Research Article | Open Access | Download PDF
Volume 74 | Issue 9 | Year 2026 | Article Id. IJETT-V74I9P117 | DOI : https://doi.org/10.14445/22315381/IJETT-V74I9P117SpeciNet-IDS: A False-Alarm-Aware Intrusion Detection System for Reliable Network Security
Sailaja Rani Setty, Valli Kumari Vatsavayi
| Received | Revised | Accepted | Published |
|---|---|---|---|
| 29 Jan 2026 | 25 Jul 2026 | 13 Aug 2026 | 30 Sep 2026 |
Citation :
Sailaja Rani Setty, Valli Kumari Vatsavayi, "SpeciNet-IDS: A False-Alarm-Aware Intrusion Detection System for Reliable Network Security," International Journal of Engineering Trends and Technology (IJETT), vol. 74, no. 9, pp. 205-219, 2026. Crossref, https://doi.org/10.14445/22315381/IJETT-V74I9P117
Abstract
In practice, false alarms still plague the ability of deployed intrusion detection systems to be effective. If models are primarily tuned for accuracy, with unbalanced traffic, they're overly tolerant of benign misclassifications; analysts become overwhelmed by a rising number of false alarms, and real threats go unnoticed. We suggest a new hybrid network (CNN-Dense) called SpeciNet, which is trained with specificity, rather than accuracy. There are 4 mechanisms that function together. A parallel Conv1D branch learns local statistical patterns, and a Dense Residual branch learns multi-feature global interactions that are important for rare attack classes. The training is based on a focal loss (γ=2, αₜ=0.75) which pulls towards flows that are borderline benign behind the majority of false alarms. The operating threshold is selected based on the far target calibration process, which is a threshold that is as high as possible and does not exceed the 2% validation far threshold. The gains are confirmed by a SHAP-based attribution gate (not used after configuration is selected), but during configuration selection. We evaluate on CICIDS2017 as the primary benchmark and NSL-KDD for corroboration. SpeciNet-IDS reaches binary false alarm rates of 0.01% and 2.71%, with specificity of 99.99% and 97.29%. On CICIDS2017, only 16 false alarms occur across 318,547 benign test instances - a 13-fold reduction over the strongest baseline, significant against all baselines (McNemar p < 0.001). On NSL-KDD, McNemar's test shows significant FAR reductions over three of four baselines and equivalence with the best classical model. Component analysis identifies three dominant sources of false alarm suppression - class weighting, the Dense Residual branch, and threshold calibration - each contributing measurably and independently.
Keywords
Intrusion detection systems, False alarm rate, Hybrid CNN-Dense architecture, Focal loss, Threshold calibration, IDS using Deep Learning-based models, Network security, Explainable Artificial Intelligence.
References
[1] Markus Ring et al., “A
Survey of Network-based Intrusion Detection Data Sets,” Computers and
Security, vol. 86, pp. 147-167, 2019.
[CrossRef] [Google Scholar] [Publisher Link]
[2] Anna L. Buczak, and Erhan
Guven, “A Survey of Data Mining and Machine Learning Methods for Cyber Security
Intrusion Detection,” IEEE Communications Surveys and Tutorials, vol.
18, no. 2, pp. 1153-1176, 2016.
[CrossRef] [Google Scholar] [Publisher Link]
[3] Nathan Shone et al., “A Deep
Learning Approach to Network Intrusion Detection,” IEEE Transactions on
Emerging Topics in Computational Intelligence, vol. 2, no. 1, pp. 41-50,
2018.
[CrossRef] [Google Scholar] [Publisher Link]
[4] Stefan Axelsson, “The
Base-Rate Fallacy and the Difficulty of Intrusion Detection,” ACM
Transactions on Information and System Security (TISSEC), vol. 3, no. 3,
pp. 186-205, 2000.
[CrossRef] [Google Scholar] [Publisher Link]
[5] Mahbod Tavallaee et al., “A
Detailed Analysis of the KDD CUP 99 Data Set,” 2009 IEEE Symposium on
Computational Intelligence for Security and Defense Applications, Ottawa,
ON, Canada, pp. 1-6, 2009.
