Abstract
Wireless networks and communications have witnessed tremendous development and growth in recent periods and up until now, as there is a group of diverse networks such as the well-known wireless communication networks and others that are not linked to an infrastructure such as telephone networks, sensors and wireless networks, especially in important applications that work to send and receive important data and information in relatively unsafe environments, cybersecurity technologies pose an important challenge in protecting unsafe networks in terms of their impact on reducing crime. Detecting hacking in electronic networks and penetration testing. Therefore, these environments must be monitored and protected from hacking and malicious attacks. In this manuscript, a correspondence model is designed to discuss the algorithm in the environment of wireless communication systems and distributed computing by adopting the protocol data enhancement to the network using structured construction and diversity algorithm to improve the effectiveness of the intrusion detection system. Next, a multi-label convolutional neural network model is used to detect business transactions. An CNN was trained on the WSN-DS dataset using 5-Fold in CV technique with three hidden layers. The highest Precision values 0.951 of Grayhole attack for multi-classification.
Introduction
With the increasing use of communication and networking software, the security assessment of computer network environment and operating systems - where most users of networked computers need to secure their data in the client and server environment.1–3 The networking and communication applications has raised many concerns about the possibility of threatening the networks used and violating the security and privacy of data and information.4,5
Due to the special use of Internet applications over computer networks, cyber-attacks and the use of unauthorized applications have increased. This increase has posed a threat to the availability of the service and consumer privacy.6,7 The main goal of designing network intrusion detection systems (IDS) is to detect anomalous traffic behaviors that firewalls may not be able to detect. 8
Machine learning algorithms and deep learning are the basic material and IDS in networks. Because it is important, the dependency is more important in discovering the tools used and alerting the attack in the stations of the properties in the place that contains the data to detect the intrusion. 9 For this reason, the procedure of selecting characters and important infections. 10 The system is located on an important page in the pre-classification and detection stage, without the wrong selection of features causing incomplete results, without active feature selection algorithms as more important. IDS are divided into three main types: signature-based protection systems, network anomaly detection systems, and hybrid detection systems of the two types mentioned above. 11
Anomaly-based IDS excel at detecting zero-day attacks by identifying behaviors that deviate from established normal activities. However, their effectiveness in detecting known attacks is generally lower compared to signature-based systems. To address the limitations of both approaches, hybrid IDS have been developed. These systems combine the strengths of both signature-based and anomaly-based methods, allowing them to detect both known and unknown threats. 12
A network sequence detection system was adopted using machine learning and neural network methodologies, which is important in the field of IDS. Machine learning techniques have recently emerged as promising solutions for the development of IDS. Machine learning includes a set of methods that use mathematical models to automatically identify, analyze, and extract patterns from data.11,13
Intrusion detection involves continuously monitoring and modeling normal network behaviors, which allows potential threats to be identified by detecting deviations from established patterns. They are particularly important because they indicate the emergence of rare and potentially dangerous conditions, such as atypical traffic patterns that indicate ongoing attacks or unauthorized data transfers. These anomalies fall into three categories: individual anomalies, contextual anomalies, and mass anomalies. These can lead to DoS (DoS) within the system and other devices, user-to-root (U2R) attacks, and remote-to-local (R2L) attacks. 14 Using machine learning as an anomaly detection mechanism to distinguish between benign and malicious traffic is a topic of contemporary research that shows promising results. in most approaches, packets or traffic flows are represented using key features such as packet size, protocol, and inter-packet interval.15,16
Most researchers face problems in the stages of detecting attacks on wireless networks, which are constantly changing due to the real-time handling of them. Among these challenges and problems is classifying the binary attack separately from the multi-classification, which depends on the type of attack itself and not only on its impact.
To address the limitations faced by researchers in this field, the proposed approach entails integrating deep learning into IDS with both binary and multiclassification based on the dynamic threshold of the DNN classifier to classify the type of attack. The proposed approach aims to take advantage of deep learning model, such as its ability to train on its own and handle large amounts of data.
Related works
Cybersecurity is a critical challenge for current and future generations of networks. Although many articles have been published on the development of IDS.
Ioannou, C., et al. (2017) 17 proposed a generalized approach for anomaly-based intrusion detection (IDS), using binary logistic regression (BLR) statistics. The researchers named the proposed system mIDS, which mainly classifies local sensor activity as normal or malicious. The proposal was evaluated using routing layer attacks and the system achieved a classification accuracy of 88% in detecting malicious activity.
Ioannou, C. and V. Vassiliou (2018) 18 Once again, the researcher used his mIDS system to monitor and detect attacks based on the local node. The proposed system relied on local node parameters of benign and malicious behaviors to detect network anomalies within the associated node. mIDS was tested in an environment where attacks are present at the network layer. The results showed that the proposal achieved an accuracy of up to 96% in attack detection.
Hu, Z., et al. (2020) 19 employed a fusion of Convolutional Neural Network (CNN) with Adaptive Synthetic Sampling techniques to improve the efficacy of IDS. A consolidated approach was implemented to improve the accuracy and resilience of the IDS in efficiently detect and identify network intrusion. This model need for further evaluation across diverse datasets and network environments
Derweesh, M. S., et al. (2024), 20 a system is proposed to detect the nature of the attack and classify the network data of suspicious attacks based on binary classification into normal and dangerous attacks. In the initial steps, the authors adopt preprocessing operations to prepare the data for normal or attack classification by the proposed classifier, such as feature normalization and feature selection. A CNN model is built using the KDD99 dataset, and then the CNN model is used to find outliers.
Alazawi, S. A. H., et al. (2024). 21 A method for detecting intrusion attacks based on analysing the natural behavior of the system is presented by constructing a special convolutional network to achieve this goal. Classification and detection of intrusion detection programs are of vital importance. The results of the proposed CNN are compared with the regular machine learning method (SVM), with feature selection by association for both methods. The same datasets are used to train and test both CNN and SVM. Some metrics are defined to evaluate the performance of classification and prediction models for a specific type of regular attacks, denial of service attacks, and BOT attacks, where SVM and CNN achieved an accuracy of 85.58% and 95.59%, respectively.
Albarka Umar, M., et al. (2020). 22 Hybrid feature and candidate selection algorithms were designed for network intrusion detection based on envelope with tar tree classifier to guide the decision selection in attack type. Machine learning algorithms adopted - UNSW-NB15 dataset was used for training data. Experimental results show that the proposed approach, although effective, is computationally time-consuming compared to the filter-based methods while achieving similar results. It is also found that there are unobserved issues related to the consistency of the UNSW-NB15 dataset., the accuracy of the system was up to 91 percent.
Abdulhameed, A. A., et al. (2024) 23 Designing a Network Intrusion Detection Model. Since Deep Neural Networks (DNNs) are classical deep learning models known for their strong classification performance, which makes them popular in intrusion detection alongside other machine learning algorithms, they have been chosen to improve dataset-based intrusion classification models for IDS. The developed coronavirus algorithm is adopted to improve the system performance by identifying optimal features. The test results showed exceptional performance on the NSL-KDD dataset, where the proposed CNN model achieved 99.3% accuracy for multi-class classification, while the decision tree (DT) achieved 88.64% accuracy for anomaly detection in two-class classification.
Dharini, N., et al. (2023), 24 the authors used Matrix Laboratory to collect data on wireless sensor network attacks. The proposed method included evaluating the performance of a set of machines learning techniques and calculating the time required to build classification models for the collected dataset. The XGBoost algorithm achieved an accuracy of 99.16%, while the Bagging algorithm demonstrated efficient performance, achieving an accuracy of 99.8%. XGBoost outperformed the others in terms of speed when measuring the time factor.
WSN-Operating system
A WSN operating system selection is a challenging task which requires balancing a number of factors. These consist of the OS's system requirements, its ability to accommodate the particular requirements of the application, and its interoperability with other devices. 25 As shown in Figure 1, the architecture and platform support, memory limitations, and computational capabilities of the microcontroller unit (MCU) utilized in the sensor nodes are all included in the system requirements. The OS's suitability for the desired application is determined by its features, including memory management, multitasking, multithreading, and synchronization.26,27 Furthermore, the extent to which an OS supports peripheral devices from simple sensors to advanced wireless communication protocols can significantly impact the overall functionality and efficiency of the WSN.

