Leveraging CNN-LSTM Networks for Real-Time Intrusion Detection and Classification in IoT

PDF (1418KB), PP.377-397

Views: 0 Downloads: 0

Author(s)

Sabeena S. 1,* Chitra S. 1

1. Department of Computer Science, Bishop Heber College, Bharathidasan University, Trichy, Tamil Nadu, India

* Corresponding author.

DOI: https://doi.org/10.5815/ijwmt.2026.05.23

Received: 5 Mar. 2026 / Revised: 28 May 2026 / Accepted: 27 Aug. 2026 / Published: 8 Oct. 2026

Index Terms

Intrusion Detection Systems, Internet of Things, Deep Learning, Convolutional Neural Networks, Long Short Term Memory

Abstract

The IoT (Internet of Things) devices extend the attack surface for cybercriminals, requiring robust IDS (Intrusion Detection Systems). In order to tackle the issues, the AI (Artificial Intelligence), especially the ML (Machine Learning) and DL (Deep Learning) is incorporated into IoT IDS to analyze large datasets, identify complex patterns, and adapt to evolving threats. Hence, the study proposes a modified CNN-LSTM model for real-time intrusion detection and classification in IoT Device Network Logs. The proposed model utilizes the CNNs (Convolutional Neural Networks) for spatial feature extraction and LSTM (Long Short-Term Memory) networks for capturing temporal dependencies, augmenting the accuracy and detection efficiency. The proposed CNN-LSTM model enhances the real-time intrusion detection and contains the ability to detect developing attacks in dynamic IoT environments, which makes it highly flexible for large-scale deployments. The IoT Device Network Logs dataset is used for evaluating the proposed modified CNN-LSTM model. The modified CNN-LSTM model is assessed using the performance metrics such as accuracy, precision, recall, F1-score, time complexity and false alarm rate. As a result, the modified CNN-LSTM model achieves superior performance and earlier detection in contrast to the conventional models deliberating its potential for enhancing IoT security. 

Cite This Paper

Sabeena S., Chitra S., "Leveraging CNN-LSTM Networks for Real-Time Intrusion Detection and Classification in IoT", International Journal of Wireless and Microwave Technologies(IJWMT), Vol.16, No.5, pp. 377-397, 2026. DOI:10.5815/ijwmt.2026.05.23

