Author
Listed:
- Arun Pandey
(Department of Information Technology and Computer Science, C. V. Raman University, Bilaspur 752054, India)
- Ayush Kumar Agrawal
(Department of Information Technology and Computer Science, C. V. Raman University, Bilaspur 752054, India)
- Abhinav Shukla
(Department of Information Technology and Computer Science, C. V. Raman University, Bilaspur 752054, India)
- Gunjan Keswani
(Department of Computer Science and Engineering, School of Computer Science and Engineering, Ramdeobaba University, Nagpur 440013, India)
- Pitshou N. Bokoro
(Department of Electrical Engineering Technology, University of Johannesburg, Johannesburg 2006, South Africa)
- Parul Dubey
(Symbiosis Institute of Technology, Nagpur Campus, Symbiosis International (Deemed University), Pune 440035, India)
Abstract
Intrusion detection systems (IDSs) play a vital role in safeguarding modern computer networks against increasingly sophisticated and high-volume cyber threats. Recent progress in artificial intelligence, especially deep learning, has allowed IDSs to go from static rule-based systems to adaptive and data-driven security solutions. But traditional machine learning- and convolution-based IDSs often have trouble finding long-range dependencies and temporal correlations in large-scale network traffic. This makes detection less accurate and increases the number of false alarms. This challenge becomes more pronounced in heterogeneous and evolving network environments. To address this, experiments are conducted on two widely used benchmark datasets: CIC-IDS2017 for binary intrusion detection and CICIDS2018 for multiclass attack classification. These datasets represent realistic network traffic with diverse attack categories and severe class imbalance. The proposed methodology employs a Transformer-based intrusion detection framework incorporating sequence windowing, positional encoding, and multi-head self-attention to learn contextual traffic representations. The primary contribution of this study lies in systematically integrating sliding temporal windowing, positional encoding, and multi-head self-attention into flow-level intrusion modeling, accompanied by empirical ablation analysis and statistical validation across two large-scale CIC benchmark datasets. Performance is evaluated using accuracy, precision, recall, F1-score, ROC-AUC, and false alarm rate. Experimental results demonstrate that the proposed model achieves high detection accuracy, strong discriminative capability, and low false alarm rates across both datasets, confirming its effectiveness and scalability for next-generation cybersecurity applications.
Suggested Citation
Arun Pandey & Ayush Kumar Agrawal & Abhinav Shukla & Gunjan Keswani & Pitshou N. Bokoro & Parul Dubey, 2026.
"From Signature to Attention: Transformer-Powered Intrusion Detection Systems for Cybersecurity,"
Future Internet, MDPI, vol. 18(8), pages 1-23, July.
Handle:
RePEc:gam:jftint:v:18:y:2026:i:8:p:398-:d:2002559
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jftint:v:18:y:2026:i:8:p:398-:d:2002559. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager The email address of this maintainer does not seem to be valid anymore. Please ask MDPI Indexing Manager to update the entry or send us the correct address
(email available below). General contact details of provider: https://www.mdpi.com .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.