Hybrid CNN–LSTM Intrusion Detection Framework for Industrial IoT Security
DOI:
https://doi.org/10.65080/mjai.v1.CM2601105006Keywords:
Industrial internet of things, intrusion detection system, deep learning, CNN–LSTM, network security, temporal traffic analysis, false alarm rate, cyber-physical systemsAbstract
Introduction: The rapid adoption of the Industrial Internet of Things (IIoT) has increased the exposure of safety-critical industrial systems to sophisticated cyberattacks, requiring intrusion detection mechanisms that are accurate, computationally efficient, and operationally reliable. Traditional intrusion detection systems often struggle with correlated traffic descriptors, temporal attack evolution, false alarm control, and deployment-level reliability in resource-constrained industrial environments.
Methodology: This study proposes a lightweight hybrid CNN–LSTM intrusion detection framework for binary IIoT attack detection. Convolutional layers learn compact representations from high-dimensional statistical traffic descriptors, while an LSTM layer captures short-term temporal dependencies associated with multi-stage and slow-rate attacks. The model was evaluated on the BoTNeTIoT-L01 Industrial IoT benchmark using a leakage-controlled split, imbalance-aware metrics, threshold-specific false alarm analysis, probability calibration, temporal robustness assessment, and CPU-only inference benchmarking.
Results: The proposed CNN–LSTM achieved accuracy = 0.99875, precision = 0.99930, recall/sensitivity = 0.99820, F1-score = 0.99875, and FAR = 0.00070 on the held-out test set. At the selected deployment threshold, the model produced a ROC operating point with TPR = 0.99820 and FPR = 0.00070. Same-split baseline and ablation comparisons further demonstrated that the proposed model provided a strong balance between detection performance, false-alarm control, calibration reliability, and CPU inference efficiency.
Conclusion: The results indicate that the proposed CNN–LSTM framework is suitable for near-real-time IIoT intrusion detection where low false alarms, calibrated confidence, temporal stability, and lightweight deployment are critical.
References
S. F. Ahmed, M. S. Alam, M. Hoque, A. Lameesa, S. Afrin, T. Farah, M. Kabir, G. M. Shafiullah, and S. M. Muyeen, "Industrial Internet of Things enabled technologies, challenges, and future directions," Comput. Electr. Eng., vol. 110, Art. no. 108847, 2023, https://doi.org/10.1016/j.compeleceng.2023.108847
A. Buja, Cybersecurity of Industrial Internet of Things (IIoT). Routledge, 2026, Available from: https://www.routledge.com/Cybersecurity-of-Industrial-Internet-of-Things-IIoT/Buja/p/book/9781032467832
A. Mustafa, F. Trad, and A. Chehab, "Leveraging large language models for reducing false positives and prioritizing alerts in intrusion detection systems," in Proc. Int. Conf. Adv. Inf. Netw. Appl., Cham, Switzerland: Springer Nature Switzerland, 2025, pp. 432-443, https://doi.org/10.1007/978-3-031-87772-8_37
A. Kaur, "Intrusion detection approach for industrial Internet of Things traffic using deep recurrent reinforcement learning assisted federated learning," IEEE Trans. Artif. Intell., vol. 6, no. 1, pp. 37-50, 2025, https://doi.org/10.1109/TAI.2024.3443787
M. Landauer, F. Skopik, B. Stojanović, A. Flatscher, and T. Ullrich, "A review of time-series analysis for cyber security analytics: From intrusion detection to attack prediction," Int. J. Inf. Secur., vol. 24, no. 1, Art. no. 3, 2025, https://doi.org/10.1007/s10207-024-00921-0
A. Balla, M. H. Habaebi, M. R. Islam, and S. Mubarak, "Applications of deep learning algorithms for supervisory control and data acquisition intrusion detection system," Cleaner Eng. Technol., vol. 9, Art. no. 100532, 2022, https://doi.org/10.1016/j.clet.2022.100532
