Optimizing Cloud Security with a Hybrid BiLSTM-BiGRU Model for Efficient Intrusion Detection
Research Article  ·  Published: 19 May 2025
Issue cover
ICCK Transactions on Sensing, Communication, and Control
Volume 2, Issue 2, 2025: 106-121
Research Article Free to Read

Optimizing Cloud Security with a Hybrid BiLSTM-BiGRU Model for Efficient Intrusion Detection

1 Department of Computer Science, Qurtuba University of Science & Information Technology, Peshawar 25000, Pakistan
2 Department of Computer Science, Abbottabad University of Science and Technology, Abbottabad 22010, Pakistan
3 Department of Computer Science, University of Bari Aldo Moro, Bari (BA), Italy
4 College of Mechatronics and Control Engineering, Shenzhen University, Shenzhen 518060, China
5 College of Computer Science and Software Engineering, Shenzhen University, Shenzhen 518060, China
6 Faculty of Electrical Engineering, West Pomeranian University of Technology, Szczecin, Poland
7 Department of Computer Engineering, Gachon University, Seongnam 13120, Republic of Korea
* Corresponding Authors: Asim Zeb, [email protected]; Inam Ullah, [email protected]
Volume 2, Issue 2
You have access to this article · Limited-Time Free Access

Abstract

To address evolving security challenges in cloud computing, this study proposes a hybrid deep learning architecture integrating Bidirectional Long Short-Term Memory (BiLSTM) and Bidirectional Gated Recurrent Units (BiGRU) for cloud intrusion detection. The BiLSTM-BiGRU model synergizes BiLSTM's long-term dependency modeling with BiGRU's efficient gating mechanisms, achieving a detection accuracy of 96.7% on the CIC-IDS 2018 dataset. It outperforms CNN-LSTM baselines by 2.2% accuracy, 3.3% precision, 3.6% recall, and 3.6% F1-score, demonstrating consistently superior performance across all evaluation metrics. The architecture demonstrates operational efficiency through 20% reduced computational latency and 15% lower memory footprint compared to conventional models, enabled by residual memory preservation and parallel processing capabilities. Experimental results further validate strong detection capability across diverse attack categories, including DDoS (97.3%), DoS (98.0%), and brute-force attacks (96.1%), establishing a methodological framework for real-time cloud security services. This work advances hybrid deep learning applications in trusted computing environments through optimized temporal feature extraction and resource-aware threat detection.

Graphical Abstract

Optimizing Cloud Security with a Hybrid BiLSTM-BiGRU Model for Efficient Intrusion Detection

Keywords

cloud security network intrusion detection deep learning BiLSTM-BiGRU hybrid models cybersecurity cloud computing

Data Availability Statement

Data will be made available on request.

Funding

This work was supported without any funding.

Conflicts of Interest

The authors declare no conflicts of interest.

Ethical Approval and Consent to Participate

Not applicable.

