An adaptive contextual memory controller based long short-term memory (ACMC-LSTM) for intrusion detection in network traffic
Abstract Intrusion detection systems (IDSs) are essential for protecting contemporary networks from ever-more-sophisticated cyberattacks. It is difficult for traditional detection techniques to identify long-term dependencies in sequential network traffic data. Long-Short-Term Memory (LSTM) is an important type of recurrent neural network (RNN) used to model long-duration dependencies. This paper presents an intelligent conceptual framework that simulates how humans manage memory. More specifically, it proposes an adaptive contextual memory controller (ACMC) with an LSTM model by integrating (1) the feature-wise attention and (2) the temporal attention mechanism for detecting the attacks in the network. The first assigns context-dependent weights to each feature of each input sample during model training through a lightweight sub-network with two dense layers to learn attention weights. Whereas, the second enhances the capacity to identify subtle attack patterns in network traffic by preferentially focusing on the most pertinent time steps in a sequence. In the feature selection step, a median-based relevance threshold on the normalized hybrid feature importance scores derived from the mutual information (MI) and random forest (RF) method is applied. The ACMC-LSTM model is rigorously tested on the CICIDS2017 and IoTID20 datasets, while its results are evaluated in terms of accuracy, precision, recall, F1_score, ROC-AUC, and FPR. Experimental results show that this model improves detection accuracy, reduces FPR, and outperforms standard LSTM and many neural network methods, achieving accuracies of 0.9804 and 0.9358 on these datasets, respectively. The results of the proposed model outperform those of many machine learning models, including standard LSTM, multilayer perceptron (MLP), logistic regression with SGD (SGD Logistic), recurrent neural network (RNN), gated recurrent unit (GRU), Autoencoder models, and many previously proposed models.
Authors
- Mohd Aliff Afira Sani (ORCID: https://orcid.org/0000-0002-6039-3833)
- Mayameen S. Kadhim (ORCID: https://orcid.org/0000-0002-4263-5659)
- Ahmed Dheyaa Radhi (ORCID: https://orcid.org/0000-0001-7194-8972)
- Nor Samsiah Sani (ORCID: https://orcid.org/0000-0001-5802-5946)
- Mohammed Amin Almaiah (ORCID: https://orcid.org/0009-0008-9785-485X)
- Hussein A. A. Al-Khamees (ORCID: https://orcid.org/0000-0002-3200-8889)
- Mudatheer M. Al-Slivani (ORCID: https://orcid.org/0009-0004-5231-7461)
- Ibrahim Oday Alrubaye (ORCID: https://orcid.org/0009-0006-3459-7660)
Institutions
- University of Jordan (JO)
- University of Mosul (IQ)
- University of Kerbala (IQ)
- Al-Bayan University
- Al-Mustaqbal University
- University of Al-Ameed (IQ)
- University of Kuala Lumpur (MY)
- National University of Malaysia (MY)
Publication Details
- Journal
- Scientific Reports
- Published
- 2026-10-06
- DOI
- https://doi.org/10.1038/s41598-026-64248-7
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00