Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Search Results (726)

Search Parameters:
Keywords = Intrusion Detection Systems (IDS)

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
36 pages, 998 KB  
Article
An Applied Mathematical Protocol for Evidence Admission and History Replacement in Evolving IoT Intrusion Detection
by Zheng Li, Jian Wang, Xiaosong Meng and Yafei Song
Mathematics 2026, 14(17), 3030; https://doi.org/10.3390/math14173030 (registering DOI) - 22 Aug 2026
Abstract
Recursive evidence fusion gives an intrusion detection system temporal memory, but it also gives unreliable windows and erroneous review outcomes a path to influence later diagnoses. Existing drift-handling, open-set, conformal, continual-learning, and human-in-the-loop methods provide useful signals or update classifiers and memories; they [...] Read more.
Recursive evidence fusion gives an intrusion detection system temporal memory, but it also gives unreliable windows and erroneous review outcomes a path to influence later diagnoses. Existing drift-handling, open-set, conformal, continual-learning, and human-in-the-loop methods provide useful signals or update classifiers and memories; they do not, by themselves, specify when a post-classification evidential state may be written or replaced. We present RTEF-IDS, a protocol that separates current action, model-evidence admission, reviewed-feedback admission, and history replacement. The protocol retains the history-relative reliability principle from our previous work, instantiates it for singleton-plus-ignorance IDS evidence, and assigns operation-specific credentials. Reviewed windows make no base-state change, mapped-known feedback may be appended, and replacement requires persistent confirmation. On 33,384 frozen windows, 30% retrospective admission excludes 26.3% of held-out-or-misclassified mass while retaining 94.8% of known-correct evidence. Under paired imperfect feedback, retrospective replacement increases one-window future history-state agreement by 0.107 in the primary block and 0.129 in IoT-23 leave-scenario-out replay. Under a past-only rolling-budget gate within externally supplied frozen partitions, the corresponding increments are 0.001 and 0.000, indicating that the tested gate exposes few qualifying replacement opportunities; bounded external short streams show the same opportunity constraint. Independent second review reduces false authorization from 5.66 to 0.124 per 1000 first-stage reviewed windows under independent errors and from 34.27 to 0.181 under five-window correlated errors, with a corresponding increase in review demand and a reduction in admitted corrective feedback. A shared systematic label alias remains unresolved by the tested review arms. These results support explicit, auditable state-mutation control while identifying the causal-opportunity and feedback-provenance conditions under which it operates. Full article
(This article belongs to the Special Issue Artificial Intelligence for Network Security and IoT Applications)
23 pages, 4134 KB  
Article
An Explainable and Interpretable GNN Based on Temporal Time Series: An IDS Approach
by Alberto Caballero Ferrero, Shadi Motaali, Xavier Larriva-Novo, Andrés Marín-López, Luis de Pedro and Jorge E. López de Vergara
Electronics 2026, 15(17), 3764; https://doi.org/10.3390/electronics15173764 (registering DOI) - 22 Aug 2026
Abstract
Intrusion Detection Systems (IDSs) based on traditional machine learning treat network flows as independent tabular samples, ignoring the relational and topological structure that characterizes modern distributed attacks. Graph Neural Networks (GNNs) overcome this limitation by modeling network topology, which in turn raise the [...] Read more.
Intrusion Detection Systems (IDSs) based on traditional machine learning treat network flows as independent tabular samples, ignoring the relational and topological structure that characterizes modern distributed attacks. Graph Neural Networks (GNNs) overcome this limitation by modeling network topology, which in turn raise the need to make their predictions transparent. This work develops and compares traditional classifiers against a GNN-based IDS on the UNSW-NB15 dataset, for both binary and multiclass classification. A novel graph construction is proposed in which each node is an individual flow and edges are defined by temporal proximity through three complementary strategies (conversation chains and temporal k-NN by source and destination IP). Three GNN backbones—GraphSAGE, Graph Convolutional Network (GCN) and Graph Attention Network (GAT)—are trained under an identical, matched pipeline and a chronological, inductive evaluation protocol, so that any difference is attributable to the backbone alone. A two-stage classifier then separates detection from attack-type categorisation, with GNNExplainer providing interpretability, and SHAP applied to the traditional models. In binary classification, GraphSAGE achieves an Accuracy of 0.9906, Precision of 0.9856, Recall of 0.9998, F1-Score of 0.9927 and ROC-AUC of 0.9965, exceeding the traditional baselines in their conventional evaluation setting, while GCN and GAT reach comparable detection (F1 ≈ 0.99), showing that the temporal graph rather than the specific backbone drives detection. The explainability analysis identifies TTL-related and connection-state variables as dominant predictors and reveals attack-specific structural patterns, confirming that temporally structured GNNs improve detection while providing interpretable predictions. Full article
(This article belongs to the Special Issue Novel Approaches for Deep Learning in Cybersecurity)
Show Figures

