Enhancing SDN Intrusion Detection via Multi-Hybrid Deep Learning Fusion and Explainable AI
Abstract
1. Introduction
1.1. Software-Defined Networking and Its Relevance
1.2. Main Contributions
- Heterogeneous Architecture Integration: The framework combines four different types of deep neural networks that excel in specific areas. The strengths are: Deep Neural Networks (DNNs) for abstract pattern recognition; Convolutional Neural Networks (CNNs) for spatial feature recognition; Recurrent Neural Networks (RNNs) for short-term sequence recognition; and Long Short-Term Memory (LSTM) for long-term temporal dependencies. The multiple-view approach can capture all aspects of network traffic, whereas any single model cannot. It is tested on two large datasets of attack data (NSL-KDD, CIC-IDS2017) using a stratified split to ensure accurate, generalizable results.
- LSTM-based Meta-Classification: Unlike traditional methods such as voting or averaging, MHDLFE uses an LSTM-based meta-classifier to classify the fused feature space that has 512 dimensions. This allows MHDLFE to accurately recognize and classify various types of attacks with complex, time-varying characteristics (e.g., brute-force, SQL injection, DDoS).
- Integrating Explainability: To make MHDLFE decision-making processes more transparent, explainable, and aligned with real-world requirements, SHAP and LIME are integrated for both global and local explanations.
1.3. Paper Organization
2. Background and Related Work
2.1. SDN Security and Network Intrusion Detection
2.2. Machine Learning Approaches for Intrusion Detection
2.3. Attention-Based Intrusion Detection Systems
2.4. Federated Learning for Privacy-Preserving Intrusion Detection
2.5. Explainable AI in Network Security
2.6. Research Gaps and Motivation
2.7. Deep Learning Models Overview
2.7.1. Deep Neural Network (DNN)
- is the processed output at stage s;
- is the transformation matrix associated with stage s;
- is the shift term (bias) for stage s;
- is a non-linear activation like sigmoid, tanh, or ReLU.
2.7.2. Convolutional Neural Networks (CNNs)
- is the transformed value at spatial location in the r-th output channel;
- denotes the transformation kernel’s parameter at index for input channel d and output channel r;
- is the input feature at adjusted location within channel d;
- is the bias associated with the r-th output channel;
- is a non-linear activation function (ReLU or sigmoid).
2.7.3. Recurrent Neural Networks (RNNs)
- is the latent state at time index t;
- is the transformation matrix associated with prior states;
- is the transformation matrix linked to the new input ;
- is the bias term;
- is a non-linear activation function, such as sigmoid, tanh, or ReLU.
2.7.4. Long Short-Term Memory (LSTM)
3. Dataset & Preprocessing
3.1. Dataset Selection and Characteristics
3.2. Data Preprocessing
- 1.
- Handling Missing Values: NSL-KDD uses mean/median imputation; CIC-IDS2017 uses forward/backward filling.
- 2.
- Removing Duplicates: Duplicate records eliminated from both datasets.
- 3.
- Outlier Removal: NSL-KDD uses z-score (); CIC-IDS2017 uses IQR-based filtering.
- 4.
- Categorical Encoding: One-hot and label encoding were applied to convert categorical variables to a numerical format.
- 5.
- Normalization: Min-max scaling followed by z-score normalization applied to all features.
- 6.
- Class Imbalance Handling: SMOTE applied to NSL-KDD; SMOTE or ADASYN applied to CIC-IDS2017, followed by majority class undersampling for both datasets.
- 7.
- Train/Validation/Test Splitting: Stratified sampling into 70% training, 10% validation, and 20% testing subsets.
4. Proposed Methodology
4.1. System Architecture and Feature Fusion Strategy
- DNN: Final dense layer →.
- CNN: Global Average Pooling →.
- RNN: Final hidden state →.
- LSTM: Memory cell output →.
4.2. Meta-Classification Architecture
- LSTM layers: Model temporal dynamics across the fused feature space.
