{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T16:03:14Z","timestamp":1783612994368,"version":"3.55.0"},"reference-count":60,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T00:00:00Z","timestamp":1738022400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Algorithms"],"abstract":"<jats:p>As security threats become more complex, the need for effective intrusion detection systems (IDSs) has grown. Traditional machine learning methods are limited by the need for extensive feature engineering and data preprocessing. To overcome this, we propose two enhanced hybrid deep learning models, an autoencoder\u2013convolutional neural network (Autoencoder\u2013CNN) and a transformer\u2013deep neural network (Transformer\u2013DNN). The Autoencoder reshapes network traffic data, addressing class imbalance, and the CNN performs precise classification. The transformer component extracts contextual features, which the DNN uses for accurate classification. Our approach utilizes an enhanced hybrid adaptive synthetic sampling\u2013synthetic minority oversampling technique (ADASYN-SMOTE) for binary classification and enhanced SMOTE for multi-class classification, along with edited nearest neighbors (ENN) for further class imbalance handling. The models were designed to minimize false positives and negatives, improve real-time detection, and identify zero-day attacks. Evaluations based on the CICIDS2017 dataset showed 99.90% accuracy for Autoencoder\u2013CNN and 99.92% for Transformer\u2013DNN in binary classification, and 99.95% and 99.96% in multi-class classification, respectively. On the NF-BoT-IoT-v2 dataset, the Autoencoder\u2013CNN achieved 99.98% in binary classification and 97.95% in multi-class classification, while the Transformer\u2013DNN reached 99.98% and 97.90%, respectively. These results demonstrate the superior performance of the proposed models compared with traditional methods for handling diverse network attacks.<\/jats:p>","DOI":"10.3390\/a18020069","type":"journal-article","created":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T07:54:08Z","timestamp":1738050848000},"page":"69","update-policy":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":35,"title":["Enhanced Hybrid Deep Learning Models-Based Anomaly Detection Method for Two-Stage Binary and Multi-Class Classification of Attacks in Intrusion Detection Systems"],"prefix":"10.3390","volume":"18","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0009-1042-7503","authenticated-orcid":false,"given":"Hesham","family":"Kamal","sequence":"first","affiliation":[{"name":"Networks Department, Faculty of Information Engineering and Technology (IET), German University in Cairo (GUC), New Cairo 11835, Egypt"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-8313-5554","authenticated-orcid":false,"given":"Maggie","family":"Mashaly","sequence":"additional","affiliation":[{"name":"Networks Department, Faculty of Information Engineering and Technology (IET), German University in Cairo (GUC), New Cairo 11835, Egypt"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,1,28]]},"reference":[{"key":"ref_1","unstructured":"TechTarget (2025, January 21). 6 Common Types of Cyber Attacks and How to Prevent Them. Available online: https:\/\/2.zoppoz.workers.dev:443\/https\/www.techtarget.com\/searchsecurity\/tip\/6-common-types-of-cyber-attacks-and-how-to-prevent-them."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Tariq, U., Ahmed, I., Bashir, A.K., and Shaukat, K. (2023). A critical cybersecurity analysis and future research directions for the internet of things: A comprehensive review. Sensors, 23.","DOI":"10.3390\/s23084117"},{"key":"ref_3","unstructured":"BlackBerry (2025, January 21). Quarterly Global Threat Report\u2014September 2024. Available online: https:\/\/2.zoppoz.workers.dev:443\/https\/www.blackberry.com\/us\/en\/solutions\/threat-intelligence\/threat-report."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Conti, M., Dargahi, T., and Dehghantanha, A. (2018). Cyber Threat Intelligence: Challenges and Opportunities, Springer International Publishing.","DOI":"10.1007\/978-3-319-73951-9_1"},{"key":"ref_5","unstructured":"Osama, F., and Dogdu, E. (2019). Intrusion detection using big data and deep learning techniques. Proceedings of the 2019 ACM Southeast Conference, AMC."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Kaur, G., Lashkari, A.H., and Rahali, A. (2020, January 17\u201322). Intrusion traffic detection and characterization using deep image learning. Proceedings of the 2020 IEEE Intl Conf on Dependable, Autonomic and Secure Computing, Intl Conf on Pervasive Intelligence and Computing, Intl Conf on Cloud and Big Data Computing, Intl Conf on Cyber Science and Technology Congress (DASC\/PiCom\/CBDCom\/CyberSciTech), Calgary, AB, Canada.","DOI":"10.1109\/DASC-PICom-CBDCom-CyberSciTech49142.2020.00025"},{"key":"ref_7","unstructured":"(2022, July 18). Internet Security Threat Report. Available online: https:\/\/2.zoppoz.workers.dev:443\/https\/docs.broadcom.com\/doc\/istr-23-2018-en."