Figure 1

17 pages, 10299 KB  
Article
Benchmark-Shift-Aware Intrusion Detection for Evolving Network Traffic: Cross-Dataset Generalization, Calibrated Alerting, and Score-Orientation Diagnostics
by Hyejin Jin and Hongchul Lee
Electronics 2026, 15(17), 3761; https://doi.org/10.3390/electronics15173761 (registering DOI) - 22 Aug 2026
Abstract
Modern intrusion detection systems (IDSs) are often evaluated under matched training and test conditions, whereas deployment environments involve changing traffic distributions, heterogeneous feature-generation pipelines, and shifting attack prevalence. This study investigates benchmark-shift-aware intrusion detection through harmonized cross-dataset evaluation of HIKARI-2021, CICIDS2017, and a [...] Read more.
Modern intrusion detection systems (IDSs) are often evaluated under matched training and test conditions, whereas deployment environments involve changing traffic distributions, heterogeneous feature-generation pipelines, and shifting attack prevalence. This study investigates benchmark-shift-aware intrusion detection through harmonized cross-dataset evaluation of HIKARI-2021, CICIDS2017, and a CICIoT2023 sample subset. Two payload-free feature spaces are constructed: Rich-64 for detailed HIKARI-2021/CICIDS2017 analysis and Minimal-13 for three-way comparison. Using XGBoost, a supervised Transformer, and a masked-feature self-supervised Transformer, we evaluate discrimination, calibration, threshold transfer, alert-budget behavior, chronological robustness, and score-orientation stability. Across five in-domain XGBoost settings, observed false-positive rates were 4.94–5.40%, and F1-scores ranged from 0.507 to 0.995. Under strict Rich-64 HIKARI-2021-to-CICIDS2017 transfer, all models had zero recall at source-derived thresholds, with two showing inverted score orientation. In the reverse direction, XGBoost reached an 18.9% target false-positive rate, while a nominal 5% target-side alert budget yielded F1 = 0.112. Chronological evaluation further showed that improved ranking metrics did not guarantee stable validation-derived operating behavior. The study provides a reproducible diagnostic framework for evaluating IDS robustness under evolving benchmark conditions. Full article
(This article belongs to the Special Issue Advanced Technologies in Intrusion Detection System)
Show Figures

Figure 1

33 pages, 1120 KB  
Article
Investigating Contrastive Learning for Conditional Variational Autoencoders in Network Intrusion Detection
by Huy Minh Dinh, Wei Zong, Yang-Wai Chow and Willy Susilo
Appl. Sci. 2026, 16(16), 8323; https://doi.org/10.3390/app16168323 - 21 Aug 2026
Abstract
Class imbalance, where majority-class samples vastly outnumber minority-class samples, remains a persistent challenge in network intrusion detection systems (NIDS), often causing classifiers to overlook rare but critical attack types while yielding misleadingly optimistic performance metrics. Synthetic data generation is a common mitigation strategy. [...] Read more.
Class imbalance, where majority-class samples vastly outnumber minority-class samples, remains a persistent challenge in network intrusion detection systems (NIDS), often causing classifiers to overlook rare but critical attack types while yielding misleadingly optimistic performance metrics. Synthetic data generation is a common mitigation strategy. However, existing methods often fail to capture the non-linear network traffic and neglect inter-class relationships with the majority class, resulting in inconsistent performance gains. This study investigates three contrastive learning loss functions, Contrastive Loss, Soft Nearest Neighbor Loss, and Supervised Contrastive Loss, integrated into a Conditional Variational Autoencoder (CVAE) regularised via the standard Kullback-Leibler divergence objective. Experiments were conducted on four widely used NIDS benchmark datasets (NSL-KDD, UNSW-NB15, CIC-IDS2017, and CSE-CIC-IDS2018), with synthetic data evaluated using four machine learning classifiers against the original imbalanced data, a non-contrastive CVAE, and conventional oversampling approaches. The results show that the effectiveness of integrating contrastive learning into the CVAE framework is dependent on the specific dataset, minority class, contrastive loss function, and distance metric, with the proposed approach outperforming traditional oversampling techniques in several settings without degrading majority-class performance or overall accuracy. These findings provide practical guidance for selecting contrastive learning objectives in class-imbalanced NIDS scenarios. Full article
Show Figures

