ISSN: 2245-4578 (Online Version) ISSN:2245-1439 (Print Version)
A Privacy-Aware Multi-Scale Feature Fusion and Adaptive Class Optimization Method for Network Intrusion Detection Based on the SOR Model
PDF
HTML

Keywords

Network intrusion detection
CNN–BiLSTM
multi-scale feature fusion
class imbalance
privacy-aware learning
SOR theoretical model
University network education

How to Cite

[1]
J. . Bai, “A Privacy-Aware Multi-Scale Feature Fusion and Adaptive Class Optimization Method for Network Intrusion Detection Based on the SOR Model”, JCSANDM, vol. 15, no. 05, pp. 1161–1180, Oct. 2026.

Abstract

As a critical educational carrier, university cyberspace bears the important mission of educating students. Network intrusion – unauthorized and improper activities such as penetration, theft, surveillance, and destruction targeting university networks – not only threatens campus cybersecurity but also constitutes illegal technical conduct that erodes the outcomes of higher education. As attack techniques grow increasingly sophisticated, university intrusion detection systems urgently need to accurately identify increasingly complex attack behaviors from massive, rapidly evolving campus network traffic. Integrating the SOR (Stimulus-Organism-Response) theoretical model, this study conceptualizes network attack events and abnormal traffic as external environmental stimuli (S). The system performs privacy-aware feature processing on raw network traffic data, reducing unnecessary collection of personal information of faculty and students from the technical source, and minimizing the model’s reliance on sensitive or directly identifiable traffic attributes. Parallel convolutional branches with different kernel sizes (3×3, 5×5, 7×7) are employed to extract local, medium-range, and global campus network traffic patterns from multiple receptive fields. The extracted multi-scale features are fused and then fed into a BiLSTM module (O). The optimized adaptive class balancing, precise intrusion recognition, and classification decisions are conceptualized as behavioral responses (R). To address the class imbalance problem, an adaptive class optimization strategy is incorporated into the training objective, assigning greater learning weights to minority classes and hard-to-classify attack categories at the loss function level, thereby constructing an intelligent intrusion detection theoretical-practical model for university network security. Experiments are evaluated on three benchmark datasets – CIC-IDS2017, UNSW-NB15, and CSE-CIC-IDS2018 – achieving 98.84% accuracy on CIC-IDS2017 and 99.98% accuracy on CSE-CIC-IDS2018, while robustness experiments under feature missing and noise perturbation conditions further validate its security and stability. In conclusion, the proposed SOR theory-driven privacy-aware multi-scale feature fusion and adaptive class optimization practical model provides an effective and practical technical solution for complex university network security scenarios, and can offer solid technical support for the construction of smart campus networks and ideological and political education platforms in universities.

https://doi.org/10.13052/jcsm2245-1439.1551
PDF
HTML

References

Thakkar, A., and Lohiya, R. “Intrusion detection of imbalanced network traffic based on machine learning and deep learning,” IEEE Access, vol. 9, pp. 7550–7563, 2021.

Wang, X., Li, Y., and Zhang, J. “Deep learning intrusion detection model based on optimized imbalanced network data,” in Proc. IEEE International Conference on Communication Technology (ICCT), 2018.

Khan, M. A. “CSE-IDS: Using cost-sensitive deep learning and ensemble algorithms to handle class imbalance in network-based intrusion detection systems,” Computers & Security, vol. 112, pp. 102499, 2022.

Khan, M. A. “Addressing the class imbalance problem in network intrusion detection systems using data resampling and deep learning,” The Journal of Supercomputing, 2023.

Khan, M. A., and Salah, K. “Siam-IDS: Handling class imbalance problem in intrusion detection systems using Siamese neural network,” Procedia Computer Science, vol. 171, pp. 2148–2157, 2020.

Singh, S. K., Gupta, R., and Verma, A. K. “Multiclass imbalance resampling techniques for network intrusion detection,” in Proc. IEEE International Conference on Smart Computing and Communication (ICSCC), 2024.

Liu, Y., Zhang, J., and Shen, X. “Attack classification of imbalanced intrusion data for IoT network using ensemble-learning-based deep neural network,” IEEE Internet of Things Journal, vol. 10, no. 12, pp. 10345–10358, 2023.

Zhang, X., Li, Y., and Wang, Z. “NIDS-CNNLSTM: Network intrusion detection classification model based on deep learning,” IEEE Access, vol. 11, pp. 24567–24579, 2023.

Chen, H., Wu, Y., and Liu, Z. “A hybrid CNN-LSTM model with attention mechanism for improved intrusion detection in wireless IoT sensor networks,” IEEE Access, vol. 13, 2025.

Park, J., Lee, S., and Kim, H. “ENIDS: A deep learning-based ensemble framework for network intrusion detection systems,” IEEE Transactions on Network and Service Management, 2024.

Zhao, L., Sun, Y., and Xu, H. “A network intrusion detection method based on bagging ensemble,” Symmetry, vol. 16, no. 7, p. 850, 2024.

Althobaiti, M. A. “Ensemble learning for network intrusion detection based on correlation and embedded feature selection techniques,” Computers, vol. 14, no. 3, p. 82, 2025.