- Dense layers with ReLU activation: Introduce non-linearity and enhance learning capacity.
- Dropout regularization: Prevents overfitting and improves generalization to unseen network traffic patterns.
- Sigmoid output layer: Generates probabilistic intrusion predictions.
| Algorithm 1 Proposed Multi-hybrid Deep Learning Fusion Ensemble (MHDLFE) |
|
4.3. Framework Capabilities and Integration
- SDN-Specific Security: Targets vulnerabilities inherent to SDN’s centralized control architecture, addressing novel attack vectors that exploit centralized network management.
- Adaptive Threat Detection: Network anomaly detection (both general and specific) and the detection of various types of cyber-attacks (e.g., DDoS, SQL Injection, and Brute-Force) are enabled by its Hybrid Deep Learning Architecture, which evolves to adapt to changing threats.
- Explainable Decision-Making: The addition of SHAP and LIME enables the system to provide an understandable explanation for why a decision was made. This addresses one of the major challenges in using deep learning models for high-stakes applications like cybersecurity. (i.e., “Black Box” problem.)
- Superior Performance: Achieves high accuracy in both binary and multiclass classification tasks, demonstrating effectiveness across various network conditions and attack scenarios.
5. Experimental Setup
5.1. Evaluation Metrics
| Algorithm 2 History Data Frame Creation for Model Training |
| Require: Training data , Validation data , Number of epochs Ensure: the History data frame contains training and validation metrics |
|
| Algorithm 3 Plot Training Progress for Deep Learning Model |
| Require: Training history dictionary H containing loss and accuracy metrics Ensure: Line plots for training progress |
|
| Algorithm 4 Training LSTM Model and Plotting Training History |
| Require: (Training data), (Training labels) Ensure: Training history as a DataFrame, Performance visualization |
|
5.2. Hardware & Software Configuration
5.3. Reproducibility
- All random seeds are fixed and documented.
- Detailed hyperparameter settings are provided.
- Dataset preprocessing steps are fully specified.
5.4. Training, Validation, and Testing Protocol
6. Results and Discussion
6.1. Confusion Matrix Binary and Multiclass
6.2. ROC Curve Analysis
6.3. Learning Curve Analysis
6.4. Comparative Study
6.4.1. Comparison with Classical Methods
6.4.2. Comparison with SOTA Methods
6.5. Explainable AI
6.5.1. SHAP Analysis
6.5.2. LIME Analysis
6.6. Most Influential Features in Detecting Cyber Threats
- Timing-Related Features: Bwd IAT Std and Bwd IAT Total: If you see high variation or large values for backward inter-arrival time, there is likely no attack. However, if you observe a deviation from the standard value, it is possible to determine that an attack has occurred.
- Fwd IAT Min and Fwd IAT Total: A short or inconsistent forward inter-arrival time is typically indicative of some form of malicious activity.
- Rate-Based Features: Bwd Packets/s and Flow Packets/s: High packet rates (in either direction) are an excellent indicator that you have been attacked by a Denial-of-Service (DoS) or flooding type of attack.
- Flow Bytes/s: When the number of bytes per second within the flow exceeds a predetermined threshold, it can be a sign that you have been attacked using malicious payloads or attempting to exfiltrate your data.
- Network Flow and Packet Attributes: Destination Port Attacks may target a specific port to isolate the attack. Therefore, this could be a critical discriminator.
- ACK Flag Count and URG Flag Count: While unusual flag usage (or combinations of flags) can indicate a scan or exploit, they do not necessarily indicate an attack.
- Bwd Packet Length Max: A large maximum backward packet length may indicate that you have experienced a large volume of data being transferred related to an attack.
6.7. Improving Trust in the Model’s Decisions
- Transparency: Figure 19a,b visually demonstrate how the model uses the features of network traffic, specifically the timing and/or packet rate, to make decisions. These are two well-established indicators of an attack used by cybersecurity experts.
