Deep Learning Techniques for Network Intrusion Detection: A Comparative Survey
Alaa Prince AbdelHalim, Alshaimaa Abo‐alian, Nagwa L. Badr · International journal of intelligent computing and information sciences/International Journal of Intelligent Computing and Information Sciences · 2025
The growing complexity and scale of cyberattacks have driven the evolution of Network Intrusion Detection Systems from traditional signature-based methods to deep learning-driven approaches capable of detecting novel and adversarial threats. This survey presents a comprehensive analysis of recent advances in flow-based and packet-based NIDS, with a focus on robustness, real-time performance, and adaptability to zero-day and adversarial attacks. State-of-the-art methods have been examined in each category, covering a diverse range of deep learning architectures including Convolutional Neural Networks (CNNs), Long Short-Term Memory (LSTMs), transformers, federated learning frameworks, and adversarial training techniques. The surveyed works are evaluated based on data modality, learning paradigm, deployment setting, detection capability, and resilience against evolving threats. Through structured taxonomy and comparative analysis, Key strengths, limitations, and performance trade-offs between flow-level and packet-level systems have been highlighted. Finally, open research challenges have been identified such as data heterogeneity, explainability, and adversarial robustness, and propose future directions for building adaptive and trustworthy intrusion detection systems suitable for real-world deployment.