{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/deep-learning-applications-for-intrusion","title":"Deep Learning Applications for Intrusion Detection in Network Traffic","arxiv_id":null,"date":"2024-01-13","proceeding":"Proceedings of the Institute for System Programming of the RAS (Proceedings of ISP RAS) 2024 1","authors":["Aleksandr Getman","Maxim Goryunov","Andrey Matskevich","Dmitry Rybolovlev","Anastasiya Nikolskaya"],"abstract":"The paper discusses the issues of applying deep learning methods for detecting computer attacks in network traffic. The results of the analysis of relevant studies and reviews of deep learning applications for intrusion detection are presented. The most used deep learning methods are discussed and compared. The classification system of deep learning methods for intrusion detection is proposed. Current trends and challenges of applying deep learning methods for detecting computer attacks in network traffic are identified. The CNN-BiLSTM neural network is synthesized to assess the applicability of deep learning methods for intrusion detection. The synthesized neural network is compared to the previously developed model based on the use of the Random Forest classifier. The usage of the deep learning method enabled to simplify the feature engineering stage, and evaluation metrics of Random Forest and CNN-BiLSTM models are close. This confirms the prospects for the application of deep learning methods for intrusion detection.","url_abs":"https://www.researchgate.net/publication/377458356_Deep_Learning_Applications_for_Intrusion_Detection_in_Network_Traffic","url_pdf":"https://ispranproceedings.elpub.ru/jour/article/view/1696/1505","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"deep-learning-applications-for-intrusion","repo_url":"https://github.com/fisher85/ml-cybersecurity/tree/master/python-web-attack-detection","is_official":1,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"none","reach":null}],"tasks":[{"task_slug":"deep-learning","task_name":"Deep Learning"},{"task_slug":"feature-engineering","task_name":"Feature Engineering"},{"task_slug":"intrusion-detection","task_name":"Intrusion Detection"},{"task_slug":"network-intrusion-detection","task_name":"Network Intrusion Detection"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[{"leaderboard":"/sota/network-intrusion-detection-on-cicids2017","task":"Network Intrusion Detection","dataset":"CICIDS2017","model":"CNN-BiLSTM","rank_in_archive_order":4,"of":5,"metrics":{"Avg F1":"0.908","Precision":"95.9","Recall":"86.2"},"uses_additional_data":true}],"syntology":{"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}