Figure 1

26 pages, 2394 KB  
Article
An Intrusion Detection Method Based on Dynamic Social Structure Gray Wolf Optimization and Multi-Scale Temporal Perception
by Yijian Weng, Zhiliang Zhu, Congjie Wen, Zekai Cai and Xinli Wang
Electronics 2026, 15(16), 3730; https://doi.org/10.3390/electronics15163730 - 20 Aug 2026
Abstract
The dispatching data network and information management system in smart grids constitute a critical communication infrastructure that requires continuous security monitoring. However, network attacks exhibit multi-scale temporal characteristics ranging from microsecond-level bursts to slow intrusions lasting minutes, making single-scale detection models insufficient. Moreover, [...] Read more.
The dispatching data network and information management system in smart grids constitute a critical communication infrastructure that requires continuous security monitoring. However, network attacks exhibit multi-scale temporal characteristics ranging from microsecond-level bursts to slow intrusions lasting minutes, making single-scale detection models insufficient. Moreover, the hyperparameter space of deep learning models is large and highly non-convex, rendering traditional manual tuning inefficient. To address these challenges, this paper proposes an intrusion detection method based on the Dynamic Social Gray Wolf Optimizer (DSGWO) and the Multi-Scale Temporal Convolutional Network (MSTCN). The DSGWO maintains population diversity via an underdog alliance and breaks elite monopoly through a rank promotion challenge mechanism, balancing exploration and exploitation to avoid premature convergence. The MSTCN employs multi-scale parallel branches whose key training hyperparameters are optimized by the DSGWO, with residual connections and feature fusion for robust temporal modeling. Experiments on UNSW-NB15 and CIC-IDS-2017 demonstrate that DSGWO-MSTCN achieves F1-scores of 0.9933 and 0.9892, respectively, outperforming GWO, PSO, and NGO-based optimization approaches. Full article
Show Figures

Figure 1

31 pages, 3892 KB  
Article
HTPI: A New Head–Tail Population Initialization for Feature Selection Stability in IoT IDSs with Post Hoc Explainable AI Analysis
by Saud Abdullah Alzughaibi, Iftikhar Ahmad and Madini Alassafi
Sensors 2026, 26(16), 5207; https://doi.org/10.3390/s26165207 - 17 Aug 2026
Viewed by 238
Abstract
Stochastic metaheuristic feature selection (FS) may generate unstable feature subsets across repeated runs, undermining reproducibility in Internet of Things (IoT) intrusion detection systems (IDSs). This paper presents Head–Tail Population Initialization (HTPI), a feature-importance-guided initialization approach for enhancing the stability of Adaptive Hybrid Genetic [...] Read more.
Stochastic metaheuristic feature selection (FS) may generate unstable feature subsets across repeated runs, undermining reproducibility in Internet of Things (IoT) intrusion detection systems (IDSs). This paper presents Head–Tail Population Initialization (HTPI), a feature-importance-guided initialization approach for enhancing the stability of Adaptive Hybrid Genetic Algorithm–Simulated Annealing (AHGA-SA)-based FS. HTPI uses feature-importance scores to split candidate features into Head and Tail groups and initializes candidate subsets by prioritizing Head features and sampling Tail features with importance-based weights. HTPI is integrated into AHGA-SA as an incremental extension, termed HTPI-AHGA-SA, and modifies only the initialization and reinitialization steps. Experiments on eight IoT-oriented IDS datasets using 50 runs per configuration, with seeds paired across methods, showed significantly higher Nogueira stability under HTPI-AHGA-SA on all datasets after Holm correction, with non-overlapping 95% leave-one-run-out jackknife confidence intervals in every case. These results characterize algorithmic cross-run stability under a fixed data partition. All absolute differences in dataset-level mean F1 Macro remained below 0.003; formal equivalence at this margin was supported for six datasets, while dataset-specific security-metric trade-offs remained. On three representative datasets, post hoc explainable artificial intelligence (XAI) analyses indicated generally higher permutation importance (PI)-based cross-run consistency and measurable predictive utility in the selected Head and Tail portions under retraining. Full article
Show Figures

