A Multi-Head Attention and Residual Dense Network with Dynamic Sampling for Fine-Grained Network Intrusion Classification
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216305%3A26220%2F26%3A0201253" target="_blank" >RIV/00216305:26220/26:0201253 - isvavai.cz</a>
Result on the web
<a href="http://dx.doi.org/10.1109/icumt67815.2025.11268763" target="_blank" >http://dx.doi.org/10.1109/icumt67815.2025.11268763</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1109/icumt67815.2025.11268763" target="_blank" >10.1109/icumt67815.2025.11268763</a>
Alternative languages
Result language
angličtina
Original language name
A Multi-Head Attention and Residual Dense Network with Dynamic Sampling for Fine-Grained Network Intrusion Classification
Original language description
Network Intrusion Detection Systems are essential for monitoring and analyzing network traffic to detect and prevent unauthorized access, malicious activities, and security breaches in real time. Network intrusion detection systems face persistent challenges in accurately identifying finegrained attack subcategories due to class imbalance, limited feature interactions in tabular data, and variability across different time windows. Models often struggle to capture the hidden patterns required for multi-class classification in imbalanced flow-based datasets. To overcome these limitations, this work proposes a deep learning framework that combines Multi-Head Self-Attention (MHSA) with Residual Dense Blocks (RDBs) for fine-grained intrusion classification. The MHSA layers enable the model to learn complex, non-sequential feature dependencies by attending multiple feature interactions simultaneously. The RDBs enhance depth and gradient stability, facilitating effective learning in deep networks, especially under sparse class conditions. A dynamic sampling strategy is incorporated during training, employing SMOTE for oversampling minority classes and random under-sampling of majority classes to ensure balanced learning. The model is trained and evaluated on the large dataset across four temporal resolutions (5s, 10s, 30s, 60s), targeting classification across 13 subcategories. The proposed architecture achieves a peak accuracy of 99.89% on the 10 -second window and maintains high recall across rare attack types such as recon-dns and brute force-ftp. This methodology demonstrates a robust and scalable solution for real-time, multi-class intrusion detection, offering improvements in accuracy, fairness, and adaptability over existing baseline models.
Czech name
—
Czech description
—
Classification
Type
O - Miscellaneous
CEP classification
—
OECD FORD branch
20200 - Electrical engineering, Electronic engineering, Information engineering
Result continuities
Project
<a href="/en/project/FW10010014" target="_blank" >FW10010014: Novel AI-Driven Process Automation for Simplifying and Enhancing Telecommunication Processes</a><br>
Continuities
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Others
Publication year
2025
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů