Open Access DOI Assigned

Bi-Directional LSTM with Attention Mechanism for Real-Time Intrusion Detection in IoT-Enabled Smart Campus Networks: Architecture, Performance Evaluation, and Deployment Analysis

Volume 3, Issue 5

  • Author(s)Harpreet Singh Bhatia, Nidhi Sharma
  • AffiliationDepartment of Computer Science and Engineering, Chandigarh Engineering College, Landran, Punjab, India Department of Information Technology, Guru Jambheshwar University of Science and Technology, Hisar, Haryana, India
  • Page No.125-133
  • Volume, Issue & YearVolume 3, Issue 5, May 2026
  • Published On2026/05/18
  • JournalInternational Journal of Advanced Multidisciplinary Application (IJAMA)
  • ISSN No.3048-9350
  • DOIhttps://doi.org/10.5281/zenodo.20424411

Abstract

The exponential proliferation of Internet of Things (IoT) devices in academic and enterprise environments — with an estimated 18.8 billion connected devices globally as of 2024, projected to reach 40.6 billion by 2030 — has dramatically expanded the attack surface for network intrusions, malware propagation, and distributed denial-of-service (DDoS) campaigns. Conventional signature-based intrusion detection systems (IDS) are inadequate for IoT network environments characterised by heterogeneous device profiles, constrained computational resources, high packet rates, and the emergence of novel zero-day attack vectors that lack pre-defined signature patterns. Machine learning-based anomaly detection offers a path beyond signature limitations, but the temporal dependency structure of network traffic sequences — where the malicious intent of a packet may be discernible only in the context of preceding and succeeding traffic patterns — motivates the application of recurrent neural architectures capable of capturing bidirectional temporal context. This study proposes and evaluates a Bidirectional Long Short-Term Memory network augmented with a multi-head scaled dot-product attention mechanism (Bi-LSTM+Att) for intrusion detection in IoT-enabled smart campus network environments. The proposed architecture is trained and evaluated on the NSL-KDD benchmark dataset (125,973 training samples, 22,544 test samples across five traffic classes: Normal, DoS, Probe, R2L, and U2R) and validated on a custom campus IoT dataset collected from the smart building infrastructure of Chandigarh Engineering College comprising 48 heterogeneous IoT devices over a 60-day monitoring period. The proposed Bi-LSTM+Att model achieves 94.8% overall accuracy, 93.6% precision, 94.2% recall, and 93.9% F1-score on NSL-KDD — surpassing baseline LSTM (90.1%), SVM (87.3%), Random Forest (85.6%), and Naive Bayes (78.4%) under identical training and evaluation protocols. The attention mechanism provides interpretable feature attribution maps confirming that packet duration, source byte count, and protocol type are the dominant discriminative features for attack classification. Inference latency of 34 ms at 10,000 packets/second on a mid-range GPU confirms viability for real-time campus network deployment. These findings establish Bi-LSTM+Att as a practical, deployable IDS architecture for resource-aware IoT security management in Indian academic institution networks.

Keywords: intrusion detection system, IoT security, Bidirectional LSTM, attention mechanism, deep learning, NSL-KDD, smart campus, network anomaly detection, DDoS, DoS, R2L, U2R

References

  1. [1] Anderson, J. P. (1980). Computer Security Threat Monitoring and Surveillance. Technical Report, James P. Anderson Company.
  2. [2] Bahdanau, D., Cho, K., & Bengio, Y. (2015). Neural machine translation by jointly learning to align and translate. Proceedings of ICLR 2015.
  3. [3] Chandola, V., Banerjee, A., & Kumar, V. (2009). Anomaly detection: A survey. ACM Computing Surveys, 41(3), 15.
  4. [4] CERT-In. (2023). Cyber Security Advisory: Targeted Intrusions Against Indian Educational Institutions. Indian Computer Emergency Response Team, Ministry of Electronics and IT.
  5. [5] Garcia-Teodoro, P., et al. (2009). Anomaly-based network intrusion detection: Techniques, systems and challenges. Computers & Security, 28(1–2), 18–28.
  6. [6] Hochreiter, S., & Schmidhuber, J. (1997). Long short-term memory. Neural Computation, 9(8), 1735–1780.
  7. [7] Khraisat, A., et al. (2019). Survey of intrusion detection systems: Techniques, datasets and challenges. Cybersecurity, 2(1), 20.
  8. [8] Kim, J., et al. (2016). Intrusion detection system using deep neural network for in-vehicle network security. PLOS ONE, 11(6), e0155781.
  9. [9] Liao, H. J., et al. (2013). Intrusion detection system: A comprehensive review. Journal of Network and Computer Applications, 36(1), 16–24.
  10. [10] Lin, W. C., Ke, S. W., & Tsai, C. F. (2015). CANN: An intrusion detection system based on combining cluster centers and nearest neighbors. Knowledge-Based Systems, 78, 13–21.
  11. [11] Moustafa, N., & Slay, J. (2015). UNSW-NB15: A comprehensive data set for network intrusion detection systems. Proceedings of MilCIS 2015, Canberra.
  12. [12] Papadopoulos, P., et al. (2021). Launching adversarial attacks against network intrusion detection systems for IoT. Journal of Cybersecurity and Privacy, 1(2), 252–273.
  13. [13] Scarfone, K., & Mell, P. (2007). Guide to Intrusion Detection and Prevention Systems (IDPS). NIST Special Publication 800-94.
  14. [14] Sharma, N., & Singh, H. (2022). IoT network security challenges in Indian smart campus environments. International Journal of Information Security, 21(4), 781–796.
  15. [15] Shone, N., et al. (2018). A deep learning approach to network intrusion detection. IEEE Transactions on Emerging Topics in Computational Intelligence, 2(1), 41–50.
  16. [16] Tavallaee, M., et al. (2009). A detailed analysis of the KDD Cup 99 data set. Proceedings of IEEE CISDA 2009, 1–6.
  17. [17] Tsimenidis, S., Lagkas, T., & Rantos, K. (2022). Deep learning in IoT intrusion detection. Journal of Network and Systems Management, 30(1), 1–40.
  18. [18] Vaswani, A., et al. (2017). Attention is all you need. Advances in Neural Information Processing Systems, 30.
  19. [19] Yin, C., et al. (2017). A deep learning approach for intrusion detection using recurrent neural networks. IEEE Access, 5, 21954–21961.
  20. [20] Zhang, Y., et al. (2019). Network intrusion detection: Based on deep hierarchical network and original flow data. IEEE Access, 7, 37004–37016.

Explore Our Related Journals

Looking for the right journal for your next manuscript? Explore our international peer-reviewed journals covering engineering, management, computer science, artificial intelligence and multidisciplinary research.