Addressing Class Imbalance in Network Intrusion Detection: An Enhanced Hybrid Deep Learning Framework with Advanced Sampling and Attention Mechanisms

preprint OA: closed CC-BY-4.0
📄 Open PDF Full text JSON View at publisher

Abstract

Abstract Network intrusion detection systems (NIDS) are critical components of cybersecurity infrastructure, yet they face significant challenges when dealing with highly imbalanced datasets where critical attack types comprise less than 0.001\% of network traffic. This severe class imbalance leads to poor detection rates for rare but potentially devastating attacks such as Heartbleed, SQL injection, and infiltration attempts. This paper proposes an adaptive SMOTE-based sampling strategy combined with feature selection to address extreme class imbalance in the CIC-IDS2017 dataset, which exhibits an imbalance ratio of 191,678:1. Our methodology involves comprehensive data preprocessing, XGBoost-based feature selection reducing dimensionality from 78 to 50 features, and an adaptive SMOTE strategy that strategically oversamples minority classes based on their severity and rarity. The proposed approach achieved a 99.9\% improvement in class imbalance ratio (from 191,678:1 to 204:1), increasing minority class samples by up to 1,916 times for Heartbleed attacks, 958 times for SQL injection, and 583 times for infiltration attempts. Experimental results using a Random Forest classifier demonstrated 99.79\% overall accuracy on 504,473 test samples, with significant improvements in detecting specific minority classes including SSH-Patator (97.5\% accuracy) and Bot attacks (60.1\% accuracy). While some ultra-rare classes with fewer than 10 test samples presented ongoing challenges, the study validates the effectiveness of adaptive sampling strategies for improving minority class representation in highly imbalanced network intrusion datasets. The framework demonstrates practical applicability for cloud computing environments where diverse attack patterns must be detected despite severe data imbalance.
Full text 13,408 characters · extracted from preprint-html · click to expand
Addressing Class Imbalance in Network Intrusion Detection: An Enhanced Hybrid Deep Learning Framework with Advanced Sampling and Attention Mechanisms | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Addressing Class Imbalance in Network Intrusion Detection: An Enhanced Hybrid Deep Learning Framework with Advanced Sampling and Attention Mechanisms Oluwapelumi Bankole This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-8542449/v1 This work is licensed under a CC BY 4.0 License Status: Under Review Version 1 posted 10 You are reading this latest preprint version Abstract Network intrusion detection systems (NIDS) are critical components of cybersecurity infrastructure, yet they face significant challenges when dealing with highly imbalanced datasets where critical attack types comprise less than 0.001% of network traffic. This severe class imbalance leads to poor detection rates for rare but potentially devastating attacks such as Heartbleed, SQL injection, and infiltration attempts. This paper proposes an adaptive SMOTE-based sampling strategy combined with feature selection to address extreme class imbalance in the CIC-IDS2017 dataset, which exhibits an imbalance ratio of 191,678:1. Our methodology involves comprehensive data preprocessing, XGBoost-based feature selection reducing dimensionality from 78 to 50 features, and an adaptive SMOTE strategy that strategically oversamples minority classes based on their severity and rarity. The proposed approach achieved a 99.9% improvement in class imbalance ratio (from 191,678:1 to 204:1), increasing minority class samples by up to 1,916 times for Heartbleed attacks, 958 times for SQL injection, and 583 times for infiltration attempts. Experimental results using a Random Forest classifier demonstrated 99.79% overall accuracy on 504,473 test samples, with significant improvements in detecting specific minority classes including SSH-Patator (97.5% accuracy) and Bot attacks (60.1% accuracy). While some ultra-rare classes with fewer than 10 test samples presented ongoing challenges, the study validates the effectiveness of adaptive sampling strategies for improving minority class representation in highly imbalanced network intrusion datasets. The framework demonstrates practical applicability for cloud computing environments where diverse attack patterns must be detected despite severe data imbalance. Network intrusion detection Class imbalance SMOTE Deep learning Feature selection CIC-IDS2017 Minority class detection Adaptive sampling Cybersecurity Cloud computing security Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Under Review Version 1 posted Reviewers agreed at journal 14 May, 2026 Reviewers agreed at journal 12 May, 2026 Reviews received at journal 22 Mar, 2026 Reviewers agreed at journal 19 Mar, 2026 Reviewers agreed at journal 06 Mar, 2026 Reviewers agreed at journal 03 Mar, 2026 Reviewers invited by journal 03 Mar, 2026 Editor assigned by journal 09 Jan, 2026 Submission checks completed at journal 08 Jan, 2026 First submitted to journal 07 Jan, 2026 You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-8542449","acceptedTermsAndConditions":true,"allowDirectSubmit":false,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":601327788,"identity":"24daed45-6198-4563-aa7d-07409fd2edb2","order_by":0,"name":"Oluwapelumi Bankole","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA+ElEQVRIiWNgGAWjYBACAwYGZgaGAiCLHYgTKoAEM3MDEVoMGMAUQ8IZEIORFC2MbSAxAlrM2c8eNvhgYJPHz8xjuuHhvNpo/naglh8V23BqsezJS06cYZBWLNnMY3Yjcdvx3BmHGRsYe87cxu2wAznGh3kMDiduOAzWciy3AaiFmbENj5bzb0Ba/ifuB2uZcyx3PkEtN3KMk3kMDiRuYAZpaajJ3UBIi+WMN8aGMwySiyUOs5XdSDh2IHcjUMtBfH4x588xlvhQYZfH39687eaPmrrceecPH3zwowK3FhhIgNKHweQBguqRtNQRo3gUjIJRMApGGAAASrJcTnc3EHkAAAAASUVORK5CYII=","orcid":"","institution":"University of Nevada, Las Vegas","correspondingAuthor":true,"prefix":"","firstName":"Oluwapelumi","middleName":"","lastName":"Bankole","suffix":""}],"badges":[],"createdAt":"2026-01-07 14:09:02","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-8542449/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-8542449/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":104402646,"identity":"7320e532-a55e-4188-85af-d943ad414f26","added_by":"auto","created_at":"2026-03-11 12:15:59","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":1687480,"visible":true,"origin":"","legend":"","description":"","filename":"Paper2.pdf","url":"https://assets-eu.researchsquare.com/files/rs-8542449/v1_covered_41036769-21b7-4018-957a-f89b15514fbb.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Addressing Class Imbalance in Network Intrusion Detection: An Enhanced Hybrid Deep Learning Framework with Advanced Sampling and Attention Mechanisms","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"journal-of-cloud-computing","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"clco","sideBox":"Learn more about [Journal of Cloud Computing](http://journalofcloudcomputing.springeropen.com)","snPcode":"13677","submissionUrl":"https://submission.nature.com/new-submission/13677/3","title":"Journal of Cloud Computing","twitterHandle":"@SpringerOpen","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"BMC/SO AJ","inReviewEnabled":true,"inReviewRevisionsEnabled":true},"keywords":"Network intrusion detection, Class imbalance, SMOTE, Deep learning, Feature selection, CIC-IDS2017, Minority class detection, Adaptive sampling, Cybersecurity, Cloud computing security","lastPublishedDoi":"10.21203/rs.3.rs-8542449/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-8542449/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\nNetwork intrusion detection systems (NIDS) are critical components of cybersecurity infrastructure, yet they face significant challenges when dealing with highly imbalanced datasets where critical attack types comprise less than 0.001\\% of network traffic. This severe class imbalance leads to poor detection rates for rare but potentially devastating attacks such as Heartbleed, SQL injection, and infiltration attempts. This paper proposes an adaptive SMOTE-based sampling strategy combined with feature selection to address extreme class imbalance in the CIC-IDS2017 dataset, which exhibits an imbalance ratio of 191,678:1. Our