AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
PDF (2 MB)
Collect
Submit Manuscript AI Chat Paper
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Article | Open Access

A Two-Layer Network Intrusion Detection Method Incorporating LSTM and Stacking Ensemble Learning

Jun Wang1,2Chaoren Ge1,2Yihong Li1,2Huimin Zhao1,2Qiang Fu1,2( )Kerang Cao1,2Hoekyung Jung3( )
College of Computer Science and Technology, Shenyang University of Chemical Technology, Shenyang, 110142, China
Key Laboratory of Intelligent Technology for Chemical Process Industry of Liaoning Province, Shenyang, 110142, China
Computer Engineering Department, Paichai University, Daejeon, 35345, Republic of Korea
Show Author Information

Abstract

Network Intrusion Detection System (NIDS) detection of minority class attacks is always a difficult task when dealing with attacks in complex network environments. To improve the detection capability of minority-class attacks, this study proposes an intrusion detection method based on a two-layer structure. The first layer employs a CNN-BiLSTM model incorporating an attention mechanism to classify network traffic into normal traffic, majority class attacks, and merged minority class attacks. The second layer further segments the minority class attacks through Stacking ensemble learning. The datasets are selected from the generic network dataset CIC-IDS2017, NSL-KDD, and the industrial network dataset Mississippi Gas Pipeline dataset to enhance the generalization and practical applicability of the model. Experimental results show that the proposed model achieves an overall detection accuracy of 99%, 99%, and 95% on the CIC-IDS2017, NSL-KDD, and industrial network datasets, respectively. It also significantly outperforms traditional methods in terms of detection accuracy and recall rate for minority class attacks. Compared with the single-layer deep learning model, the two-layer structure effectively reduces the false alarm rate while improving the minority-class attack detection performance. The research in this paper not only improves the adaptability of NIDS to complex network environments but also provides a new solution for minority-class attack detection in industrial network security.

References

【1】
【1】
 
 
Computers, Materials & Continua
Pages 5129-5153

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Wang J, Ge C, Li Y, et al. A Two-Layer Network Intrusion Detection Method Incorporating LSTM and Stacking Ensemble Learning. Computers, Materials & Continua, 2025, 83(3): 5129-5153. https://doi.org/10.32604/cmc.2025.062094

260

Views

3

Downloads

6

Crossref

7

Web of Science

11

Scopus

Received: 10 December 2024
Accepted: 10 March 2025
Published: 19 May 2025
© The Author 2025.

This work is licensed under a Creative Commons Attribution 4.0 International License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.