- The local explanations provided by LIME (Figure 20, Figure 21 and Figure 22) provide insight into each prediction and show how each decision is made. A user can see how a particular instance was labeled as either malicious or normal and how it was determined. For example, if Bwd Packets/s drove a particular prediction of a malicious connection, the user can immediately correlate it with real-world attack signatures.
- Interpretability: By quantifying how much each feature contributes to the final model output (i.e., SHAP values or LIME weights), the user can be assured that the model is not making decisions based on spurious relationships or unnecessary information. For example, the fact that the model places greater emphasis on Bwd IAT Std than on other, less relevant features (such as the actual packet payload) increases confidence in the model’s logic.
- Actionable Insights: Cybersecurity professionals can narrow the scope of their monitoring to the metrics most important to them, such as Flow Bytes/s and Destination Port. In doing so, they ensure the AI-driven decision-making process aligns with their organization’s operational needs. As such, an additional level of trust is created through actionable insights.
- Validation Against Expectations: When both SHAP/LIME outputs align with a cybersecurity professional’s expectations (for example, high packet rates indicating an attack), this adds credibility to the reasoning behind the model’s decision. If the model identifies traffic as malicious based on Bwd Packets/s and LIME shows that this decision aligns with a known attack signature, the user will be more likely to trust the model’s decision.
6.8. Discussion
6.8.1. Model Architecture and Explainability Framework
6.8.2. Adversarial Security in SDN Environments
6.8.3. Mitigation Strategies
6.8.4. Computational Considerations
6.8.5. Model-Related Ablation Studies
6.9. Comparative Analysis Methodology
6.9.1. Literature-Based Benchmarking
6.9.2. Experimental Validation of Proposed Method
- Fair Comparison: Baseline methods are compared using their best reported performance, while our method undergoes rigorous experimental validation.
- Reproducibility: Our experimental methodology is fully documented, enabling independent verification of results.
- Statistical Validity: Multiple experimental runs with statistical analysis ensure robust performance assessment.
6.9.3. Validity and Limitations
6.9.4. Comparative Analysis Framework
- 1.
- Standardized Metrics: Consistent use of accuracy, precision, recall, and F1-score enables direct performance comparison across methods.
- 2.
- Dataset Alignment: Focus on widely-used benchmark datasets (NSL-KDD, CIC-IDS2017) ensures reasonable comparability.
- 3.
- Performance Context: Results are interpreted considering the experimental conditions and constraints reported in the original studies.
7. Conclusions and Future Work
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- Beck, M.; Moore, T. How we ruined the Internet. arXiv 2023, arXiv:2306.01101. [Google Scholar]
- Nazir, A.; He, J.; Zhu, N.; Qureshi, S.S.; Qureshi, S.U.; Ullah, F.; Wajahat, A.; Pathan, M.S. A deep learning-based novel hybrid CNN-LSTM architecture for efficient detection of threats in the IoT ecosystem. Ain Shams Eng. J. 2024, 15, 102777. [Google Scholar] [CrossRef]
- Winder, P. Reinforcement Learning: Industrial Applications with Intelligent Agents; O’Reilly Media, Inc.: Santa Rosa, CA, USA, 2020. [Google Scholar]
- Sajid, M.; Malik, K.R.; Almogren, A.; Malik, T.S.; Khan, A.H.; Tanveer, J.; Rehman, A.U. Enhancing intrusion detection: A hybrid machine and deep learning approach. J. Cloud Comput. 2024, 13, 123. [Google Scholar] [CrossRef]