Figure 1

43 pages, 15065 KB  
Article
A Privacy-Conscious and Explainable IDS-Oriented Triage and Response Pipeline for Mobile Network Infrastructure Using Aggregated Cellular Traffic Signatures
by Özcan Dimez and Fatih Cogen
Computers 2026, 15(8), 531; https://doi.org/10.3390/computers15080531 - 16 Aug 2026
Viewed by 148
Abstract
Mobile-network operators must interpret spatial anomalies in aggregated cell-level telemetry and decide whether, where, and how to respond. This paper presents a privacy-conscious, intrusion detection system (IDS)-oriented triage and response architecture that consumes cell-level anomaly signatures and couples spatial reconstruction, short-horizon forecasting, origin [...] Read more.
Mobile-network operators must interpret spatial anomalies in aggregated cell-level telemetry and decide whether, where, and how to respond. This paper presents a privacy-conscious, intrusion detection system (IDS)-oriented triage and response architecture that consumes cell-level anomaly signatures and couples spatial reconstruction, short-horizon forecasting, origin inference, self-resolution and remaining-time estimation, adaptive gating, ETA-aware team selection, conservative redeployment, explanation, and audit logging. It is a downstream spatial-attribution and response-orchestration layer, not a packet- or flow-level attack detector. The evaluated configuration uses transparent deterministic, heuristic, and optimization-based procedures and synthetic aggregated signatures without subscriber identifiers; aggregation is treated as data minimization, not a formal privacy guarantee. Across 20 paired synthetic scenarios, the full policy reduced conditional mean response time from 37.58 to 22.86 min, total travel from 576.0 to 273.5 min, and coverage ETA from 32.28 to 26.76 min, while on-time service increased from 54.0% to 60.0%. These benefits were accompanied by lower persistent-incident coverage (91.1% to 72.1%) and a higher miss rate (8.9% to 27.9%). The inverse-origin configuration showed no repeated localization-error advantage, and conservative redeployment had only a marginal average effect. The results therefore demonstrate a configurable downstream triage trade-off under controlled synthetic conditions, not attack-classification accuracy, adversarial robustness, formal privacy, or deployment readiness. Full article
Show Figures

Figure 1

21 pages, 3394 KB  
Article
Hybrid Intrusion Detection System with Real-Time Concept Drift Detection for Enhanced IoT Security
by Muath A. Obaidat, Meryem Abouali and Aneeza Shakeel
Sensors 2026, 26(16), 5117; https://doi.org/10.3390/s26165117 - 12 Aug 2026
Viewed by 336
Abstract
The rapid deployment of Internet of Things (IoT) devices across smart cities, healthcare systems, industrial automation, transportation networks, smart grids, and cyber-physical infrastructures has expanded the modern cyberattack surface. IoT devices are often constrained by limited processing capacity, memory, battery power, and communication [...] Read more.
The rapid deployment of Internet of Things (IoT) devices across smart cities, healthcare systems, industrial automation, transportation networks, smart grids, and cyber-physical infrastructures has expanded the modern cyberattack surface. IoT devices are often constrained by limited processing capacity, memory, battery power, and communication bandwidth, making conventional security mechanisms difficult to deploy consistently at scale. Intrusion detection systems (IDSs) provide an important defensive layer; however, many machine-learning-based IDSs are developed under static assumptions and may experience performance degradation as traffic distributions evolve due to firmware changes, device onboarding, protocol updates, user behavior variation, or adaptive attacks. This paper presents a hybrid IDS framework that integrates supervised Random Forest classification, unsupervised Isolation Forest anomaly monitoring, and Kolmogorov–Smirnov (KS)-based concept drift monitoring. In the experimental pipeline, Isolation Forest is trained exclusively on benign traffic to ensure that the anomaly detector models normal behavior rather than an attack-dominated training distribution. The evaluation uses a large-scale chronologically sampled subset of the CICIoT2023 dataset containing 3,890,621 records while preserving the natural class distribution of 2.35% benign traffic and 97.65% attack traffic. The chronological 80/20 train/test split is established first at the file level, followed by systematic sampling within each split to reduce the risk of leakage across the evaluation boundary. On the 746,094-record test set, the proposed hybrid IDS achieved 99.73% accuracy, 99.89% precision, 99.83% recall, 99.86% F1-score, and a false positive rate of 4.77%. The corresponding confusion matrix contains TN = 16,683, FP = 836, FN = 1205, and TP = 727,370, yielding 95.23% specificity and 97.53% balanced accuracy. Standalone Random Forest marginally outperformed the hybrid model in raw accuracy and false positive rate; therefore, the contribution of the proposed framework is centered on deployment-oriented anomaly monitoring, drift awareness, and generalization rather than absolute superiority in static classification metrics. A leave-one-attack-family-out experiment withholding MITM-ArpSpoofing from training showed that the hybrid model detected 85.26% of the unseen attack-family samples, compared with 85.18% for Random Forest alone and 7.05% for Isolation Forest alone. These findings provide initial evidence of generalization to one held-out attack family but should not be interpreted as proof of broad zero-day detection capability. The framework is therefore positioned as a competitive IDS that combines supervised detection with anomaly monitoring and concept drift awareness for deployment-oriented IoT security. Full article
(This article belongs to the Special Issue Sensor Security and Beyond)
Show Figures

