
Lightweight CNN–BiLSTM Intrusion Detection on the CICIoT2023 Benchmark: Balancing Multi-Class Accuracy and Edge Deployability | IJCT Volume 13 – Issue 4 | IJCT-V13I4P26
IJCT
International Journal of Computer Techniques
ISSN 2394-2231 · Peer-Reviewed · Open Access
📚 Volume 13, Issue 4
📅 August 24, 2026
📄 Pages 253–265
🔖 ID: IJCT-V13I4P26
Table of Contents
ToggleLightweight CNN–BiLSTM Intrusion Detection on the CICIoT2023 Benchmark: Balancing Multi-Class Accuracy and Edge Deployability
Author(s)
Mothanna Abu Judeh, Adnan H. Al-Helali
Abstract
IoT devices are now everywhere: smart homes, hospitals, factories, and surveillance networks. Most of them ship with weak default security and rarely get patched, which has made them an easy target. Signature-based intrusion detection systems miss attacks they have never seen before, and most deep learning alternatives are too heavy to run anywhere near the devices they are supposed to protect. This paper presents a hybrid model that pairs a one-dimensional convolutional neural network (1D-CNN) with a bidirectional long short-term memory network (BiLSTM). The CNN extracts spatial features from traffic records, and the BiLSTM captures how those features change over time. We train and evaluate the model on CICIoT2023, a recent benchmark containing 33 attacks in seven categories, including distributed denial of service (DDoS), Mirai botnet traffic, reconnaissance, spoofing, and web attacks. Preprocessing consists of class balancing, feature normalization, and feature reduction to keep the model small. The evaluation reports detection quality and computational cost together, comparing the hybrid against classical machine learning baselines and against standalone CNN and BiLSTM ablations, and measuring parameter count and central processing unit (CPU) inference latency rather than accuracy alone. We close by discussing the limits of the current design and two directions we plan to explore next: federated training across devices and explainable outputs for security analysts
Keywords
Internet of Things; intrusion detection; deep learning; CNN–BiLSTM; CICIoT2023; edge computing.
Conclusion
his paper set out to answer whether a compact hybrid deep learning model can detect intrusions in IoT traffic accurately enough to be useful while staying small enough to run at the network edge. The question came from a specific gap: hybrid CNN–recurrent architectures perform well on IoT intrusion detection, and lightweight versions of them have been shown to work on UNSW-NB15, but the combination had not been tested on CICIoT2023, where 33 attack types and a heavily skewed class distribution make the problem harder. The study proposed a 1D-CNN feeding a bidirectional LSTM, trained on a balanced subsample of CICIoT2023, and evaluated it on both binary and eight-category classification. Two things distinguish the evaluation from most of the work reviewed. Detection quality and computational cost are reported together, with parameter counts and CPU inference latency measured alongside accuracy. And the hybrid is compared against its own components in an ablation, so that the contribution of each half can be seen rather than assumed. Three findings follow from the results in Section IV. The ablation shows whether combining convolutional and recurrent layers earns its added cost, which is the question most hybrid IDS papers leave open. The gap between binary and multi-class performance confirms the pattern seen across the literature: separating benign from malicious traffic is close to solved on this data, while assigning attacks to the right category is not, and per-class results show the weakness concentrated in the smallest categories. And the cost measurements establish whether the model is deployable on gateway-class hardware, which is the claim that studies using Transformer-scale architectures for IoT security make implicitly without testing. The practical implication is modest but real. An organisation running IoT devices behind a gateway, whether that is a hospital, a municipality, or a protected area with surveillance cameras across remote sites, cannot install a server-scale model at every location. A model that fits on the gateway can flag a compromised device locally, before traffic reaches a central collector. Given that the devices most often compromised in the field are precisely the cameras and recorders that Mirai targeted, local detection has value independent of how sophisticated the model is. The limitations in Section IV-J bound these conclusions. Results describe a subsample rather than the full dataset; evaluation was offline rather than streaming; cross-dataset generalisation was not tested; and no adversarial evaluation was performed. The last is the most consequential for a security tool, since an attacker who knows a detector exists will try to work around it.
References
[1] IoT Analytics. (2025). State of IoT 2025: Number of connected IoT devices growing 14% to 21.1 billion globally. [Online]. Available: https://iot-analytics.com/number-connected-iot-devices/
[2] M. Antonakakis et al., “Understanding the Mirai botnet,” in Proc. 26th USENIX Security Symp., 2017, pp. 1093–1110.