References

  1. Modi, C., Patel, D., Borisaniya, B., Patel, H., Patel, A., & Rajarajan, M. (2013). A survey of intrusion detection techniques in cloud. Journal of network and computer applications, 36(1), 42-57.
    [CrossRef] [Google Scholar]
  2. Mishra, P., Pilli, E. S., Varadharajan, V., & Tupakula, U. (2017). Intrusion detection techniques in cloud environment: A survey. Journal of Network and Computer Applications, 77, 18-47.
    [CrossRef] [Google Scholar]
  3. Bhushan, K., & Gupta, B. B. (2019). Distributed denial of service (DDoS) attack mitigation in software defined network (SDN)-based cloud computing environment. Journal of Ambient Intelligence and Humanized Computing, 10(5), 1985-1997.
    [CrossRef] [Google Scholar]
  4. Aslan, Ö., Aktuğ, S. S., Ozkan-Okay, M., Yilmaz, A. A., & Akin, E. (2023). A comprehensive review of cyber security vulnerabilities, threats, attacks, and solutions. Electronics, 12(6), 1333.
    [CrossRef] [Google Scholar]
  5. Otta, S. P., Panda, S., Gupta, M., & Hota, C. (2023). A systematic survey of multi-factor authentication for cloud infrastructure. Future Internet, 15(4), 146.
    [CrossRef] [Google Scholar]
  6. Abdallah, A. M., Alkaabi, A. S. R. O., Alameri, G. B. N. D., Rafique, S. H., Musa, N. S., & Murugan, T. (2024). Cloud network anomaly detection using machine and deep learning techniques—recent research advancements. IEEE access, 12, 56749-56773.
    [CrossRef] [Google Scholar]
  7. Srilatha, D., & Thillaiarasu, N. (2023). Implementation of Intrusion detection and prevention with Deep Learning in Cloud Computing. Journal of Information Technology Management, 15(Special Issue), 1-18. https://www.sid.ir/paper/1095792/en
    [Google Scholar]
  8. Moizuddin, M. D., & Jose, M. V. (2022). A bio-inspired hybrid deep learning model for network intrusion detection. Knowledge-based systems, 238, 107894.
    [CrossRef] [Google Scholar]
  9. Guo, Y. (2023). A review of machine learning-based zero-day attack detection: Challenges and future directions. Computer communications, 198, 175-185.
    [CrossRef] [Google Scholar]
  10. Soltani, M., Ousat, B., Siavoshani, M. J., & Jahangir, A. H. (2023). An adaptable deep learning-based intrusion detection system to zero-day attacks. Journal of Information Security and Applications, 76, 103516.
    [CrossRef] [Google Scholar]
  11. Ferrag, M. A., Maglaras, L., Moschoyiannis, S., & Janicke, H. (2020). Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. Journal of Information Security and Applications, 50, 102419.
    [CrossRef] [Google Scholar]
  12. Kocher, G., & Kumar, G. (2021). Machine learning and deep learning methods for intrusion detection systems: recent developments and challenges. Soft Computing, 25(15), 9731-9763.
    [CrossRef] [Google Scholar]
  13. Naveed, M., Arif, F., Usman, S. M., Anwar, A., Hadjouni, M., Elmannai, H., ... & Umar, F. (2022). A deep learning‐based framework for feature extraction and classification of intrusion detection in networks. Wireless Communications and Mobile Computing, 2022(1), 2215852.
    [CrossRef] [Google Scholar]
  14. Sajid, M., Malik, K. R., Almogren, A., Malik, T. S., Khan, A. H., Tanveer, J., & Rehman, A. U. (2024). Enhancing intrusion detection: a hybrid machine and deep learning approach. Journal of Cloud Computing, 13(1), 123.
    [CrossRef] [Google Scholar]
  15. Aljuaid, W. A. H., & Alshamrani, S. S. (2024). A deep learning approach for intrusion detection systems in cloud computing environments. Applied Sciences, 14(13), 5381.
    [CrossRef] [Google Scholar]
  16. Hu, Z., Liu, G., Li, Y., & Zhuang, S. (2024). SAGB: self-attention with gate and BiGRU network for intrusion detection. Complex & Intelligent Systems, 10(6), 8467-8479.
    [CrossRef] [Google Scholar]
  17. Gao, J. (2022). Network intrusion detection method combining CNN and BiLSTM in cloud computing environment. Computational intelligence and neuroscience, 2022(1), 7272479.
    [CrossRef] [Google Scholar]
