A Hybrid CNN–LSTM-Based Intrusion Detection System Trained on UNSW-NB15 for Accurate Cyber Threat Detection

Authors

  • Karimullah Department of Computer Science, Lahore Garrison University, Lahore, Pakistan.
  • Khushbu Khalid Butt Department of Information Technology, Lahore Garrison University, Lahore, Pakistan.
  • Rania Naveed Department of Information Technology, Lahore Garrison University, Lahore, Pakistan.
  • Maria Tariq Department of Computer Science, Lahore Garrison University, Lahore, Pakistan.
  • Khadija Javed Lahore Business School, University of Lahore, Lahore, Pakistan.

Keywords:

Intrusion Detection System, Deep Learning, Convolutional Neural Networks, Long Short-Term Memory, Cybersecurity, UNSW-NB15, Network Security

Abstract

The increasing sophistication of cyber threats requires advanced intrusion detection systems that is capable of detecting both known and unknown attack patterns. Traditional Intrusion Detection Systems (IDS) that rely on signatures for detection have fundamental limitations when facing zero-day attacks and advanced persistent threats. This research proposes a hybrid deep learning architecture that combines Convolutional Neural Networks (CNN) with Long Short-Term Memory (LSTM) networks to enhance detection accuracy and maintain reliable performance across intrusion scenarios. While many earlier studies have relied on datasets such as NSL-KDD, this work uses the more contemporary UNSWNB15 dataset which labor under an outdated assumption of attack vectors, our model is built, trained, and evaluated using the UNSW-NB15 dataset that contains modern attack vectors, and more realistic network traffic scenarios. The CNN component is able to extract spatial features from the characteristics of the network traffic, and the LSTM component in the hybrid model is able to learn the temporal dependencies and sequence of packet flows in the traffic. On the UNSW-NB15 dataset, the hybrid architecture reached 96.78% validation accuracy and an F1-score above 96%, indicating competitive performance relative to published UNSW-NB15 benchmarks, while demonstrating improved performance over baseline machine learning and single-model deep learning approaches on UNSW-NB15. Through comprehensive evaluation using confusion matrix, ROC-AUC curves, precision and recall metrics, and computational efficiency, we established evidence of the model’s efficacy for real-time deployments. The findings show that the model achieves strong detection accuracy while maintaining a reasonable balance between precision and false alarms.

Downloads

Published

2025-12-01

How to Cite

Karimullah, Khushbu Khalid Butt, Rania Naveed, Maria Tariq, & Khadija Javed. (2025). A Hybrid CNN–LSTM-Based Intrusion Detection System Trained on UNSW-NB15 for Accurate Cyber Threat Detection. Journal of Computing & Biomedical Informatics. Retrieved from https://jcbi.org/index.php/Main/article/view/1129

Issue

Section

Articles