Book Details

A HYBRID DEEP LEARNING APPROACH FOR EARLY ANOMALY DETECTION IN HIGH-DIMENSIONAL IOT DATA

International Journal of Computer Science (IJCS) Published by SK Research Group of Companies (SKRGC)

Download this PDF format

Abstract

The rapid proliferation of Internet of Things (IoT) devices has led to the generation of massive volumes of high-dimensional, heterogeneous, and streaming sensor data, making timely and accurate anomaly detection a critical yet challenging task. Conventional machine learning techniques often struggle to capture the complex spatial and temporal dependencies present in such data, and typically detect anomalies only after significant deviations have already occurred. This paper proposes a hybrid deep learning framework that integrates a one-dimensional Convolutional Neural Network (1D-CNN) for local spatial feature extraction, a Bidirectional Long Short-Term Memory (BiLSTM) network for modeling long-range temporal dependencies, an attention mechanism for adaptive feature weighting, and a deep autoencoder branch for unsupervised reconstruction-based anomaly scoring. The fused representation is passed through a lightweight classification head that produces both a discrete anomaly label and a continuous anomaly severity score, enabling early detection before faults propagate. The proposed model is evaluated on four widely used benchmark datasets—NSL-KDD, CICIDS2017, TON_IoT, and N-BaIoT—and compared against seven baseline methods. Experimental results demonstrate that the proposed hybrid architecture achieves up to 95.1% F1-score and 0.978 AUC-ROC, outperforming the best baseline by 3.9 percentage points, while reducing average detection latency by 27% relative to a standard CNN-LSTM model. An ablation study confirms that each architectural component contributes measurably to overall performance, and a complexity analysis shows the model remains suitable for deployment on resource-constrained edge gateways.

References

  1. M. Ahmed, A. N. Mahmood, and J. Hu, "A survey of network anomaly detection techniques," J. Netw. Comput. Appl., vol. 60, pp. 19–31, 2016.
  2. R. Chalapathy and S. Chawla, "Deep learning for anomaly detection: A survey," arXiv preprint, 2019.
  3. M. Tavallaee, E. Bagheri, W. Lu, and A. A. Ghorbani, "A detailed analysis of the KDD CUP 99 data set," in Proc. IEEE Symp. Comput. Intell. Secur. Defense Appl., 2009, pp. 1–6.
  4. I.Sharafaldin, A. H. Lashkari, and A. A. Ghorbani, "Toward generating a new intrusion detection dataset and intrusion traffic characterization," in Proc. Int. Conf. Inf. Syst. Secur. Privacy, 2018, pp. 108–116.
  5. N. Moustafa, "A new distributed architecture for evaluating AI-based security systems at the edge: Network TON_IoT datasets," Sustain. Cities Soc., vol. 72, 2021.
  6. Y. Meidan et al., "N-BaIoT: Network-based detection of IoT botnet attacks using deep autoencoders," IEEE Pervasive Comput., vol. 17, no. 3, pp. 12–22, 2018.
  7. S. Hochreiter and J. Schmidhuber, "Long short-term memory," Neural Comput., vol. 9, no. 8, pp. 1735–1780, 1997.
  8. A.Vaswani et al., "Attention is all you need," in Proc. Adv. Neural Inf. Process. Syst., 2017, pp. 5998–6008.
  9. Y. LeCun, Y. Bengio, and G. Hinton, "Deep learning," Nature, vol. 521, pp. 436–444, 2015.
  10. P. Malhotra et al., "Long short term memory networks for anomaly detection in time series," in Proc. Eur. Symp. Artif. Neural Netw., 2015, pp. 89–94.
  11. J. Kim, J. Kim, H. Kim, M. Shim, and E. Choi, "CNN-based network intrusion detection against denial-of-service attacks," Electronics, vol. 9, no. 6, p. 916, 2020.
  12. T. Kim and W. Pak, "Early detection of network intrusions using a GRU-based one-class classifier," IEEE Access, vol. 10, pp. 5330–5340, 2022.
  13. W. Wang, Y. Sheng, J. Wang, X. Zeng, X. Ye, Y. Huang, and M. Zhu, "HAST-IDS: Learning hierarchical spatial-temporal features using deep neural networks for intrusion detection," IEEE Access, vol. 6, pp. 1792–1806, 2018.
  14. A.Zhang, D. Song, Y. Chen, X. Feng, C. Lumezanu, W. Cheng, J. Ni, B. Zong, H. Chen, and N. V. Chawla, "A deep neural network for unsupervised anomaly detection and diagnosis in multivariate time series data," in Proc. AAAI Conf. Artif. Intell., 2019, pp. 1409–1416.
  15. A.Zong et al., "Deep autoencoding Gaussian mixture model for unsupervised anomaly detection," in Proc. Int. Conf. Learn. Represent., 2018.
  16. A.Kwon, H. Kim, J. Kim, S. C. Suh, I. Kim, and K. J. Kim, "A survey of deep learning-based network anomaly detection," Cluster Comput., vol. 22, pp. 949–961, 2019.
  17. M. Sabokrou, M. Fayyaz, M. Fathy, Z. Moayed, and R. Klette, "Deep-anomaly: Fully convolutional neural network for fast anomaly detection," Comput. Vis. Image Underst., vol. 172, pp. 88–97, 2018.
  18. L. Ruff et al., "Deep one-class classification," in Proc. Int. Conf. Mach. Learn., 2018, pp. 4393–4402.
  19. R. Vinayakumar, M. Alazab, K. P. Soman, P. Poornachandran, A. Al-Nemrat, and S. Venkatraman, "Deep learning approach for intelligent intrusion detection system," IEEE Access, vol. 7, pp. 41525–41550, 2019.
  20. A.A. Diro and N. Chilamkurti, "Distributed attack detection scheme using deep learning approach for Internet of Things," Future Gener. Comput. Syst., vol. 82, pp. 761–768, 2018.
  21. H. H. Pajouh, R. Javidan, R. Khayami, A. Dehghantanha, and K.-K. R. Choo, "A two-layer dimension reduction and two-tier classification model for anomaly-based intrusion detection in IoT backbone networks," IEEE Trans. Emerg. Topics Comput., vol. 7, no. 2, pp. 314–323, 2019.
  22. Y. Zhou, G. Cheng, S. Jiang, and M. Dai, "Building an efficient intrusion detection system based on feature selection and ensemble classifier," Comput. Netw., vol. 174, 2020.
  23. T. Bakhshi and B. Ghita, "Anomaly detection in encrypted IoT traffic using hybrid deep learning," in Proc. Int. Conf. Cyber Situational Awareness, Data Anal. Assessment, 2021, pp. 1–8.
  24. M. Injadat, A. Moubayed, A. B. Nassif, and A. Shami, "Multi-stage optimized machine learning framework for network intrusion detection," IEEE Trans. Netw. Serv. Manage., vol. 18, no. 2, pp. 1803–1816, 2021.
  25. S. Garcia, M. Grill, J. Stiborek, and A. Zunino, "An empirical comparison of botnet detection methods," Comput. Secur., vol. 45, pp. 100–123, 2014.

 

 

Keywords

Internet of Things, anomaly detection, deep learning, hybrid neural network, convolutional neural network, long short-term memory, attention mechanism, autoencoder, edge computing, intrusion detection.

Image
  • Format Volume 14, Issue 2, No 02, 2026
  • Copyright All Rights Reserved ©2026
  • Year of Publication 2026
  • Author Dr.Booba, Dr.J.Isabella
  • Reference IJCS-731
  • Page No 022-036

Copyright 2026 SK Research Group of Companies. All Rights Reserved.