Reference

[1]Z. Yang, X. Liu, T. Li, D. Wu, J. Wang, Y. Zhao, and H. Han, "A systematic literature review of methods and datasets for anomaly-based network intrusion detection," Computers & Security, vol. 116, Art. no. 102675, 2022.
[2]S. Muneer, U. Farooq, A. Athar, M. Ahsan Raza, T. M. Ghazal, and S. J. J. o. E. Sakib, "A critical review of artificial intelligence based approaches in intrusion detection: A comprehensive analysis," Journal of Engineering vol. 2024, no. 1, p. 3909173, 2024, doi: https://doi.org/10.1155/2024/3909173.
[3]M. Shafi, A. H. Lashkari, A. H. J. J. o. N. Roudsari, and S. Management, "Toward Generating a Large Scale Intrusion Detection Dataset and Intruders Behavioral Profiling Using Network and Transportation Layers Traffic Flow Analyzer (NTLFlowLyzer)," Journal of Network Systems Management vol. 33, no. 2, p. 44, 2025, doi: https://doi.org/10.1007/s10922-025-09917-0.
[4]E. Hallaji, R. Razavi-Far, M. J. C. Saif, and Security, "Expanding analytical capabilities in intrusion detection through ensemble-based multi-label classification," Computers Security vol. 139, p. 103730, 2024, doi: https://doi.org/10.1016/j.cose.2024.103730.
[5]H. Satilmiş, S. Akleylek, and Z. Y. J. I. A. Tok, "A systematic literature review on host-based intrusion detection systems," Ieee Access vol. 12, pp. 27237-27266, 2024, doi: 10.1109/ACCESS.2024.3367004.
[6]O. I. Falowo, M. Ozer, C. Li, and J. B. J. I. A. Abdo, "Evolving malware & ddos attacks: Decadal longitudinal study," IEEE Access 2024, doi: 10.1109/ACCESS.2024.3376682.
[7]B. Isong, O. Kgote, and A. J. E. Abu-Mahfouz, "Insights into Modern Intrusion Detection Strategies for Internet of Things Ecosystems," Electronics vol. 13, no. 12, p. 2370, 2024, doi: https://doi.org/10.3390/electronics13122370.
[8]K. K. BN, R. Balakrishna, and M. P. Rao, "AN ENSEMBLE COGNITIVE LEARNING-BASED INTRUSION DETECTION SYSTEM FOR SECURE IOT ENVIRONMENTS," doi: https://doie.org/10.0113/Jbse.2025967844.
[9]A. Zohourian, S. Dadkhah, H. Molyneaux, E. C. P. Neto, A. A. J. C. Ghorbani, and Security, "IoT-PRIDS: Leveraging packet representations for intrusion detection in IoT networks," Computers Security vol. 146, p. 104034, 2024, doi: https://doi.org/10.1016/j.cose.2024.104034.
[10]S. Remya, M. J. Pillai, C. Arjun, S. R. Subbareddy, and Y. J. I. A. yun Cho, "Enhancing security in llns using a hybrid trust-based intrusion detection system for rpl," IEEE Access 2024, doi: 10.1109/ACCESS.2024.3391918.
[11]S. Tabbassum, R. K. J. V. R. Pathak, and I. Hardware, "Effective data transmission through energy-efficient clus-tering and fuzzy-based IDS routing approach in WSNs," Virtual Reality Intelligent Hardware vol. 6, no. 1, pp. 1-16, 2024, doi: https://doi.org/10.1016/j.vrih.2022.10.002.
[12]A. I. Gide and A. A. J. B. J. o. I. o. T. Mu’azu, "A real-time intrusion detection system for dos/ddos attack classification in IoT networks using KNN-neural network hybrid technique," Babylonian Journal of Internet of Things vol. 2024, pp. 60-69, 2024, doi: https://doi.org/10.58496/BJIoT/2024/008.
[13]M. Thankappan, H. Rifà-Pous, and C. J. I. J. o. I. S. Garrigues, "A distributed and cooperative signature-based intrusion detection system framework for multi-channel man-in-the-middle attacks against protected Wi-Fi networks," International Journal of Information Security vol. 23, no. 6, pp. 3527-3546, 2024, doi: https://doi.org/10.1007/s10207-024-00899-9.
[14]H. Fereidouni, O. Fadeitcheva, M. J. S. Zalai, and Privacy, "IoT and man‐in‐the‐middle attacks," Security Privacy vol. 8, no. 2, p. e70016, 2025, doi: https://doi.org/10.1002/spy2.70016.
[15]S. Javanmardi, M. Ghahramani, M. Shojafar, M. Alazab, A. M. J. C. Caruso, and Security, "M-RL: A mobility and impersonation-aware IDS for DDoS UDP flooding attacks in IoT-Fog networks," Computers Security vol. 140, p. 103778, 2024, doi: https://doi.org/10.1016/j.cose.2024.103778.
[16]S. Racherla, P. Sripathi, N. Faruqui, M. A. Kabir, M. Whaiduzzaman, and S. A. J. I. A. Shah, "Deep-IDS: A Real-Time Intrusion Detector for IoT Nodes Using Deep Learning," IEEE Access 2024, doi: 10.1109/ACCESS.2024.3396461.
[17]B. Sharma, L. Sharma, C. Lal, and S. J. E. S. w. A. Roy, "Explainable artificial intelligence for intrusion detection in IoT networks: A deep learning based approach," Expert Systems with Applications vol. 238, p. 121751, 2024, doi: 10.1016/j.eswa.2023.121751.