[CrossRef] [Google Scholar] [Publisher Link]
[6] Iman Sharafaldin, Arash
Habibi Lashkari, and Ali A. Ghorbani, “Toward Generating a New Intrusion
Detection Dataset and Intrusion Traffic Characterization,” Proceedings of
the 4th International Conference on Information Systems Security and
Privacy, Funchal, Madeira, Portugal, vol. 1, pp. 108-116, 2018.
[CrossRef] [Google Scholar] [Publisher Link]
[7] Shraddha Mane, and Dattaraj
Rao, “Explaining Network Intrusion Detection System using Explainable AI
Framework,” arXiv, pp. 1-10, 2021.
[CrossRef] [Google Scholar] [Publisher
Link]
[8] Kijung Bong, and Jonghyun
Kim, “Analysis of Intrusion Detection Performance using Gaussian Naive Bayes on
NSL-KDD Dataset,” 2022 13th International Conference on
Information and Communication Technology Convergence (ICTC), Jeju Island,
Korea, pp. 1471-1476, 2022.
[CrossRef] [Google Scholar] [Publisher Link]
[9] Scott M. Lundberg, and Su-In
Lee, “A Unified Approach to Interpreting Model Predictions,” Advances in
Neural Information Processing Systems, vol. 30, 2017.
[Google Scholar] [Publisher Link]
[10] Marco Tulio Ribeiro, Sameer
Singh, and Carlos Guestrin, “Why should I trust you?: Explaining the
Predictions of Any Classifier,” Proceedings of the 22nd ACM
SIGKDD International Conference on Knowledge Discovery and Data Mining,
Association for Computing Machinery, New York, United States, pp. 1135-1144,
2016.
[CrossRef] [Google Scholar] [Publisher Link]
[11] Robin Sommer, and Vern
Paxson, “Outside the Closed World: On using Machine Learning for Network
Intrusion Detection,” 2010 IEEE Symposium on Security and Privacy,
Oakland, CA, USA, pp. 305-316, 2010.
[CrossRef] [Google Scholar] [Publisher Link]
[12] Omar Alghushairy et al., “An
Efficient Support Vector Machine Algorithm based Network Outlier Detection
System,” IEEE Access, vol. 12, pp. 24428-24441, 2020.
[CrossRef] [Google Scholar] [Publisher Link]
[13] Ishita Karna et al.,
“Ensemble-based Filter Feature Selection Technique for Flow-based IDS,” 2021
2nd International Conference on Advances in Computing,
Communication, Embedded and Secure Systems (ACCESS), Ernakulam, India, pp.
324-328, 2021.
[CrossRef] [Google Scholar] [Publisher Link]
[14] Daniel L. Marino, Chathurika
S. Wickramasinghe, and Milos Manic, “An Adversarial Approach for Explainable AI
in Intrusion Detection Systems,” IECON 2018 - 44th Annual
Conference of the IEEE Industrial Electronics Society, Washington, DC, USA,
pp. 3237-3243, 2018.
[CrossRef] [Google Scholar] [Publisher Link]
[15] Pieter Barnard, Nicola
Marchetti, and Luiz A. DaSilva, “Robust Network Intrusion Detection through
Explainable Artificial Intelligence (XAI),” IEEE Networking Letters,
vol. 4, no. 3, pp. 167-171, 2022.
[CrossRef] [Google Scholar] [Publisher Link]
[16] V.V. Mandhare, D.R Pede, and
P.S. Vikhe, “Network Intrusion Detection using Deep Learning,” International
Journal of Recent Technology and Engineering, vol. 9, no. 3, pp. 59-64,
2020.
[CrossRef] [Google Scholar] [Publisher Link]
[17] Alfredo Nascita et al.,
“Interpretability and Complexity Reduction in IoT Network Anomaly Detection Via
XAI,” 2024 IEEE International Conference on Acoustics, Speech, and Signal
Processing Workshops (ICASSPW), Seoul, Korea, Republic of, pp. 325-329,
2024.