Figure 1

47 pages, 7088 KB  
Article
APCI: A Complexity-Aware Framework for Computational Software Effort Estimation in Machine Learning-Based Intrusion Detection Systems
by Vignaraj Ananth Vikraman, Sumendra Yogarayan, Kalaiarasi Sonai Muthu and Manikandan Thirumalaisamy
Future Internet 2026, 18(8), 424; https://doi.org/10.3390/fi18080424 - 11 Aug 2026
Viewed by 214
Abstract
The increasing adoption of machine learning and deep learning techniques in intrusion detection systems (IDSs) has substantially increased the computational complexity of model development due to large-scale datasets, sophisticated model architectures, extensive hyperparameter optimization, and repeated experimentation. Despite these demands, existing IDS research [...] Read more.
The increasing adoption of machine learning and deep learning techniques in intrusion detection systems (IDSs) has substantially increased the computational complexity of model development due to large-scale datasets, sophisticated model architectures, extensive hyperparameter optimization, and repeated experimentation. Despite these demands, existing IDS research primarily emphasizes detection performance while providing limited support for estimating the computational effort required during model development and evaluation. This study proposes the Adaptive Project Complexity Index (APCI), a complexity-aware framework for estimating Computational Software Effort (CSE), a computational resource-based effort metric derived from model training and execution characteristics to support planning and resource estimation in machine learning-based IDS development. To support this objective, a complexity- and effort-oriented benchmark comprising 1040 IDS project instances was constructed using diverse datasets, model architectures, feature configurations, and hyperparameter settings. Statistical analysis demonstrated a strong positive relationship between APCI and CSE, with a Pearson correlation coefficient of 0.834. Building upon this benchmark, multiple machine learning models were evaluated to predict CSE from project characteristics available before implementation, with LightGBM achieving the best predictive performance (R2 = 0.963). Furthermore, explainability analysis identified the dominant computational effort drivers and enabled the development of APCI-Adaptive, improving the APCI–CSE correlation from 0.834 to 0.904 (8.4%). By integrating dataset complexity, model complexity, and computational resource requirements within a unified framework, APCI enables computational software effort estimation prior to IDS implementation, supporting resource planning, experimental design, and complexity-aware project management for machine learning-based IDS development. Consequently, APCI provides a practical decision-support framework for resource planning, experimental design, and complexity-aware project management in modern machine learning-based cybersecurity applications. Full article
(This article belongs to the Special Issue Anomaly and Intrusion Detection in Networks)
Show Figures