The dataset includes 17 features of the wireless sensor network monitoring environment for 374,000 cases and is classified as either a natural (non-malicious) attack or an abnormally effective attack.
The general structure of the proposed system requires performing some necessary procedures on the data set in order to use it in the classification model, such as data pre-processing operations by data normalization and data balancing.
The proposed model for attack detection includes two stages: the first is the pre-processing stage, and the second stage is the multi-classification stage based on the dynamic threshold of the DNN classifier to classify the type of attack.
Preprocessing operations
The dataset is built from within the wireless network by monitoring the transmitted and received packets. A WSN dataset was created to four types of denial-of-service attacks classes as well as normal behavior when there are no attacks. In this study, the attributes of WSNs and the challenges they face when using the Low Energy Aware Cluster Hierarchy (LEACH) routing protocol were considered. 28 This choice was made because LEACH is one of the most popular hierarchical routing protocols in WSNs, which consumes limited power and is characterized by its simplicity. The resulting dataset is called WSN-DS dataset, it contains four types of DoS attacks which are Blackhole, Grayhole, Scheduling, and Flooding attacks, and includes instance where there was not attack. 29
Dataset balancing
The WSN-DS dataset has various distributions that are not equal or skewed. This ranges from a slight to a severe imbalance in terms of balance. This imbalance poses a challenge to the classifier's parameters, as most algorithms assume that the classes are equal in distribution.30,31 Table 1 and Figure 2 including the distribution of features for WSN-DS dataset in multi-classification.
Dos distribution in multi classification.
Dos distribution in multi classification.

