Abstract
<title>Abstract</title> <p>To address class imbalance, weak minority-attack recognition, and complex traffic feature representation in Industrial Internet of Things (IIoT) cyberattack detection, this study proposes an IIoT attack detection method based on class imbalance processing and an attention mechanism. The TON-IoT dataset is first cleaned, encoded, and normalized, and oversampling and class-aware learning strategies are introduced to reduce the negative effect of minority samples. Feature selection is then applied to reduce redundant information, and a CNN–BiLSTM–Attention model is constructed for multi-class attack detection. Experimental results show that, under the original imbalanced setting, the MITM recall is only 0.005, while Borderline-SMOTE improves it to 0.584. In the baseline comparison, the proposed model achieves an Accuracy of 0.869, Macro-F1 of 0.852, and MCC of 0.853, outperforming Naive Bayes, Random Forest, MLP, and CNN–BiLSTM–Attention. The results demonstrate that the proposed method improves both overall detection performance and minority-class attack recognition.</p>