Figure 1

36 pages, 5064 KB  
Article
BHM-IDS: Behavior-Driven Hierarchy and Multi-Dataset Training for Cross-Dataset Generalization
by Mounira Zekiouk, Madjed Bencheikh Lehocine, Yehya Bouzeraa, Ahlam Bouanane, Georgi Hristov and Plamen Zahariev
Appl. Sci. 2026, 16(16), 7885; https://doi.org/10.3390/app16167885 - 7 Aug 2026
Viewed by 210
Abstract
Digital infrastructures are increasingly exposed to diverse and evolving cyber threats, highlighting the need for robust intrusion detection systems (IDSs). Although machine learning (ML)-based IDSs have achieved strong performance, most existing frameworks are still developed and evaluated mainly under intra-dataset settings, providing limited [...] Read more.
Digital infrastructures are increasingly exposed to diverse and evolving cyber threats, highlighting the need for robust intrusion detection systems (IDSs). Although machine learning (ML)-based IDSs have achieved strong performance, most existing frameworks are still developed and evaluated mainly under intra-dataset settings, providing limited evidence of their ability to generalize across unseen environments. Moreover, few studies go beyond simply reporting cross-dataset performance to propose dedicated mechanisms for improving generalization. To address this limitation, we propose BHM-IDS, a three-stage hierarchical intrusion detection framework that combines behavior-driven hierarchy with multi-dataset training to improve generalization. The first stage performs binary detection of benign versus malicious traffic, while the second stage classifies malicious traffic into two behaviorally distinct groups: the first corresponding to flood and exhaustion attacks and the second to infiltration and exploitation attacks. The final stage performs fine-grained attack classification through two specialized multi-class classifiers. To expose the framework to more diverse attacks, CIC-IDS2017 is enriched with CIC-DDoS2019 during training, while CSE-CIC-IDS2018 is used as an external test dataset to evaluate generalization. The cross-dataset validation results yielded stage-wise accuracies of 0.93, 0.96, and 0.99, respectively, while the complete end-to-end framework achieved a weighted recall of 0.93. Recall values ranging from 0.76 to 1.00 were obtained for several major classes, including benign traffic, Patator, DoS, and DDoS, although limitations remained for certain attack categories, particularly Web Attack. Overall, the proposed framework demonstrated promising and competitive performance compared with simpler frameworks and existing state-of-the-art approaches. These findings highlight the potential of combining behavior-driven hierarchical classification with multi-dataset training to improve cross-dataset generalization in IDSs. Full article
Show Figures

Figure 1

25 pages, 1597 KB  
Article
From Classical to Deep Learning: A Hybrid CNN–Ensemble Framework for Intrusion Detection in Internet of Medical Things
by Faris Kateb, Owais Khan and Fazal Qudus Khan
Computers 2026, 15(8), 512; https://doi.org/10.3390/computers15080512 - 7 Aug 2026
Viewed by 251
Abstract
With the rapid expansion of the Internet of Medical Things (IoMT), the risks of cybersecurity have increased exponentially in healthcare settings, exposing patients’ safety. Three fundamental issues that existing intrusion detection systems (IDS) are challenged by are: (1) limited cross-domain generalization, (2) high [...] Read more.
With the rapid expansion of the Internet of Medical Things (IoMT), the risks of cybersecurity have increased exponentially in healthcare settings, exposing patients’ safety. Three fundamental issues that existing intrusion detection systems (IDS) are challenged by are: (1) limited cross-domain generalization, (2) high computation requirements not suitable for edge deployment, and (3) absence of systematic comparison between classical machine learning (ML) and deep learning (DL) approaches on IoMT-specific data. In this paper, we propose a multi-dataset evaluation framework that covers six models (Random Forest, XGBoost, DNN, CNN, LSTM, and CNN-LSTM) across three different datasets: WUSTL-EHMS-2020, Edge-IIoTset, and UNSW-NB15. We show that there is a scale-dependent pattern: classical ensemble methods work best when the data is small (F1 = 0.914 ± 0.013 on WUSTL-EHMS-2020); the proposed hybrid CNN–Ensemble framework performs best when the data is large (F1 = 0.968 ± 0.002 on UNSW-NB15 with 62.8% fewer features). The proposed framework achieves a total model size of 2.11 MB and an inference latency of 111.6 ms, with seven out of the top 15 discriminative features being patient vital signs, giving the first quantitative evidence that physiological data systematically contributes to IoMT attack detection, which is demonstrated through an explainability analysis using the SHAP approach. Cross-dataset generalization experiments across six transfer scenarios expose fundamental limitations in domain transfer, establishing an important baseline for future research. Full article
(This article belongs to the Special Issue IoT: Security, Privacy and Best Practices (3rd Edition))
Show Figures

