{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,27]],"date-time":"2026-07-27T10:19:08Z","timestamp":1785147548069,"version":"3.55.0"},"reference-count":29,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2023,2,16]],"date-time":"2023-02-16T00:00:00Z","timestamp":1676505600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Natural Science Foundation of China","award":["62071056"],"award-info":[{"award-number":["62071056"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>In computer networks, Network Intrusion Detection System (NIDS) plays a very important role in identifying intrusion behaviors. NIDS can identify abnormal behaviors by analyzing network traffic. However, the performance of classifier is not very good in identifying abnormal traffic for minority classes. In order to improve the detection rate on class imbalanced dataset, we propose a network intrusion detection model based on two-layer CNN and Cluster-SMOTE + K-means algorithm (CSK-CNN) to process imbalanced dataset. CSK combines the cluster based Synthetic Minority Over Sampling Technique (Cluster-SMOTE) and K-means based under sampling algorithm. Through the two-layer network, abnormal traffic can not only be identified, but also be classified into specific attack types. This paper has been verified on UNSW-NB15 dataset and CICIDS2017 dataset, and the performance of the proposed model has been evaluated using such indicators as accuracy, recall, precision, F1-score, ROC curve, AUC value, training time and testing time. The experiment shows that the proposed CSK-CNN in this paper is obviously superior to other comparison algorithms in terms of network intrusion detection performance, and is suitable for deployment in the real network environment.<\/jats:p>","DOI":"10.3390\/info14020130","type":"journal-article","created":{"date-parts":[[2023,2,17]],"date-time":"2023-02-17T01:32:56Z","timestamp":1676597576000},"page":"130","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":23,"title":["CSK-CNN: Network Intrusion Detection Model Based on Two-Layer Convolution Neural Network for Handling Imbalanced Dataset"],"prefix":"10.3390","volume":"14","author":[{"given":"Jiaming","family":"Song","sequence":"first","affiliation":[{"name":"Institute of Cloud Computing and Big Data, China Academy of Information and Communications Technology, Beijing 100191, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaojuan","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2896-4595","authenticated-orcid":false,"given":"Mingshu","family":"He","sequence":"additional","affiliation":[{"name":"School of Electronic Engineering, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4855-2464","authenticated-orcid":false,"given":"Lei","family":"Jin","sequence":"additional","affiliation":[{"name":"School of Computer Science, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2023,2,16]]},"reference":[{"key":"ref_1","first-page":"16","article-title":"Challenges and Future Directions for Intrusion Detection Systems Based on AutoML","volume":"2021","author":"Abbood","year":"2021","journal-title":"Mesop. J. CyberSecurity"},{"key":"ref_2","first-page":"1","article-title":"Intrusion Detection: A Review","volume":"2021","author":"Alajanbi","year":"2021","journal-title":"Mesop. J. CyberSecurity"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"14027","DOI":"10.1007\/s10586-018-2173-4","article-title":"Honeypot TB-IDS: Trace back model based intrusion detection system using knowledge based honeypot construction model","volume":"22","author":"Umamaheswari","year":"2019","journal-title":"Clust. Comput."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"292","DOI":"10.1016\/j.future.2019.07.045","article-title":"Interactive three-dimensional visualization of network intrusion detection data for machine learning","volume":"102","author":"Zong","year":"2020","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"428","DOI":"10.1016\/j.procs.2015.03.174","article-title":"Feature selection based hybrid anomaly intrusion detection system using k-means and RBF kernel function","volume":"45","author":"Ravale","year":"2015","journal-title":"Procedia Comput. Sci."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Chen, T.Q., and Guestrin, C. (2016, January 13\u201317). XGBoost: A scalable tree boosting system. Proceedings of the 22nd ACM Sigkdd International Conference on Knowledge Discovery and Data Mining, San Francisco, CA, USA.","DOI":"10.1145\/2939672.2939785"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"2227","DOI":"10.1016\/j.comcom.2011.07.001","article-title":"Practical real-time intrusion detection using machine learning approaches","volume":"34","author":"Sangkatsanee","year":"2011","journal-title":"Comput. Commun."},{"key":"ref_8","first-page":"90","article-title":"Multiscale convolutional CNN model for network intrusion detection","volume":"55","author":"Liu","year":"2019","journal-title":"Comput. Eng. Appl."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"1185","DOI":"10.1007\/s00521-010-0487-0","article-title":"Intrusion detection using reduced-size RNN based on feature grouping","volume":"21","author":"Sheikhan","year":"2012","journal-title":"Neural Comput. Appl."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Althubiti, S.A., Jones, E.M., and Roy, K. (2018, January 21\u201323). LSTM for anomaly-based network intrusion detection. Proceedings of the 2018 28th International Telecommunication Networks and Applications Conference (ITNAC), Sydney, NSW, Australia.","DOI":"10.1109\/ATNAC.2018.8615300"},{"key":"ref_11","first-page":"30","article-title":"Towards developing network forensic mechanism for botnet activities in the IoT based on machine learning techniques","volume":"235","author":"Koroniotis","year":"2018","journal-title":"Mob. Netw. Manag."