SCDF-CNN-BiGRU: A Spatial-Contextual Dual Feature Fusion Framework for Multi dataset Hierarchical Network Intrusion Detection

Main Article Content

Aseel M. Mahdi
Haider K. Hoomod

Abstract

Network Intrusion Detection Systems (NIDSs) are deployed and constitute an essential component of modern network defense against adversaries employing more and more advanced cyberattack strategies. Nevertheless, maintaining high detection accuracy in heterogeneous network environments still faces great challenges because of the diversity of traffic patterns and attack behaviors. This paper proposes a new Spatial–Contextual Dual-Feature Fusion (SCDF-CNN-BiGRU) framework in the context of hierarchical network intrusion detection employing multiple benchmark cybersecurity datasets. The proposed framework utilizes a lightweight shared convolutional neural network (CNN) feature extraction stage followed by 2 parallel and complimentary learning branches. The first branch employs Bidirectional Gated Recurrent Unit (BiGRU) to extract temporal dependencies and contextual relationships of network traffic while the second one adopts bidirectional convolutional processing to learn discriminative spatial representations. The features extracted from both branches are then fused via feature aggregation module to create an overall traffic representation. It also establishes hierarchical intrusion analysis through binary attack detection and multi-class attack categorization, along with an attack-level mapping strategy to connect different levels of attack types and the corresponding highly representative fine-grained attack descriptions. The framework was evaluated using six heterogeneous benchmark datasets, including UNSW-NB15, NSL-KDD, NF-ToN-IoT-v3, CICIOT2023, BCCC and CIC-UNSW-NB15. Experimental results showed strong detection performance with binary classification accuracies of up to 0.999 and multi-class accuracies of up to 0.988. These findings indicate that the proposed SCDF-CNN-BiGRU framework gives robust representations and consistent performance across multiple heterogeneous datasets via unified learning and ensemble inference.

Downloads

Download data is not yet available.

Article Details

Section

Articles

Author Biography

Haider K. Hoomod, Computer Department, College of Education, Al-Mustansiriyah University

استاذ دكتور في قسم الحاسوب كلية التربية الجامعة المستنصرية 

How to Cite

“SCDF-CNN-BiGRU: A Spatial-Contextual Dual Feature Fusion Framework for Multi dataset Hierarchical Network Intrusion Detection” (2026) Journal of Engineering, 32(9), pp. 264–278. doi:10.31026/j.eng.2026.09.12.

References

Adefemi, K.O., M.B.M., and Alimi, O.A., 2025. A hybrid CNN–GRU deep learning model for IoT network intrusion detection. Journal of Sensor and Actuator Networks, 14(5), 96. https://doi.org/10.3390/jsan14050096

Akuthota, U.C., and Bhargava, L., 2025. Transformer-based intrusion detection for IoT networks. IEEE Internet of Things Journal, 12, pp. 6062–6067. https://doi.org/10.1109/JIOT.2025.3525494.

Alabbadi, A., and Bajaber, F., 2025. X-FuseRLSTM: A cross-domain explainable intrusion detection framework in IoT using the attention-guided dual-path feature fusion and residual LSTM. Sensors, 25(12), P. 3693. https://doi.org/10.3390/s25123693.

Alalwany, E., Alsharif, B., Alotaibi, Y., Alfahaid, A., Mahgoub, I., and Ilyas, M., 2025. Stacking ensemble deep learning for real-time intrusion detection in IoMT environments. Sensors, 25(3), P. 624. https://doi.org/10.3390/s25030624 .

Alayash, W., Rahrouh, M., Ibrahim, A.A., Mohamed, M.H., Ahmed, S.T., Albarri, M.H., and Ahmed, M.H., 2026. Assessing LSTM and GRU for multi-dataset intrusion detection in IoT environments. Statistics, Optimization & Information Computing, 15(4), pp. 3155–3173. https://doi.org/10.19139/soic-2310-5070-3226.

Ayantayo, A., Kaur, A., Schmid, A., and Waismann, B., 2023. Network intrusion detection using feature fusion with deep learning. Journal of Big Data, 10, P. 167. https://doi.org/10.1186/s40537-023-00834-0.