},{"key":"ref_8","unstructured":"Cybersecurity Ventures (2025, January 21). Cybercrime to Cost the World $9 Trillion Annually in 2024. Available online: https:\/\/2.zoppoz.workers.dev:443\/https\/cybersecurityventures.com\/cybercrime-to-cost-the-world-9-trillion-annually-in-2024\/."},{"key":"ref_9","first-page":"45","article-title":"Real-Time Intrusion Detection Using Deep Learning Techniques","volume":"140","author":"Zhang","year":"2020","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_10","first-page":"101944","article-title":"A Review of Real-Time Intrusion Detection Systems Using Machine Learning Approaches","volume":"95","author":"Kumar","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_11","first-page":"123","article-title":"Enhancing Network Security with Real-Time Intrusion Detection Systems","volume":"21","author":"Smith","year":"2021","journal-title":"Int. J. Inf. Secur."},{"key":"ref_12","unstructured":"UNB (2025, January 21). Intrusion Detection Evaluation Dataset (CICIDS2017), University of New Brunswick. Available online: https:\/\/2.zoppoz.workers.dev:443\/https\/www.unb.ca\/cic\/datasets\/ids-2017.html."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"357","DOI":"10.1007\/s11036-021-01843-0","article-title":"Towards a standard feature set for network intrusion detection system datasets","volume":"27","author":"Sarhan","year":"2022","journal-title":"Mob. Netw. Appl."},{"key":"ref_14","unstructured":"Anderson, J.P. (1980). Computer Security Threat Monitoring and Surveillance, Technical Report; James P. Anderson Company."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"41525","DOI":"10.1109\/ACCESS.2019.2895334","article-title":"Deep learning approach for intelligent intrusion detection system","volume":"7","author":"Vinayakumar","year":"2019","journal-title":"IEEE Access"},{"key":"ref_16","first-page":"5514","article-title":"An intrusion detection system for packet and flow based networks using deep neural network approach","volume":"10","author":"Farhana","year":"2020","journal-title":"Int. J. Electr. Comput. Eng."},{"key":"ref_17","unstructured":"Razan, A., Faezipour, M., Musafer, H., and Abuzneid, A. (2019, January 18\u201320). Efficient network intrusion detection using PCA-based dimensionality reduction of features. Proceedings of the 2019 International Symposium on Networks, Computers and Communications (ISNCC), Istanbul, Turkey."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"709","DOI":"10.5267\/j.ijdns.2024.1.007","article-title":"An innovative network intrusion detection system (NIDS): Hierarchical deep learning model based on Unsw-Nb15 dataset","volume":"8","author":"Alsharaiah","year":"2024","journal-title":"Int. J. Data Netw. Sci."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Jouhari, M., Benaddi, H., and Ibrahimi, K. (2024). Efficient Intrusion Detection: Combining \u03c72 Feature Selection with CNN-BiLSTM on the UNSW-NB15 Dataset. arXiv.","DOI":"10.1109\/WINCOM62286.2024.10658099"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"14459","DOI":"10.1007\/s00521-021-06085-5","article-title":"Hybrid semantic deep learning architecture and optimal advanced encryption standard key management scheme for secure cloud storage and intrusion detection","volume":"33","author":"Prabhakaran","year":"2021","journal-title":"Neural Comput. Appl."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Kao, M.-T., Sung, D.-Y., Kao, S.-J., and Chang, F.-M. (2022). A novel two-stage deep learning structure for network flow anomaly detection. Electronics, 11.","DOI":"10.3390\/electronics11101531"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Fu, Y., Du, Y., Cao, Z., Li, Q., and Xiang, W. (2022). A deep learning model for network intrusion detection with imbalanced data. Electronics, 11.","DOI":"10.3390\/electronics11060898"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Kamal, H., and Mashaly, M. (2024). Advanced Hybrid Transformer-CNN Deep Learning Model for Effective Intrusion Detection Systems with Class Imbalance Mitigation Using Resampling Techniques. Future Internet, 16.","DOI":"10.3390\/fi16120481"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Alzughaibi, S., and El Khediri, S. (2023). A cloud intrusion detection systems based on dnn using backpropagation and pso on the cse-cic-ids2018 dataset. Appl. Sci., 13.","DOI":"10.3390\/app13042276"},{"key":"ref_25","first-page":"565","article-title":"FastTrafficAnalyzer: An efficient method for intrusion detection systems to analyze network traffic","volume":"12","author":"Arslan","year":"2021","journal-title":"Dicle \u00dcniversitesi M\u00fchendislik Fak\u00fcltesi M\u00fchendislik Derg."