Toward Generalization and Interpretable Deep Learning-Based Intrusion Detection System for Heterogeneous Network Environments

2Citations
Citations of this article
7Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

The growing complexity and heterogeneity of modern network environments have intensified the demand for intrusion detection systems (IDSs) that are not only accurate but also generalizable and interpretable. Although deep learning (DL) models have shown remarkable performance in detecting cyberattacks, their limited cross-dataset generalization and opaque decision-making remain significant barriers to practical deployment. This study proposes a generalizable deep-learning-based IDS framework that operates effectively across a heterogeneous network environment. The framework is evaluated on three benchmark datasets: CSE-CIC-IDS2018, CICDDoS2019 and TII-SSRC-23 to ensure robustness and diversity in assessment. The methodology involves comprehensive data preprocessing and feature engineering, followed by SMOTE-based oversampling of minority classes in the training set to address class imbalance. Highly correlated features are removed to enhance model efficiency, and a lightweight convolutional neural network (CNN) is trained to extract spatial-temporal attack patterns. Shapley additive explanations (SHAP) are applied for feature importance analysis and selection, and the model is retrained using the most informative features. Performance evaluation employs standard metrics, including F1-score, recall, precision, and ROC-AUC, supplemented by statistical analyses such as 95% bootstrap confidence intervals, chi-square tests, Cohen's kappa, Mathew's correlation coefficient (MCC), and permutation tests to ensure reliability and robustness. The results demonstrate improved cross-dataset generalization, interpretability and statistical significance, highlighting the framework's potential for scalable, transparent, and trustworthy IDS deployment in real-world networks.

Cite

CITATION STYLE

APA

Onuorah, M. O., Sun, Y., & Mashao, D. (2026). Toward Generalization and Interpretable Deep Learning-Based Intrusion Detection System for Heterogeneous Network Environments. IEEE Access, 14, 46085–46101. https://doi.org/10.1109/ACCESS.2026.3675887

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free