O. Polat, A. A. Ahmad, S. Oyucu, E. Algül, F. Doğan, and A. Aksöz, "Temporal-spatial feature extraction in IoT-based SCADA system security: Hybrid CNN-LSTM and attention-based architectures for malware classification and attack detection," IEEE Access, vol. 13, pp. 102109-102132, 2025, https://doi.org/10.1109/ACCESS.2025.3577761
W. Oñate and R. Sanz, "Fog computing architecture for load balancing in parallel production with a distributed MES," Appl. Sci., vol. 15, no. 13, Art. no. 7438, 2025,https://doi.org/10.3390/app15137438
A. Q. Khan, N. Tamani, S. El Jaouhari, and L. Mroueh, "A contextual derivation algorithm for cybersecurity in IoT environments," in Proc. IEEE 22nd Int. Conf. Trust, Secur. Privacy Comput. Commun. (TrustCom), pp. 1430-1435, 2023, https://doi.org/10.1109/TrustCom60117.2023.00195
I. Ahmad, M. N. Amin, K. Hamid, S. M. Rizwan, and S. A. Naqvi, "Enhanced IoT network security for network intrusion detection," Int. J. Comput. Eng. Technol., vol. 3, no. 8, 2025, https://doi.org/10.63075/0vcg0093
L. Mohammadpour, T. C. Ling, C. S. Liew, and A. Aryanfar, "A survey of CNN-based network intrusion detection," Appl. Sci., vol. 12, no. 16, Art. no. 8162, 2022, https://doi.org/10.3390/app12168162
K. Noor, A. L. Imoize, C. T. Li, and C. Y. Weng, "A review of machine learning and transfer learning strategies for intrusion detection systems in 5G and beyond," Mathematics, vol. 13, no. 7, Art. no. 1088, 2025, https://doi.org/10.3390/math13071088
A. S. Gaafar, J. M. Dahr, and A. K. Hamoud, "Comparative analysis of performance of deep learning classification approach based on LSTM-RNN for textual and image datasets," Informatica, vol. 46, no. 5, 2022, https://doi.org/10.31449/inf.v46i5.3872
Y. Tang, Y. Wang, C. Liu, X. Yuan, K. Wang, and C. Yang, "Semi-supervised LSTM with historical feature fusion attention for temporal sequence dynamic modeling in industrial processes," Eng. Appl. Artif. Intell., vol. 117, no. A, Art. no. 105547, 2023, https://doi.org/10.1016/j.engappai.2022.105547
A. Nazir, J. He, N. Zhu, S. S. Qureshi, S. U. Qureshi, F. Ullah, A. Wajahat, and M. S. Pathan, "A deep learning-based novel hybrid CNN-LSTM architecture for efficient detection of threats in the IoT ecosystem," Ain Shams Eng. J., vol. 15, no. 7, Art. no. 102777, 2024, https://doi.org/10.1016/j.asej.2024.102777
M. Sajid, K. R. Malik, A. Almogren, T. S. Malik, A. H. Khan, J. Tanveer, and A. U. Rehman, "Enhancing intrusion detection: A hybrid machine and deep learning approach," J. Cloud Comput., vol. 13, no. 1, Art. no. 123, 2024, https://doi.org/10.1186/s13677-024-00685-x
D. M. Afraji, J. Lloret, and L. Peñalver, "An integrated hybrid deep learning framework for intrusion detection in IoT and IIoT networks using CNN-LSTM-GRU architecture," Computation, vol. 13, no. 9, Art. no. 222, 2025, https://doi.org/10.3390/computation13090222
C. K. Wikle and A. Zammit-Mangion, "Statistical deep learning for spatial and spatiotemporal data," Annu. Rev. Stat. Its Appl., vol. 10, no. 1, pp. 247-270, 2023, https://doi.org/10.1146/annurev-statistics-033021-112628
X. Liu, J. Shan, C. Liu, S. Zhang, D. Zhang, Z. Hao, and S. Huang, "An operating condition diagnosis method for electric submersible screw pumps based on CNN-ResNet-RF," Processes, vol. 13, no. 7, Art. no. 2043, 2025, https://doi.org/10.3390/pr13072043
K. Bansal and A. Singhrova, "Review on intrusion detection system for IoT/IIoT: Brief study," Multimed. Tools Appl., vol. 83, no. 8, pp. 23083-23108, 2024, https://doi.org/10.1007/s11042-023-16395-6
