A Hybrid Approach for Anomaly Detection with PCA-Driven CNNs

Ashraf S. Mashaleh, Mohammad Almseidin, Hind Alhamadeen, Sami Jamil Aljarrah, Mohammad Alauthman, Amjad Gawanmeh, Issa Qiqieh · 2025

Intrusion detection systems play an important part in network security by detecting malicious activity in real-time. To effectively identify different kinds of network intrusions in the MSCAD dataset, we provide a model based on Convolutional Neural Networks (CNNs) with Principal Component Analysis (PCA) for dimensionality reduction. The model combines CNN's feature extraction capabilities with PCA's capacity to reduce data dimensionality to strike a compromise between accuracy and computational efficiency. Our experimental results show that the proposed model achieves a high test accuracy of 99.73% across six intrusion classes: Brute Force, HTTP DDoS, ICMP Flood, Normal, Port Scan, and Web Crawling. The model performs at detecting Brute Force and Port Scan attacks, with near-perfect precision and recall ratings. However, it has difficulty effectively categorizing the Normal and Web Crawling classes because of their low representation and resemblance to other attack types. The research conducted indicates that CNNs paired with PCA can be an effective and scalable intrusion detection method, giving good classification performance while requiring fewer computational resources.

Read the paper · More papers on PaperTik