Skip to content
Open access

Hierarchical Expert-Routed Boosting with Probability Fusion for Multiclass Intrusion Detection in Edge-IoT and IIoT Networks

Sep 2026 · Black Sea Journal of Engineering and Science · 0 citations · 1 references

TL;DR

Findings indicate that attack-family information can provide useful complementary structure when fused with a strong flat boosting classifier, however, the evaluation is limited to Edge-IIoTset, and external validation on additional IoT/IIoT datasets is required in future work.

Abstract

The increasing deployment of Internet of Things (IoT) and Industrial Internet of Things (IIoT) systems has created a need for intrusion detection methods that can identify fine-grained attack categories under class imbalance. This study proposes HERB-Fusion-IDS, a hierarchical expert-routed boosting framework for multiclass intrusion detection. The method combines a flat XGBoost classifier with an attack-family router and family-specific expert classifiers, and the final class probabilities are obtained through validation-selected probability fusion. Experiments were conducted on the Edge-IIoTset benchmark as a 15-class classification task using five independent stratified repetitions. The proposed method achieved mean accuracy, macro-F1, MCC, and rare-class F1 values of 0.961, 0.851, 0.913, and 0.746, respectively. Compared with flat XGBoost, HERB-Fusion-IDS produced small but consistent improvements in macro-F1, MCC, and rare-class F1 while maintaining a comparable false-alarm rate. The rare-class improvement was mainly associated with improved Fingerprinting detection. These findings indicate that attack-family information can provide useful complementary structure when fused with a strong flat boosting classifier. However, the evaluation is limited to Edge-IIoTset, and external validation on additional IoT/IIoT datasets is required in future work.

Read PDF

Similar papers

Open access Aug 2026

Machine learning approaches for intrusion Detection in IOT networks

Internet of Things (IoT) technologies have introduced a new complexity in the network environment and made it larger, leading to the demand for accurate, robust and interpretable Intrusion Detection System (IDS). This study presents a machine-learning framework for multi-class IoT intrusion detection system (IDS) with...

Assistant Lecturer Ahmed Ridha Khudhur · 0 citations
Open access 2026

A Family-Aware Hierarchical XGBoost Framework for Efficient IoT Intrusion Detection

A family-aware hierarchical intrusion detection framework for attack-family prediction that first separates normal and attack traffic, then routes attack samples into empirically defined majority and minority attack-family branches, and finally performs branch-specific family classification.

Motab F. Alenezi, F. Alotaibi, B. Alturki et al. · 0 citations
Conference Aug 2026

Framework for Intrusion Detection in IoT Networks: A Lightweight Soft-Voting Ensemble of XGBoost and LightGBM with Explainable AI

The rapid propagation of Internet of Things (IoT) devices has significantly expanded the cyber-attack surface, particularly in essential infrastructure sectors such as energy, water, and healthcare. Machine learning (ML) based intrusion detection systems (IDS) offer a promising defense, but their real-world deployment...

Nooruddine F. Assarwie, F. Alqasemi, Tasnim M. Al-Khawlani et al. · 0 citations
Conference Aug 2026

Energy-Efficient Machine Learning (ML)-Based Intrusion Detection System (IDS) for IoT Devices

The majority of assaults in heterogeneous networks are detected by intrusion detection systems (IDS). Cyberattack kinds that seriously harm networks are difficult for conventional IDSs to detect. The majority of existing solutions rely on deep learning models, which have a significant computational and energy overhead...

Abhinay Kumar Reddy Seella, Rupesh Shirke, Vijay Kumar Kasuba et al. · 0 citations
Open access Sep 2026

Intrusion detection in evolving internet of things environments using decentralized data systems

A hybrid IDS framework built on a stacking ensemble of four heterogeneous base classifiers, namely random forest, extreme gradient boosting, light gradient-boosting machine, and a shallow multi-layer perceptron (MLP), coupled with a PyTorch-based neural network meta-classifier, establishing that pairing meta-learning w...

Zobayer Alam, Arnab Bishakh Sarker, Jariatun Islam et al. · 0 citations
Open access Sep 2026

Performance Evaluation of Boosting Algorithms on Intrusion Detection System Based on Real-Time CICIoT2023 Dataset

Currently, the utilization of machine learning methods for identifying intrusions in Internet of Things (IoT) networks demonstrates intriguing prospects. Choosing the appropriate machine learning technique for intrusion detection poses a significant challenge. Choosing the wrong algorithm may reduce threat-detection ac...

Muhammad Hafiz Amrullah, Favian Dewanta, Muhamad Erza Aminanto · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.