Sresth Khaitan, Islabudeen Mohamed Meerasha
The escalating scale and sophistication of cyberattacks pose a formidable challenge to conventional intrusion detection systems (IDS) because they lack the flexibility to adapt to evolving threats. We propose a composite deep learning architecture that integrates an autoencoder (AE) for unsupervised feature compression alongside a one-dimensional (1D) convolutional neural network (CNN) to extract local patterns and a soft voting ensemble of Support Vector Machine (SVM), Random Forest (RF), and XGBoost classifiers. We test our approach on three standard benchmarks – UNSW NB15, NSL KDD, and CICIDS2017 – to illustrate its robustness across both legacy and modern attack scenarios. Our approach achieves 99.81 % accuracy on binary classification and 99.90 % on multi-class classification for NSL KDD. On UNSW NB15, it delivers 99.19 % binary accuracy and 98.41 % multi-class accuracy. For CICIDS2017, the model attains 99.59 % binary and 99.76 % multi-class accuracy. These results outperform conventional machine learning baselines and confirm the benefit of combining deep feature learning with ensemble methods. Ablation studies show that each component – autoencoder, convolutional network, and ensemble – contributes meaningful gains, and statistical tests, including paired t tests and analysis of variance, validate the significance of these improvements. We evaluate our model on both classic and modern benchmarks to demonstrate a versatile framework for real‑time intrusion detection that delivers consistently high precision while adapting smoothly to new attack patterns.