- Jhanjhi, N.Z.; Shah, I.A. Cybersecurity Measures for Logistics Industry Framework; IGI Global: Hershey, PA, USA, 2024. [Google Scholar]
- Sandberg, H.; Gupta, V.; Johansson, K.H. Secure networked control systems. Annu. Rev. Control. Robot. Auton. Syst. 2022, 5, 445–464. [Google Scholar] [CrossRef]
- Ahmed, U.; Jiangbin, Z.; Almogren, A.; Sadiq, M.; Rehman, A.U.; Sadiq, M.; Choi, J. Hybrid bagging and boosting with SHAP based feature selection for enhanced predictive modeling in intrusion detection systems. Sci. Rep. 2024, 14, 30532. [Google Scholar] [CrossRef]
- Coussement, K.; Abedin, M.Z.; Kraus, M.; Maldonado, S.; Topuz, K. Explainable AI for enhanced decision-making. Decis. Support Syst. 2024, 184, 114276. [Google Scholar] [CrossRef]
- Wijesekara, P.A.D.S.N.; Gunawardena, S. A comprehensive survey on knowledge-defined networking. Telecom 2023, 4, 477–596. [Google Scholar] [CrossRef]
- Arevalo-Herrera, J.; Camargo Mendoza, J.; Martínez Torre, J.I.; Zona-Ortiz, T.; Ramirez, J.M. Assessing SDN Controller Vulnerabilities: A Survey on Attack Typologies, Detection Mechanisms, Controller Selection, and Dataset Application in Machine Learning. Wirel. Pers. Commun. 2025, 140, 739–775. [Google Scholar] [CrossRef]
- De Neira, A.B.; Kantarci, B.; Nogueira, M. Distributed denial of service attack prediction: Challenges, open issues and opportunities. Comput. Netw. 2023, 222, 109553. [Google Scholar] [CrossRef]
- Amiri, Z.; Heidari, A.; Navimipour, N.J.; Esmaeilpour, M.; Yazdani, Y. The deep learning applications in IoT-based bio-and medical informatics: A systematic literature review. Neural Comput. Appl. 2024, 36, 5757–5797. [Google Scholar]
- Asadi, M.; Jamali, M.A.J.; Heidari, A.; Navimipour, N.J. Botnets unveiled: A comprehensive survey on evolving threats and defense strategies. Trans. Emerg. Telecommun. Technol. 2024, 35, e5056. [Google Scholar] [CrossRef]
- Ataa, M.S.; Sanad, E.E.; El-Khoribi, R.A. Intrusion detection in software defined network using deep learning approaches. Sci. Rep. 2024, 14, 29159. [Google Scholar] [CrossRef]
- Laghrissi, F.; Douzi, S.; Douzi, K.; Hssina, B. IDS-attention: An efficient algorithm for intrusion detection systems using attention mechanism. J. Big Data 2021, 8, 149. [Google Scholar] [CrossRef]
- Yang, K.; Wang, J.; Li, M. An improved intrusion detection method for IIoT using attention mechanisms, BiGRU, and Inception-CNN. Sci. Rep. 2024, 14, 19339. [Google Scholar] [CrossRef]
- Buyuktanir, B.; Altinkaya, Ş.; Karatas Baydogmus, G.; Yildiz, K. Federated learning in intrusion detection: Advancements, applications, and future directions. Clust. Comput. 2025, 28, 473. [Google Scholar] [CrossRef]
- Yelle, L.E. The learning curve: Historical review and comprehensive survey. Decis. Sci. 1979, 10, 302–328. [Google Scholar] [CrossRef]
- Ingre, B.; Yadav, A. Performance analysis of NSL-KDD dataset using ANN. In Proceedings of the 2015 International Conference on Signal Processing and Communication Engineering Systems; IEEE: New York, NY, USA, 2015; pp. 92–96. [Google Scholar]
- Song, S.; Du, S.; Song, Y.; Zhu, Y. DualPFL: A Dual Sparse Pruning Method with Efficient Federated Learning for Edge-Based Object Detection. Appl. Sci. 2024, 14, 10547. [Google Scholar] [CrossRef]
- Waskom, M.; Botvinnik, O.; Hobson, P.; Warmenhoven, J.; Cole, J.B.; Halchenko, Y.; Vanderplas, J.; Hoyer, S.; Villalba, S.; Quintero, E.; et al. Seaborn: V0.6.0 (June 2015). Zenodo. 2015. Available online: https://zenodo.org/records/19108 (accessed on 25 December 2025).
