Related Experiment Videos
Self-learning model fusion for network anomaly detection: A hybrid CNN-LSTM-transformer framework
Jun Wang1,2, Ning Huang1,2, Houzhong Zhang1,2
1College of Computer Science and Technology, Shenyang University of Chemical Technology, Shenyang, Liaoning, China.
Plos One
|October 29, 2025
Summary
This study introduces a hybrid deep learning framework for network anomaly detection, featuring a self-learning mechanism to adapt to evolving cyber threats and maintain high detection accuracy.
Area of Science:
- Cybersecurity
- Artificial Intelligence
- Network Security
Background:
- Rapidly evolving cyber threats challenge traditional anomaly detection systems.
- Existing systems struggle with adaptability and performance against novel attack patterns.
- Need for autonomous systems that can learn and adapt to dynamic threat landscapes.
Purpose of the Study:
- To develop an innovative hybrid deep learning framework for enhanced network traffic anomaly detection.
- To integrate Convolutional Neural Networks (CNN), Long Short-Term Memory (LSTM), and Transformer models with a self-learning mechanism.
- To improve the adaptability and robustness of anomaly detection systems against evolving cyber threats.
Main Methods:
- A synergistic two-stage model fusion architecture combining CNN, LSTM, and Transformer models.
- An adaptive learning mechanism with multi-metric drift detection for autonomous threat response.
- A knowledge preservation strategy to maintain detection capabilities during adaptation.
Main Results:
- CNN-LSTM model achieved F1-scores of 0.9778 (UNSW-NB15) and 0.9695 (CICIDS2017) for binary classification.
- LSTM-Transformer model achieved accuracies of 0.9632 and 0.9528 for specific anomaly type classification.
- Framework maintained an average accuracy of 0.955 over 15 days with induced concept drifts.
- Self-learning mechanism detected drifts and recovered performance within 23.4 hours, with a 92.8% detection rate for zero-day attacks.
Conclusions:
- The proposed hybrid deep learning framework effectively enhances network traffic anomaly detection.
- The self-learning mechanism provides autonomous adaptation to evolving threats and concept drifts.
- The framework demonstrates robustness and improved performance, offering a promising direction for future cybersecurity systems.