International Journal of Engineering
Trends and Technology

Research Article | Open Access | Download PDF
Volume 74 | Issue 9 | Year 2026 | Article Id. IJETT-V74I9P117 | DOI : https://doi.org/10.14445/22315381/IJETT-V74I9P117

SpeciNet-IDS: A False-Alarm-Aware Intrusion Detection System for Reliable Network Security


Sailaja Rani Setty, Valli Kumari Vatsavayi

Received Revised Accepted Published
29 Jan 2026 25 Jul 2026 13 Aug 2026 30 Sep 2026

Citation :

Sailaja Rani Setty, Valli Kumari Vatsavayi, "SpeciNet-IDS: A False-Alarm-Aware Intrusion Detection System for Reliable Network Security," International Journal of Engineering Trends and Technology (IJETT), vol. 74, no. 9, pp. 205-219, 2026. Crossref, https://doi.org/10.14445/22315381/IJETT-V74I9P117

Abstract

In practice, false alarms still plague the ability of deployed intrusion detection systems to be effective. If models are primarily tuned for accuracy, with unbalanced traffic, they're overly tolerant of benign misclassifications; analysts become overwhelmed by a rising number of false alarms, and real threats go unnoticed. We suggest a new hybrid network (CNN-Dense) called SpeciNet, which is trained with specificity, rather than accuracy. There are 4 mechanisms that function together. A parallel Conv1D branch learns local statistical patterns, and a Dense Residual branch learns multi-feature global interactions that are important for rare attack classes. The training is based on a focal loss (γ=2, αₜ=0.75) which pulls towards flows that are borderline benign behind the majority of false alarms. The operating threshold is selected based on the far target calibration process, which is a threshold that is as high as possible and does not exceed the 2% validation far threshold. The gains are confirmed by a SHAP-based attribution gate (not used after configuration is selected), but during configuration selection. We evaluate on CICIDS2017 as the primary benchmark and NSL-KDD for corroboration. SpeciNet-IDS reaches binary false alarm rates of 0.01% and 2.71%, with specificity of 99.99% and 97.29%. On CICIDS2017, only 16 false alarms occur across 318,547 benign test instances - a 13-fold reduction over the strongest baseline, significant against all baselines (McNemar p < 0.001). On NSL-KDD, McNemar's test shows significant FAR reductions over three of four baselines and equivalence with the best classical model. Component analysis identifies three dominant sources of false alarm suppression - class weighting, the Dense Residual branch, and threshold calibration - each contributing measurably and independently.

Keywords

Intrusion detection systems, False alarm rate, Hybrid CNN-Dense architecture, Focal loss, Threshold calibration, IDS using Deep Learning-based models, Network security, Explainable Artificial Intelligence.

References

[1] Markus Ring et al., “A Survey of Network-based Intrusion Detection Data Sets,” Computers and Security, vol. 86, pp. 147-167, 2019.
[CrossRef] [Google Scholar] [Publisher Link]

[2] Anna L. Buczak, and Erhan Guven, “A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection,” IEEE Communications Surveys and Tutorials, vol. 18, no. 2, pp. 1153-1176, 2016.
[CrossRef] [Google Scholar] [Publisher Link]

[3] Nathan Shone et al., “A Deep Learning Approach to Network Intrusion Detection,” IEEE Transactions on Emerging Topics in Computational Intelligence, vol. 2, no. 1, pp. 41-50, 2018.
[CrossRef] [Google Scholar] [Publisher Link]

[4] Stefan Axelsson, “The Base-Rate Fallacy and the Difficulty of Intrusion Detection,” ACM Transactions on Information and System Security (TISSEC), vol. 3, no. 3, pp. 186-205, 2000.
[CrossRef] [Google Scholar] [Publisher Link]

[5] Mahbod Tavallaee et al., “A Detailed Analysis of the KDD CUP 99 Data Set,” 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications, Ottawa, ON, Canada, pp. 1-6, 2009.
[CrossRef] [Google Scholar] [Publisher Link]