A. Nascita, G. Aceto, D. Ciuonzo, A. Montieri, V. Persico, and A. Pescapé, "A survey on explainable artificial intelligence for Internet traffic classification and prediction, and intrusion detection," IEEE Commun. Surv. Tutor., vol. 27, no. 5, pp. 3165-3198, 2025, https://doi.org/10.1109/COMST.2024.350495
S. Rekik and S. Mehmood, "Hybrid GNN-LSTM defense with differential privacy and secure multi-party computation for edge-optimized neuromorphic autonomous systems," Sci. Rep., vol. 15, no. 1, Art. no. 43939, 2025, https://doi.org/10.1038/s41598-025-27691-6
U. K. Lilhore, P. Manoharan, S. Simaiya, R. Alroobaea, M. Alsafyani, A. M. Baqasah, S. Dalal, A. Sharma, and K. Raahemifar, "HIDM: Hybrid intrusion detection model for Industry 4.0 networks using an optimized CNN-LSTM with transfer learning," Sensors, vol. 23, no. 18, Art. no. 7856, 2023, https://doi.org/10.3390/s23187856
H. C. Altunay and Z. Albayrak, "A hybrid CNN+LSTM-based intrusion detection system for industrial IoT networks," Eng. Sci. Technol. Int. J., vol. 38, Art. no. 101322, 2023, https://doi.org/10.1016/j.jestch.2022.101322
H. Gupta, A. Jadhav, and A. S. Bisht, "Comparative analysis of machine and deep learning models for intrusion detection in fog-enabled IoT networks," Int. J. Netw. Distrib. Comput., vol. 14, no. 1, Art. no. 1, 2026, https://doi.org/10.1007/s44227-025-00079-8
N. Verma, N. Kumar, K. K. Almuzaini, A. Sinha, S. A. Hussain, "A real-time intelligent intrusion detection framework for robotic system cybersecurity," Peer-to-Peer Netw. Appl., vol. 19, no. 1, Art. no. 30, 2026, https://doi.org/10.1007/s12083-025-02175-6
T. B. Ogunseyi, G. Thiyagarajan, H. He, V. Bist, and Z. Du, "Performance analysis of explainable deep learning-based intrusion detection systems for IoT networks: A systematic review," Sensors, vol. 26, no. 2, Art. no. 363, 2026, https://doi.org/10.3390/s26020363
S. Kalyani and D. Vydeki, "A resource-efficient ensemble machine learning framework for detecting rank attacks in RPL-based IoT networks," J. Economy Technol., vol. 4, pp. 171-185, 2026, https://doi.org/10.1016/j.ject.2025.06.003
M. Zahid and T. S. Bharati, "Leveraging machine learning and deep learning in IoT security: A review," Secur. Privacy, vol. 9, no. 1, Art. no. e70144, 2026, https://doi.org/10.1002/spy2.70144
Q. Alasad, M. Ahmed, S. Alahmed, O. T. Khattab, S. A. Abdulwahhab, and J. S. Yuan, "A comprehensive review: The evolving cat-and-mouse game in network intrusion detection systems leveraging machine learning," J. Cybersecur. Privacy, vol. 6, no. 1, Art. no. 13, 2026, https://doi.org/10.3390/jcp6010013
A. Alhowaide, "IoT Dataset for Intrusion Detection Systems (IDS)," Kaggle, Dataset, 2023. Available from: https://www.kaggle.com/datasets/azalhowaide/iot-dataset-for-intrusion-detection-systems-ids. (Accessed on: 9 July 2026).
J. Jose and D. V. Jose, "AS-CL IDS: Anomaly and signature-based CNN-LSTM intrusion detection system for Internet of Things," Int. J. Adv. Technol. Eng. Explor., vol. 10, no. 109, pp. 1622-1639, 2023, http://doi.org/10.19101/IJATEE.2022.10100187
Z. Benamor, Z. A. Seghir, M. Djezzar, and M. Hemam, "A comparative study of machine learning algorithms for intrusion detection in IoT networks," Rev. d'Intell. Artif., vol. 37, no. 3, pp. 567-576, 2023, https://doi.org/10.18280/ria.370305
M. Z. Mahmud, S. Islam, S. R. Alve, and A. Jubayer Pial, “Optimized IoT Intrusion Detection using Machine Learning Technique,” in Proc. IEEE 3rd Int. Conf. Robot., Autom., Artif.-Intell. Internet-of-Things (RAAICON), Dhaka, Bangladesh, 2024, pp. 167–172, https://doi.org/10.1109/RAAICON64172.2024.10928532
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Mushtaq Ali, Imad Ullah (Authors)

This work is licensed under a Creative Commons Attribution 4.0 International License.