methodology involves comprehensive data preprocessing, XGBoost-based feature selection reducing dimensionality from 78 to 50 features, and an adaptive SMOTE strategy that strategically oversamples minority classes based on their severity and rarity. The proposed approach achieved a 99.9\\% improvement in class imbalance ratio (from 191,678:1 to 204:1), increasing minority class samples by up to 1,916 times for Heartbleed attacks, 958 times for SQL injection, and 583 times for infiltration attempts. Experimental results using a Random Forest classifier demonstrated 99.79\\% overall accuracy on 504,473 test samples, with significant improvements in detecting specific minority classes including SSH-Patator (97.5\\% accuracy) and Bot attacks (60.1\\% accuracy). While some ultra-rare classes with fewer than 10 test samples presented ongoing challenges, the study validates the effectiveness of adaptive sampling strategies for improving minority class representation in highly imbalanced network intrusion datasets. The framework demonstrates practical applicability for cloud computing environments where diverse attack patterns must be detected despite severe data imbalance.\n","manuscriptTitle":"Addressing Class Imbalance in Network Intrusion Detection: An Enhanced Hybrid Deep Learning Framework with Advanced Sampling and Attention Mechanisms","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2026-03-06 03:22:16","doi":"10.21203/rs.3.rs-8542449/v1","editorialEvents":[{"type":"communityComments","content":0},{"type":"reviewerAgreed","content":"3541407952778504847781871402051835473","date":"2026-05-14T17:51:12+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"119827641910603195908343826815400602044","date":"2026-05-13T02:55:36+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2026-03-22T22:15:05+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"235182894219395402725991598138622513564","date":"2026-03-19T14:56:51+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"233749138373442336463367953984051131344","date":"2026-03-06T17:48:56+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"99063509262055457704494599605068903269","date":"2026-03-03T13:14:51+00:00","index":"hide","fulltext":""},{"type":"reviewersInvited","content":"","date":"2026-03-03T12:44:08+00:00","index":"","fulltext":""},{"type":"editorAssigned","content":"","date":"2026-01-09T08:42:34+00:00","index":"","fulltext":""},{"type":"checksComplete","content":"","date":"2026-01-08T18:45:36+00:00","index":"","fulltext":""},{"type":"submitted","content":"Journal of Cloud Computing","date":"2026-01-07T14:00:31+00:00","index":"","fulltext":""}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"journal-of-cloud-computing","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"clco","sideBox":"Learn more about [Journal of Cloud Computing](http://journalofcloudcomputing.springeropen.com)","snPcode":"13677","submissionUrl":"https://submission.nature.com/new-submission/13677/3","title":"Journal of Cloud Computing","twitterHandle":"@SpringerOpen","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"BMC/SO AJ","inReviewEnabled":true,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"dae2c545-d15f-4dd6-959a-e7cc0b536f03","owner":[],"postedDate":"March 6th, 2026","published":true,"recentEditorialEvents":[{"type":"reviewerAgreed","content":"3541407952778504847781871402051835473","date":"2026-05-14T17:51:12+00:00","index":86,"fulltext":""},{"type":"reviewerAgreed","content":"119827641910603195908343826815400602044","date":"2026-05-13T02:55:36+00:00","index":85,"fulltext":""}],"rejectedJournal":[],"revision":"","amendment":"","status":"under-review","subjectAreas":[],"tags":[],"updatedAt":"2026-03-06T03:22:16+00:00","versionOfRecord":[],"versionCreatedAt":"2026-03-06 03:22:16","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-8542449","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-8542449","identity":"rs-8542449","version":["v1"]},"buildId":"XKTyCvWXoU3ODBz1xrDgd","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2026) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00
unpaywall
last seen: 2026-05-30T02:00:01.510937+00:00
License: CC-BY-4.0