Related Experiment Videos
Metaheuristic-driven LSTM framework for advanced cyberthreat detection and response using a hybrid firefly-whale-grey
Sreekanth Rallapalli1,2, Weiwei Jiang3,4
1Lincoln University College, Petaling Jaya, Malaysia. sreekanth.rallapalli@nmit.ac.in.
Scientific Reports
|June 20, 2026
Summary
This study introduces a novel hybrid intrusion detection system (IDS) combining Long Short-Term Memory (LSTM) networks with bio-inspired algorithms for enhanced cyber threat detection. The advanced model significantly improves accuracy in identifying sophisticated cyberattacks.
Area of Science:
- Cybersecurity
- Artificial Intelligence
- Machine Learning
Background:
- Conventional signature-based Intrusion Detection Systems (IDSs) struggle against advanced cyber threats like APTs, zero-day exploits, and polymorphic malware.
- The dynamic nature of modern cyber threats necessitates more adaptive and intelligent detection mechanisms.
Purpose of the Study:
- To develop a novel, three-step hybrid optimization model for enhanced intrusion detection.
- To leverage the pattern-learning capabilities of Long Short-Term Memory (LSTM) networks combined with metaheuristic algorithms for improved accuracy and robustness.
Main Methods:
- A hybrid model integrating LSTM networks with three bio-inspired algorithms: Firefly Algorithm (FA) for feature selection, Whale Optimization Algorithm (WOA) for LSTM parameter tuning, and Grey Wolf Optimizer (GWO) for ensemble weight optimization.
- The framework was rigorously tested on the NSL-KDD and CICIDS2017 benchmark datasets using a protocol of 30 independent runs.
Main Results:
- The hybrid model achieved high detection accuracy: 98.62% on NSL-KDD (SD 0.21) and 99.1% on CICIDS2017 (SD 0.18).
- Achieved a low False Positive Rate (FPR) of 1.2% and a high Area Under the ROC Curve (AUC-ROC) of 0.992.
- Statistical significance was confirmed using Wilcoxon signed-rank and paired t-tests (p < 0.001).
Conclusions:
- The proposed hybrid optimization model demonstrates significant potential for near-real-time cyber threat detection.
- Further validation in real-world network environments is recommended to fully assess its practical applicability.