Hybrid deep learning model for network intrusion detection using optimal feature fusion
M.S Harish, S Lokesh, P Sakthivel, B Akshaya · Ain Shams Engineering Journal · 2025
Recent Intrusion Detection (ID) networks face difficulties in handling the enlarging volume of network traffic and adapting to emerging cyber threats. Handling data traffic and addressing data imbalance are key requirements for identifying recent cyber threats. This paper proposes a novel hybrid ID system designed to mitigate data imbalance issues. The proposed methodology uses advanced deep learning techniques and optimized characteristic fusion models, making it suitable for high-traffic environments. This research conducts a comprehensive experimental study on five standard ID datasets, focusing on network traffic and system behavior data, which are crucial for detecting potential intrusions. In the deep feature extraction phase, multiple features are considered, including statistical information, T-SNE features, and high-level deep learning features. T-SNE features capture similarities between data points, helping preserve the most important features. For feature fusion, optimal weights are identified using the proposed RCMPA. The fused feature set, created from these optimized weights, improves that a more appropriate and discriminative characteristics are utilized for training. A system then employs a “Multi-scale Dilated Deep Hybrid Network with Attention Mechanism” (MDDHN-AM) for intrusion diagnosis. This developed model integrates TCNN and RNN to detain both temporal and spatial dependencies. TCNN processes sequential information to identify temporal patterns, while RNN captures the dynamic nature of network traffic. The attention mechanism prioritizes the most significant features, enabling more accurate intrusion detection. At last, the presentation of MDDHN-AM was compared to traditional and state-of-the-art intrusion detection methods across multiple metrics. The developed model achieved 96.43% detection accuracy and 97.38% precision, illustrating its efficiency in handling diverse digital attacks and data imbalance. An improved performance over traditional methods highlights its potential as a robust solution for secure communication and protection against evolving digital attacks.