GateIDS: A Single Network Architecture for Attack Detection and Multi-Class Classification
Sungkwan Youm, Kwang-Seong Shin · IEEE Access · 2025
Network security faces escalating challenges from sophisticated cyber threats, necessitating advanced Intrusion Detection Systems (IDS) capable of both detecting attacks and classifying their patterns. This paper introduces GateIDS, a pioneering single-network architecture that integrates binary attack detection and multi-class attack pattern classification within a unified framework. Leveraging Deep Neural Networks (DNN), Long Short-Term Memory (LSTM), and Transformer backbones, GateIDS employs a bifurcated design trained end-to-end to address these dual tasks efficiently. To mitigate class imbalance in the UNSW-NB15 dataset, a class-specific oversampling strategy is applied, enhancing the detection of minority attack types. Experimental results demonstrate that theDNNvariant achieves superior performance, with a binary classification accuracy of 98.30% and a pattern classification accuracy of 86.68%, alongside an inference time of 0.1752 seconds, outperforming LSTM (89.17%, 46.71%) and Transformer (90.63%, 45.79%) variants. This work marks the first unified dual-task IDS, offering computational efficiency and scalability over traditional separate-model approaches. GateIDS establishes a robust baseline for future IDS research, with potential enhancements through clustering and real-world deployment.