Percent of attacks in WSN-DS dataset.
Hence, it was important to balance and clean the data sets before entering them into the workbook as part of the pre-processing stage. Equ.1 is used for the calculation of the imbalance ratio:32,33
Where: Ci shows the data size in the class i.
Feature selection is a common and useful technique to reduce computational cost, data, and increase accuracy.34,35 Feature ranking and selection is usually applied for dimensionality reduction which in turn lowers model computational cost. The features of the initial dataset were reduced by using the information gain algorithm which is then relied upon to classify the data after the pre-processing stage operations. The calculation of the IG is mainly based on identifying the best feature.
The feature ‘A’ with the highest Information Gain, Gain ‘A’, is chosen as the split feature at node N. This is equivalent to saying that we want to divide by attribute ‘A’, which will serve as “best classification,” therefore, the amount of information required to complete the classification of the data set is small.36,37
Entropy is used to count inconstancy of a set by using the likelihood of a certain feature or attribute. IG is inverse of Entropy. The plan of Entropy to analyse multiclass ‘more than 2’ is shown below36,37
K is the number of classes. And IG of feature X and the class labels Y are calculated as follows:
E(X) is Entropy of X and E (X|Y) is Entropy of X after remark Y. Now IG is a filter method, it can scale well with the multi dimensions of data. It is also relevant with many classifiers to being classified independent.36,37
In the proposed ID – WSN model, the data set was divided into 80% for training and 20% for testing, which helps in achieving optimization for model learning and evaluation accurately.
The two basic layers of the ID – WSN model are the multiple classification part using the CNN model, and the binary classification part using the KNN classifier, where the second part of the model produces the outputs of the first part and then classifies the ID – WSN data into normal user or an untrusted attacker.
The K-NN algorithm understands that the label k in the sample space is far from the sample to be classified. The sample falls into a specific class in the case where it should already be done k does so as well. 29 There are several scales for measuring distances; the most commonly used is the Euclidean distance scale. 30
CNN model in the first part is consists of nine convolutional layers depending on problem complexity. The first layer contains 16 filters, the second layer contains 32 filters, and the last one contains 64 filters. These filters are necessary to break the problem of facial emotion recognition, which is according to previous studies a nonlinear problem. Kernel size for all filters is 3,
A max-pooling layer is added with a 1 × 2 to reduce the size of a tensor to half of its current size and stride of 1 after each layer. The max pooling layer reduces the spatial dimensions of the length and width, and therefore the number of parameters will decrease, which reduces the computations because once it is known that there is a feature then its exact location is not as important as its relative location to other features.
The nine convolutional layers are followed by a FC linear layer with 1024 neurons to allow processing on the entire data. A ReLU activation function is used on the output of FC layer, which increases the nonlinear properties of the decision function, by replacing the negative values of each pixel in the activation map with zero.
Results performance
In order to evaluate the proposed classification and detection models, we relied on the confusion matrix to extract and from the metrics used to evaluate the classifier performance, TPR, TNR, Precision, Recall, F-measure.
K-NN and CNN algorithms are evaluated using three metrics commonly used in the machine learning community: recall, precision, and F-measure (FP) - items incorrectly classified as belonging to a given class; false negatives (FN) - items incorrectly classified as not belonging to a given class; and true negatives (TN) - items correctly classified as not belonging to a given class.
Table 2 shows the improvement of the CNN training accuracy over 100 epochs, and the variation between the loss values and training accuracy as the CNN training epoch increases. As shown in Figure 3, the highest training accuracy was achieved at epoch 100, where the accuracy reached 0.9886 with a training time of 1.005 s, and the lowest loss value was achieved at the same epoch.
CNN training performance.
CNN training performance.

CNN training performance.
Performance measures for CNN multiclass.
The performance measures for applying CNN classifier on the ID – WSN is shown in Table 3 and Figure 3 Result show that CNN model can be used for ID – WSN prediction effectively with 0.958 precision rate for Grayhole class. Table 4 and Figure 4 show the performance measures for applying KNN classifier.
Performance measures for KNN multiclass for ID – WSN.

CNN performance for ID – WSN.

KNN performance for ID – WSN.
Figure 5 shows Recall, Precision, and F_measure values for the used KNN algorithm on ID – WSN. Were KNN having the highest values in Grayhole class in Recall, Precision, and F_measure measurement, the TNR is highest values for Flooding class. Scheduling class has lowest values in all performance measures.
Creating reliable security plans with minimal operating expenses is sometimes hampered by the particular protocols and operational needs of wireless sensor networks (WSNs). This study identifies the security issues in WSNs as a crucial and exciting field for further investigation, underscoring the ongoing need for research in this area. This work shows the efficacy of the proposed CNN-based classifier by classifying WSN-specific attacks in binary and multi-class formats. According to experimental data, the method not only outperforms previous research in terms of accuracy but also offers valuable information on the types and classifications of threats unique to a certain network. These findings highlight how crucial it is to incorporate security features early on when designing WSN protocols. According to the results, the suggested CNN classifier is a useful instrument for choosing the best protocols for certain real-time applications while maintaining security and efficiency. Further research avenues may concentrate on expanding this framework to encompass a wider variety of network layers, protocols, and threats in addition to investigating the use of different machine learning classifiers. Furthermore, including adaptive security measures and real-time monitoring systems might improve WSNs’ resilience and suitability for a range of situations.
Footnotes
Funding
The authors received no financial support for the research, authorship, and/or publication of this article.
Declaration of conflicting interests
The authors declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
