A Systematic Review and Comparative Analysis of Deep Learning and Transformer-Based Methods for Cyberattack Detection
Keywords:
intrusion detection, deep learning, Transformer, Vision TransformerAbstract
The escalating sophistication and volume of cyberattacks have necessitated the development of advanced intrusion detection systems capable of identifying both known and emerging threats. Deep learning approaches have emerged as promising solutions, with recent attention shifting toward Transformer and attention-based architectures that leverage self-attention mechanisms for capturing long-range dependencies in network traffic. This systematic literature review synthesizes evidence from peer-reviewed studies published between 2020 and 2026 to provide a comprehensive comparative analysis of deep learning architectures for cyberattack detection. Following PRISMA 2020 guidelines [1], we conducted systematic searches across IEEE Xplore, ScienceDirect, SpringerLink, ACM Digital Library, and Wiley databases. Our analysis encompasses convolutional neural networks, recurrent architectures including LSTM and GRU, autoencoders, attention mechanisms, Transformer models, and Vision Transformers. Descriptive quality considerations examined studies regarding methodological clarity, dataset transparency, evaluation rigor, reproducibility, baseline comparisons, and reporting completeness. Our findings indicate that while Transformer-based methods demonstrate superior performance on certain benchmarks, their advantages are contingent upon dataset characteristics, computational resources, and evaluation protocols. Vision Transformers show promise for traffic visualization approaches but face constraints regarding computational requirements. The review identifies critical unresolved challenges including class imbalance, concept drift, adversarial robustness, and cross-dataset generalization. We present evidence-based research gaps and future directions, emphasizing the need for standardized evaluation frameworks, reproducible experimental designs, and realistic deployment assessments. This review contributes a rigorous comparative framework that advances understanding of architecture selection trade-offs in practical cybersecurity applications.