Fine-Grained IoT Attack Classification Using a Cross-Attention CNN-BiLSTM Model
Mohamed Ali Fakri, Abdellah Najid, Rachid Ben Said, Nezha El IdrissiDeep learning intrusion detection systems perform well when traffic is merely separated into normal and malicious, but fine-grained recognition of the specific attack family remains difficult in Internet of Things (IoT) environments because of severe class imbalance and overlapping feature distributions. This work proposes an attention-enhanced CNN-BiLSTM fusion model for the multi-class classification of IoT attacks over eight families. A convolutional branch extracts local feature interactions, whereas a bidirectional Long Short-Term Memory (BiLSTM) branch reads the standardized flow descriptor as an ordered sequence and encodes dependencies among non-adjacent feature segments in both directions. Multi-head self-attention and a bidirectional cross-attention block let the two representations interact dynamically and suppress redundant information. Class imbalance is addressed with a focal loss and class-balanced weighting. The framework was evaluated on the large-scale CIC-IoT2023 benchmark under an eight-class taxonomy. On more than 3.5 × 105 test flows, the proposed model reached 99.06% accuracy and a 98.99% weighted F1-score, outperforming standalone CNN, LSTM, CNN-LSTM, and CNN-BiLSTM baselines retrained on the same corrected data pipeline under an identical objective and budget.