[6] Iman Sharafaldin, Arash Habibi Lashkari, and Ali A. Ghorbani, “Toward Generating a New Intrusion Detection Dataset and Intrusion Traffic Characterization,” Proceedings of the 4th International Conference on Information Systems Security and Privacy, Funchal, Madeira, Portugal, vol. 1, pp. 108-116, 2018.
[CrossRef] [Google Scholar] [Publisher Link]

[7] Shraddha Mane, and Dattaraj Rao, “Explaining Network Intrusion Detection System using Explainable AI Framework,” arXiv, pp. 1-10, 2021.
[CrossRef] [Google Scholar] [Publisher Link]

[8] Kijung Bong, and Jonghyun Kim, “Analysis of Intrusion Detection Performance using Gaussian Naive Bayes on NSL-KDD Dataset,” 2022 13th International Conference on Information and Communication Technology Convergence (ICTC), Jeju Island, Korea, pp. 1471-1476, 2022.
[CrossRef] [Google Scholar] [Publisher Link]

[9] Scott M. Lundberg, and Su-In Lee, “A Unified Approach to Interpreting Model Predictions,” Advances in Neural Information Processing Systems, vol. 30, 2017.
[Google Scholar] [Publisher Link]

[10] Marco Tulio Ribeiro, Sameer Singh, and Carlos Guestrin, “Why should I trust you?: Explaining the Predictions of Any Classifier,” Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Association for Computing Machinery, New York, United States, pp. 1135-1144, 2016.
[CrossRef] [Google Scholar] [Publisher Link]

[11] Robin Sommer, and Vern Paxson, “Outside the Closed World: On using Machine Learning for Network Intrusion Detection,” 2010 IEEE Symposium on Security and Privacy, Oakland, CA, USA, pp. 305-316, 2010.
[CrossRef] [Google Scholar] [Publisher Link]

[12] Omar Alghushairy et al., “An Efficient Support Vector Machine Algorithm based Network Outlier Detection System,” IEEE Access, vol. 12, pp. 24428-24441, 2020.
[CrossRef] [Google Scholar] [Publisher Link]

[13] Ishita Karna et al., “Ensemble-based Filter Feature Selection Technique for Flow-based IDS,” 2021 2nd International Conference on Advances in Computing, Communication, Embedded and Secure Systems (ACCESS), Ernakulam, India, pp. 324-328, 2021.
[CrossRef] [Google Scholar] [Publisher Link]

[14] Daniel L. Marino, Chathurika S. Wickramasinghe, and Milos Manic, “An Adversarial Approach for Explainable AI in Intrusion Detection Systems,” IECON 2018 - 44th Annual Conference of the IEEE Industrial Electronics Society, Washington, DC, USA, pp. 3237-3243, 2018.
[CrossRef] [Google Scholar] [Publisher Link]

[15] Pieter Barnard, Nicola Marchetti, and Luiz A. DaSilva, “Robust Network Intrusion Detection through Explainable Artificial Intelligence (XAI),” IEEE Networking Letters, vol. 4, no. 3, pp. 167-171, 2022.
[CrossRef] [Google Scholar] [Publisher Link]

[16] V.V. Mandhare, D.R Pede, and P.S. Vikhe, “Network Intrusion Detection using Deep Learning,” International Journal of Recent Technology and Engineering, vol. 9, no. 3, pp. 59-64, 2020.
[CrossRef] [Google Scholar] [Publisher Link]

[17] Alfredo Nascita et al., “Interpretability and Complexity Reduction in IoT Network Anomaly Detection Via XAI,” 2024 IEEE International Conference on Acoustics, Speech, and Signal Processing Workshops (ICASSPW), Seoul, Korea, Republic of, pp. 325-329, 2024.
[CrossRef] [Google Scholar] [Publisher Link]

[18] Diogo Gaspar, Paulo Silva, and Catarina Silva, “Explainable AI for Intrusion Detection Systems: LIME and SHAP Applicability on Multi-Layer Perceptron,” IEEE Access, vol. 12, pp. 30164 - 30175, 2024.
[CrossRef] [Google Scholar] [Publisher Link]

