Hybrid Ensemble Learning for Real-Time Intrusion Detection in Critical Infrastructure Environments.
Abstract: The increasing digitization of critical infrastructure environments has significantly enhanced operational efficiency while simultaneously exposing industrial systems to sophisticated cyber threats. Critical sectors such as oil and gas, energy, transportation, and manufacturing rely heavily on interconnected Information Technology (IT) and Operational Technology (OT) systems, making them attractive targets for cybercriminals and nation-state actors. Traditional intrusion detection systems (IDSs), which are primarily signature-based and rule-driven, often struggle to detect advanced persistent threats (APTs), zero-day attacks, and other evolving cyber threats in real time. Consequently, there is a growing need for intelligent cybersecurity solutions capable of adaptive threat detection and automated response. This study proposes a hybrid ensemble learning framework for real-time intrusion detection in critical infrastructure environments. The framework integrates machine learning and deep learning techniques to leverage the strengths of individual algorithms while mitigating their weaknesses. Specifically, Random Forest (RF), Convolutional Neural Networks (CNN), Long Short-Term Memory (LSTM) networks, and Transformer models are combined within an ensemble architecture designed to improve detection accuracy, reduce false positive rates, and enhance system resilience against emerging threats. Experimental evaluation was conducted using benchmark cybersecurity datasets and a hybrid OT/IT dataset representative of industrial environments. The results demonstrated that the proposed hybrid ensemble model achieved an accuracy of 98.5%, a precision of 97.6%, a recall of 97.8%, and an F1-score of 97.7%, outperforming traditional intrusion detection approaches and individual machine learning models. The findings suggest that hybrid ensemble learning provides a robust and scalable solution for real-time cyberattack detection in critical infrastructure systems. The study contributes to the growing body of knowledge on artificial intelligence-driven cybersecurity and offers practical implications for securing industrial environments against increasingly sophisticated cyber threats.