DOI: 10.3390/fi18100521 ISSN: 1999-5903

Fine-Grained IoT Attack Classification Using a Cross-Attention CNN-BiLSTM Model

Mohamed Ali Fakri, Abdellah Najid, Rachid Ben Said, Nezha El Idrissi

Deep learning intrusion detection systems perform well when traffic is merely separated into normal and malicious, but fine-grained recognition of the specific attack family remains difficult in Internet of Things (IoT) environments because of severe class imbalance and overlapping feature distributions. This work proposes an attention-enhanced CNN-BiLSTM fusion model for the multi-class classification of IoT attacks over eight families. A convolutional branch extracts local feature interactions, whereas a bidirectional Long Short-Term Memory (BiLSTM) branch reads the standardized flow descriptor as an ordered sequence and encodes dependencies among non-adjacent feature segments in both directions. Multi-head self-attention and a bidirectional cross-attention block let the two representations interact dynamically and suppress redundant information. Class imbalance is addressed with a focal loss and class-balanced weighting. The framework was evaluated on the large-scale CIC-IoT2023 benchmark under an eight-class taxonomy. On more than 3.5 × 105 test flows, the proposed model reached 99.06% accuracy and a 98.99% weighted F1-score, outperforming standalone CNN, LSTM, CNN-LSTM, and CNN-BiLSTM baselines retrained on the same corrected data pipeline under an identical objective and budget.