Cybersecurity Automation Using Capsule Networks for Adaptive Threat Detection and Defense

Ediga Poornima, S. Devanand, Haeedir Mohameed, R. Shirisha, D Rahul, Aanandha Saravanan K · 2025

In recent years, network security research has focused on using deep learning for malware detection. Conventional deep learning models like CNNs have minimal generalizability, little feature extraction, and great complexity. These constraints apply to traditional deep learning. CNNbased models that don't store feature hierarchies lose spatial connectivity information to detect dangerous network traffic patterns. They lose information about a feature's precise placement in the feature area. Malware files often have recognizable portions. This study presents an Adaptive Cybersecurity Automation using Capsule Networks (ACA-CapNet) to intelligently identify and defend against cyber threats and tackle these difficulties. This paper presents a new approach to intrusion detection using capsule networks with hyper-parameter-tuned convolutional layers. The method is based on the idea of anomaly detection in the field of network security. It aims to overcome the limitations of traditional deep learning models by eliminating the need for a pooling layer and introducing capsule layers. The first step is to create a structured feature representation from the network traffic data. Next, a capsule network based on dynamic routing is employed to identify and categorize the network anomalies correctly. With an accuracy of 95.21% and an F1 score of 94.2%, CapsNet outperformed the baseline CNN on the same data set. These results demonstrate that the suggested model effectively detects cyberattacks and can adapt to detect many cyberattacks within network security.

Read the paper · More papers on PaperTik