Deep Learning-Based Intrusion Detection: A CNN-LSTM-Transformer Approach for Enhanced Network Security

N/ACitations
Citations of this article
40Readers
Mendeley users who have this article in their library.
Get full text

Abstract

This research proposes a hybrid deep learning model for network intrusion detection, combining Convolutional Neural Networks (CNNs), Long Short-Term Memory (LSTM) networks, and Transformers to address the limitations of single-model architecture in capturing the multi-dimensional characteristics of network traffic. The CNN module extracts spatial features by identifying local patterns in traffic feature matrices, such as correlations between protocol types, port numbers, and packet lengths; the LSTM network leverages its gating mechanism to capture short-term temporal dependencies, effectively recognizing time-series patterns in sequential traffic data like the periodicity of DDoS attack flows; the Transformer, through its multi-head self-attention mechanism, models long-range sequence dependencies, enabling the detection of complex attack patterns with scattered or delayed behavioral clues across extended time windows. The model is trained and evaluated using the CICIDS2017 dataset, which includes diverse attack types (e.g., DoS, DDoS, web attacks, botnet activities) and normal traffic, ensuring comprehensive validation. Experimental results show that the proposed model outperforms traditional machine learning models (e.g., SVM, Random Forest) and single deep learning models (e.g., standalone CNN or LSTM) in key metrics such as accuracy, precision, and recall, with particularly strong performance in detecting sophisticated attacks like zero-day threats and multi-stage intrusions. These findings not only validate the effectiveness of integrating spatial, temporal, and long-range dependency modeling for intrusion detection but also highlight the potential of deep learning techniques in enhancing the robustness of network security systems, providing valuable insights for optimizing hybrid model architectures and expanding detection capabilities in dynamic network environments.

Cite

CITATION STYLE

APA

Liu, D., Zheng, X., Wang, P., Chuan, J., Lv, Y., Zhou, B., … Jiao, W. (2025). Deep Learning-Based Intrusion Detection: A CNN-LSTM-Transformer Approach for Enhanced Network Security. In Proceedings of 10th International Conference on Cyber Security and Information Engineering, ICCSIE 2025 (pp. 318–325). Association for Computing Machinery, Inc. https://doi.org/10.1145/3759179.3760451

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free