- Barnard, P.; Marchetti, N.; DaSilva, L.A. Robust network intrusion detection through explainable artificial intelligence (XAI). IEEE Netw. Lett. 2022, 4, 167–171. [Google Scholar] [CrossRef]
- Goodfellow, I.; Bengio, Y.; Courville, A. Deep Learning; MIT Press: Cambridge, MA, USA, 2016. [Google Scholar]
- Krizhevsky, A.; Sutskever, I.; Hinton, G.E. ImageNet classification with deep convolutional neural networks. Commun. ACM 2017, 60, 84–90. [Google Scholar]
- Iosif, R.; Rogalewicz, A. Automata-Based Termination Proofs. Comput. Inform. 2013, 2013, 739–775. [Google Scholar]
- Hochreiter, S.; Schmidhuber, J. Long short-term memory. Neural Comput. 1997, 9, 1735–1780. [Google Scholar] [CrossRef]
- Liu, C.; Gu, Z.; Wang, J. A Hybrid Intrusion Detection System Based on Scalable K-Means+ Random Forest and Deep Learning. IEEE Access 2021, 9, 75729–75740. [Google Scholar] [CrossRef]
- Protić, D.; Stanković, M. Cybersecurity attacks: Which dataset should be used to evaluate an intrusion detection system? Vojnoteh. Glas. 2023, 71, 970–995. [Google Scholar] [CrossRef]
- Liao, Y.; Vemuri, V.R. Use of k-nearest neighbor classifier for intrusion detection. Comput. Secur. 2002, 21, 439–448. [Google Scholar] [CrossRef]
- Roeder, L. Netron. Available online: https://github.com/lutzroeder/netron (accessed on 25 December 2025).
- Dhanabal, L.; Shantharajah, S. A study on NSL-KDD dataset for intrusion detection system based on classification algorithms. Int. J. Adv. Res. Comput. Commun. Eng. 2015, 4, 446–452. [Google Scholar]
- Javaid, A.; Niyaz, Q.; Sun, W.; Alam, M. A deep learning approach for network intrusion detection system. In Proceedings of the 9th EAI International Conference on Bio-Inspired Information and Communications Technologies (Formerly BIONETICS); ICST (Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering): Brussels, Belgium, 2016; pp. 21–26. [Google Scholar]
- Caminero, G.; Lopez-Martin, M.; Carro, B. Adversarial environment reinforcement learning algorithm for intrusion detection. Comput. Netw. 2019, 159, 96–109. [Google Scholar] [CrossRef]
- Feng, F.; Liu, X.; Yong, B.; Zhou, R.; Zhou, Q. Anomaly detection in ad-hoc networks based on deep learning model: A plug and play device. Ad Hoc Netw. 2019, 84, 82–89. [Google Scholar] [CrossRef]
- Aminanto, M.E.; Kim, K. Improving detection of Wi-Fi impersonation by fully unsupervised deep learning. In Proceedings of the Information Security Applications: 18th International Conference, WISA 2017, Jeju Island, Republic of Korea, 24–26 August 2017; Revised Selected Papers 18; Springer: Berlin/Heidelberg, Germany, 2018; pp. 212–223. [Google Scholar]
- Cui, J.; Zong, L.; Xie, J.; Tang, M. A novel multi-module integrated intrusion detection system for high-dimensional imbalanced data. Appl. Intell. 2023, 53, 272–288. [Google Scholar] [CrossRef]
- Ieracitano, C.; Adeel, A.; Morabito, F.C.; Hussain, A. A novel statistical analysis and autoencoder driven intelligent intrusion detection approach. Neurocomputing 2020, 387, 51–62. [Google Scholar] [CrossRef]
- Ma, X.; Shi, W. Aesmote: Adversarial reinforcement learning with smote for anomaly detection. IEEE Trans. Netw. Sci. Eng. 2020, 8, 943–956. [Google Scholar] [CrossRef]
