ADVANCED AI AND MACHINE LEARNING FOR IOT–CLOUD SECURITY: A HYBRID CNN–BILSTM–ATTENTION FRAMEWORK FOR REAL-TIME MULTI-CLASS CYBERATTACK DETECTION AND INTELLIGENT THREAT CLASSIFICATION

Authors

  • Irfan Ali Author
  • Shoaib Hayat Author
  • Muhammad Sajjad Author
  • Muhammad Nauman Hameed Author
  • Shahzeb Iqbal Author
  • Komal Tanveer Author

Keywords:

IoT–cloud security; artificial intelligence; machine learning; CNN–BiLSTM–Attention; cyberattack detection; threat classification; deep learning; real-time intrusion detection.

Abstract

The rapid expansion of Internet of Things (IoT) devices and their integration with cloud platforms have created highly connected environments that are increasingly exposed to sophisticated, heterogeneous, and rapidly evolving cyberattacks. This study proposes an advanced hybrid convolutional neural network–bidirectional long short-term memory–attention (CNN–BiLSTM–Attention) framework for real-time multi-class cyberattack detection and intelligent threat classification in IoT–cloud ecosystems. A consolidated dataset containing 285,000 network-flow and device-activity records was constructed from smart sensors, IoT gateways, cloud servers, authentication logs, and communication traffic. The dataset represented normal behavior and eight attack categories: distributed denial-of-service, denial-of-service, botnet, malware, brute-force, reconnaissance, data-injection, and device-spoofing attacks. Data preprocessing included duplicate removal, missing-value treatment, categorical encoding, feature normalization, class balancing through synthetic minority oversampling, and correlation-based feature selection. The processed records were divided into training, validation, and testing sets using a 70:15:15 ratio. In the proposed architecture, one-dimensional CNN layers extract local spatial patterns, BiLSTM layers capture forward and backward temporal dependencies, and an attention mechanism assigns greater importance to the most informative features and time steps. Experimental performance was evaluated through accuracy, precision, recall, F1-score, specificity, Matthews correlation coefficient, and area under the receiver operating characteristic curve. The proposed framework achieved 98.47% accuracy, 98.31% precision, 98.18% recall, 98.24% F1-score, 99.12% specificity, 0.978 Matthews correlation coefficient, and 0.996 area under the curve. It outperformed logistic regression, support vector machine, random forest, XGBoost, standalone CNN, and standalone BiLSTM models, whose accuracies ranged from 84.26% to 96.73%. The model also reduced the false-positive rate to 0.88% and achieved an average inference latency of 18.6 milliseconds per record, demonstrating suitability for real-time edge-assisted cloud deployment. Ablation analysis confirmed that combining convolutional extraction, bidirectional sequence learning, and attention improved accuracy by 3.42 percentage points compared with the standalone CNN. Its lightweight design further supports continuous monitoring, rapid incident prioritization, and reliable defensive decision-making without imposing excessive computational overhead on distributed environments. These findings demonstrate that the framework provides accurate, scalable, and context-aware threat recognition, enabling early attack identification, automated classification, and adaptive security responses across resource-constrained IoT devices and cloud infrastructures.

Downloads

Published

2026-08-15