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Yaras, S., and Dener, M. (2024). IoT-Based Intrusion Detection System Using New Hybrid Deep Learning Algorithm. Electronics, 13.","DOI":"10.3390\/electronics13061053"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"ElKashlan, M., Elsayed, M.S., Jurcut, A.D., and Azer, M. (2023). A machine learning-based intrusion detec-tion system for iot electric vehicle charging stations (evcss). Electronics, 12.","DOI":"10.3390\/electronics12041044"},{"key":"ref_28","first-page":"126","article-title":"An intelligent intrusion detection system for internet of things attack detection and identification using machine learning","volume":"11","author":"Othman","year":"2023","journal-title":"ARO-THE Sci. J. KOYA Univ."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Wang, Y., Li, J., Zhao, W., Han, Z., Zhao, H., Wang, L., and He, X. (2023). N-STGAT: Spatio-Temporal Graph Neural Network Based Network Intrusion Detection for Near-Earth Remote Sensing. Remote Sens., 15.","DOI":"10.20944\/preprints202305.1455.v1"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"110495","DOI":"10.1016\/j.comnet.2024.110495","article-title":"Applying self-supervised learning to network intrusion detection for network flows with graph neural network","volume":"248","author":"Xu","year":"2024","journal-title":"Comput. Netw."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"227","DOI":"10.1007\/s12083-023-01595-6","article-title":"Pre-trained language model-enhanced conditional generative adversarial networks for intrusion detection","volume":"17","author":"Li","year":"2024","journal-title":"Peer-to-Peer Netw. Appl."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"100924","DOI":"10.1016\/j.measen.2023.100924","article-title":"A model for multi-attack classification to improve intrusion detection performance using deep learning approaches","volume":"30","author":"Silivery","year":"2023","journal-title":"Meas. Sens."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"367","DOI":"10.1089\/big.2021.0268","article-title":"A network intrusion detection system using hybrid multilayer deep learning model","volume":"12","author":"Umair","year":"2022","journal-title":"Big Data"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"465","DOI":"10.17798\/bitlisfen.1240469","article-title":"Analysis of intrusion detection systems in UNSW-NB15 and NSL-KDD datasets with machine learning algorithms","volume":"12","year":"2023","journal-title":"Bitlis Eren \u00dcniversitesi Fen Bilim. Derg."},{"key":"ref_35","first-page":"1165","article-title":"Performance analysis of intrusion detection for deep learning model based on CSE-CIC-IDS2018 dataset","volume":"26","author":"Farhan","year":"2022","journal-title":"Indones. J. Electr. Eng. Comput. Sci."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/s10922-022-09691-3","article-title":"Cyber threat intelligence sharing scheme based on federated learning for network intrusion detection","volume":"31","author":"Sarhan","year":"2023","journal-title":"J. Netw. Syst. Manag."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"147","DOI":"10.1016\/j.cose.2019.06.005","article-title":"A survey of network-based intrusion detection data sets","volume":"86","author":"Ring","year":"2019","journal-title":"Comput. Secur."},{"key":"ref_38","first-page":"108","article-title":"Toward generating a new intrusion detection dataset and intrusion traffic characterization","volume":"1","author":"Sharafaldin","year":"2018","journal-title":"ICISSp 1"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Breunig, M.M., Kriegel, H.-P., Ng, R.T., and Sander, J. (2000, January 15\u201318). LOF: Identifying Density-Based Local Outliers. Proceedings of the 2000 ACM SIGMOD International Conference on Management of Data, Dallas, TX, USA.","DOI":"10.1145\/342009.335388"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"20","DOI":"10.17148\/IARJSET.2015.2305","article-title":"Normalization: A preprocessing stage","volume":"2","author":"Patro","year":"2015","journal-title":"Int. Adv. Res. J. Sci. Eng. Technol."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"6","DOI":"10.1186\/s40537-020-00390-x","article-title":"Resampling imbalanced data for network intrusion detection datasets","volume":"8","author":"Bagui","year":"2021","journal-title":"J Big Data."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"919","DOI":"10.1111\/coin.12220","article-title":"Empirical study on multiclass classifcation-based network intrusion detection","volume":"35","author":"Elmasry","year":"2019","journal-title":"Comput Intell"},{"key":"ref_43","first-page":"467","article-title":"Handling class imbalance problem in intrusion detection system based on deep learning","volume":"12","author":"Mbow","year":"2022","journal-title":"Int. J. Netw. Comput."