arXiv Machine Learning

A Hybrid CNN-LSTM Intrusion Detection Framework for Cybersecurity in Smart Renewable Energy Grids

arXiv:2606. 25200v1 Announce Type: new Abstract: The accelerated digitalization of renewable energy smart grids through IoT sensors, AMI, and SCADA systems has significantly expanded the attack surface for sophisticated cyberattacks, FDI attacks that stealthily distort state estimation and DoS/DDoS attacks that flood communication channels.

arXiv Machine Learning
Jun 5

Hybrid CNN-LSTM Framework for Intelligent Cyber Attack Detection and Prevention in U.S. Critical Digital Infrastructure: A Comparative Machine Learning Evaluation on CSE-CIC-IDS2018

arXiv:2606. 05714v1 Announce Type: cross Abstract: Digital infrastructure is growing at a rapid pace in the United States, and as a result, exposure to advanced cyber threats to critical sectors including healthcare, finance, transportation, energy and government systems is growing.

By Md. Iqbal Hossan, Md. Serajul Kabir Chowdhury Rubel, Md. Arifur Rahman, B. M. Taslimul Haque
arXiv Machine Learning
Jun 10

Do Transformers Actually Help Intrusion Detection? A Temporal Sequence Evaluation on CIC-IDS2017

arXiv:2606. 11098v1 Announce Type: cross Abstract: Recent deep learning approaches for network intrusion detection increasingly incorporate temporal architectures such as recurrent networks and Transformers, often reporting near-perfect performance on CIC-IDS2017.

By Zach Moczkodan (Royal Military College of Canada, Kingston, Canada), Hany Ragab (Royal Military College of Canada, Kingston, Canada)
arXiv Machine Learning
Jun 5

An Improved CNN-LSTM Based Intrusion Detection System for IoT Networks

arXiv:2606. 05776v1 Announce Type: cross Abstract: With the rapid proliferation of IoT devices, security concerns have dramatically escalated and intrusion detection systems have become critical for protecting networked environments.

By Mohammad Tariq Ikhlas, Pohanyar Khowaja Khil, Malik Muhammad Mueed Aslam, Muhammad Khuram Shahzad
arXiv Machine Learning
Sep 25

Unmasking Shortcut Learning in IoT Intrusion Detection: A Forensic, Multi-Paradigm Evaluation of Feature Dependence and Data Leakage

The paper investigates whether machine learning models for IoT intrusion detection truly learn attack patterns or rely on dataset shortcuts. Using the CyberFlowIoT-GICAP benchmark, the authors evaluate four learning paradigms across different feature sets and split strategies, finding that performance is largely driven by feature representation and that tree-based models can exploit temporal artifacts. The study also highlights asymmetric attack detectability and proposes a four-point protocol checklist for realistic evaluation.

By Uday Shankar Roy, Mahbuba Jahan Minu
arXiv Machine Learning
Aug 19

Diff-DDoS: Realistic Cyber-Physical Attack Synthesis and Robust Detection for 5G-Enabled CPS Using Tabular Diffusion Models

Diff‑DDoS is a three‑phase framework that uses tabular diffusion models to generate realistic cyber‑physical attacks and strengthen DDoS detectors for 5G‑enabled systems. First, a CNN cell‑level detector is trained on call detail record (CDR) grids; second, a tabular denoising diffusion probabilistic model (TabDDPM) learns normal CDR aggregates to synthesize realistic attacks; third, adversarial diffusion training (ADT) iteratively produces hard, distribution‑preserving samples that harden the detector. On the Milano CDR dataset, ResNet50 with ADT achieves near‑perfect F1‑scores across multiple attack scenarios, outperforming existing synthetic‑data methods such as CTGAN.

By Bilal Hussain, Xiao Tang, Qinghe Du, Tan Li, Muhammad Azhar, Danista Khan