An Efficacious Feature Fusion-based approach for Network Intrusion Detection using Attention Mechanism | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article An Efficacious Feature Fusion-based approach for Network Intrusion Detection using Attention Mechanism Divya Nehra, Veenu Mangat, Krishan Kumar This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-6579811/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract A Network Intrusion Detection System (NIDS) analyses incoming network traffic at strategic points within a network to detect any abnormal or malignant activity. A malignant activity is termed as an intrusion. From a machine learning perspective, network intrusion detection is essentially a multi-classification task with various types of known and unknown intrusions. The accuracy of the detection can be significantly improved by intelligent feature engineering. The primary challenge is that feature extraction problem in NIDS is aggravated by the large scale high dimensional network traffic data. Additionally, there is the challenge related to capability of the model to generalise between different networks. The proposed approach in this paper attempts to alleviate above issues by utilizing models of deep learning for intrusion detection in a novel manner. After initial preprocessing of data, the efficacious features are extracted by application of two techniques in parallel: the first technique uses a Autoencoder (AE) to learn the latent patterns in data, and the second technique uses a customised Residual Network (ResNet) model to extract features from network traffic. The features identified from these two techniques are then made to undergo late feature fusion to obtain a complete set of network traffic input features. Further, an Attention Mechanism (AM) based method is used to obtain optimal feature set by assigning different attention weights to input features. Finally, detection of intrusions is done by employing embedded Convolutional Neural Network (CNN) layers. The CNN is used for learning the changes occurring in abnormal i.e. network attack data. Extensive experimentation is done to compare proposed approach with other state-of-the-art techniques. Experimental results obtained over three benchmark datasets for four performance metrics- accuracy, precision, recall and F1-Score, clearly demonstrate the superior performance of proposed approach, both for binary as well as multiple intrusion detection problem. Network Intrusion Attention Mechanism Feature Fusion Deep Learning Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-6579811","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":467913407,"identity":"51de2924-30e0-4946-b4d5-06ed0c09a37f","order_by":0,"name":"Divya Nehra","email":"","orcid":"","institution":"Panjab University","correspondingAuthor":false,"prefix":"","firstName":"Divya","middleName":"","lastName":"Nehra","suffix":""},{"id":467913408,"identity":"286c2fb7-e032-4221-affa-b0c32c763189","order_by":1,"name":"Veenu Mangat","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAAuElEQVRIiWNgGAWjYBADOSgtQbQOA2PStSQ2EK/22uFnD7/U/EnfLpHA+OEHg0UeYS2308yNZY4Z5O6ckcAs2cMgUUxQi+TsBDNpCTaD3A03EhikgX4h7ELJ2enfpCX+GaQb3Ehg/k2UFn7pHDPJj20GCUAtbMTZAtRSJs3YZ2y4s+dhm2WPARFa2KTTt0n++CYnb86efPjGj4o64kKbmQdIGDAwNoBI4gDjDwbiFY+CUTAKRsEIBAAPoDU+bDecYQAAAABJRU5ErkJggg==","orcid":"","institution":"Panjab University","correspondingAuthor":true,"prefix":"","firstName":"Veenu","middleName":"","lastName":"Mangat","suffix":""},{"id":467913409,"identity":"04616cf3-e919-4914-987f-3bf76db77461","order_by":2,"name":"Krishan Kumar","email":"","orcid":"","institution":"Panjab University","correspondingAuthor":false,"prefix":"","firstName":"Krishan","middleName":"","lastName":"Kumar","suffix":""}],"badges":[],"createdAt":"2025-05-02 16:23:17","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-6579811/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-6579811/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":103817578,"identity":"b8189d7f-0d96-47d6-904f-d260d75ba94a","added_by":"auto","created_at":"2026-03-03 09:27:38","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":674229,"visible":true,"origin":"","legend":"","description":"","filename":"ClusterComputingSubmissionmanuscript1May2025.pdf","url":"https://assets-eu.researchsquare.com/files/rs-6579811/v1_covered_a0d5a67c-961e-47a8-9c0f-4f0b42538fea.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"An Efficacious Feature Fusion-based approach for Network Intrusion Detection using Attention Mechanism","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"Network Intrusion, Attention Mechanism, Feature Fusion, Deep Learning","lastPublishedDoi":"10.21203/rs.3.rs-6579811/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-6579811/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eA Network Intrusion Detection System (NIDS) analyses incoming network traffic at strategic points within a network to detect any abnormal or malignant activity. A malignant activity is termed as an intrusion. From a machine learning perspective, network intrusion detection is essentially a multi-classification task with various types of known and unknown intrusions. The accuracy of the detection can be significantly improved by intelligent feature engineering. The primary challenge is that feature extraction problem in NIDS is aggravated by the large scale high dimensional network traffic data. Additionally, there is the challenge related to capability of the model to generalise between different networks. The proposed approach in this paper attempts to alleviate above issues by utilizing models of deep learning for intrusion detection in a novel manner. After initial preprocessing of data, the efficacious features are extracted by application of two techniques in parallel: the first technique uses a Autoencoder (AE) to learn the latent patterns in data, and the second technique uses a customised Residual Network (ResNet) model to extract features from network traffic. The features identified from these two techniques are then made to undergo late feature fusion to obtain a complete set of network traffic input features. Further, an Attention Mechanism (AM) based method is used to obtain optimal feature set by assigning different attention weights to input features. Finally, detection of intrusions is done by employing embedded Convolutional Neural Network (CNN) layers. The CNN is used for learning the changes occurring in abnormal i.e. network attack data. Extensive experimentation is done to compare proposed approach with other state-of-the-art techniques. Experimental results obtained over three benchmark datasets for four performance metrics- accuracy, precision, recall and F1-Score, clearly demonstrate the superior performance of proposed approach, both for binary as well as multiple intrusion detection problem.\u003c/p\u003e","manuscriptTitle":"An Efficacious Feature Fusion-based approach for Network Intrusion Detection using Attention Mechanism","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2025-06-09 09:04:25","doi":"10.21203/rs.3.rs-6579811/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"44a1f896-1a02-466b-aa2f-0bfd4cc7f834","owner":[],"postedDate":"June 9th, 2025","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2026-03-03T09:26:07+00:00","versionOfRecord":[],"versionCreatedAt":"2025-06-09 09:04:25","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-6579811","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-6579811","identity":"rs-6579811","version":["v1"]},"buildId":"XKTyCvWXoU3ODBz1xrDgd","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.