  18. Einy, S., Oz, C., & Navaei, Y. D. (2021). The anomaly‐and signature‐based IDS for network security using hybrid inference systems. Mathematical Problems in Engineering, 2021(1), 6639714.
    [CrossRef] [Google Scholar]
  19. Ahmad, R., Alsmadi, I., Alhamdani, W., & Tawalbeh, L. A. (2023). Zero-day attack detection: a systematic literature review. Artificial Intelligence Review, 56(10), 10733-10811.
    [CrossRef] [Google Scholar]
  20. Khraisat, A., Gondal, I., Vamplew, P., & Kamruzzaman, J. (2019). Survey of intrusion detection systems: techniques, datasets and challenges. Cybersecurity, 2(1), 1-22.
    [CrossRef] [Google Scholar]
  21. Zhou, Y., Cheng, G., Jiang, S., & Dai, M. (2020). Building an efficient intrusion detection system based on feature selection and ensemble classifier. Computer networks, 174, 107247.
    [CrossRef] [Google Scholar]
  22. Al-Saleh, A. (2023). A balanced communication-avoiding support vector machine decision tree method for smart intrusion detection systems. Scientific Reports, 13(1), 9083.
    [CrossRef] [Google Scholar]
  23. Kunang, Y. N., Nurmaini, S., Stiawan, D., & Zarkasi, A. (2018, October). Automatic features extraction using autoencoder in intrusion detection system. In 2018 International conference on electrical engineering and computer science (ICECOS) (pp. 219-224). IEEE.
    [CrossRef] [Google Scholar]
  24. Long, Z., Yan, H., Shen, G., Zhang, X., He, H., & Cheng, L. (2024). A Transformer-based network intrusion detection approach for cloud security. Journal of Cloud Computing, 13(1), 5.
    [CrossRef] [Google Scholar]
  25. Ring, M., Wunderlich, S., Scheuring, D., Landes, D., & Hotho, A. (2019). A survey of network-based intrusion detection data sets. Computers & Security, 86, 147-167.
    [CrossRef] [Google Scholar]
  26. Zhao, R., Mu, Y., Zou, L., & Wen, X. (2022). A hybrid intrusion detection system based on feature selection and weighted stacking classifier. IEEE Access, 10, 71414-71426.
    [CrossRef] [Google Scholar]
  27. Aldallal, A. (2022). Toward efficient intrusion detection system using hybrid deep learning approach. Symmetry, 14(9), 1916.
    [CrossRef] [Google Scholar]
  28. Kheddar, H. (2024). Transformers and large language models for efficient intrusion detection systems: A comprehensive survey. arXiv preprint arXiv:2408.07583.
    [CrossRef] [Google Scholar]
  29. Kaur, R., Gabrijelčič, D., & Klobučar, T. (2023). Artificial intelligence for cybersecurity: Literature review and future research directions. Information Fusion, 97, 101804.
    [CrossRef] [Google Scholar]
  30. Imrana, Y., Xiang, Y., Ali, L., Abdul-Rauf, Z., Hu, Y. C., Kadry, S., & Lim, S. (2022). $\chi$2-bidLSTM: A feature driven intrusion detection system based on $\chi$2 statistical model and bidirectional LSTM. Sensors, 22(5), 2018.
    [CrossRef] [Google Scholar]
  31. Li, L., Lu, Y., Yang, G., & Yan, X. (2024). End-to-end network intrusion detection based on contrastive learning. Sensors, 24(7), 2122.
    [CrossRef] [Google Scholar]
  32. Wu, Z., Zhang, H., Wang, P., & Sun, Z. (2022). RTIDS: A robust transformer-based approach for intrusion detection system. IEEE Access, 10, 64375-64387.
    [CrossRef] [Google Scholar]
  33. Vinayakumar, R., Alazab, M., Soman, K. P., Poornachandran, P., Al-Nemrat, A., & Venkatraman, S. (2019). Deep learning approach for intelligent intrusion detection system. IEEE Access, 7, 41525-41550.
    [CrossRef] [Google Scholar]
  34. Xu, B., Sun, L., Mao, X., Liu, C., & Ding, Z. (2024). Strengthening Network Security: Deep Learning Models for Intrusion Detection with Optimized Feature Subset and Effective Imbalance Handling. Computers, Materials & Continua, 78(2).
    [CrossRef] [Google Scholar]
  35. Alsaffar, A. M., Nouri-Baygi, M., & Zolbanin, H. M. (2024). Shielding networks: enhancing intrusion detection with hybrid feature selection and stack ensemble learning. Journal of Big Data, 11(1), 133.
    [CrossRef] [Google Scholar]