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"58392","DOI":"10.1109\/ACCESS.2020.2982418","article-title":"Network intrusion detection based on PSO-XGBoost model","volume":"8","author":"Jiang","year":"2020","journal-title":"IEEE Access"},{"key":"ref_13","unstructured":"Aljbali, S., and Roy, K. (2020). Intelligent Systems and Applications. IntelliSys 2020, Springer International Publishing. Advances in Intelligent Systems and Computing."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"106798","DOI":"10.1016\/j.knosys.2021.106798","article-title":"Nearest cluster-based intrusion detection through convolutional neural networks","volume":"216","author":"Andresini","year":"2021","journal-title":"Knowl.-Based Syst."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"21954","DOI":"10.1109\/ACCESS.2017.2762418","article-title":"A deep learning approach for intrusion detection using recurrent neural networks","volume":"5","author":"Yin","year":"2017","journal-title":"IEEE Access"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Faker, O., and Dogdu, E. (2019, January 18\u201320). Intrusion detection using big data and deep learning techniques. Proceedings of the ACMSE 2019, Kennesaw, GA, USA.","DOI":"10.1145\/3299815.3314439"},{"key":"ref_17","first-page":"8890306","article-title":"DL-IDS: Extracting features using CNN-LSTM hybrid network for intrusion detection system","volume":"2020","author":"Sun","year":"2020","journal-title":"Sec. Commun. Netw."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"107315","DOI":"10.1016\/j.comnet.2020.107315","article-title":"An effective convolutional neural network based on SMOTE and Gaussian mixture model for intrusion detection in imbalanced dataset","volume":"177","author":"Zhang","year":"2020","journal-title":"Comput. Netw."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"108076","DOI":"10.1016\/j.comnet.2021.108076","article-title":"LIO-IDS: Handling class imbalance using LSTM and Improved One-vs-One technique in Intrusion Detection System","volume":"192","author":"Gupta","year":"2021","journal-title":"Comput. Netw."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Abdulhammed, R., Musafer, H., Alessa, A., Faezipour, M., and Abuzneid, A. (2019). Features dimensionality reduction approaches for machine learning based network intrusion detection. Electronics, 8.","DOI":"10.3390\/electronics8030322"},{"key":"ref_21","unstructured":"Cieslak, D.A., Chawla, N.V., and Striegel, A. (2006, January 10\u201312). Combating imbalance in network intrusion datasets. Proceedings of the 2006 IEEE International Conference on Granular Computing, Atlanta, GA, USA."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Moustafa, N., and Slay, J. (2015, January 10\u201312). UNSW-NB15: A comprehensive dataset for network intrusion detection systems (UNSW-NB15 network dataset). Proceedings of the IEEE: 2015 Military Communications and Information Systems Conference, IEEE, Canberra, ACT, Australia.","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., and Ghorbani, A.A. (2018, January 22\u201324). Toward generating a new intrusion detection dataset and intrusion traffic characterization. Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP 2018), Funchal, Madeira, Portugal.","DOI":"10.5220\/0006639801080116"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Tahmassebi, A., Gandomi, A.H., Fong, S., Meyer-Baese, A., and Foo, S.Y. (2018). Multistage optimization of a deep model: A case study on ground motion modeling. PLoS ONE, 13.","DOI":"10.1371\/journal.pone.0203829"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"2875","DOI":"10.3233\/JIFS-169230","article-title":"A multiclass cascade of artificial neural network for network intrusion detection","volume":"32","author":"Baig","year":"2017","journal-title":"J. Intell. Fuzzy Syst."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"102684","DOI":"10.1016\/j.cose.2022.102684","article-title":"Chameleon: Optimized feature selection using particle swarm optimization and ensemble methods for network anomaly detection","volume":"117","author":"Chohra","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Yang, Y., Zheng, K., Wu, C., and Yang, Y. (2019). Improving the classification effectiveness of intrusion detection by using improved conditional variational autoencoder and deep neural network. Sensors, 19.","DOI":"10.3390\/s19112528"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"107247","DOI":"10.1016\/j.comnet.2020.107247","article-title":"Building an efficient intrusion detection system based on feature selection and ensemble classifier","volume":"174","author":"Zhou","year":"2020","journal-title":"Comput. Netw."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"119904","DOI":"10.1109\/ACCESS.2019.2933165","article-title":"PCCN: Parallel cross convolutional neural network for abnormal network traffic flows detection in multiclass imbalanced network traffic flows","volume":"7","author":"Zhang","year":"2019","journal-title":"IEEE Access"}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/14\/2\/130\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T18:38:25Z","timestamp":1760121505000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/14\/2\/130"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,2,16]]},"references-count":29,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2023,2]]}},"alternative-id":["info14020130"],"URL":"https:\/\/doi.org\/10.3390\/info14020130","relation":{},"ISSN":["2078-2489"],"issn-type":[{"value":"2078-2489","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,2,16]]}}}