[3] E. C. P. Neto, S. Dadkhah, R. Ferreira, A. Zohourian, R. Lu, and A. A. Ghorbani, “CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment,” Sensors, vol. 23, no. 13, art. no. 5941, 2023, doi: 10.3390/s23135941.
[4] S.-M. Tseng, Y.-Q. Wang, and Y.-C. Wang, “Multi-class intrusion detection based on Transformer for IoT networks using CIC-IoT-2023 dataset,” Future Internet, vol. 16, no. 8, art. no. 284, 2024, doi: 10.3390/fi16080284.
[5] A. Javed, A. Ehtsham, M. Jawad, M. N. Awais, A. H. Qureshi, and H. Larijani, “Implementation of lightweight machine learning-based intrusion detection system on IoT devices of smart homes,” Future Internet, vol. 16, no. 6, art. no. 200, 2024, doi: 10.3390/fi16060200.
[6] S. Hizal, U. Cavusoglu, and D. Akgun, “A novel deep learning-based intrusion detection system for IoT DDoS security,” Internet of Things, vol. 28, art. no. 101336, 2024, doi: 10.1016/j.iot.2024.101336.
[7] S. A. Wahab, S. Sultana, N. Tariq, M. Mujahid, J. A. Khan, and A. Mylonas, “A multi-class intrusion detection system for DDoS attacks in IoT networks using deep learning and transformers,” Sensors, vol. 25, no. 15, art. no. 4845, 2025, doi: 10.3390/s25154845.
[8] H. C. Altunay and Z. Albayrak, “A hybrid CNN+LSTM-based intrusion detection system for industrial IoT networks,” Eng. Sci. Technol., Int. J., vol. 38, art. no. 101322, 2023, doi: 10.1016/j.jestch.2022.101322.
[9] A. Nazir et al., “A deep learning-based novel hybrid CNN-LSTM architecture for efficient detection of threats in the IoT ecosystem,” Ain Shams Eng. J., vol. 15, no. 7, art. no. 102777, 2024, doi: 10.1016/j.asej.2024.102777.
[10] A. Gueriani, H. Kheddar, and A. C. Mazari, “Enhancing IoT security with CNN and LSTM-based intrusion detection systems,” in Proc. 6th Int. Conf. Pattern Analysis and Intelligent Systems (PAIS), 2024, pp. 1–7.
[11] S. Sadhwani, M. A. H. Khan, R. Muthalagu, P. M. Pawar, and K. Suresh, “A hybrid BiLSTM-CNN approach for intrusion detection for IoT applications,” Sci. Rep., vol. 16, art. no. 155, 2026, doi: 10.1038/s41598-025-29079-y.
[12] P. Sinha, D. Sahu, S. Prakash, T. Yang, R. S. Rathore, and V. K. Pandey, “A high performance hybrid LSTM CNN secure architecture for IoT environments using deep learning,” Sci. Rep., vol. 15, no. 1, pp. 1–26, 2025, doi: 10.1038/s41598-025-94500-5.
[13] H. Peng, C. Wu, and Y. Xiao, “CBF-IDS: Addressing class imbalance using CNN-BiLSTM with focal loss in network intrusion detection system,” Appl. Sci., vol. 13, no. 21, art. no. 11629, 2023, doi: 10.3390/app132111629.
[14] H. Alzahrani, T. Sheltami, A. Barnawi, M. Imam, and A. Yaser, “A lightweight intrusion detection system using convolutional neural network and long short-term memory in fog computing,” Comput. Mater. Continua, vol. 80, no. 3, pp. 4703–4728, 2024, doi: 10.32604/cmc.2024.054203.
[15] M. Jouhari and M. Guizani, “Lightweight CNN-BiLSTM based intrusion detection systems for resource-constrained IoT devices,” in Proc. Int. Wireless Commun. and Mobile Computing (IWCMC), 2024, doi: 10.1109/IWCMC61514.2024.10592352
[2] M. Antonakakis et al., “Understanding the Mirai botnet,” in Proc. 26th USENIX Security Symp., 2017, pp. 1093–1110.
