Lightweight AI Models for Cyber Threat Detection: An Evaluation of MobileNetV2, Random Forest, and CNN-LSTM for Phishing and Network Anomaly Detection
DOI:
https://doi.org/10.33003/fjs-2026-1018-5899Keywords:
Cybersecurity, Real-Time Threat Detection, Phishing Detection, Network Intrusion Detection, IoT Security, Explainable AIAbstract
The rising sophistication of cyber threats - including phishing, malware, and network anomalies - demands detection mechanisms beyond traditional rule-based systems. This study defines real-time detection as low-latency inference suitable for continuous monitoring in edge or cloud environments, enabling per-sample or per-flow predictions without offline batch processing. Within this framework, we evaluate lightweight models - MobileNetV2, Random Forest, and CNN-LSTM - using the UNSW-NB15 and CICIDS2017 network datasets, along with a public phishing image dataset of over 5,000 labeled samples. This heterogeneous data mix ensures exposure to diverse attack patterns and realistic deployment conditions. Given resource constraints in IoT and small-scale settings, our analysis emphasizes scalability, interpretability, and computational efficiency alongside detection performance. MobileNetV2 (2.3 million parameters, 300 million FLOPs) achieved 85.4% accuracy, Precision 0.84, Recall 0.82, F1-Score 0.83, and AUC 0.87, supporting its use as a first-stage phishing filter in low-resource environments. Random Forest initially showed reduced sensitivity to minority classes; however, SMOTE and cost-sensitive learning improved Recall to 83.2%, F1-Score to 0.81, and AUC to 0.88, yielding balanced anomaly detection. The optimized CNN-LSTM, with regularization and early stopping, achieved Precision 0.80, Recall 0.77, F1-Score 0.79, and AUC 0.84, demonstrating improved generalization. For transparency, SHAP analysis identified Packet Header Length, Domain Entropy, and Connection Duration as dominant predictive features. This work contributes a comparative evaluation of lightweight detection models, consistent attention to security-critical metrics, and interpretable insights to support practical cybersecurity deployment.
References
Alghamdi, A., Al Shahrani, A. M., AlYami, S. S., Khan, I. R., Sri, P. A., Dutta, P., & Venkatareddy, P. (2024). Security and energy efficient cyber-physical systems using predictive modeling approaches in wireless sensor network. Wireless Networks, 30(6), 5851–5866. https://doi.org/10.1007/s11276-023-03345-1
Al Shahrani, A. M., Alomar, M. A., Alqahtani, K. N., Basingab, M. S., Sharma, B., & Rizwan, A. (2022). Machine learning-enabled smart industrial automation systems using internet of things. Sensors, 23(1), 324. https://doi.org/10.3390/s23010324
Al Shahrani, A. M., Rizwan, A., Sánchez-Chero, M., Cornejo, L. L. C., & Shabaz, M. (2024). Blockchain-enabled federated learning for prevention of power terminals threats in IoT environment using edge zero-trust model. The Journal of Supercomputing, 80(6), 7849–7875. https://doi.org/10.1007/s11227-023-05763-6
Aldaej, A., Ahanger, T. A., & Ullah, I. (2024). Deep neural network-based secure healthcare framework. Neural Computing and Applications, 1–16. https://doi.org/10.1007/s00521-024-10039-y
Alzubaidi, L., Zhang, J., Humaidi, A. J., Al-Dujaili, A., Duan, Y., Al-Shamma, O., Santamaría, J., Fadhel, M. A., Al-Amidie, M., & Farhan, L. (2021). Review of deep learning: Concepts, CNN architectures, challenges, applications, future directions. Journal of Big Data, 8, 1–74. https://doi.org/10.1186/s40537-021-00444-8
Baller, S. P., Jindal, A., Chadha, M., & Gerndt, M. (2021). DeepEdgeBench: Benchmarking deep neural networks on edge devices. In 2021 IEEE International Conference on Cloud Engineering (IC2E) (pp. 20–30). IEEE. https://doi.org/10.1109/IC2E52221.2021.00016
Chen, J., Chen, J., Guo, K., Hu, R., Zou, T., Zhu, J., Zhang, H., & Liu, J. (2024). Fault tolerance-oriented SFC optimization in SDN/NFV-enabled cloud environment based on deep reinforcement learning. IEEE Transactions on Cloud Computing. https://doi.org/10.1109/TCC.2024.3357061
Conti, M., Kumar, E. S., Lal, C., & Ruj, S. (2018). A survey on security and privacy issues of bitcoin. IEEE Communications Surveys & Tutorials, 20(4), 3416–3452. https://doi.org/10.1109/COMST.2018.2842460
Debnath, S., & Das, R. (2026). A hybrid CNN-LSTM intrusion detection framework for cybersecurity in smart renewable energy grids. arXiv preprint arXiv:2606.25200.
