{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T12:44:00Z","timestamp":1784637840277,"version":"3.55.0"},"reference-count":34,"publisher":"MDPI AG","issue":"16","license":[{"start":{"date-parts":[[2020,8,15]],"date-time":"2020-08-15T00:00:00Z","timestamp":1597449600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"European Union\u2019s Horizon 2020 research and innovation programme","award":["833088 (InfraStress)"],"award-info":[{"award-number":["833088 (InfraStress)"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Currently, expert systems and applied machine learning algorithms are widely used to automate network intrusion detection. In critical infrastructure applications of communication technologies, the interaction among various industrial control systems and the Internet environment intrinsic to the IoT technology makes them susceptible to cyber-attacks. Given the existence of the enormous network traffic in critical Cyber-Physical Systems (CPSs), traditional methods of machine learning implemented in network anomaly detection are inefficient. Therefore, recently developed machine learning techniques, with the emphasis on deep learning, are finding their successful implementations in the detection and classification of anomalies at both the network and host levels. This paper presents an ensemble method that leverages deep models such as the Deep Neural Network (DNN) and Long Short-Term Memory (LSTM) and a meta-classifier (i.e., logistic regression) following the principle of stacked generalization. To enhance the capabilities of the proposed approach, the method utilizes a two-step process for the apprehension of network anomalies. In the first stage, data pre-processing, a Deep Sparse AutoEncoder (DSAE) is employed for the feature engineering problem. In the second phase, a stacking ensemble learning approach is utilized for classification. The efficiency of the method disclosed in this work is tested on heterogeneous datasets, including data gathered in the IoT environment, namely IoT-23, LITNET-2020, and NetML-2020. The results of the evaluation of the proposed approach are discussed. Statistical significance is tested and compared to the state-of-the-art approaches in network anomaly detection.<\/jats:p>","DOI":"10.3390\/s20164583","type":"journal-article","created":{"date-parts":[[2020,8,17]],"date-time":"2020-08-17T04:35:51Z","timestamp":1597638951000},"page":"4583","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":175,"title":["A Deep Learning Ensemble for Network Anomaly and Cyber-Attack Detection"],"prefix":"10.3390","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9640-4725","authenticated-orcid":false,"given":"Vibekananda","family":"Dutta","sequence":"first","affiliation":[{"name":"Institute of Telecommunications and Computer Science, UTP University of Science and Technology, Kaliskiego 7, 85-976 Bydgoszcz, Poland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Micha\u0142","family":"Chora\u015b","sequence":"additional","affiliation":[{"name":"Institute of Telecommunications and Computer Science, UTP University of Science and Technology, Kaliskiego 7, 85-976 Bydgoszcz, Poland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marek","family":"Pawlicki","sequence":"additional","affiliation":[{"name":"Institute of Telecommunications and Computer Science, UTP University of Science and Technology, Kaliskiego 7, 85-976 Bydgoszcz, Poland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rafa\u0142","family":"Kozik","sequence":"additional","affiliation":[{"name":"Institute of Telecommunications and Computer Science, UTP University of Science and Technology, Kaliskiego 7, 85-976 Bydgoszcz, Poland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2020,8,15]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"783","DOI":"10.1007\/s12652-015-0283-x","article-title":"Advanced services for critical infrastructures protection","volume":"6","author":"Kozik","year":"2015","journal-title":"J. Ambient. Intell. Humaniz. Comput."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Wang, E.K., Ye, Y., Xu, X., Yiu, S.M., Hui, L.C.K., and Chow, K.P. (2010, January 18\u201320). Security issues and challenges for cyber physical system. Proceedings of the 2010 IEEE\/ACM Int\u2019l Conference on Green Computing and Communications & Int\u2019l Conference on Cyber, Physical and Social Computing, Hangzhou, China.","DOI":"10.1109\/GreenCom-CPSCom.2010.36"},{"key":"ref_3","first-page":"446","article-title":"A study on NSL-KDD dataset for intrusion detection system based on classification algorithms","volume":"4","author":"Dhanabal","year":"2015","journal-title":"Int. J. Adv. Res. Comput. Commun. Eng."