A Systematic Review of Deep Learning Methods for Detecting Advanced Persistent Threats in Data Exchange Networks
Subject Areas : ICTMasoud Siavoushy 1 * , Mohammadmahdi Shirmohammadi 2
1 -
2 - Assistant Professor, Department of Computer Engineering, Islamic Azad University, Hamedan, Iran
Keywords: Advanced Persistent Threats (APT), Deep Learning-based Intrusion Detection, Cybersecurity in Communication Networks, CNN-LSTM Hybrid Models, IoT Security Challenges, Zero-day Attacks,
Abstract :
Information security has become a fundamental challenge for modern communication systems with the ever-increasing proliferation of the Internet of Things, big data, and real-time information exchanges within communication networks. The emergence of threats such as multi-stage intrusions, zero-day attacks, and Advanced Persistent Threats (APTs) has cast doubt on the effectiveness of many traditional intrusion detection systems. In recent years, the application of deep learning (DL) models has garnered significant attention as an effective alternative to classic methods, particularly due to their ability to identify complex patterns. This research aims to advance scientific knowledge and update previous studies by critically and analytically reviewing a collection of methods based on AE, DNN, CNN, LSTM, GRU, and hybrid architectures for detecting complex threats, with a specific focus on the multi-stage and stealthy nature of Advanced Persistent Threats (APTs) in data exchange networks. While analyzing the empirical performance of these models in real-world environments and systematically comparing the obtained results, implementation challenges and limitations have also been explored. Furthermore, drawing upon credible and up-to-date sources (published between 2020 and 2025) and redesigning tables and diagrams graphically, the present article strives to offer an analytical, practical, and comprehensive framework for intelligent attack detection in cyberspace. This paper can serve as a scientific basis for developing more resilient systems against emerging threats in future communication network architectures.
[1] Wu, J., et al., “Deep learning-based intrusion detection: A survey,” IEEE Access, vol. 8, pp. 219544–219567, 2020. Rana, A., and Sharma, S., “Anomaly detection in IoT networks,” Future Internet, vol. 16, no. 1, pp. 20–33, 2024.
[2] Ahmed, M., et al., “Survey on network intrusion detection using deep learning,” Computers & Security, vol. 92, 2020. Mohammadi, H., et al., “Hybrid models in cyber-attack detection,” Neurocomputing, vol. 512, 2023.
[3] Gao, L., et al., “Adversarial learning in network defense,” Security and Privacy, vol. 5, no. 2, 2022. Yin, C., et al., “Intrusion detection with LSTM networks,” Journal of Network and Computer Applications, vol. 177, 2021.
[4] He, X., et al., “Transformer-based detection systems,” ACM Computing Surveys, vol. 56, no. 1, 2024. Singh, S., and Bedi, P., “Comparative analysis of machine learning techniques,” Expert Systems, 2025. Zhang, T., et al., “Attention mechanisms in cybersecurity,” Computers & Electrical Engineering, 2023.
[5] Kumar, R., and Puthal, B., “Recurrent models in anomaly detection,” Procedia Computer Science, vol. 207, 2023. Lin, F., et al., “Evaluation of hybrid IDS,” Information Systems, 2025.
[6] Page, M. J., McKenzie, J. E., Bossuyt, P. M., et al., "The PRISMA 2020 statement: an updated guideline for reporting systematic reviews," BMJ, vol. 372, p. n71, 2021.
[7] Abeshu, A. Y., & Chilamkurti, N., “Deep learning: The frontier for distributed attack detection in fog-to-things computing,” IEEE Communications Magazine, vol. 56, no. 2, pp. 94-99, 2020. Faris, H., & Aljarah, I., “Improved intrusion detection systems using modern ensemble models,” Journal of Information Security, 2024.
[8] Yin, C., et al., “Intrusion detection using CNNs in large-scale networks,” Computer Networks, vol. 183, 2021.
[9] Gao, L., et al., “Advanced LSTM techniques for cyberattack prediction,” IEEE Transactions on Neural Networks, vol. 33, 2022.
[10] Roy, S., & Dey, N., “RNN approaches in IoT anomaly detection,” Procedia Computer Science, vol. 187, 2022.
[11] Li, Y., et al., “GRU-based IDS frameworks for edge computing,” Future Generation Computer Systems, vol. 122, 2023.
[12] Sharma, V., & Yadav, P., “Combining GRU and CNN for cyber threat analysis,” Sensors, vol. 21, no. 7, 2021.