Cited By (14)

  1. Muhammad Shoaib Khan, Hongsong Chen, XinJian Ma. Resource-efficient anomaly detection in social media accounts using lightweight LLM models: a review of methods, challenges, and future trends. Cluster Computing, 2026 , 29 (5).
    [CrossRef]
  2. Ehigiator Iyobor Egho-Promise, Ekereuke Udoh, Edita Gashi, Bamidele Ola, Vijay Chennareddy, Malleswar Reddy Yerabolu. AI-Driven Intelligent Intrusion Detection for Real-Time Network Threat Analysis in Enterprise and Cloud Networks. Information, 2026 , 17 (7).
    [CrossRef]
  3. T. Ammannamma, ASN Chakravarthy. A hybrid lightweight feature extraction assisted ensemble approach for intrusion detection with ESMOTE-based class imbalance handling in IoT networks. Computers and Electrical Engineering, 2026 , 130 .
    [CrossRef]
  4. Yuting Bai, Haoran Tian, Xinyi Xue, Tingli Su, Xuebo Jin, Jianlei Kong. Echo state network and variational autoencoder integrated with online optimization for robust pose estimation in unmanned surface vehicles. Measurement, 2026 , 276 .
    [CrossRef]
  5. Nasser A. Alsadhan, Inam Ullah Khan, Zeeshan Ali Haider, Fida Muhammad Khan, Inam Ullah. CFSL-BC: Compression-enabled federated split learning with blockchain for robust android malware detection. Computer Networks, 2026 , 287 .
    [CrossRef]
  6. Peng You, Peng Chen, Xi Li, Ang Bian. Gated Memory-Guided Multi-scale spatio–temporal–spectral feature fusion network for unsupervised Internet of Things time series anomaly detection. Engineering Applications of Artificial Intelligence, 2026 , 169 .
    [CrossRef]
  7. Lucija Žužić, Franko Hržić, Jonatan Lerga. Collision course detection for personal watercrafts using models based on recurrent neural networks. Knowledge-Based Systems, 2026 , 333 .
    [CrossRef]
  8. Yuxin Jia, Nan Guo, |Tiewei Shang, Wenlu Li, Yueyang Sun, Junfei Qiao. A Bayesian‐Optimized GRU Network With WMD‐EFAST Self‐Organizing Mechanism for Multimodal Atmospheric Pollutant Prediction. International Journal of Adaptive Control and Signal Processing, 2026 .
    [CrossRef]
  9. Pradnya V. Patil, Jagdish W. Bakal. . 2026 7th International Conference on Smart Systems and Inventive Technology (ICSSIT), 2026 .
    [CrossRef]
  10. Songlin Fu, Wei Xie, Qingxin Wang, Haoyang Fu, Yichen Yang, Ziming Chen, Tingting Zhou, Madal Artur. CABT-Net: A hybrid CNN-Attention-BiLSTM-Transformer model for short-term PM2.5 forecasting in Colorado's Front Range. Atmospheric Pollution Research, 2026 , 17 (9).
    [CrossRef]
  11. Lijun Mao, Tianxiang Zhou, Chenghui Nan. Rapid extraction of forest burned areas using Sentinel-2 satellite imagery on the PIE-engine platform. Journal of Measurements in Engineering, 2026 .
    [CrossRef]
  12. Guangming Li, Zhi-Ping Fan, Gongshu Wang. Blockchain technology adoption decisions and investment cost sharing in the context of consumer privacy protection in online shopping. Expert Systems with Applications, 2026 , 299 .
    [CrossRef]
  13. Wenyi Liu, Tongming Jian, Lei Meng, Di Song, Jianbin Cao. A novel wind turbine fault diagnosis method based on improved TFMST and DSC-CNN-GRU model. Journal of Measurements in Engineering, 2026 , 14 (1).
    [CrossRef]
  14. Xiaorui Guo, Jiayue Zhang. A Hybrid Sensing-Prediction Framework for Soft Robot Deformation Perception: Coupling Field Simulation With Gated Recurrent Unit. IEEE Sensors Journal, 2025 , 25 (19).
    [CrossRef]
* Citation data provided by Crossref Cited-by.

