Master'sOpen AccessCrossrefindexed

Performance evaluation of deep learning models for intrusion detection using network traffic

2026
92 pages
3 views
0 downloads
Advisor: Dr. Öğr. Üyesi Samet TONYALI

Abstract (EN)

Digital infrastructures are growing rapidly and cyberattacks are becoming increasingly sophisticated. As a result, Network-based Intrusion Detection Systems have become a critical component of modern cybersecurity. Signature-based methods sometimes fail to detect new threats, where machine learning and deep learning can provide a valuable alternative. This study examines a one-dimensional Convolutional Neural Network and a hybrid model called CNN-BiLSTM, investigating how both architectures can detect network attacks in binary and multiclass classification settings. Both architectures were evaluated on the CIC-IDS2017 and UNSW-NB15 benchmark datasets through a rigorous experimental protocol incorporating stratified 5-fold cross-validation, Focal Loss, QuantileTransformer scaling, and SMOTE oversampling. Random Forest and XGBoost were additionally tested on UNSW-NB15 as classical baselines. The results show that CNN achieves near-perfect binary classification performance on CIC-IDS2017, with 99.75% accuracy and a ROC-AUC of 0.9999. CNN-BiLSTM reduces false negatives by approximately 36% in the binary UNSW-NB15 setting, albeit at the cost of 4–6 times higher inference latency. In multiclass classification, CNN outperforms CNN-BiLSTM on CIC-IDS2017 with a higher macro F1-Score (0.701 vs. 0.671). XGBoost achieves comparable F1 performance to deep learning models in significantly less training time, once again demonstrating the enduring value of ensemble methods. Minority attack class detection remains a fundamental unresolved challenge across all configurations, laying the groundwork for future research on class-wise threshold calibration and Transformer-based architectures. The findings provide actionable insights for practitioners choosing between deep learning and classical approaches under real-world NIDS deployment constraints.

How to Cite

Rachid Cheıck Mohamed (Master Thesis). Performance evaluation of deep learning models for intrusion detection using network traffic, 2026, pp. 1-92, Gümüşhane University, DOI: https://doi.org/10.71008/gumushane.thesis.2026.207.

Figures & Images (49)

Performance evaluation of deep learning models for intrusion detection using network traffic — Figure 1
Performance evaluation of deep learning models for intrusion detection using network traffic — Figure 2
Performance evaluation of deep learning models for intrusion detection using network traffic — Figure 3
Performance evaluation of deep learning models for intrusion detection using network traffic — Figure 4
Performance evaluation of deep learning models for intrusion detection using network traffic — Figure 5
Performance evaluation of deep learning models for intrusion detection using network traffic — Figure 6

DOI Status

Requested
Under Review
Approved
DOI Assigned

License

CC BY 4.0

This work is shared under the specified license terms.

More theses from Gümüşhane University