Comparative Analysis of Deep LSTM Architectures with Multi-Head Attention for Enhanced IoT Intrusion Detection: A Memory-Efficient Approach
Journal of Engineering Research and Reports · pp. 413–448 · Published 25 Feb 2026
10.9734/jerr/2026/v28i21812Abstract
The proliferation of Internet of Things (IoT) devices has introduced significant cybersecurity challenges, necessitating robust intrusion detection systems capable of identifying sophisticated attacks in resourceconstrained environments. This study presents a comprehensive comparative analysis of eight Long Short-Term Memory (LSTM) architectural variants for network intrusion detection, addressing the research gap identified in recent literature regarding the systematic evaluation of deep LSTM architectures. Using the CICIDS2017 benchmark dataset, we evaluated Vanilla LSTM, Bidirectional LSTM, Stacked LSTM (shallow and deep), Stacked Bidirectional LSTM, LSTM with Self-Attention, LSTM with Multi-Head Attention, and a novel hybrid CNN-LSTM-Attention architecture. Our experimental results demonstrate that the LSTM with Multi-Head Attention architecture achieved superior performance with 98.41% accuracy, 98.51% precision, 98.40% recall, 98.44% F1-score, and 99.67% ROC-AUC, utilizing only 14,290 parameters. Notably, our memoryefficient implementation successfully trained all architectures within 1GB RAM constraints using 400,000 samples, making the approach viable for edge computing scenarios. The novel hybrid CNN-LSTM-Attention architecture—which synergistically combines convolutional local-pattern extraction, bidirectional recurrent temporalmodeling, and self-attention dynamic feature weighting—achieved 96.37% accuracy with the highest ROC-AUC of 99.75%, demonstrating exceptional discriminative capability with only 7,010 parameters. All evaluations were performed on a held-out stratified test set with SMOTE applied exclusively to the training partition, ensuring realistic assessment under natural class imbalance conditions. These results provide practical, empirically grounded deployment guidelines for IoT intrusion detection across resource availability scenarios spanning edge devices (1GB RAM)to cloud environments, with direct relevance to emerging regulatory frameworks emphasizing efficient and interpretable AI-powered security systems.
Cited by 0
No indexed citations yet.
Related research
- Automatic Segmentation of Organ at Risk in Head and Neck Cancer CT Images Using Medical Open Network for Artificial Intelligence (MONAI) with Deep Learning Techniques — shares topic coverage
- Diagnostic Accuracy of Artificial Intelligence for Breast Cancer Detection: A Systematic Review — shares topic coverage
- Leveraging Deep Learning Algorithms for Predicting Power Outages and Detecting Faults: A Review — shares topic coverage
- Bridging Prenatal Diagnostics and AI: A Systematic Review and Meta-Analysis of the Efficacy of Advanced Algorithms in Identifying Congenital Fetal Abnormalities — shares topic coverage
- Applications of Deep Learning in Predicting the Risk of Metabolic Syndrome from Lifestyle and Behavioral Factors: A Scoping Review — shares topic coverage
Article metrics
Real usage data collected on this platform.
0
Page views
0
PDF downloads
0
Outbound clicks
0
Citations
Views by country
Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".
No views recorded yet.
Traffic sources
Referring site, by host.
No traffic recorded yet.
Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.