- Xu, X.; Li, J.; Yang, Y.; Shen, F. Toward effective intrusion detection using log-cosh conditional variational autoencoder. IEEE Internet Things J. 2020, 8, 6187–6196. [Google Scholar] [CrossRef]
- Shams, E.A.; Rizaner, A.; Ulusoy, A.H. A novel context-aware feature extraction method for convolutional neural network-based intrusion detection systems. Neural Comput. Appl. 2021, 33, 13647–13665. [Google Scholar] [CrossRef]
- Qaddos, A.; Yaseen, M.U.; Al-Shamayleh, A.S.; Imran, M.; Akhunzada, A.; Alharthi, S.Z. A novel intrusion detection framework for optimizing IoT security. Sci. Rep. 2024, 14, 21789. [Google Scholar] [CrossRef]
- Fitni, Q.R.S.; Ramli, K. Implementation of ensemble learning and feature selection for performance improvements in anomaly-based intrusion detection systems. In Proceedings of the 2020 IEEE International Conference on Industry 4.0, Artificial Intelligence, and Communications Technology (IAICT); IEEE: New York, NY, USA, 2020; pp. 118–124. [Google Scholar]
- Khan, M.A.; Kim, J. Toward developing efficient Conv-AE-based intrusion detection system using heterogeneous dataset. Electronics 2020, 9, 1771. [Google Scholar] [CrossRef]
- Liu, L.; Wang, P.; Lin, J.; Liu, L. Intrusion detection of imbalanced network traffic based on machine learning and deep learning. IEEE Access 2020, 9, 7550–7563. [Google Scholar] [CrossRef]
- Cao, Z.; Zhao, Z.; Shang, W.; Ai, S.; Shen, S. Using the ToN-IoT dataset to develop a new intrusion detection system for industrial IoT devices. Multimed. Tools Appl. 2025, 84, 16425–16453. [Google Scholar] [CrossRef]
- Hariharan, S.; Rejimol Robinson, R.; Prasad, R.R.; Thomas, C.; Balakrishnan, N. XAI for intrusion detection system: Comparing explanations based on global and local scope. J. Comput. Virol. Hacking Tech. 2023, 19, 217–239. [Google Scholar] [CrossRef]
- Ahmed, U.; Jiangbin, Z.; Almogren, A.; Khan, S.; Sadiq, M.T.; Altameem, A.; Rehman, A.U. Explainable AI-based innovative hybrid ensemble model for intrusion detection. J. Cloud Comput. 2024, 13, 150. [Google Scholar] [CrossRef]
- Lundberg, S.M.; Lee, S.I. Consistent feature attribution for tree ensembles. arXiv 2017, arXiv:1706.06060. [Google Scholar]
- Liao, Q.V.; Gruen, D.; Miller, S. Questioning the AI: Informing design practices for explainable AI user experiences. In Proceedings of the 2020 CHI Conference on Human Factors in Computing Systems; Association for Computing Machinery: New York, NY, USA, 2020; pp. 1–15. [Google Scholar]
- Novaes, M.P.; Carvalho, L.F.; Lloret, J.; Proença, M.L., Jr. Adversarial Deep Learning approach detection and defense against DDoS attacks in SDN environments. Future Gener. Comput. Syst. 2021, 125, 156–167. [Google Scholar] [CrossRef]
- Ganesan, A.; Sarac, K. Mitigating evasion attacks on machine learning based nids systems in sdn. In Proceedings of the 2021 IEEE 7th International Conference on Network Softwarization (NetSoft); IEEE: New York, NY, USA, 2021; pp. 268–272. [Google Scholar]