Figure 1

23 pages, 1863 KB  
Article
From Signature to Attention: Transformer-Powered Intrusion Detection Systems for Cybersecurity
by Arun Pandey, Ayush Kumar Agrawal, Abhinav Shukla, Gunjan Keswani, Pitshou N. Bokoro and Parul Dubey
Future Internet 2026, 18(8), 398; https://doi.org/10.3390/fi18080398 - 29 Jul 2026
Viewed by 361
Abstract
Intrusion detection systems (IDSs) play a vital role in safeguarding modern computer networks against increasingly sophisticated and high-volume cyber threats. Recent progress in artificial intelligence, especially deep learning, has allowed IDSs to go from static rule-based systems to adaptive and data-driven security solutions. [...] Read more.
Intrusion detection systems (IDSs) play a vital role in safeguarding modern computer networks against increasingly sophisticated and high-volume cyber threats. Recent progress in artificial intelligence, especially deep learning, has allowed IDSs to go from static rule-based systems to adaptive and data-driven security solutions. But traditional machine learning- and convolution-based IDSs often have trouble finding long-range dependencies and temporal correlations in large-scale network traffic. This makes detection less accurate and increases the number of false alarms. This challenge becomes more pronounced in heterogeneous and evolving network environments. To address this, experiments are conducted on two widely used benchmark datasets: CIC-IDS2017 for binary intrusion detection and CICIDS2018 for multiclass attack classification. These datasets represent realistic network traffic with diverse attack categories and severe class imbalance. The proposed methodology employs a Transformer-based intrusion detection framework incorporating sequence windowing, positional encoding, and multi-head self-attention to learn contextual traffic representations. The primary contribution of this study lies in systematically integrating sliding temporal windowing, positional encoding, and multi-head self-attention into flow-level intrusion modeling, accompanied by empirical ablation analysis and statistical validation across two large-scale CIC benchmark datasets. Performance is evaluated using accuracy, precision, recall, F1-score, ROC-AUC, and false alarm rate. Experimental results demonstrate that the proposed model achieves high detection accuracy, strong discriminative capability, and low false alarm rates across both datasets, confirming its effectiveness and scalability for next-generation cybersecurity applications. Full article
Show Figures

Figure 1

25 pages, 11108 KB  
Article
Defending Against State-Inducing Spoofing Attacks in Intelligent Connected Vehicles: A Real-Time Temporal Feature Fusion Framework
by Chen Dong, Hao Wu and Cheng Li
Sensors 2026, 26(15), 4758; https://doi.org/10.3390/s26154758 - 27 Jul 2026
Viewed by 331
Abstract
As intelligent connected vehicles (ICVs) integrate advanced driver-assistance systems (ADAS) and autonomous-driving functions, CAN bus attacks have become more diverse in mechanism and safety impact. Beyond flooding or direct command injection, state-inducing spoofing attacks inject falsified CAN frames to manipulate vehicle-state signals. Rather [...] Read more.
As intelligent connected vehicles (ICVs) integrate advanced driver-assistance systems (ADAS) and autonomous-driving functions, CAN bus attacks have become more diverse in mechanism and safety impact. Beyond flooding or direct command injection, state-inducing spoofing attacks inject falsified CAN frames to manipulate vehicle-state signals. Rather than directly controlling vehicle behavior, they mislead ADAS state estimation, potentially triggering inappropriate control responses and threatening driving safety. Existing intrusion detection methods mainly target conventional CAN attacks and limited operating states, leaving limited detection generalization in complex attack scenarios. Accordingly, this paper proposes MTFF, a multi-scale temporal feature fusion framework for CAN intrusion detection. MTFF builds two complementary CAN streams: an intra-ID kinematic sequence capturing short-term state continuity under the same identifier and an inter-ID scheduling sequence capturing timing relationships among neighboring frames, thereby characterizing CAN traffic from state-continuity and scheduling-relation perspectives. Multi-scale 1-D convolutions extract local temporal features, while positional self-attention and symmetric cross-attention model long-range dependencies and fuse the streams to detect contextual temporal and state inconsistencies. Experiments on multi-vehicle CAN datasets covering representative operating states show that, in the most challenging setting, MTFF achieves F1-scores above 0.94 on two production vehicles, with per-frame latency below 0.006 ms. Full article
Show Figures