[3] E. C. P. Neto, S. Dadkhah, R. Ferreira, A. Zohourian, R. Lu, and A. A. Ghorbani, “CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment,” Sensors, vol. 23, no. 13, art. no. 5941, 2023, doi: 10.3390/s23135941.
[4] S.-M. Tseng, Y.-Q. Wang, and Y.-C. Wang, “Multi-class intrusion detection based on Transformer for IoT networks using CIC-IoT-2023 dataset,” Future Internet, vol. 16, no. 8, art. no. 284, 2024, doi: 10.3390/fi16080284.
[5] A. Javed, A. Ehtsham, M. Jawad, M. N. Awais, A. H. Qureshi, and H. Larijani, “Implementation of lightweight machine learning-based intrusion detection system on IoT devices of smart homes,” Future Internet, vol. 16, no. 6, art. no. 200, 2024, doi: 10.3390/fi16060200.
[6] S. Hizal, U. Cavusoglu, and D. Akgun, “A novel deep learning-based intrusion detection system for IoT DDoS security,” Internet of Things, vol. 28, art. no. 101336, 2024, doi: 10.1016/j.iot.2024.101336.
[7] S. A. Wahab, S. Sultana, N. Tariq, M. Mujahid, J. A. Khan, and A. Mylonas, “A multi-class intrusion detection system for DDoS attacks in IoT networks using deep learning and transformers,” Sensors, vol. 25, no. 15, art. no. 4845, 2025, doi: 10.3390/s25154845.
[8] H. C. Altunay and Z. Albayrak, “A hybrid CNN+LSTM-based intrusion detection system for industrial IoT networks,” Eng. Sci. Technol., Int. J., vol. 38, art. no. 101322, 2023, doi: 10.1016/j.jestch.2022.101322.
[9] A. Nazir et al., “A deep learning-based novel hybrid CNN-LSTM architecture for efficient detection of threats in the IoT ecosystem,” Ain Shams Eng. J., vol. 15, no. 7, art. no. 102777, 2024, doi: 10.1016/j.asej.2024.102777.
[10] A. Gueriani, H. Kheddar, and A. C. Mazari, “Enhancing IoT security with CNN and LSTM-based intrusion detection systems,” in Proc. 6th Int. Conf. Pattern Analysis and Intelligent Systems (PAIS), 2024, pp. 1–7.
[11] S. Sadhwani, M. A. H. Khan, R. Muthalagu, P. M. Pawar, and K. Suresh, “A hybrid BiLSTM-CNN approach for intrusion detection for IoT applications,” Sci. Rep., vol. 16, art. no. 155, 2026, doi: 10.1038/s41598-025-29079-y.
[12] P. Sinha, D. Sahu, S. Prakash, T. Yang, R. S. Rathore, and V. K. Pandey, “A high performance hybrid LSTM CNN secure architecture for IoT environments using deep learning,” Sci. Rep., vol. 15, no. 1, pp. 1–26, 2025, doi: 10.1038/s41598-025-94500-5.
[13] H. Peng, C. Wu, and Y. Xiao, “CBF-IDS: Addressing class imbalance using CNN-BiLSTM with focal loss in network intrusion detection system,” Appl. Sci., vol. 13, no. 21, art. no. 11629, 2023, doi: 10.3390/app132111629.
[14] H. Alzahrani, T. Sheltami, A. Barnawi, M. Imam, and A. Yaser, “A lightweight intrusion detection system using convolutional neural network and long short-term memory in fog computing,” Comput. Mater. Continua, vol. 80, no. 3, pp. 4703–4728, 2024, doi: 10.32604/cmc.2024.054203.
[15] M. Jouhari and M. Guizani, “Lightweight CNN-BiLSTM based intrusion detection systems for resource-constrained IoT devices,” in Proc. Int. Wireless Commun. and Mobile Computing (IWCMC), 2024, doi: 10.1109/IWCMC61514.2024.10592352
📋 How to Cite This Paper
Mothanna Abu Judeh, Adnan H. Al-Helali (2026). Lightweight CNN–BiLSTM Intrusion Detection on the CICIoT2023 Benchmark: Balancing Multi-Class Accuracy and Edge Deployability. International Journal of Computer Techniques, 13(4), 253–265. ISSN: 2394-2231. DOI: https://doi.org/10.5281/zenodo.22076367









