Title: Performance comparison of random forest and BILSTM for intrusion detection in cyber security environment
Authors: A. Prashanthi; R. Ravinder Reddy
Addresses: Department of Computer Science and Engineering, Affiliated to Osmania University, Hyderabad, India ' Department of Computer Science and Engineering, affiliated to Chaitanya Bharathi Institute of Technology, TS, India
Abstract: The widespread adoption of the internet has led to an increase in network attacks, making traditional signature-based detection methods less effective against zero-day attacks. This research examines the efficacy of anomaly-based detection techniques in identifying these threats, using two artificial intelligence models: CNN-BiLSTM and random forest classifier. Data for training and testing these models was sourced from the CICIDS2017 dataset. Results showed a high success rate, with CNN-BiLSTM achieving 95% and random forest classifier achieving 98%. These findings suggest that anomaly-based detection offers a robust strategy for detecting zero-day network attacks. The research also underscores the necessity of assessing detection systems through various performance metrics, including accuracy, precision, recall, and F1 score. Such metrics provide a comprehensive understanding of an algorithm's effectiveness in diverse scenarios, which is crucial for developing more advanced and secure network security systems capable of addressing emerging threats.
Keywords: anomaly-based detection; zero-day attacks; machine learning; BiLSTM; random forest classifier; CICIDS2017.
DOI: 10.1504/IJMOR.2026.152320
International Journal of Mathematics in Operational Research, 2026 Vol.33 No.2, pp.168 - 183
Received: 24 Nov 2023
Accepted: 11 Dec 2023
Published online: 16 Mar 2026 *