Das, A. K., Roy, P., and Ghosh, S. “Improving intrusion detection systems by using deep learning methods on time series data,” Engineering, Technology & Applied Science Research, vol. 15, 2025.

Mehrabian, A., and Russell J. A. An Approach to Environmental Psychology. Cambridge, MA: The MIT Press, 1974: 62–65.

Deng, W., and Yi, M. “Research on the adoption mechanism of online user added comment information based on SOR model,” Journal of Library Theory and Practice, no. 8, pp. 33–39, 2018.

Li, Q., Li, X., and Wei J. “Research on consumer community group buying integrating SOR and promise trust theory,” Journal of Xi’an Jiaotong University (Social Sciences Edition), no. 2, pp. 25–35, 2020.

Wang, Y., Wang, T., Liu, Z., and Li, J. “Research on public emergency behavior in sudden public health emergencies based on SOR model,” Journal of Chongqing Social Sciences, no. 5, pp. 19–31, 2020.

Wang, W., Zhang, Z., Zhang, K., Liu, Y., and Xie, Y. “Research on discontinuous use behavior of smart health bracelet users integrating SOR theory,” Journal of Library Forum, no. 5, pp. 92–102, 2020.

Ferrag, M. A., Maglaras, L., and Janicke, H. “Artificial intelligence based network intrusion detection with hyper-parameter optimization tuning on the realistic cyber dataset CSE-CIC-IDS2018 using cloud computing,” ICT Express, vol. 6, no. 3, pp. 200–205, 2020.

Sharafaldin, I., Lashkari, A. H., and Ghorbani, A. A. “A survey and analysis of intrusion detection models based on CSE-CIC-IDS2018 big data,” Journal of Big Data, vol. 7, no. 1, p. 104, 2020.

Tolman, E. C. Purposive Behavior in Animals and Men. California:University of California Press, 1951: 8–19.

Chang, H. J., Eckman, M., Yan, R. N. “Application of the Stimulus-Organism-Response model to the retail environment: The role of hedonic motivation in impulse buying behavior,” The International Review of Retail, Distribution and Consumer Research, vol. 21, no. 3, pp. 233–249, 2011.

Xu, X., Zhao, Y., Wu, M., Zhu, Q., and Shao, Y. “Empirical study on user churn behavior on social networking sites from the perspective of S-O-R theory,” Journal of Intelligence Magazine, no. 7, pp. 188–194, 2017.

Y. Wang. “Research on network threat hunting system based on multi-scale Light GBM ensemble learning,” Journal of Cyber Security and Mobility, vol. 14, no. 3, pp. 701–722, 2025.

I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani. “Toward generating a new intrusion detection dataset and intrusion traffic characterization,” in Proceedings of the 4th International Conference on Information Systems Security and Privacy, pp. 108–116, 2018.

N. Moustafa and J. Slay. “UNSW-NB15: A comprehensive data set for network intrusion detection systems,” in 2015 Military Communications and Information Systems Conference, pp. 1–6, 2015.

Lu, J. “Research on network intrusion detection and optimization strategies based on artificial intelligence,” Journal of Network Security Technology and Applications, no. 6, pp. 35–37, 2026.

Wu, Y. “Application of artificial intelligence in computer network intrusion detection,” Journal of Computer Knowledge and Technology, no. 10, pp. 35–37, 2026.

Sharafaldin, I., Lashkari, A. H., and Ghorbani, A. A. “A survey and analysis of intrusion detection models based on CSE-CIC-IDS2018 big data,” Journal of Big Data, vol. 7, no. 1, p. 104, 2020.

N. Moustafa and J. Slay. “UNSW-NB15: A comprehensive data set for network intrusion detection systems,” in 2015 Military Communications and Information Systems Conference, pp. 1–6, 2015.

A. Khraisat, I. Gondal, P. Vamplew, and J. Kamruzzaman. “Survey of intrusion detection systems: techniques, datasets and challenges,” Cybersecurity, vol. 2, article 20, 2019.

J. L. Leevy and T. M. Khoshgoftaar. “A survey and analysis of intrusion detection models based on CSE-CIC-IDS2018 Big Data,” Journal of Big Data, vol. 7, article 104, 2020.

T.-Y. Lin, P. Goyal, R. Girshick, K. He, and P. Dollár. “Focal Loss for dense object detection,” in Proceedings of the IEEE International Conference on Computer Vision, pp. 2980–2988, 2017.

Y. Cui, M. Jia, T.-Y. Lin, Y. Song, and S. Belongie. “Class-balanced loss based on effective number of samples,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, pp. 9260–9269, 2019.

H. He and E. A. Garcia. “Learning from imbalanced data,” IEEE Transactions on Knowledge and Data Engineering, vol. 21, no. 9, pp. 1263–1284, 2009.

N. V. Chawla, K. W. Bowyer, L. O. Hall, and W. P. Kegelmeyer. “SMOTE: Synthetic minority over-sampling technique,” Journal of Artificial Intelligence Research, vol. 16, pp. 321–357, 2002. doi: 10.1613/jair.953.

Creative Commons License

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.

Copyright (c) 2026 Journal of Cyber Security and Mobility

Downloads

Download data is not yet available.