Bamber, S.S., Katkuri, A.V.R., Sharma, S. and Angurala, M., 2025. A hybrid CNN-LSTM approach for intelligent cyber intrusion detection system. Computers & Security, 148, P. 104146. https://doi.org/10.1016/j.cose.2024.104146.

Canadian Institute for Cybersecurity, 2025. UNSW-NB15 Augmented Dataset. University of New Brunswick. Available at: https://www.unb.ca/cic/datasets/cic-unsw-nb15.html [Accessed 27 June 2025].

Dai, W., Li, X., Ji, W., and He, S., 2024. Network intrusion detection method based on CNN, BiLSTM, and attention mechanism. IEEE Access, 12, pp. 53099–53111. https://doi.org/10.1109/ACCESS.2024.3385928.

Dhanabal, L., and Shantharajah, D.S.P., 2015. A study on NSL-KDD dataset for intrusion detection system based on classification algorithms. https://doi.org/10.17148/IJARCCE.2015.4696 .

Gaspar, D., Antunes, A., and Bacao, F., 2024. Explainable AI for intrusion detection systems: LIME and SHAP applicability on multi-layer perceptron. IEEE Access, 12, pp. 30164–30178. https://doi.org/10.1109/ACCESS.2024.3368377.

Hussein, M.A., Alazawi, S.A.H., and Hoomod, H.K., 2026. Analysis of hybrid OS security using machine learning and deep learning. In: Advanced Engineering, Technology and Applications on Power Systems. Cham: Springer Nature Switzerland. https://doi.org/10.1007/978-3-032-13921-4_47 .

Imrana, Y., Xiang, Y., Ali, L., Noor, A., Sarpong, K., and Abdullah, A. A., 2024. CNN-GRU-FF: A double-layer feature fusion-based network intrusion detection system using convolutional neural network and gated recurrent units. Complex & Intelligent Systems, 10, pp. 3353–3370. https://doi.org/10.1007/s40747-023-01313-y.

Kaur, J., Randhawa, S.K., and Singh, S., 2025. Ensemble learning approaches for multi-class intrusion detection systems for the Internet of Vehicles: A comprehensive survey. Future Internet, 17(7), P. 317. https://doi.org/10.3390/fi17070317.

Kavitha, P., and Harini, S.R., 2026. A dual-path hybrid deep learning framework with BiLSTM, multi-head attention, and intelligent feature engineering in IoT networks. Research Square Preprint. https://doi.org/10.21203/rs.3.rs-9302453/v1.

Li, B., Li, J., and Jia, M., 2025. ADFCNN-BiLSTM: A deep neural network based on attention and deformable convolution for network intrusion detection. Sensors, 25(5), P. 1382. https://doi.org/10.3390/s25051382.

Liu, L., and Xu, M., 2025. A network intrusion detection method based on contrastive learning and Bayesian Gaussian Mixture Model. Cybersecurity, 8(1), P. 59. https://doi.org/10.1186/s42400-025-00364-7 .

Liu, S., Yu, Y., Zong, Y., Yeoh, P.L., Guo, L., Vucetic, B., Duong, T.Q., and Li, Y., 2024. Delay and energy-efficient asynchronous federated learning for intrusion detection in heterogeneous industrial internet of things. IEEE Internet of Things Journal, 11(8), pp. 14739–14754. https://doi.org/10.1109/JIOT.2023.3335112.

Ma, X., Liang, J., and Yin, G., 2025. IoT intrusion detection technology based on DenseNet1D and Bi-GRU hybrid model. Discover Applied Sciences, 8(2), P. 115. https://doi.org/10.1007/s42452-025-08126-3 .

Mishra, S., Alshammari, N.S., Hussain, H., and Alfahidah, R.A., 2026. A cross-dataset harmonized intrusion detection framework with statistically validated multi-model learning. PLOS ONE, 21(4), P. e0346982. https://doi.org/10.1371/journal.pone.0346982 .

Mohammed, A.M., and Hoomod, H.K., 2026. A two-stage hybrid intrusion detection framework based on hierarchical attack mapping and pruned CNN-GRU models. Engineering, Technology & Applied Science Research, 16(1), pp. 32342–32347. https://doi.org/10.48084/etasr.16210.

