An LSTM-based intrusion detection model utilizing feature selection and dropout
With the advancement of network technology, cybersecurity concerns have intensified, as intrusions pose significant risks to both individuals and organizations. In order to solve the problem of low detection accuracy and high false alarm rate caused by redundant features in network traffic data, a new model is thus developed in this study for intrusion detection that employs Long Short-Term Memory (LSTM) networks to learn the temporal attributes of network traffic data, complemented by feature selection and dropout techniques, to enhance detection accuracy. The approach begins by applying the eXtreme Gradient Boosting (XGBoost) algorithm for feature selection on network traffic data, reducing feature redundancy. Consequently, the most relevant features are identified for effective classification. The selected features undergo preprocessing through one-hot encoding and normalization before being input into the LSTM network for training. To enhance performance, dropout is employed to minimize overfitting and boost generalization. When tested on the CICIDS2017, the model outperforms traditional methods such as convolutional neural network (CNN), Logistic Regression, and Bayesian models in binary as well as multi-class classification tasks. Significantly, this approach is particularly effective at detecting minority attack types, especially Web attack and Bot, in the multi-class classification.
Authors
- Yongqing He
- Yang Liu
- Qi Wu
- Wenfeng Cai
- Junhao Ruan
- Ziyin Wang
- Wenxi Deng
- Xiaoyu Rong
Publication Details
- Journal
- PeerJ Computer Science
- Published
- 2026-09-21
- DOI
- https://doi.org/10.7717/peerj-cs.4057
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00