Logo Lanfrica

Bayesian-Optimised Compact CNN-LSTM for Efficient Network Intrusion Detection: A Cross-Dataset Evaluation

Domaine:

digital infrastructure

Type de record:

paper
Créateur:
ChrGusSte
Éditeur:
Eas
Hôte:
Intrusion detection research has consistently prioritised classification accuracy while treating computational cost as a secondary concern, producing models that perform well on individual benchmarks but whose efficiency properties, and whether those properties hold consistently across different network environments, are rarely evaluated systematically. Using a quantitative, experimental research design, this paper presents a Bayesian-optimised compact CNN-LSTM intrusion detection model and evaluates whether a favourable accuracy-efficiency trade-off, once achieved through hardware-aware hyperparameter optimisation, generalises across structurally heterogeneous benchmarks rather than being an artefact of a single dataset. Using a composite optimisation objective that jointly penalises inference latency and parameter count alongside macro-F1, the proposed model converges to architectures of 8,258 to 12,905 trainable parameters, a reduction of 70.8 to 81.4 per cent relative to a non-optimised baseline, across three heterogeneous benchmarks: InSDN (SDN), ToN-IoT (IoT telemetry), and Edge-IIoTset (edge-IoT). Six of nine optimised hyperparameters converge to consistent values across all three benchmarks, and a penalty weight sensitivity analysis confirms this compact configuration is a structural property of the optimisation objective rather than a per-dataset coincidence. The model achieves macro-F1 between 81.20% and 88.76% across the three benchmarks, with per-sample inference latency of 2.2 to 2.4 ms at batch size 1 on a controlled GPU benchmark, and performance differences across the eight evaluated methods are confirmed statistically significant by Friedman and Kruskal-Wallis tests. Gradient boosting baselines (XGBoost, LightGBM, CatBoost) consistently achieve higher macro-F1 than the compact CNN-LSTM across all three benchmarks, a finding this paper reports directly rather than minimises. The results characterise a reproducible, cross-dataset accuracy-efficiency trade-off pattern for compact sequential IDS models in resource-constrained deployment contexts, illustrated here with documented infrastructure and threat data from Sub-Saharan African institutional networks, presented as one practically relevant setting in which this trade-off is potentially meaningful, rather than as a claim validated through deployment on target hardware.