Moustafa, N., and Slay, J., 2015. UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In: 2015 Military Communications and Information Systems Conference (MilCIS), Australia, pp. 1–6. https://doi.org/10.1109/MilCIS.2015.7348942 .

Nandanwar, H., and Katarya, R., 2024. Deep learning enabled intrusion detection system for industrial IoT environment. Expert Systems with Applications, 249, P. 123808. https://doi.org/10.1016/j.eswa.2024.123808.

Nandanwar, H., and Katarya, R., 2025. Securing Industry 5.0: An explainable deep learning model for intrusion detection in cyber-physical systems. Computers & Electrical Engineering, 123, P. 110161. https://doi.org/10.1016/j.compeleceng.2025.110161.

Neto, E.C.P., Dadkhah, S., Ferreira, R., Zohourian, A., Lu, R., and Ghorbani, A.A., 2023. CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment. Sensors, 23(13), https://doi.org/10.3390/s23135941 .

Peng, H., Wu, C., and Xiao, Y., 2023. CBF-IDS: Addressing class imbalance using CNN-BiLSTM with focal loss in network intrusion detection system. Applied Sciences,13(21), P. 11629. https://doi.org/10.3390/app132111629.

Sagu, A., Gill, N.S., Gulia, P., Alduaiji, N., Shukla, P.K., and Shah, M.A., 2025. Advances to IoT security using a GRU-CNN deep learning model trained on SUCMO algorithm. Scientific Reports, 15(1), P. 16485. https://doi.org/10.1038/s41598-025-99574-9.

Sarhan, M., Layeghy, S., Moustafa, N., and Portmann, M., 2021. NetFlow datasets for machine learning-based network intrusion detection systems. In: Deze, Z., Huang, H., Hou, R., Rho, S. and Chilamkurti, N., eds. Big Data Technologies and Applications. Cham: Springer. https://doi.org/10.1007/978-3-030-72802-1_9 .

Shafi, M., Lashkari, A.H., Rodriguez, V., and Nevo, R., 2024. Toward generating a new cloud-based distributed denial of service (DDoS) dataset and cloud intrusion traffic characterization. Information, 15(4), P. 195. https://doi.org/10.3390/info15040195 .

Sharma, S.B., and Bairwa, A.K., 2025. Leveraging AI for intrusion detection in IoT ecosystems: A comprehensive study. IEEE Access, 13, pp. 66290–66317. https://doi.org/10.1109/ACCESS.2025.3556701.

Thaljaoui, A., 2025. Intelligent network intrusion detection system using optimized deep CNN-LSTM with UNSW-NB15. International Journal of Information Technology. https://doi.org/10.1007/s41870-025-02416-0.

Wang, Z., Zainal, A., Siraj, M.M., Ghaleb, F.A., Hao, X., and Han, S., 2025. An intrusion detection model based on convolutional Kolmogorov-Arnold networks. Scientific Reports, 15(1), P. 1917. https://doi.org/10.1038/s41598-025-85700-4.

Xi, C., Wang, H., and Wang, X., 2024. A novel multi-scale network intrusion detection model with transformer. Scientific Reports, 14, P. 23239. https://doi.org/10.1038/s41598-024-74419-5.

Xu, H., Sun, L., Fan, G., Li, W., and Kuang, G., 2023. A hierarchical intrusion detection model combining multiple deep learning models with attention mechanism. IEEE Access, 11, pp. 66212–66226. https://doi.org/10.1109/ACCESS.2023.3290613.

Yang, K., Wang, J., and Li, M., 2024. An improved intrusion detection method for IIoT using attention mechanisms, BiGRU, and Inception-CNN. Scientific Reports, 14(1), P. 19339. https://doi.org/10.1038/s41598-024-70094-2.

Yaras, S., and Dener, M., 2024. IoT-based intrusion detection system using new hybrid deep learning algorithm. Electronics, 13, P. 1053. https://doi.org/10.3390/electronics13061053.

Zahid, M., and Bharati, T.S., 2025. Enhancing cybersecurity in IoT systems: A hybrid deep learning approach for real-time attack detection. Discover Internet of Things, 5, P. 73. https://doi.org/10.1007/s43926-025-00083-w.

Similar Articles

You may also start an advanced similarity search for this article.