An adaptive contextual memory controller based long short-term memory (ACMC-LSTM) for intrusion detection in network traffic

Abstract Intrusion detection systems (IDSs) are essential for protecting contemporary networks from ever-more-sophisticated cyberattacks. It is difficult for traditional detection techniques to identify long-term dependencies in sequential network traffic data. Long-Short-Term Memory (LSTM) is an important type of recurrent neural network (RNN) used to model long-duration dependencies. This paper presents an intelligent conceptual framework that simulates how humans manage memory. More specifically, it proposes an adaptive contextual memory controller (ACMC) with an LSTM model by integrating (1) the feature-wise attention and (2) the temporal attention mechanism for detecting the attacks in the network. The first assigns context-dependent weights to each feature of each input sample during model training through a lightweight sub-network with two dense layers to learn attention weights. Whereas, the second enhances the capacity to identify subtle attack patterns in network traffic by preferentially focusing on the most pertinent time steps in a sequence. In the feature selection step, a median-based relevance threshold on the normalized hybrid feature importance scores derived from the mutual information (MI) and random forest (RF) method is applied. The ACMC-LSTM model is rigorously tested on the CICIDS2017 and IoTID20 datasets, while its results are evaluated in terms of accuracy, precision, recall, F1_score, ROC-AUC, and FPR. Experimental results show that this model improves detection accuracy, reduces FPR, and outperforms standard LSTM and many neural network methods, achieving accuracies of 0.9804 and 0.9358 on these datasets, respectively. The results of the proposed model outperform those of many machine learning models, including standard LSTM, multilayer perceptron (MLP), logistic regression with SGD (SGD Logistic), recurrent neural network (RNN), gated recurrent unit (GRU), Autoencoder models, and many previously proposed models.

Authors

Institutions

Publication Details

Journal
Scientific Reports
Published
2026-10-06
DOI
https://doi.org/10.1038/s41598-026-64248-7
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

An adaptive contextual memory controller based long short-term memory (ACMC-LSTM) for intrusion detection in network traffic

Mohd Aliff Afira Sani, Mayameen S. Kadhim, Ahmed Dheyaa Radhi, Nor Samsiah Sani et al.
Scientific Reports
Network Security and Intrusion Detection
article

An adaptive contextual memory controller based long short-term memory (ACMC-LSTM) for intrusion detection in network traffic

Mohd Aliff Afira Sani, Mayameen S. Kadhim, Ahmed Dheyaa Radhi, Nor Samsiah Sani, Mohammed Amin Almaiah, Hussein A. A. Al-Khamees, Mudatheer M. Al-Slivani, Ibrahim Oday Alrubaye
article en

Abstract

Abstract Intrusion detection systems (IDSs) are essential for protecting contemporary networks from ever-more-sophisticated cyberattacks. It is difficult for traditional detection techniques to identify long-term dependencies in sequential network traffic data. Long-Short-Term Memory (LSTM) is an important type of recurrent neural network (RNN) used to model long-duration dependencies. This paper presents an intelligent conceptual framework that simulates how humans manage memory. More specifically, it proposes an adaptive contextual memory controller (ACMC) with an LSTM model by integrating (1) the feature-wise attention and (2) the temporal attention mechanism for detecting the attacks in the network. The first assigns context-dependent weights to each feature of each input sample during model training through a lightweight sub-network with two dense layers to learn attention weights. Whereas, the second enhances the capacity to identify subtle attack patterns in network traffic by preferentially focusing on the most pertinent time steps in a sequence. In the feature selection step, a median-based relevance threshold on the normalized hybrid feature importance scores derived from the mutual information (MI) and random forest (RF) method is applied. The ACMC-LSTM model is rigorously tested on the CICIDS2017 and IoTID20 datasets, while its results are evaluated in terms of accuracy, precision, recall, F1_score, ROC-AUC, and FPR. Experimental results show that this model improves detection accuracy, reduces FPR, and outperforms standard LSTM and many neural network methods, achieving accuracies of 0.9804 and 0.9358 on these datasets, respectively. The results of the proposed model outperform those of many machine learning models, including standard LSTM, multilayer perceptron (MLP), logistic regression with SGD (SGD Logistic), recurrent neural network (RNN), gated recurrent unit (GRU), Autoencoder models, and many previously proposed models.

Scientific Reports
University of Jordan (JO), University of Mosul (IQ), University of Kerbala (IQ), Al-Bayan University, Al-Mustaqbal University, University of Al-Ameed (IQ), University of Kuala Lumpur (MY), National University of Malaysia (MY)
Openalex Percentile: Top 10%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.