Skip to main navigation Skip to search Skip to main content

A hybrid deep-learning model for multi-class IoT threat detection employing attention-enhanced CNN-BiLSTM

Research output: Chapter in Book / Conference PaperConference Paperpeer-review

Abstract

The proliferation of Internet of Things (IoT) devices has exponentially increased the attack surface for cyber threats, necessitating lightweight yet effective Network Intrusion Detection Systems (NIDS). This paper proposes a novel hybrid deep learning architecture that combines Convolutional Neural Networks (CNN), Bidirectional Long Short-Term Memory (BiLSTM), and an attention mechanism to detect intrusions in IoT environments. The CNN component captures spatial dependencies from raw traffic flows, while the BiLSTM layers learn temporal patterns in both forward and backward directions. An integrated attention mechanism further refines these temporal features by selectively focusing on the most salient time steps. To ensure robustness and generalizability, the model is rigorously evaluated across two benchmark datasets, UNSW-NB15 and BoT-IoT, under multi-class and binary classification settings. The proposed framework achieves a near-perfect Area Under Curve (AUC) of 1.00, with F1-scores reaching 1.00 even under class imbalance, all while maintaining low false alarm rates. Notably, the model converges rapidly and demonstrates excellent generalization across heterogeneous traffic distributions, confirming its adaptability for real-world deployment in resource-constrained IoT networks. Results highlight the effectiveness of hybrid attention-based architectures in enhancing detection fidelity and interpretability, offering a promising pathway for next-generation, edge-deployable, and scalable IoT security solutions.

Original languageEnglish
Title of host publicationProceedings of the 2025 IEEE International Conference on Smart Internet of Things (SmartIoT 2025), 17-20 November 2025, Sydney, Australia
Place of PublicationU.S.
PublisherIEEE
Pages215-222
Number of pages8
ISBN (Electronic)9798331559786
DOIs
Publication statusPublished - 2025
EventIEEE International Conference on Smart Internet of Things - Sydney, Australia
Duration: 17 Nov 202520 Nov 2025

Conference

ConferenceIEEE International Conference on Smart Internet of Things
Abbreviated titleSmartIoT
Country/TerritoryAustralia
CitySydney
Period17/11/2520/11/25

Keywords

  • CNN-BiLSTM
  • Deep Learning
  • IoT Security
  • Network Intrusion Detection System (NIDS)

Fingerprint

Dive into the research topics of 'A hybrid deep-learning model for multi-class IoT threat detection employing attention-enhanced CNN-BiLSTM'. Together they form a unique fingerprint.

Cite this