- Das, T.; Shukla, R.M.; Sengupta, S. Poisoning the well: Adversarial poisoning on ML-based software-defined network intrusion detection systems. IEEE Trans. Netw. Sci. Eng. 2024, 12, 252–262. [Google Scholar] [CrossRef]
- Wang, Z.; Ma, J.; Wang, X.; Hu, J.; Qin, Z.; Ren, K. Threats to training: A survey of poisoning attacks and defenses on machine learning systems. ACM Comput. Surv. 2022, 55, 1–36. [Google Scholar] [CrossRef]
- Li, D.; Li, Q. Adversarial deep ensemble: Evasion attacks and defenses for malware detection. IEEE Trans. Inf. Forensics Secur. 2020, 15, 3886–3900. [Google Scholar] [CrossRef]
- Villegas-Ch, W.; Jaramillo-Alcázar, A.; Luján-Mora, S. Evaluating the robustness of deep learning models against adversarial attacks: An analysis with fgsm, pgd and cw. Big Data Cogn. Comput. 2024, 8, 8. [Google Scholar] [CrossRef]
- Alanazi, F.; Jambi, K.; Eassa, F.; Khemakhem, M.; Basuhail, A.; Alsubhi, K. Ensemble Deep Learning Models for Mitigating DDoS Attack in Software-Defined Network. Intell. Autom. Soft Comput. 2022, 33, 923–938. [Google Scholar] [CrossRef]























| Preprocessing Step | NSL-KDD | CIC-IDS2017 |
|---|---|---|
| Data Cleaning | ||
| Handling Missing Values | Replacing NaN values with mean or median. | Impute missing data using forward/backward filling. |
| Removing duplicates | eliminating duplicate records. | Eliminate duplicate records. |
| Outlier Detection | Identify outliers using z-score: ; remove if . | Use the IQR-based method to detect and remove outliers. |
| Normalization | ||
| Min-Max Scaling | Scale features to range : . | Same as NSL-KDD. |
| Z-score Normalization | Transform features to have zero mean and unit variance: . | Same as NSL-KDD. |
| Handling Categorical Variables | ||
| One-hot encoding and conversion of categorical variables into binary vectors. | Convert categorical variables to binary vectors. | |
| Label encoding and mapping categorical labels to integers. | Map the categorical labels to integers. | |
| Handling Imbalanced Classes | ||
| Oversampling and duplicate minority classes, or generating synthetic samples (SMOTE). | Use SMOTE or ADASYN to oversample minority classes. | |
| Undersampling: Remove the majority class or downsample it. | Remove or downsample the majority class. | |
| Splitting into Training and Test Sets | ||
| Stratified Sampling: Ensure that the class distribution is preserved when splitting the data. | Ensure that the class distribution is preserved while splitting the data. | |
| Model | Layer | Specifications |
|---|---|---|
| DNN Model | Input Layer | Shape: (n_samples, input_features) |
| Dense Layer 1 | 128 neurons, ReLU activation, L2 regularization (0.001) | |
| Dropout Layer 1 | Dropout rate: 0.5 | |
| Dense Layer 2 | 128 neurons, ReLU activation, L2 regularization (0.001) | |
| Dropout Layer 2 | Dropout rate: 0.5 | |
| Output Layer | 6 neurons, softmax activation for multiclass classification | |
| CNN | Conv2D Layer 1 | 64 filters, kernel size (3 × 3), ReLU, BatchNorm, MaxPooling (2 × 2) |
| Conv2D Layer 2 | 128 filters, kernel size (3 × 3), ReLU, BatchNorm, MaxPooling (2 × 2) | |
| Conv2D Layer 3 | 256 filters, kernel size (3 × 3), ReLU, Dropout (0.3) | |
