QuadFusion-IDS: Enhancing Intrusion Detection with Unified Hybrid Deep and Machine Learning Techniques in Cybersecurity Systems
As network traffic becomes increasingly complex and cyberattack behaviors continue to evolve, conventional intrusion detection approaches face challenges in accurately identifying malicious and legitimate network activities. This study proposes QuadFusion-IDS, a hybrid binary intrusion detection framework that integrates FT-Transformer with Autoencoder (FT-Transformer + AE), multi-head attention deep neural network (MHA-DNN), dilated temporal convolutional network (Dilated TCN), and XGBoost to capture complementary feature representations, temporal dependencies, and nonlinear traffic patterns. The framework employs a controlled preprocessing pipeline involving categorical encoding, variance-based filtering, correlation analysis, Random Forest-based feature selection, normalization, stratified train-validation-test partitioning, and ADASYN-based class balancing, while maintaining a locked test set to minimize information leakage. Using the UNSW-NB15 dataset, QuadFusion-IDS achieved an accuracy of 0.9545, a precision of 0.9566, a recall of 0.9775, an F1-score of 0.9669, an MCC of 0.8946, and an AUC-ROC of 0.9922 for binary classification of normal and attack traffic. Ablation experiments demonstrated the importance of ensemble components and optimized weighting, with XGBoost removal producing the largest reduction in F1-score and AUC-ROC. Multi-seed evaluation further showed small performance variations, supporting the stability of the proposed framework. Feature selection analysis indicated that the selected 20-feature configuration substantially reduces input dimensionality while retaining competitive detection performance compared with the original 42-feature configuration. SHAP and LIME analyses provide feature-level and local decision explanations for network traffic predictions. Overall, QuadFusion-IDS provides a strong and interpretable binary intrusion detection approach for the UNSW-NB15 benchmark, while further validation under live traffic, adversarial conditions, streaming workloads, and operational cybersecurity environments remains necessary.
Authors
- Janmejaya Mishra
- Nilesh Dnyaneshwar Bhandarwar
Institutions
- Capella University (US)
Publication Details
- Journal
- Electronics
- Published
- 2026-09-24
- DOI
- https://doi.org/10.3390/electronics15194388
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00