Multi-Domain Cyber Threat Classification Using Enhanced Genetic Algorithm and Deep Neural Networks
Rana Veer Samara Sihman Bharattej R, Y. M. Mahaboob John, Mamatha Bai B G, Baker Karim, G. Saritha · 2025
Industrial Internet of Things (IIoT) systems are being progressively targeted by cyber-attacks because of their distributed and heterogeneous nature. However, traditional deep-learning-based detection models struggle with highdimensional data and poor generalization across various domains. Hence, this paper proposes an enhanced cyber-attack detection framework that integrates a Genetic Algorithm (GA) for feature selection and a Deep Learning (DL) model for multiclass attack classification. Initially, data were collected from the University of New South Wales Network Behavior (UNSW-NB15) dataset. The collected data were processed using normalization, encoding, and cleaning. Subsequently, the GA chooses optimal features by estimating the deep model performance, decreasing data dimensionality, and training time. Moreover, a Deep Neural Network (DNN) was tuned using the Keras tuner to enhance the classification accuracy. Furthermore, the model integrates cross-domain generalization using transfer learning, multiple IIoT datasets such as the Botnet Internet of Things (BoT-IoT), the Canadian Institute for Cybersecurity Intrusion Detection System (CICIDS2017), and incremental modifications. Finally, the proposed GA-DNN attained better results in terms of accuracy (98.9%) than the existing Feedforward Neural Network (FNN) model.