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Dong, B., and Wang, X. (2016, January 4\u20136). Comparison deep learning method to traditional methods using for network intrusion detection. Proceedings of the 2016 8th IEEE International Conference on Communication Software and Networks (ICCSN), Beijing, China.","DOI":"10.1109\/ICCSN.2016.7586590"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"924","DOI":"10.1109\/TNSM.2019.2927886","article-title":"A hybrid deep learning-based model for anomaly detection in cloud datacenter networks","volume":"16","author":"Garg","year":"2019","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Aggarwal, C.C., and Sathe, S. (2017). Outlier Ensembles: An Introduction, Springer.","DOI":"10.1007\/978-3-319-54765-7"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Kim, J., Kim, J., Thu, H.L.T., and Kim, H. (2016, January 15\u201317). Long short term memory recurrent neural network classifier for intrusion detection. Proceedings of the IEEE 2016 International Conference on Platform Technology and Service (PlatCon), Jeju, Korea.","DOI":"10.1109\/PlatCon.2016.7456805"},{"key":"ref_8","unstructured":"Hodo, E., Bellekens, X., Hamilton, A., Tachtatzis, C., and Atkinson, R. (2017). Shallow and deep networks intrusion detection system: A taxonomy and survey. arXiv."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Abolhasanzadeh, B. (2015, January 26\u201328). Nonlinear dimensionality reduction for intrusion detection using auto-encoder bottleneck features. Proceedings of the IEEE 2015 7th Conference on Information and Knowledge Technology (IKT), Urmia, Iran.","DOI":"10.1109\/IKT.2015.7288799"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1016\/j.neucom.2012.11.050","article-title":"Network anomaly detection with the restricted Boltzmann machine","volume":"122","author":"Fiore","year":"2013","journal-title":"Neurocomputing"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Alom, M.Z., Bontupalli, V., and Taha, T.M. (2015, January 15\u201319). Intrusion detection using deep belief networks. Proceedings of the IEEE 2015 National Aerospace and Electronics Conference (NAECON), Dayton, OH, USA.","DOI":"10.1109\/NAECON.2015.7443094"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2379776.2379786","article-title":"Ensemble approaches for regression: A survey","volume":"45","author":"Soares","year":"2012","journal-title":"ACM Comput. Surv. Csur"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1662","DOI":"10.1016\/j.comnet.2010.12.008","article-title":"Intrusion detection using neural based hybrid classification methods","volume":"55","author":"Govindarajan","year":"2011","journal-title":"Comput. Netw."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"993","DOI":"10.1109\/34.58871","article-title":"Neural network ensembles","volume":"12","author":"Hansen","year":"1990","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Zhang, C., and Ma, Y. (2012). Ensemble Learning in Ensemble Machine Learning: Methods and Applications, Springer.","DOI":"10.1007\/978-1-4419-9326-7"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"241","DOI":"10.1016\/S0893-6080(05)80023-1","article-title":"Stacked generalization","volume":"5","author":"Wolpert","year":"1992","journal-title":"Neural Netw."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"21","DOI":"10.1002\/widm.1143","article-title":"Generating ensembles of heterogeneous classifiers using stacked generalization","volume":"5","author":"Sesmero","year":"2015","journal-title":"Wiley Interdiscip. Rev. Data Min. Knowl. Discov."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Cerqueira, V., Pinto, F., S\u00e1, C., and Soares, C. (2016, January 13\u201315). Combining boosted trees with metafeature engineering for predictive maintenance. Proceedings of the International Symposium on Intelligent Data Analysis, Stockholm, Sweden.","DOI":"10.1007\/978-3-319-46349-0_35"},{"key":"ref_19","unstructured":"Karthick, R.R., Hattiwale, V.P., and Ravindran, B. (2012, January 3\u20137). Adaptive network intrusion detection system using a hybrid approach. Proceedings of the IEEE 2012 Fourth International Conference on Communication Systems and Networks (COMSNETS 2012), Bangalore, India."