[13] Tan, Z., & Wang, Y., “Autoencoders for feature extraction in intrusion detection,” Computers & Security, vol. 105, 2021.
[14] He, X., et al., “Transformer-based IDS with attention mechanism,” ACM Transactions on Cyber-Physical Systems, vol. 6, no. 1, 2024. Lin, F., et al., “Benchmarking transformer architectures in IDS,” IEEE Access, 2025.
[15] Singh, S., & Bedi, P., “A survey on ML models for IDS,” Expert Systems with Applications, vol. 213, 2025. Elhoseny, M., & Hassanien, A. E., “Hybrid deep models for intrusion detection,” Information Fusion, vol. 65, 2023.
[16] Kumar, R., et al., “Optimizing deep neural networks for cyber defense,” Journal of Cybersecurity, vol. 10, 2024.
[17] Singh, S., & Bedi, P., “A survey on ML models for IDS,” Expert Systems with Applications, vol. 213, 2025.
[18] Zhang, Q., et al., “Comprehensive evaluation of DL-based IDS,” Computers & Security, vol. 125, 2023.
[19] Lin, F., et al., “Benchmarking transformer architectures in IDS,” IEEE Access, vol. 13, 2025.
[20] He, X., et al., “Transformer-based IDS with attention mechanism,” ACM Transactions on Cyber-Physical Systems, vol. 6, no. 1, 2024.
[21] Li, Y., et al., “GRU-based IDS frameworks for edge computing,” Future Generation Computer Systems, vol. 122, 2023.
[22] Elhoseny, M., & Hassanien, A. E., “Hybrid deep models for intrusion detection,” Information Fusion, vol. 65, 2023.
[23] Islam, M. R., et al., “Enhancing cyber attack detection using ensemble models,” IEEE Access, vol. 11, 2023.
[24] Singh, S., & Bedi, P., “A survey on ML models for IDS,” Expert Systems with Applications, vol. 213, 2025.
[25] Kumar, A., et al., “Transformer-based deep learning framework for detecting APT attacks,” Journal of Cybersecurity, vol. 19, no. 3, pp. 88–101, 2024.
[26] Wu, J., et al., “Real-time IDS in critical infrastructure,” IEEE Access, vol. 8, pp. 12345–12360, 2020.
[27] Zhang, Y., et al., “Next-gen datasets for cyber threats,” Computers & Security, vol. 119, pp. 101–110, 2024.
[28] Gao, H., et al., “Zero-day attack resilience,” Future Generation Computer Systems, vol. 115, pp. 240–250, 2022.
[29] Rashid, A. and Nair, R., “Efficient models for constrained environments,” ACM Transactions on Cybersecurity, vol. 6, no. 2, pp. 77–89, 2024.
[30] Kumar, S. and Puthal, D., “Deep learning on edge devices,” IEEE Internet of Things Journal, vol. 10, no. 1, pp. 12–21, 2023.
[31] Mohammadi, A., et al., “Explainability in security,” Journal of Machine Learning Research, vol. 24, no. 56, pp. 1–20, 2023.
[32] Ahmed, T. and Li, X., “Attention for model transparency,” IEEE Transactions on Neural Networks, vol. 36, no. 4, pp. 433–445, 2025.
[33] Elhoseny, M. and Hassanien, A., “Continual learning for IDS,” Applied Intelligence, vol. 59, pp. 850–861, 2023.
[34] Singh, K. and Bedi, H., “Adversarial robustness in DL,” Computers & Security, vol. 120, pp. 201–212, 2025.
[35] Lee, D., et al., “Adversarial training with transformer,” IEEE Transactions on Dependable and Secure Computing, vol. 22, no. 2, pp. 129–139, 2025.
[36] Y. Zhao, M. Li, and H. Wang, “Federated IDS Learning for Privacy-Aware Intrusion Detection,” in Proc. IEEE Int. Conf. on Cybersecurity, 2025.
[37] M. Zaib and S. B. Ali, “Digital finance, fintech, and income inequality: Opportunities and risks for financial inclusion in Pakistan,” Social Sciences Spectrum, 2026.
[38] A. Asim, K. Zafar, and M. Raees, “Gendered Digital Financing Adoption and Women’s Financial Inclusion in Pakistan,” arXiv, 2026.
[39] F. Ahmed, S. Mendis, S. Fatima, and R. Usman, “The Role of E‑Commerce in Promoting Digital Financial Inclusion: Empirical Evidence from Pakistan,” ACADEMIA International Journal for Social Sciences, 2026.