Connected devices have made network security a problem of scale as much as detection. Internet of Things systems, industrial sensors and increasingly connected vehicles generate long streams of traffic in which malicious behaviour can be rare, fast-changing and expensive to inspect. A new machine-learning study reports an intrusion-detection architecture designed to improve both classification performance and computational efficiency.
Published in Scientific Reports on 5 October 2026, the research introduces MambaEcoNet-SC1D, a neural-network pipeline that combines sparse convolution, an efficiency-oriented transformer and a state-space Mamba block. The system was evaluated on two established cybersecurity benchmark datasets and achieved 98.87% accuracy on CICDDoS-2019 and 99.99% on CSE-CIC-IDS2018.
Why intrusion detection is becoming harder
Traditional intrusion-detection systems look for signs that network activity is malicious. The difficulty is that modern networks produce huge volumes of traffic, attacks can unfold over time, and a useful detector has to distinguish unusual but legitimate behaviour from a genuine threat. High accuracy alone is therefore not enough. A model that generates too many false alarms can overwhelm security teams, while a model that is too computationally demanding may be difficult to deploy where processing power or latency is constrained.
This is particularly relevant for IoT and connected-vehicle environments. These systems can involve many endpoints with different hardware, communication patterns and security capabilities. The researchers therefore designed their model as a sequence of specialised components rather than relying on a single neural-network mechanism.
Three stages learn different features of network traffic
The first stage uses a sparse one-dimensional convolutional neural network, or Sparse CNN-1D. Convolutional networks are effective at identifying local patterns, while sparsity is intended to keep the representation compact. In practical terms, this stage extracts short-range features from network traffic without treating every possible feature interaction as equally important.
The second component is an Eco Transformer. Transformers are widely used because attention mechanisms can model relationships between elements that are separated in a sequence, but standard attention can be computationally expensive. The study uses distance-based Eco Attention to capture contextual relationships while aiming to reduce that burden.
A state-space Mamba block then addresses longer temporal patterns. State-space models have attracted attention as an alternative way to process long sequences efficiently. For cybersecurity, that matters because an attack may not be identifiable from one isolated packet or short burst of traffic. The sequence of events can carry the signal.
The architecture is paired with Multi-Objective Bayesian Optimisation. Rather than tuning the model around accuracy alone, the optimisation process is intended to balance several objectives, including detection performance, false alarms and inference efficiency. This distinction is important because the best benchmark classifier is not necessarily the most useful operational security system.
Accuracy reached 98.87% and 99.99% on two datasets
The researchers tested MambaEcoNet-SC1D on CICDDoS-2019 and CSE-CIC-IDS2018, two benchmark datasets used to evaluate intrusion-detection methods under multiple forms of malicious and benign traffic.
On CICDDoS-2019, the model achieved 98.87% accuracy, 98.85% precision and a 98.86% F1-score. Accuracy describes the proportion of classifications that were correct overall. Precision asks how often traffic flagged as malicious was actually malicious, while the F1-score balances precision with recall. Reporting the measures together gives a more useful view than accuracy in isolation, particularly when classes are unevenly represented.
Performance was even higher on CSE-CIC-IDS2018. The researchers report 99.99% across the model’s core performance metrics. Their comparative evaluation also found improvements in accuracy and specificity relative to the recent intrusion-detection frameworks included as benchmarks.
These are striking results, but their meaning needs to be kept within the experimental setting. Benchmark datasets allow models to be compared under controlled conditions. They do not reproduce every feature of a live corporate, industrial or vehicle network, where traffic changes over time, devices behave unpredictably and attackers can deliberately adapt to detection systems.
Why the architecture matters beyond the headline accuracy
The more interesting contribution may be the way the model divides the detection problem. Local traffic signatures, contextual relationships and long-range temporal dependencies are handled by different stages. The optimisation layer then attempts to find settings that perform well across competing objectives.
That reflects a broader challenge in applied artificial intelligence. Increasing model complexity can improve predictive performance, but it can also increase latency, memory requirements and energy consumption. Security systems often operate continuously, which makes those costs cumulative. An architecture that maintains high detection performance while reducing unnecessary computation could therefore matter even when percentage-point improvements in benchmark accuracy appear small.
For South African organisations, the findings are relevant to a technology environment in which connected devices are increasingly used across banking, telecommunications, logistics, utilities and industrial operations. The study does not test South African network traffic, so its reported performance cannot simply be transferred to local infrastructure. It does, however, illustrate the direction in which automated defence is moving: security models that analyse not only isolated events, but the relationships and sequences that surround them.
Benchmark success is not the same as deployment
Several limitations matter before treating near-perfect benchmark results as evidence of near-perfect real-world detection. Both datasets are established research benchmarks, meaning the model is evaluated against labelled traffic collected under particular conditions. Production networks can contain new applications, changing user behaviour, previously unseen attack techniques and data distributions that differ from the training environment.
The research also evaluates a model architecture rather than a full operational security programme. Real deployment would need to account for hardware constraints, retraining schedules, concept drift, integration with security operations, adversarial manipulation and the cost of investigating false positives. A detector can be statistically impressive while still being difficult to maintain at scale.
The results therefore support a narrower conclusion. Combining sparse local feature extraction, efficient contextual attention, long-sequence state-space modelling and multi-objective optimisation produced very strong performance on two recognised intrusion-detection datasets. The next question is how well those gains survive when the model leaves the benchmark environment and encounters the messy, evolving traffic of real networks.
Source Information
Study Title: A multi-objective bayesian optimized neural network approach for intrusion detection
Authors: S. Margret Beaula and J. Merry Geisa
Journal: Scientific Reports
Year: 2026
Published: 5 October 2026
DOI: 10.1038/s41598-026-74503-6