[19] Amjad Albashayreh et al., “Explainable-AI for DoS Attacks Detection in 5G Network using Deep Learning Models,” 2024 International Conference on Intelligent Computing, Communication, Networking and Services (ICCNS), Dubrovnik, Croatia, pp. 166-171, 2024.
[CrossRef] [Google Scholar] [Publisher Link] 

[20] Chuanlong Yin et al., “A Deep Learning Approach for Intrusion Detection using Recurrent Neural Networks,” IEEE Access, vol. 5, pp. 21954-21961, 2017.
[CrossRef] [Google Scholar] [Publisher Link] 

[21] Yuancheng Li, Rong Ma, and Runhai Jiao, “A Hybrid Malicious Code Detection Method based on Deep Learning,” International Journal of Security and its Applications, vol. 9, no. 5, pp. 205-216, 2015.
[CrossRef] [Google Scholar]

[22] Li Yang, Abdallah Moubayed, and Abdallah Shami, “MTH-IDS: A Multitiered Hybrid Intrusion Detection System for Internet of Vehicles,” IEEE Internet of Things Journal, vol. 9, no. 1, pp. 616 - 632, 2022.
[CrossRef] [Google Scholar] [Publisher Link] 

[23] Mohamed Amine Ferrag et al., “Deep Learning for Cyber Security Intrusion Detection: Approaches, Datasets, and Comparative Study,” Journal of Information Security and Applications, vol. 50, pp. 1-19, 2020.
[CrossRef] [Google Scholar] [Publisher Link] 

[24] Zhenyue Long et al., “A Transformer-based Network Intrusion Detection Approach for Cloud Security,” Journal of Cloud Computing, vol. 13, no. 5, pp. 1-11, 2024.
[CrossRef] [Google Scholar] [Publisher Link]  

[25] Maxime Lanvin et al., “Errors in the CICIDS2017 Dataset and Significant Differences in Detection Performances it Makes,” Risks and Security of Internet and Systems: 17th International Conference, CRiSIS 2022, Sousse, Tunisia, pp. 18-33, 2023.
[CrossRef] [Google Scholar] [Publisher Link]  

[26] Wai Weng Lo et al., “E-GraphSAGE: A Graph Neural Network based Intrusion Detection System for IoT,” NOMS 2022-2022 IEEE/IFIP Network Operations and Management Symposium, Budapest, Hungary, pp. 1-9, 2022.
[CrossRef] [Google Scholar] [Publisher Link]   

[27] Evan Caville et al., “Anomal-E: A Self-Supervised Network IDS based on Graph Neural Networks,” Knowledge-based Systems, vol. 258, pp. 1-11, 2022.
[CrossRef] [Google Scholar] [Publisher Link]   

[28] Tahmina Zebin, Shahadate Rezvy, and Yuan Luo, “An Explainable AI-based IDS for DNS Over HTTPS (DoH) Attacks,” IEEE Transactions on Information Forensics and Security, vol. 17, pp. 2339-2349, 2022.
[CrossRef] [Google Scholar] [Publisher Link]   

[29] Kasun Amarasinghe, Kevin Kenney, and Milos Manic, “Toward Explainable Deep Neural Network Based Anomaly Detection,” 2018 11th International Conference on Human System Interaction (HSI), Gdansk, Poland, pp. 311-317, 2018.
[CrossRef] [Google Scholar] [Publisher Link]    

[30] Muhamad Rizki Ilahi, Aji Gautama Putrada, and Hassan Rizky Putra Sailellah, “R-CICIDS2017: Making the IDS Benchmark Realistic for Quantized Models in IoT Deployments,” 2025 International Symposium on Intelligent Signal Processing and Communication Systems (ISPACS), Bandung, Indonesia, pp. 1-9, 2025.
[CrossRef] [Google Scholar] [Publisher Link]