Deep Learning-Based Intrusion Detection System for Industrial IoT Networks: A Comparative Evaluation of CNN-LSTM, Transformer, and Autoencoder Architectures on the CIC-IDS-2018 Dataset
Abstract
The proliferation of Internet of Things (IoT) devices in industrial automation, smart manufacturing, and critical infrastructure — collectively termed Industrial IoT (IIoT) — has created an expansive and heterogeneous attack surface that traditional signature-based intrusion detection systems (IDS) are ill-equipped to defend. Machine-to-machine communication protocols (MQTT, OPC-UA, Modbus TCP), legacy supervisory control and data acquisition (SCADA) systems, and resource-constrained sensor nodes operating in deterministic real-time environments present unique cybersecurity challenges that demand anomaly-based detection approaches capable of identifying zero-day attacks and novel attack variants from network traffic patterns alone, without prior knowledge of attack signatures. This paper presents a systematic comparative evaluation of three deep learning architectures — a hybrid Convolutional Neural Network-Long Short-Term Memory (CNN-LSTM) model, a multi-head self-attention Transformer encoder, and a Variational Autoencoder (VAE) — for network intrusion detection on the CIC-IDS-2018 benchmark dataset (16 million traffic flows, 14 attack categories). After class-imbalance correction via Synthetic Minority Oversampling Technique (SMOTE), the CNN-LSTM model achieves macro-average F1-score of 0.9724, outperforming the Transformer (0.9681) and VAE (0.9512) on the held-out test set. Critically, the CNN-LSTM demonstrates superior detection of low-volume attacks (Infiltration: F1 = 0.912) that pose the greatest operational risk in IIoT environments. Inference latency analysis confirms that the CNN-LSTM and Transformer models satisfy real-time detection requirements (latency < 2 ms per flow on NVIDIA RTX 3060) while the VAE's reconstruction-based detection introduces unacceptable latency for real-time deployment. The paper concludes with a deployment architecture recommendation for edge-cloud hierarchical IDS in IIoT environments.
Keywords: Industrial IoT, intrusion detection, deep learning, CNN-LSTM, Transformer, Variational Autoencoder, CIC-IDS-2018, network security, anomaly detection, SMOTE
References
- [1] Guo, L., Wu, Q., Liu, S., Duan, M., Li, H., & Sun, J. (2021). Deep learning-based real-time anomaly detection for industrial IoT. IEEE Internet of Things Journal, 8(8), 6926-6934.
- [2] Mirsky, Y., Doitshman, T., Elovici, Y., & Shabtai, A. (2018). Kitsune: An ensemble of autoencoders for online network intrusion detection. Proceedings of NDSS Symposium 2018.
- [3] Shone, N., Ngoc, T. N., Phai, V. D., & Shi, Q. (2018). A deep learning approach to network intrusion detection. IEEE Transactions on Emerging Topics in Computational Intelligence, 2(1), 41-50.
- [4] Vaswani, A., Shazeer, N., Parmar, N., Uszkoreit, J., Jones, L., Gomez, A. N., & Polosukhin, I. (2017). Attention is all you need. Advances in Neural Information Processing Systems, 30.
- [5] Wang, W., Zhu, M., Zeng, X., Ye, X., & Sheng, Y. (2017). Malware traffic classification using convolutional neural network for representation learning. Proceedings of ICOIN 2017, 712-717.
- [6] Yin, C., Zhu, Y., Fei, J., & He, X. (2017). A deep learning approach for intrusion detection using recurrent neural networks. IEEE Access, 5, 21954-21961.
- [7] Zhang, Y., Chen, X., Jin, L., Wang, X., & Guo, D. (2019). Network intrusion detection: Based on deep hierarchical network and original flow data. IEEE Access, 7, 37004-37016.
- [8] Sharafaldin, I., Habibi Lashkari, A., & Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. Proceedings of ICISSP 2018, 108-116.
- [9] Pahl, M. O., & Aubet, F. X. (2018). All eyes on you: Distributed multi-dimensional IoT microservice anomaly detection. Proceedings of IFIP/IEEE NOMS 2018, 1-9.
- [10] Diro, A. A., & Chilamkurti, N. (2018). Distributed attack detection scheme using deep learning approach for Internet of Things. Future Generation Computer Systems, 82, 761-768.
- [11] Chawla, N. V., Bowyer, K. W., Hall, L. O., & Kegelmeyer, W. P. (2002). SMOTE: Synthetic minority over-sampling technique. Journal of Artificial Intelligence Research, 16, 321-357.
Explore Our Related Journals
Looking for the right journal for your next manuscript? Explore our international peer-reviewed journals covering engineering, management, computer science, artificial intelligence and multidisciplinary research.