Fine-Grained IoT Attack Classification Using a Cross-Attention CNN-BiLSTM Model
Deep learning intrusion detection systems perform well when traffic is merely separated into normal and malicious, but fine-grained recognition of the specific attack family remains difficult in Internet of Things (IoT) environments because of severe class imbalance and overlapping feature distributions. This work proposes an attention-enhanced CNN-BiLSTM fusion model for the multi-class classification of IoT attacks over eight families. A convolutional branch extracts local feature interactions, whereas a bidirectional Long Short-Term Memory (BiLSTM) branch reads the standardized flow descriptor as an ordered sequence and encodes dependencies among non-adjacent feature segments in both directions. Multi-head self-attention and a bidirectional cross-attention block let the two representations interact dynamically and suppress redundant information. Class imbalance is addressed with a focal loss and class-balanced weighting. The framework was evaluated on the large-scale CIC-IoT2023 benchmark under an eight-class taxonomy. On more than 3.5 × 105 test flows, the proposed model reached 99.06% accuracy and a 98.99% weighted F1-score, outperforming standalone CNN, LSTM, CNN-LSTM, and CNN-BiLSTM baselines retrained on the same corrected data pipeline under an identical objective and budget.
Authors
- Rachid Ben Said (ORCID: https://orcid.org/0000-0003-0441-5548)
- Abdellah Najid (ORCID: https://orcid.org/0000-0002-5188-1886)
- Mohamed Ali FAKRI
- Nezha El Idrissi
Institutions
- Ankara University (TR)
- Institut National des Postes et Télécommunications (MA)
Publication Details
- Journal
- Future Internet
- Published
- 2026-09-29
- DOI
- https://doi.org/10.3390/fi18100521
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00