Real Time Anomaly Detection in SDN Using Deep Learning on Edge Enabled Architectures

Salman Alfarizi Novel Bajri, Ridha Muldina Negara, Sofia Naning Hertiana · 2025

The increasing complexity and scale of modern networks have made Software-Defined Networking (SDN) an essential solution for dynamic and flexible network management. However, the centralized nature of SDN makes it highly vulnerable to real-time network threats such as Distributed Denial-of-Service (DDoS) attacks and flow-based intrusions. This research presents a novel approach to real-time anomaly detection in SDN environments by integrating a deep learning model with edge-enabled architectures. The aim is to reduce inference latency and computational load on the SDN controller by deploying a quantized CNN-LSTM hybrid model on resource-constrained edge devices. The proposed system, optimized with TensorFlow Lite, enables real-time detection of network anomalies, significantly improving the performance of SDN security mechanisms. The method involves training the CNN-LSTM model on the CICIDS2017 dataset, followed by its deployment on an edge node to classify network flows in real time. Experimental results demonstrate that the system achieves an accuracy of 98.6%, an F1-score of 0.965, and inference latency within 50-100 ms. The findings indicate that the edge-enabled deep learning model outperforms conventional cloud-based approaches in terms of latency, scalability, and resource efficiency. This study contributes to enhancing SDN security by providing an efficient, scalable, and practical solution for real-time threat mitigation. The proposed system holds potential for future advancements, such as adaptive learning and encrypted traffic analysis, thereby advancing edge-computing-based SDN security frameworks.

Read the paper · More papers on PaperTik