Network Intrusion Detection Technology Integrating Density Peak Clustering Algorithm and Improved Bi‐Directional LSTM
Deyou Chen · Security and Privacy · 2025
ABSTRACT With the increasing types and complexity of network attacks, and the rapid popularization of Internet devices, network security issues have become increasingly serious. Traditional network intrusion detection models are difficult to fully capture data features in large‐scale network environments, resulting in high false positive and false negative rates. Therefore, a network intrusion detection model that integrates the density peak clustering algorithm and improved BiLSTM is designed. The model takes a convolutional neural network to extract spatial features and combines BiLSTM to extract time series features. Then, the density peak clustering algorithm is applied to filter abnormal samples, which enhances feature representation. Finally, XGBoost is used to complete classification decisions. The proposed model had a detection rate of 95.8%, a false positive rate of 4.2%, a computational efficiency of 720 samples/s, and an AUC value of 0.96, which was significantly better than other comparison models. The research results indicate that the fused density peak clustering algorithm significantly enhances the model's ability to identify unknown attacks, with efficient feature extraction and anomaly detection capabilities, providing an effective solution for improving network security detection effectiveness and important technical support for building intelligent and efficient network security systems.