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1080\/19393555.2015.1125974","article-title":"The evaluation of Network Anomaly Detection Systems: Statistical analysis of the UNSW-NB15 data set and the comparison with the KDD99 data set","volume":"25","author":"Moustafa","year":"2016","journal-title":"Inf. Secur. J. Glob. Perspect."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Chora\u015b, M., Pawlicki, M., Puchalski, D., and Kozik, R. (2020, January 3\u20135). Machine Learning\u2013The Results Are Not the only Thing that Matters! What About Security, Explainability and Fairness?. Proceedings of the International Conference on Computational Science, Amsterdam, The Netherlands.","DOI":"10.1007\/978-3-030-50423-6_46"},{"key":"ref_22","first-page":"539","article-title":"Exploratory undersampling for class-imbalance learning","volume":"39","author":"Liu","year":"2008","journal-title":"IEEE Trans. Syst. Man Cybern. Part Cybern."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1613\/jair.953","article-title":"SMOTE: Synthetic minority over-sampling technique","volume":"16","author":"Chawla","year":"2002","journal-title":"J. Artif. Intell. Res."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Rend\u00f3n, E., Alejo, R., Castorena, C., Isidro-Ortega, F.J., and Granda-Guti\u00e9rrez, E.E. (2020). Data Sampling Methods to Deal With the Big Data Multi-Class Imbalance Problem. Appl. Sci., 10.","DOI":"10.3390\/app10041276"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Zhang, C., Cheng, X., Liu, J., He, J., and Liu, G. (2018). Deep sparse autoencoder for feature extraction and diagnosis of locomotive adhesion status. J. Control. Sci. Eng., 2018.","DOI":"10.1155\/2018\/8676387"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"119","DOI":"10.1109\/TMI.2015.2458702","article-title":"Stacked sparse autoencoder (SSAE) for nuclei detection on breast cancer histopathology images","volume":"35","author":"Xu","year":"2015","journal-title":"IEEE Trans. Med. Imaging"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Dutta, V., Chora\u015b, M., Pawlicki, M., and Kozik, R. (2020, January 18\u201320). Hybrid Model for Improving the Classification Effectiveness of Network Intrusion Detection. Proceedings of the 13th International Conference on Computational Intelligence in Security for Information Systems (CISIS 2020), Burgos, Spain. accepted.","DOI":"10.1007\/978-3-030-57805-3_38"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Zhao, R., Yan, R., Wang, J., and Mao, K. (2017). Learning to monitor machine health with convolutional bi-directional LSTM networks. Sensors, 17.","DOI":"10.3390\/s17020273"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Damasevicius, R., Venckauskas, A., Grigaliunas, S., Toldinas, J., Morkevicius, N., Aleliunas, T., and Smuikys, P. (2020). LITNET-2020: An Annotated Real-World Network Flow Dataset for Network Intrusion Detection. Electronics, 9.","DOI":"10.3390\/electronics9050800"},{"key":"ref_30","unstructured":"Claise, B., Sadasivan, G., Valluri, V., and Djernaes, M. (2020, August 14). Cisco Systems Netflow Services Export Version 9. Available online: https:\/\/www.hjp.at\/doc\/rfc\/rfc3954.html."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"675","DOI":"10.1080\/01621459.1937.10503522","article-title":"The use of ranks to avoid the assumption of normality implicit in the analysis of variance","volume":"32","author":"Friedman","year":"1937","journal-title":"J. Am. Stat. Assoc."},{"key":"ref_32","unstructured":"Barut, O., Luo, Y., Zhang, T., Li, W., and Li, P. (2020). NetML: A Challenge for Network Traffic Analytics. arXiv."},{"key":"ref_33","first-page":"2","article-title":"Balanced Efficient Lifelong Learning (B-ELLA) for Cyber Attack Detection","volume":"25","author":"Kozik","year":"2019","journal-title":"J. UCS"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"148","DOI":"10.1016\/j.future.2020.04.013","article-title":"Defending network intrusion detection systems against adversarial evasion attacks","volume":"110","author":"Pawlicki","year":"2020","journal-title":"Future Gener. Comput. Syst."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/16\/4583\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T10:01:27Z","timestamp":1760176887000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/16\/4583"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,8,15]]},"references-count":34,"journal-issue":{"issue":"16","published-online":{"date-parts":[[2020,8]]}},"alternative-id":["s20164583"],"URL":"https:\/\/doi.org\/10.3390\/s20164583","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,8,15]]}}}