[18]J. Manokaran and G. J. I. A. Vairavel, "Dl-ads: Improved grey wolf optimization enabled ae-lstm technique for efficient network anomaly detection in internet of thing edge computing," IEEE Access 2024, doi: 10.1109/ACCESS.2024.3405628.
[19]B. Xu, L. Sun, X. Mao, R. Ding, and C. Liu, "IoT intrusion detection system based on machine learning," Electronics, vol. 12, no. 20, Art. no. 4289, 2023.
[20]E. Altulaihan, M. A. Almaiah, and A. J. S. Aljughaiman, "Anomaly detection IDS for detecting DoS attacks in IoT networks based on machine learning algorithms," Sensors  vol. 24, no. 2, p. 713, 2024, doi: https://doi.org/10.3390/s24020713.
[21]M. Sarhan, S. Layeghy, N. Moustafa, M. Gallagher, M. J. D. C. Portmann, and Networks, "Feature extraction for machine learning-based intrusion detection in IoT networks," Digital Communications Networks vol. 10, no. 1, pp. 205-216, 2024, doi: https://doi.org/10.1016/j.dcan.2022.08.012.
[22]R. Kumar, M. J. J. o. N. Swarnkar, and C. Applications, "QuIDS: A Quantum Support Vector machine-based Intrusion Detection System for IoT networks," Journal of Network Computer Applications vol. 234, p. 104072, 2025, doi: https://doi.org/10.1016/j.jnca.2024.104072.
[23]H. Nandanwar and R. J. E. S. w. A. Katarya, "Deep learning enabled intrusion detection system for Industrial IOT  environment," Expert Systems with Applications  vol. 249, p. 123808, 2024, doi: 10.1016/j.eswa.2024.123808.
[24]R. Alasmari and A. A. J. I. A. Alhogail, "Protecting smart-home IoT devices from MQTT attacks: An empirical study of ML-based IDS," IEEE Access vol. 12, pp. 25993-26004, 2024, doi: 10.1109/ACCESS.2024.3367113.
[25]F. Wahab, A. Shah, I. Khan, B. Ali, M. J. C. Adnan, and E. Engineering, "An SDN-based Hybrid-DL-driven cognitive intrusion detection system for IoT ecosystem," Computers Electrical Engineering vol. 119, p. 109545, 2024, doi: https://doi.org/10.1016/j.compeleceng.2024.109545.
[26]M. Benmalek, A. J. D. S. Seddiki, and Management, "Particle swarm optimization-enhanced machine learning and deep learning techniques for Internet of Things intrusion detection," Data Science Management 2025, doi: https://doi.org/10.1016/j.dsm.2025.02.005.
[27]M. B. Musthafa et al., "Optimizing IoT intrusion detection using balanced class distribution, feature selection, and ensemble machine learning techniques," Sensors vol. 24, no. 13, p. 4293, 2024, doi: https://doi.org/10.3390/s24134293.
[28]M. A. Qathrady et al., "SACNN‐IDS: A self‐attention convolutional neural network for intrusion detection in industrial internet of things," CAAI Transactions on Intelligence Technology vol. 9, no. 6, pp. 1398-1411, 2024, doi: https://doi.org/10.1049/cit2.12352.
[29]L. Saraladeve et al., "A Multiclass Attack Classification Framework for IoT Using Hybrid Deep Learning Model," Journal of Cybersecurity Information Management vol. 15, no. 1, 2025, doi: 10.54216/JCIM.150112.
[30]S. Abbas et al., "Evaluating deep learning variants for cyber-attacks detection and multi-class classification in IoT networks," PeerJ Computer Science vol. 10, p. e1793, 2024, doi: 10.7717/peerj-cs.1793.
[31]A. Momand, S. U. Jan, and N. J. W. P. C. Ramzan, "ABCNN-IDS: attention-based convolutional neural network for intrusion detection in IoT networks," Wireless Personal Communications vol. 136, no. 4, pp. 1981-2003, 2024, doi: https://doi.org/10.1007/s11277-024-11260-7.
[32]C. Hazman, A. Guezzaz, S. Benkirane, M. J. T. S. Azrour, and Technology, "Enhanced IDS with deep learning for IoT-based smart cities security," Tsinghua Science Technology vol. 29, no. 4, pp. 929-947, 2024, doi: 10.26599/TST.2023.9010033.
[33]A. Rajak and R. J. I. J. o. I. T. Tripathi, "DL-SkLSTM approach for cyber security threats detection in 5G enabled IIoT," International Journal of Information Technology vol. 16, no. 1, pp. 13-20, 2024, doi: https://doi.org/10.1007/s41870-023-01651-7.
[34]S. Hizal, U. Cavusoglu, and D. J. I. o. T. Akgun, "A novel deep learning-based intrusion detection system for IoT DDoS security," Internet of Things vol. 28, p. 101336, 2024, doi: https://doi.org/10.1016/j.iot.2024.101336.
[35]B. Olanrewaju-George, B. J. C. S. Pranggono, and Applications, "Federated learning-based intrusion detection system for the internet of things using unsupervised and supervised deep learning models," Cyber Security Applications vol. 3, p. 100068, 2025, doi: https://doi.org/10.1016/j.csa.2024.100068.