A Network Traffic Anomaly Classification Model Based on Self-Attention Mechanism and Convolutional Gated Recurrent Unit
Yulian Li, Yang Su · IEEE Access · 2025
In the context of accelerated digital transformation, cybersecurity has become a global strategic issue. With the rapid growth of network traffic and the evolving complexity of attack patterns, the stability of information systems and data security face significant challenges. The detection of minority-class traffic (anomalous traffic) is crucial for network security. However, traditional methods struggle to effectively identify minority-class traffic under conditions of data imbalance, which affects detection accuracy. To address this issue, this paper proposes a Custom Synthetic Minority Over-Sampling Technique (Custom SMOTE) algorithm, which precisely handles minority-class samples while significantly reducing memory consumption. Additionally, this paper introduces a Self-Attention based Convolutional Gated Recurrent Unit (SA_CGRU) model. By combining self-attention mechanisms, Convolutional Neural Networks (CNN), and Gated Recurrent Units (GRU), the model captures key features and models temporal dependencies. Experimental results on the CIC-IDS 2017, UNSW-NB15, and CIC-IDS 2018 datasets demonstrate that Custom SMOTE reduces memory usage by an average of 50% and improves overall detection accuracy by 5.35% compared to traditional SMOTE. The SA_CGRU model further enhances minority-class recognition and boosts overall classification accuracy, demonstrating the effectiveness of the proposed approach.