Network Intrusion Detection Model Based on Bidirectional LSTM and Attention Mechanism
Xuelong Wang, Chen Zhu · 2025
With the increasing complexity of network attacks and the diversification of attack methods, traditional intrusion detection systems (IDS) are finding it difficult to efficiently identify and respond to new threats. In recent years, deep learning technology has received widespread attention in the field of network security, with long short-term memory networks (LSTM) and attention mechanisms (Attention) demonstrating superior performance in network traffic analysis and attack detection due to their powerful feature extraction capabilities. This article proposes an IDS method based on bidirectional LSTM (BiLSTM) and the attention mechanism to enhance time series modeling capabilities and improve the accuracy of intrusion detection. We conducted experimental verification on the CIC-IDS2017 dataset, and the results showed that the method achieved extremely high accuracy (F1 score ≈ 1.00) in detecting major attack categories such as DDoS, PortScan, and DoS Hulk, significantly improving the performance of network intrusion detection. This study demonstrates the effectiveness of combining BiLSTM with the attention mechanism and provides technical support for constructing an efficient intelligent IDS.