Figure 1

34 pages, 667 KB  
Review
Security Datasets for Intrusion Detection and Prevention: A Structured Review and Dataset-Selection Framework
by Hakan Güler, Aytuğ Boyacı and Mustafa Ulaş
Appl. Sci. 2026, 16(15), 7473; https://doi.org/10.3390/app16157473 - 27 Jul 2026
Viewed by 555
Abstract
Security datasets are central to the evaluation of intrusion detection and prevention systems, but their suitability differs substantially across domains, data sources, attack scenarios, labeling practices, and reproducibility conditions. This study presents a structured evidence-mapping review of security datasets reported in intrusion detection [...] Read more.
Security datasets are central to the evaluation of intrusion detection and prevention systems, but their suitability differs substantially across domains, data sources, attack scenarios, labeling practices, and reproducibility conditions. This study presents a structured evidence-mapping review of security datasets reported in intrusion detection and prevention research between 2018 and 2025. The final evidence map includes 42 primary dataset-use publication records, 82 dataset or evidence-source mentions, and 69 unique datasets, corpora, or evidence sources after duplicate, retracted, and irrelevant records were removed. The review organizes datasets across network-based IDS, IPS, firewall, VPN, WAF, endpoint, email filtering, IAM, DDoS, Windows, Linux-Apache, NetFlow, cloud, and IoT/IIoT security settings. In addition to adoption-frequency analysis, the study assesses representative dataset families in terms of documentation, labeling information, feature representation, class balance, public availability, reproducibility, and practical usability limitations. The findings show that established benchmarks remain widely reused, but recent studies increasingly rely on domain-specific datasets for IoT/IIoT, DDoS, cloud, edge, host, and cyber-physical environments. The review also proposes and illustrates a dataset-selection framework that links dataset choice to security objectives, operational context, telemetry requirements, attack coverage, and evaluation protocol. The results support more transparent, context-aware, and reproducible dataset selection for intrusion detection and prevention research. Full article
Show Figures

Figure 1

25 pages, 9607 KB  
Article
CS-Forest: A Cost-Sensitive Explainable Ensemble Framework for Minority Attack Detection in Intrusion Detection Systems
by Muhammad Binsawad
Electronics 2026, 15(15), 3299; https://doi.org/10.3390/electronics15153299 - 27 Jul 2026
Viewed by 277
Abstract
With the proliferation of internet-connected infrastructures and the complexity of cyberattacks, cybersecurity and intelligent intrusion detection systems have become more and more critical. Intrusion detection datasets, however, are now highly imbalanced, and conventional machine learning models have become biased towards the majority of [...] Read more.
With the proliferation of internet-connected infrastructures and the complexity of cyberattacks, cybersecurity and intelligent intrusion detection systems have become more and more critical. Intrusion detection datasets, however, are now highly imbalanced, and conventional machine learning models have become biased towards the majority of benign traffic, misclassifying minority attack classes. This paper introduces a Cost-Sensitive Forest (CS-Forest) approach to enhance the detection of minority attacks in the CSE-CIC-IDS2018 dataset. The proposed framework combines cost-sensitive learning, ensemble-based Random Forest classification, feature selection, and SHAP explainability analysis to boost the performance of intrusion detection and interpretability. Various machine learning algorithms such as Decision Tree, Random Forest, AdaBoost, and XGBoost were tested and compared based on accuracy, precision, recall, F1-score, ROC-AUC, false positive rate, and false negative rate. Experimental results proved that the proposed CS-Forest has excellent performance, with 99.81% accuracy, 99.55% recall, 99.61% F1-score, and 0.998 ROC-AUC, significantly enhancing the performance of minority attack detection and reduced false negatives. The framework learned meaningful and interpretable network traffic behaviors, which was also confirmed using SHAP analysis. The research suggests that future IDS systems should incorporate cost-sensitive learning and explainable AI techniques to ensure improved reliability, transparency, and deployment in the cybersecurity landscape. Full article
Show Figures

Figure 1

Back to TopTop