[CrossRef] [Google Scholar] [Publisher Link]
[18] Diogo Gaspar, Paulo Silva,
and Catarina Silva, “Explainable AI for Intrusion Detection Systems: LIME and
SHAP Applicability on Multi-Layer Perceptron,” IEEE Access, vol. 12, pp.
30164 - 30175, 2024.
[CrossRef] [Google Scholar] [Publisher Link]
[19] Amjad Albashayreh et al.,
“Explainable-AI for DoS Attacks Detection in 5G Network using Deep Learning
Models,” 2024 International Conference on Intelligent Computing,
Communication, Networking and Services (ICCNS), Dubrovnik, Croatia, pp.
166-171, 2024.
[CrossRef] [Google Scholar] [Publisher Link]
[20] Chuanlong Yin et al., “A
Deep Learning Approach for Intrusion Detection using Recurrent Neural
Networks,” IEEE Access, vol. 5, pp. 21954-21961, 2017.
[CrossRef] [Google Scholar] [Publisher Link]
[21] Yuancheng Li, Rong Ma, and
Runhai Jiao, “A Hybrid Malicious Code Detection Method based on Deep Learning,”
International Journal of Security and its Applications, vol. 9, no. 5,
pp. 205-216, 2015.
[CrossRef] [Google Scholar]
[22] Li Yang, Abdallah Moubayed,
and Abdallah Shami, “MTH-IDS: A Multitiered Hybrid Intrusion Detection System
for Internet of Vehicles,” IEEE Internet of Things Journal, vol. 9, no.
1, pp. 616 - 632, 2022.
[CrossRef] [Google Scholar] [Publisher Link]
[23] Mohamed Amine Ferrag et al.,
“Deep Learning for Cyber Security Intrusion Detection: Approaches, Datasets,
and Comparative Study,” Journal of Information Security and Applications,
vol. 50, pp. 1-19, 2020.
[CrossRef] [Google Scholar] [Publisher Link]
[24] Zhenyue Long et al., “A
Transformer-based Network Intrusion Detection Approach for Cloud Security,” Journal
of Cloud Computing, vol. 13, no. 5, pp. 1-11, 2024.
[CrossRef] [Google Scholar] [Publisher Link]
[25] Maxime Lanvin et al.,
“Errors in the CICIDS2017 Dataset and Significant Differences in Detection
Performances it Makes,” Risks and Security of Internet and Systems: 17th
International Conference, CRiSIS 2022, Sousse, Tunisia, pp. 18-33, 2023.
[CrossRef] [Google Scholar] [Publisher Link]
[26] Wai Weng Lo et al.,
“E-GraphSAGE: A Graph Neural Network based Intrusion Detection System for IoT,”
NOMS 2022-2022 IEEE/IFIP Network Operations and Management Symposium,
Budapest, Hungary, pp. 1-9, 2022.
[CrossRef] [Google Scholar] [Publisher Link]
[27] Evan Caville et al.,
“Anomal-E: A Self-Supervised Network IDS based on Graph Neural Networks,” Knowledge-based
Systems, vol. 258, pp. 1-11, 2022.
[CrossRef] [Google Scholar] [Publisher Link]
[28] Tahmina Zebin, Shahadate
Rezvy, and Yuan Luo, “An Explainable AI-based IDS for DNS Over HTTPS (DoH)
Attacks,” IEEE Transactions on Information Forensics and Security, vol.
17, pp. 2339-2349, 2022.
[CrossRef] [Google Scholar] [Publisher Link]
[29] Kasun Amarasinghe, Kevin
Kenney, and Milos Manic, “Toward Explainable Deep Neural Network Based Anomaly
Detection,” 2018 11th International Conference on Human System
Interaction (HSI), Gdansk, Poland, pp. 311-317, 2018.
[CrossRef] [Google Scholar] [Publisher Link]
[30] Muhamad Rizki Ilahi, Aji Gautama Putrada, and Hassan Rizky Putra
Sailellah, “R-CICIDS2017: Making the IDS Benchmark Realistic for Quantized
Models in IoT Deployments,” 2025 International Symposium on Intelligent
Signal Processing and Communication Systems (ISPACS), Bandung, Indonesia,
pp. 1-9, 2025.
[CrossRef] [Google Scholar] [Publisher Link]