Eibeck, A., Zhang, S., Lim, M. Q., & Kraft, M. (2024). Research data supporting “A simple and efficient approach to unsupervised instance matching and its application to linked data of power plants.” Cambridge University Research Data Repository. https://doi.org/10.17863/CAM.82548
Garcia-Teodoro, P., Díaz-Verdejo, J., Maciá-Fernández, G., & Vázquez, E. (2009). Anomaly-based network intrusion detection: Techniques, systems and challenges. Computers & Security, 28(1–2), 18–28. https://doi.org/10.1016/j.cose.2008.08.003
Goodfellow, I., McDaniel, P., & Papernot, N. (2018). Making machine learning robust against adversarial inputs. Communications of the ACM, 61(7), 56–66. https://doi.org/10.1145/3134599
Grosse, K., Papernot, N., Manoharan, P., Backes, M., & McDaniel, P. (2017). Adversarial examples for malware detection. In Computer Security–ESORICS 2017: 22nd European Symposium on Research in Computer Security (pp. 62–79). Springer. https://doi.org/10.1007/978-3-319-66399-9_4
Hou, C. K. J., & Behdinan, K. (2022). Dimensionality reduction in surrogate modeling: A review of combined methods. Data Science and Engineering, 7(4), 402–427. https://doi.org/10.1007/s41019-022-00193-5
Jang-Jaccard, J., & Nepal, S. (2014). A survey of emerging threats in cybersecurity. Journal of Computer and System Sciences, 80(5), 973–993. https://doi.org/10.1016/j.jcss.2014.02.005
Jeeva, S. C., & Rajsingh, E. B. (2016). Intelligent phishing url detection using association rule mining. Human-Centric Computing and Information Sciences, 6(1), 10. https://doi.org/10.1186/s13673-016-0064-3
Jiang, P., Xiao, J., Li, D., Yu, H., Bai, Y., Guo, Y., & Chen, X. (2023). Detecting malicious websites from the perspective of system provenance analysis. IEEE Transactions on Dependable and Secure Computing, 21(3), 1406–1423. https://doi.org/10.1109/TDSC.2023.3277613
Karbab, E. B., Debbabi, M., Derhab, A., & Mouheb, D. (2018). MalDozer: Automatic framework for android malware detection using deep learning. Digital Investigation, 24, S48–S59. https://doi.org/10.1016/j.diin.2018.01.007
Lamina, O. A., Ayuba, W. A., Adebiyi, O. E., Michael, G. E., Samuel, O.-O. D., & Samuel, K. O. (2024). AI-powered phishing detection and prevention. Path of Science, 10(12), 4001–4010. https://doi.org/10.22178/pos.112-7
Lee, S.-W., Sidqi, H. M., Mohammadi, M., Rashidi, S., Rahmani, A. M., Masdari, M., & Hosseinzadeh, M. (2021). Towards secure intrusion detection systems using deep learning techniques: Comprehensive analysis and review. Journal of Network and Computer Applications, 187, 103111. https://doi.org/10.1016/j.jnca.2021.103111
Lezzi, M., Del Vecchio, V., & Lazoi, M. (2024). Using blockchain technology for sustainability and secure data management in the energy industry: Implications and future research directions. Sustainability, 16(18), 7949. https://doi.org/10.3390/su16187949
Ma, X., Wu, J., Xue, S., Yang, J., Zhou, C., Sheng, Q. Z., Xiong, H., & Akoglu, L. (2021). A comprehensive survey on graph anomaly detection with deep learning. IEEE Transactions on Knowledge and Data Engineering, 35(12), 12012–12038. https://doi.org/10.1109/TKDE.2021.3118815
Nair, M. M., Deshmukh, A., & Tyagi, A. K. (2024). Artificial intelligence for cybersecurity: Current trends and future challenges. In Automated Security and Computer Systems—Generative Systems (pp. 83–114). Wiley. https://doi.org/10.1002/9781394213948.ch5
Nazir, A., He, J., Zhu, N., Qureshi, S. S., Qureshi, S. U., Ullah, F., Wajahat, A., & Pathan, M. S. (2024). A deep learning-based novel hybrid CNN-LSTM architecture for efficiently detecting threats in the IoT ecosystem. Ain Shams Engineering Journal, 15(7), 102777. https://doi.org/10.1016/j.asej.2024.102777
Pascanu, R., Stokes, J. W., Sanossian, H., Marinescu, M., & Thomas, A. (2015). Malware classification with recurrent networks. In Proceedings of the IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP) (pp. 1916–1920). IEEE. https://doi.org/10.1109/ICASSP.2015.7178304
Pei, X., Yu, L., & Tian, S. (2020). AMalNet: A deep learning framework based on graph convolutional networks for malware detection. Computers & Security, 93, 101792. https://doi.org/10.1016/j.cose.2020.101792
Sharif, M., Bhagavatula, S., Bauer, L., & Reiter, M. K. (2016). Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (pp. 1528–1540). ACM. https://doi.org/10.1145/2976749.2978392
Sun, N., Ding, M., Jiang, J., Xu, W., Mo, X., Tai, Y., & Zhang, J. (2023). Cyber threat intelligence mining for proactive cybersecurity defense: A survey and new perspectives. IEEE Communications Surveys & Tutorials, 25(3), 1748–1774. https://doi.org/10.1109/COMST.2023.3273282
Trinh, N. B., Phan, T. D., & Pham, V.-H. (2022). Leveraging deep learning image classifiers for visual similarity-based phishing website detection. In Proceedings of the 11th International Symposium on Information and Communication Technology (SoICT 2022) (pp. 134–141). ACM. https://doi.org/10.1145/3568562.3568629
Yang, X., & Yan, J. (2022). On the arbitrary-oriented object detection: Classification-based approaches revisited. International Journal of Computer Vision, 130(5), 1340–1365. https://doi.org/10.1007/s11263-022-01618-4
Yuan, X., Li, C., & Li, X. (2017). DeepDefense: Identifying DDoS attack via deep learning. In Proceedings of the IEEE International Conference on Smart Computing (SMARTCOMP) (pp. 1–8). IEEE. https://doi.org/10.1109/SMARTCOMP.2017.7946998
Zhou, C., & Paffenroth, R. C. (2017). Anomaly detection with robust deep autoencoders. In Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (pp. 665–674). ACM. https://doi.org/10.1145/3097983.3098052
Downloads
Published
Issue
Section
Categories
License
Copyright (c) 2026 Nwagbara Chisom Telvin, Gilbert Imuetin Osaze Aimufua, Raymond Ternenge Igbudu

This work is licensed under a Creative Commons Attribution 4.0 International License.