AI-Driven Network Forensics Using Hybrid Anomaly Detection with Enhanced Transformer Based ISO-Encoder and LSTM-CNN Fusion
B. Abisha, Sheeja Kumari V, Wilfred Blessing N. R, Sutherlin Subitha G., C. Seldev Christopher, Wasim Haidar SK · 2025
Traditional network forensic techniques frequently find it difficult to identify and look into sophisticated cybercrimes in today's quickly changing cyber scene. A Transformer-based Iso-Encoder and a Long Short-Term Memory (LSTM) and Convolutional Neural Network (CNN) fusion model are combined in this research to present an AI-driven method that makes use of a novel hybrid anomaly detection model. The LSTM-CNN fusion model performs exceptionally well in temporal and spatial feature extraction, while the Iso-Encoder is improved to capture complex patterns in network traffic. This hybrid approach is intended to accurately detect known and undiscovered anomalies. By offering practical insights into the nature of the dangers, the suggested framework not only helps with the comprehensive investigation of cyber incidents but also identifies anomalies in real-time. The model is a powerful tool for cybersecurity experts since it incorporates cutting-edge AI techniques to guarantee that it adjusts to changing cyberthreats. According to experimental data, the hybrid model maintains a low false positive rate and processing time of 0.5 ms/packet while outperforming current techniques in terms of detection accuracy (98.7%), precision (98.4%), recall (97.8%), and F1-score (98.1%). Traditional models with somewhat poorer performance include Random Forest (94.5% accuracy), Support Vector Machine (SVM) (93.7% accuracy), and LSTM (96.2 % accuracy). This research paves the way for more resilient and intelligent network forensic solutions, enhancing the ability to counteract and investigate complex cyber threats effectively.