},{"key":"ref_44","unstructured":"He, H., Bai, Y., Garcia, E.A., and Li, S. (2008, January 1\u20138). ADASYN: Adaptive synthetic sampling approach for imbalanced learning. Proceedings of the 2008 IEEE international Joint Conference on Neural Networks (IEEE World Congress on Computational Intelligence), Hong Kong, China."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1613\/jair.953","article-title":"SMOTE: Synthetic Minority Over-sampling Technique","volume":"16","author":"Chawla","year":"2002","journal-title":"J. Artif. Intell. Res."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"408","DOI":"10.1109\/TSMC.1972.4309137","article-title":"Asymptotic properties of nearest neighbor rules using edited data","volume":"3","author":"Wilson","year":"1972","journal-title":"IEEE Trans. Syst. Man Cybern."},{"key":"ref_47","first-page":"4824","article-title":"Global climate prediction using deep learning","volume":"100","year":"2022","journal-title":"J. Theor. Appl. Inf. Technol."},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"101976","DOI":"10.1016\/j.phycom.2022.101976","article-title":"Deep learning-driven MIMO: Data encoding and processing mechanism","volume":"57","author":"Song","year":"2022","journal-title":"Phys Commun."},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Zhou, X., Zhao, C., Sun, J., Yao, K., and Xu, M. (2022). Detection of lead content in oilseed rape leaves and roots based on deep transfer learning and hyperspectral imaging technology. Spectroch Acta Part A Mol. Biomole Spectrosc., 290.","DOI":"10.1016\/j.saa.2022.122288"},{"key":"ref_50","unstructured":"Goodfellow, I., Bengio, Y., and Courville, A. (2016). Deep Learning, MIT Press."},{"key":"ref_51","unstructured":"Nair, V., and Hinton, G.E. (2010, January 21\u201324). Rectified linear units improve restricted boltzmann machines. Proceedings of the 27th International Conference on Machine Learning (ICML-10), Haifa, Israel."},{"key":"ref_52","first-page":"1929","article-title":"Dropout: A simple way to prevent neural networks from overfitting","volume":"15","author":"Srivastava","year":"2014","journal-title":"J. Mach. Learn. Res."},{"key":"ref_53","unstructured":"Bishop, C.M., and Nasser, M.N. (2006). Pattern Recognition and Machine Learning, Springer."},{"key":"ref_54","unstructured":"Nielsen, A. (2025, January 16). Neural Networks and Deep Learning. Available online: https:\/\/2.zoppoz.workers.dev:443\/https\/books.google.com.hk\/books\/about\/Neural_Networks_and_Deep_Learning.html?id=STDBswEACAAJ&redir_esc=y."},{"key":"ref_55","unstructured":"Glorot, X., Bordes, A., and Bengio, Y. (2011, January 11\u201313). Deep sparse rectifier neural networks. Proceedings of the Fourteenth International Conference on Artificial Intelligence and Statistics, Fort Lauderdale, FL, USA."},{"key":"ref_56","unstructured":"Vaswani, A., Noam, S., Niki, P., Jakob, U., Llion, J., and Aidan, N. (2017). Gomez, Lukasz Kaiser, and Illia Polosukhin. Attention Is All You Need.(Nips). arXiv."},{"key":"ref_57","unstructured":"Ba, J.L. (2016). Layer normalization. arXiv."},{"key":"ref_58","unstructured":"Jyothsna, V., and Prasad, K.M. (2025, January 16). Anomaly-Based Intrusion Detection System. Computer and Network Security 10. Available online: https:\/\/2.zoppoz.workers.dev:443\/https\/www.intechopen.com\/chapters\/67618."},{"key":"ref_59","doi-asserted-by":"crossref","unstructured":"Chen, C., Song, Y., Yue, S., Xu, X., Zhou, L., Lv, Q., and Yang, L. (2022). FCNN-SE: An Intrusion Detection Model Based on a Fusion CNN and Stacked Ensemble. Appl. Sci., 12.","DOI":"10.3390\/app12178601"},{"key":"ref_60","first-page":"37","article-title":"Evaluation: From Precision, Recall, and F-Measure to ROC, Informedness, Markedness & Correlation","volume":"2","author":"Powers","year":"2011","journal-title":"J. Mach. Learn. Technol."}],"container-title":["Algorithms"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/www.mdpi.com\/1999-4893\/18\/2\/69\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,8]],"date-time":"2025-10-08T10:37:44Z","timestamp":1759919864000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/www.mdpi.com\/1999-4893\/18\/2\/69"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,28]]},"references-count":60,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2025,2]]}},"alternative-id":["a18020069"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.3390\/a18020069","relation":{},"ISSN":["1999-4893"],"issn-type":[{"value":"1999-4893","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,28]]}}}