| GAP Layer | Global Average Pooling | |
| Feature Vector | Shape: (n_samples, 256) | |
| RNN (LSTM) | LSTM Layer 1 | 128 units, Dropout (0.3), Recurrent Dropout (0.2) |
| LSTM Layer 2 | 64 units, Dropout (0.3), BatchNorm | |
| Feature Vector | Shape: (n_samples, 64) | |
| LSTM with Attention | LSTM Layer 1 | 128 units, Dropout (0.3), Recurrent Dropout (0.2) |
| LSTM Layer 2 | 64 units, Dropout (0.3), BatchNorm | |
| Attention Layer | Focuses on relevant parts of the sequence | |
| Feature Vector | Shape: (n_samples, 64) | |
| Meta-Classifier (LSTM) | Input Layer | Shape: (n_samples, 512, 1) |
| LSTM Layer 1 | 128 units, Recurrent Dropout (0.3) | |
| Bi-LSTM Layer | 128 units, captures forward and backward dependencies | |
| Attention Layer | Highlights critical fused features | |
| Dense Layer | 256 neurons, ReLU activation, L2 regularization | |
| Dropout Layer | Dropout rate: 0.5 | |
| Output Layer | 5 neurons, softmax activation for multiclass classification |
| Reference | Dataset | Method | Precision | Recall | F1 Score | Accuracy |
|---|---|---|---|---|---|---|
| [32] | NSK-KDD | AE | 85.44 | 95.95 | 90.40 | 88.39 |
| [33] | AWID-NSL | ARL | 79.74 | 80.16 | 79.40 | 80.16 |
| [34] | KDD99 | DNN, LSTM, CNN | 97.63 | 99.59 | - | 98.50 |
| [35] | AWID | SAE | 92.18 | - | 89.06 | 94.81 |
| [36] | NSL-KDD | GMM-WGAN-(M) | 86.59 | 88.55 | 86.59 | 86.88 |
| [37] | NSL-KDD | AE-(N/A) | - | 87.85 | 82.04 | 81.21 |
| [38] | NSL-KDD | AESMOTE-(M) | 82.09 | - | - | 82.43 |
| [39] | NSL-KDD | LCVAE-(M) | 85.51 | - | 68.90 | 80.78 |
| [40] | NSL-KDD, CIC-IDS2017 | CAFE-CNN-(M) | 83.34 | 85.35 | 83.44 | 82.60 |
| [41] | IoTID20 | CNN-GRU | 86.76 | 85.55 | 87.28 | 85.25 |
| [42] | CSE-CIC-IDS2018 | EL | 98.80 | 97.10 | 97.90 | 98.80 |
| [43] | CIC-IDS2018 | CONV-AE | 98.35 | 98.20 | 98.27 | 98.00 |
| [44] | NSL-KDD, CIC-IDS2018 | DSSTE + CNN-miniVGGnet | 97.46 | 96.97 | 97.04 | 96.99 |
| [45] | ToN-IoT | Sine and Cosine | 99.36 | 99.18 | 99.18 | 98.87 |
| Proposed Method | NSL-KDD | MHDLFE-(B) | 97.93 | 97.92 | 97.92 | 97.91 |
| Proposed Method | NSL-KDD | MHDLFE-(M) | 97.76 | 98.65 | 98.19 | 98.61 |
| Proposed Method | CIC-IDS2017 | MHDLFE-(B) | 93.31 | 93.30 | 93.30 | 93.30 |
| Proposed Method | CIC-IDS2017 | MHDLFE-(M) | 97.16 | 97.65 | 97.19 | 97.81 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Ahmed, U.; Sadiq, M.T. Enhancing SDN Intrusion Detection via Multi-Hybrid Deep Learning Fusion and Explainable AI. Mathematics 2026, 14, 1498. https://doi.org/10.3390/math14091498
Ahmed U, Sadiq MT. Enhancing SDN Intrusion Detection via Multi-Hybrid Deep Learning Fusion and Explainable AI. Mathematics. 2026; 14(9):1498. https://doi.org/10.3390/math14091498
Chicago/Turabian StyleAhmed, Usman, and Muhammad Tariq Sadiq. 2026. "Enhancing SDN Intrusion Detection via Multi-Hybrid Deep Learning Fusion and Explainable AI" Mathematics 14, no. 9: 1498. https://doi.org/10.3390/math14091498
APA StyleAhmed, U., & Sadiq, M. T. (2026). Enhancing SDN Intrusion Detection via Multi-Hybrid Deep Learning Fusion and Explainable AI. Mathematics, 14(9), 1498. https://doi.org/10.3390/math14091498
