A lightweight attention-enhanced intrusion detection method for anomalous network traffic analysis
Network intrusion detection in complex traffic environments requires a careful balance between detection performance and computational efficiency, particularly when models are intended for resource-constrained scenarios. Existing deep learning-based intrusion detection methods can achieve strong detection performance, but many of them rely on relatively complex architectures and may introduce considerable computational overhead. To address this accuracy–complexity trade-off, this paper proposes ECSA-Net, a lightweight attention-enhanced intrusion detection framework for anomalous network traffic analysis. Specifically, EfficientNet-B0 is adopted as an efficient backbone, the original squeeze-and-excitation (SE) module is replaced with the Efficient Channel Attention (ECA) mechanism to reduce channel-attention overhead, and the Convolutional Block Attention Module (CBAM) is incorporated to further refine discriminative feature representations through joint channel and spatial attention. It should be noted that ECA and CBAM are not treated as newly invented attention mechanisms in this study. Instead, this work focuses on examining whether their integration within an EfficientNet-based lightweight framework can provide a favorable trade-off between detection accuracy and model complexity. Experiments conducted on two benchmark datasets, UNSW-NB15 and CIC-IDS2018, under both binary and multiclass classification settings show that ECSA-Net achieves improved detection performance compared with several baseline models while maintaining relatively low parameter count and computational complexity. The ablation study further indicates that CBAM contributes more substantially to detection accuracy, whereas ECA mainly supports lightweight channel-attention replacement and efficiency preservation. Overall, the results suggest that ECSA-Net provides a practical lightweight framework for anomalous network traffic intrusion detection, while further validation in real deployment environments remains necessary.
Authors
- Peng Wu (ORCID: https://orcid.org/0000-0003-2938-6798)
- Xingguo Li
- Yuanyuan Xiong (ORCID: https://orcid.org/0009-0001-9495-4061)
- Xiang Li
Institutions
- Sichuan University (CN)
- Sichuan Tourism University (CN)
Publication Details
- Journal
- Scientific Reports
- Published
- 2026-10-09
- DOI
- https://doi.org/10.1038/s41598-026-69052-x
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00