://doi.org/10.1109/ssci44817.2019.9003126 2019.

Hassan, M. M., Gumaei, A., Alsanad, A., Alrubaian, M. & Fortino, G. A hybrid deep learning model for efficient intrusion detection in big data environment. Inform. Sci. 513, 386–396. https://doi.org/10.1016/j.ins.2019.10.069 (2020).

Adeel, A. et al. A new ensemble-based intrusion detection system for internet of things. Arab. J. Sci. Eng. https://doi.org/10.1007/S 13369-021-06086-5 (2021).

Ravi, V., Chaganti, R. & Alazab, M. Recurrent deep learning-based feature fusion ensemble meta-classifier approach for intelligent network intrusion detection system. Comput. Electr. Eng. 102, 108156. https://doi.org/10.1016/j.compeleceng.2022.108156 (2022).

Zivkovic, M. et al. Novel hybrid firefly algorithm: An application to enhance XGBoost tuning for intrusion detection classification. PeerJ Comput. Sci. 8, e956. https://doi.org/10.7717/peerj-cs.956 (2022).

Majhi, B. Optimizing LightGBM for intrusion detection systems using GOA," in 2023 14th International Conference on Computing Communication and Networking Technologies (ICCCNT), Jul. 2023, pp. 1–5 https://doi.org/10.1109/ICCCNT56998.2023.10308360

Liu, Y. & Wu, L. Intrusion detection model based on improved transformer. Appl. Sci. 13(10), 6251. https://doi.org/10.3390/app13 106251 (2023).

Khare, P. D. N. Ensemble-based feature selection with long short-term memory for classification of network intrusion,” Advances in Social Networking and Online Communities, pp. 228–245, https://doi.org/10.4018/978-1-7998-7764-6.ch008(2021).

Donkol, A. A., Hafez, A. G., Hussein, A. I. & Mabrook, M. M. Optimization of intrusion detection using likely point PSO and enhanced LSTM-RNN hybrid technique in communication networks. IEEE Access 11, 9469–9482. https://doi.org/10.1109/access. 2023.3240109 (2023).

Kumari, T. A. & Mishra, S. Tachyon: Enhancing stacked models using Bayesian optimization for intrusion detection using different sampling approaches. Egypt. Inform. J. 27, 100520. https://doi.org/10.1016/j.eij.2024.100520 (2024).

Y. Yin, J. Jang-Jaccard, W. Xu, A. Singh, J. Zhu, F. Sabrina, J. Kwak, IGRF-RFE: A hybrid feature selection method for MLP-based network intrusion detection on UNSW-NB15 dataset, 2022, arXiv preprint arXiv:2203.16365.

S.U. Jafri, S. Rao, V. Shrivastav, M. Tawarmalani, Leo: Online {ML-based} traffic classification at {Multi-Terabit} line rate, in: 21st USENIX Symposium on Networked Systems Design and Implementation (NSDI 24), 2024, pp. 1573–1591.

M. Ali, M. Shahroz, M.F. Mushtaq, S. Alfarhood, M. Safran, I. Ashraf, Hybrid machine learning model for efficient botnet attack detection in IoT environment, IEEE Access (2024).

Nagarajan, R., Batumalay, M., & Xu, Z. (2024). IoT based Intrusion Detection for Edge Devices using Augmented System. Journal of Applied Data Sciences, 5(3), 1412-1423

Zegarra Rodriguez, D., Daniel Okey, O., Maidin, S. S., Umoren Udo, E., & Kleinschmidt, J. H. (2023). Attentive transformer deep learning algorithm for intrusion detection on IoT systems using automatic Xplainable feature selection. Plos one, 18(10), e0286652.

Sirisha, U., Kumar, C. K., Narahari, S. C., & Srinivasu, P. N. (2025). An Iterative PRISMA Review of GAN Models for Image Processing, Medical Diagnosis, and Network Security. Computers, Materials & Continua, 82(2).

Praveen, S. P., Chokka, A., Sarala, P., Nakka, R., Chandolu, S. B., & Jyothi, V. E. (2024). Investigating the Efficacy of Deep Reinforcement Learning Models in Detecting and Mitigating Cyber-attacks: a Novel Approach. Journal of Cybersecurity & Information Management, 14(1).

BIYYAPU, N. S., CHANDOLU, S. B., GORINTLA, S., TIRUMALASETTI, N. R., CHOKKA, A., & PRAVEEN, S. P. (2024). ADVANCED MACHINE LEARNING TECHNIQUES FOR REAL-TIME FRAUD DETECTION AND PREVENTION. Journal of Theoretical and Applied Information Technology, 102(20).

Praveen, S. P., Lalitha, S., Sarala, P., Satyanarayana, K., & Karras, D. A. (2025). Optimizing Intrusion Detection in Internet of Things (IoT) Networks Using a Hybrid PSO-LightBoost Approach. International Journal of Intelligent Engineering & Systems, 18(3).

D. Pambudi, F. Fadly, M. H. Kurniawan, and H. Haryanto, “The Eye’s Signature: Innovative Approaches to Iris Detection,” International Journal of Advances in Artificial Intelligence and Machine Learning, vol. 2, no. 1, pp. 38–43, Mar. 2025, doi: 10.58723/IJAAIML.V2I1.379.




DOI: https://doi.org/10.47738/jads.v7i1.764

Refbacks

  • There are currently no refbacks.



Barcode

Journal of Applied Data Sciences

ISSN:2723-6471 (Online)
Publisher:Bright Publisher
Website:http://bright-journal.org/JADS
Email:taqwa@amikompurwokerto.ac.id (principal contact)
  support@bright-journal.org (technical issues)

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0