Cite This Article

APA Style
Haider, Z. A., Zeb, A., Rahman, T., Khan, F. M., Khan, I. U., Sohail, Q., Bilal, H., Khan, M. A., & Ullah, I. (2025). Optimizing Cloud Security with a Hybrid BiLSTM-BiGRU Model for Efficient Intrusion Detection. ICCK Transactions on Sensing, Communication, and Control, 2(2), 106-121. https://doi.org/10.62762/TSCC.2024.433246
Export Citation
RIS Format
Compatible with EndNote, Zotero, Mendeley, and other reference managers
TY  - JOUR
AU  - Haider, Zeeshan Ali
AU  - Zeb, Asim
AU  - Rahman, Taj
AU  - Khan, Fida Muhammad
AU  - Khan, Inam Ullah
AU  - Sohail, Qaisar
AU  - Bilal, Hazrat
AU  - Khan, Muhammad Abbas
AU  - Ullah, Inam
PY  - 2025
DA  - 2025/05/19
TI  - Optimizing Cloud Security with a Hybrid BiLSTM-BiGRU Model for Efficient Intrusion Detection
JO  - ICCK Transactions on Sensing, Communication, and Control
T2  - ICCK Transactions on Sensing, Communication, and Control
JF  - ICCK Transactions on Sensing, Communication, and Control
VL  - 2
IS  - 2
SP  - 106
EP  - 121
DO  - 10.62762/TSCC.2024.433246
UR  - https://www.icck.org/article/abs/TSCC.2024.433246
KW  - cloud security
KW  - network intrusion detection
KW  - deep learning
KW  - BiLSTM-BiGRU
KW  - hybrid models
KW  - cybersecurity
KW  - cloud computing
AB  - To address evolving security challenges in cloud computing, this study proposes a hybrid deep learning architecture integrating Bidirectional Long Short-Term Memory (BiLSTM) and Bidirectional Gated Recurrent Units (BiGRU) for cloud intrusion detection. The BiLSTM-BiGRU model synergizes BiLSTM's long-term dependency modeling with BiGRU's efficient gating mechanisms, achieving a detection accuracy of 96.7% on the CIC-IDS 2018 dataset. It outperforms CNN-LSTM baselines by 2.2% accuracy, 3.3% precision, 3.6% recall, and 3.6% F1-score, demonstrating consistently superior performance across all evaluation metrics. The architecture demonstrates operational efficiency through 20% reduced computational latency and 15% lower memory footprint compared to conventional models, enabled by residual memory preservation and parallel processing capabilities. Experimental results further validate strong detection capability across diverse attack categories, including DDoS (97.3%), DoS (98.0%), and brute-force attacks (96.1%), establishing a methodological framework for real-time cloud security services. This work advances hybrid deep learning applications in trusted computing environments through optimized temporal feature extraction and resource-aware threat detection.
SN  - 3068-9287
PB  - Institute of Central Computation and Knowledge
LA  - English
ER  - 
BibTeX Format
Compatible with LaTeX, BibTeX, and other reference managers
@article{Haider2025Optimizing,
  author = {Zeeshan Ali Haider and Asim Zeb and Taj Rahman and Fida Muhammad Khan and Inam Ullah Khan and Qaisar Sohail and Hazrat Bilal and Muhammad Abbas Khan and Inam Ullah},
  title = {Optimizing Cloud Security with a Hybrid BiLSTM-BiGRU Model for Efficient Intrusion Detection},
  journal = {ICCK Transactions on Sensing, Communication, and Control},
  year = {2025},
  volume = {2},
  number = {2},
  pages = {106-121},
  doi = {10.62762/TSCC.2024.433246},
  url = {https://www.icck.org/article/abs/TSCC.2024.433246},
  abstract = {To address evolving security challenges in cloud computing, this study proposes a hybrid deep learning architecture integrating Bidirectional Long Short-Term Memory (BiLSTM) and Bidirectional Gated Recurrent Units (BiGRU) for cloud intrusion detection. The BiLSTM-BiGRU model synergizes BiLSTM's long-term dependency modeling with BiGRU's efficient gating mechanisms, achieving a detection accuracy of 96.7\% on the CIC-IDS 2018 dataset. It outperforms CNN-LSTM baselines by 2.2\% accuracy, 3.3\% precision, 3.6\% recall, and 3.6\% F1-score, demonstrating consistently superior performance across all evaluation metrics. The architecture demonstrates operational efficiency through 20\% reduced computational latency and 15\% lower memory footprint compared to conventional models, enabled by residual memory preservation and parallel processing capabilities. Experimental results further validate strong detection capability across diverse attack categories, including DDoS (97.3\%), DoS (98.0\%), and brute-force attacks (96.1\%), establishing a methodological framework for real-time cloud security services. This work advances hybrid deep learning applications in trusted computing environments through optimized temporal feature extraction and resource-aware threat detection.},
  keywords = {cloud security, network intrusion detection, deep learning, BiLSTM-BiGRU, hybrid models, cybersecurity, cloud computing},
  issn = {3068-9287},
  publisher = {Institute of Central Computation and Knowledge}
}

Article Metrics

Citations
Crossref
14
Scopus
14
Views
4414
PDF Downloads
605

Publisher's Note

ICCK stays neutral with regard to jurisdictional claims in published maps and institutional affiliations.

Rights and Permissions

Institute of Central Computation and Knowledge (ICCK) or its licensor holds exclusive rights to this article under a publishing agreement with the author(s) or other rightsholder(s); author self-archiving of the accepted manuscript version of this article is solely governed by the terms of such publishing agreement and applicable law.
ICCK Transactions on Sensing, Communication, and Control
ICCK Transactions on Sensing, Communication, and Control
ISSN: 3068-9287 (Online) | ISSN: 3068-9279 (Print)
Portico
Preserved at
Portico