Fine-Grained IoT Attack Classification Using a Cross-Attention CNN-BiLSTM Model

Deep learning intrusion detection systems perform well when traffic is merely separated into normal and malicious, but fine-grained recognition of the specific attack family remains difficult in Internet of Things (IoT) environments because of severe class imbalance and overlapping feature distributions. This work proposes an attention-enhanced CNN-BiLSTM fusion model for the multi-class classification of IoT attacks over eight families. A convolutional branch extracts local feature interactions, whereas a bidirectional Long Short-Term Memory (BiLSTM) branch reads the standardized flow descriptor as an ordered sequence and encodes dependencies among non-adjacent feature segments in both directions. Multi-head self-attention and a bidirectional cross-attention block let the two representations interact dynamically and suppress redundant information. Class imbalance is addressed with a focal loss and class-balanced weighting. The framework was evaluated on the large-scale CIC-IoT2023 benchmark under an eight-class taxonomy. On more than 3.5 × 105 test flows, the proposed model reached 99.06% accuracy and a 98.99% weighted F1-score, outperforming standalone CNN, LSTM, CNN-LSTM, and CNN-BiLSTM baselines retrained on the same corrected data pipeline under an identical objective and budget.

Authors

Institutions

Publication Details

Journal
Future Internet
Published
2026-09-29
DOI
https://doi.org/10.3390/fi18100521
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Fine-Grained IoT Attack Classification Using a Cross-Attention CNN-BiLSTM Model

Rachid Ben Said, Abdellah Najid, Mohamed Ali FAKRI, Nezha El Idrissi
Future Internet
Network Security and Intrusion Detection
article

Fine-Grained IoT Attack Classification Using a Cross-Attention CNN-BiLSTM Model

Rachid Ben Said, Abdellah Najid, Mohamed Ali FAKRI, Nezha El Idrissi
article en

Abstract

Deep learning intrusion detection systems perform well when traffic is merely separated into normal and malicious, but fine-grained recognition of the specific attack family remains difficult in Internet of Things (IoT) environments because of severe class imbalance and overlapping feature distributions. This work proposes an attention-enhanced CNN-BiLSTM fusion model for the multi-class classification of IoT attacks over eight families. A convolutional branch extracts local feature interactions, whereas a bidirectional Long Short-Term Memory (BiLSTM) branch reads the standardized flow descriptor as an ordered sequence and encodes dependencies among non-adjacent feature segments in both directions. Multi-head self-attention and a bidirectional cross-attention block let the two representations interact dynamically and suppress redundant information. Class imbalance is addressed with a focal loss and class-balanced weighting. The framework was evaluated on the large-scale CIC-IoT2023 benchmark under an eight-class taxonomy. On more than 3.5 × 105 test flows, the proposed model reached 99.06% accuracy and a 98.99% weighted F1-score, outperforming standalone CNN, LSTM, CNN-LSTM, and CNN-BiLSTM baselines retrained on the same corrected data pipeline under an identical objective and budget.

Future InternetVol. 18(10)
Ankara University (TR), Institut National des Postes et Télécommunications (MA)
Openalex Percentile: Top 9%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.