Jul 2026· International Conference on Ubiquitous and Future Networks· pp. 911-916· 0 citations· 13 references
Abstract
Deploying effective intrusion detection systems (IDS) on resource-constrained embedded hardware demands models that maximise threat recall under severe class imbalance and tight computational budgets. This paper presents a systematic, multi-cycle experimental study comparing neural network architectures—multi-layer perceptrons (MLPs) of varying depth, a long short-term memory (LSTM) network, and classical machine-learning baselines (Random Forest, XGBoost)—for binary classification of network traffic in an embedded testbed environment. Three findings distinguish our work. First, we show that temporal holdout splitting consistently outperforms k-fold cross-validation for network traffic data because random fold assignment violates the temporal autocorrelation structure of network flows, inflating k-fold recall estimates by 4–7 percentage points. Second, we demonstrate that removing four machine-specific identifiers (source/destination IP addresses and port numbers) improves recall by approximately 20 percentage points—a larger gain than any architectural change evaluated. Third, despite its theoretical suitability for sequential data, the LSTM underperforms the optimised MLP ($26.7\%$ vs. $50.7\%$ recall) on this small, imbalanced dataset, while classical tree-based methods achieve competitive recall with substantially lower inference cost. These results provide concrete, empirically grounded guidelines for IDS practitioners targeting embedded deployment, and highlight systematic evaluation pitfalls that are widespread in the network-security literature.
This paper evaluates an ultra-compact five-feature polling scheme (F1–F5) designed to preserve statistical symmetry between control-plane monitoring and telemetry overhead within a dynamic Mininet–Ryu testbed and reveals that tree-based ensembles consistently outperform deep learning approaches.
An Enhanced Multi-Model Ensemble Network Intrusion Detection System (EME-NIDS), a deep meta-learning system that combines five different heterogeneous learning paradigms, including Convolutional Neural Networks, Dense Neural Networks, Transformers, XGBoost, and Random Forests is introduced.
Controller Area Network (CAN) is the dominant in-vehicle bus, yet its broadcast design and absent authentication leave it exposed to injection and spoofing attacks. Existing deep-learning intrusion detection systems achieve strong accuracy but depend on ML inference frameworks incompatible with the resource budgets of...
Amirmasoud Pourmiri, Ali Eslami, Sergio A. Salinas Monroy· International Conference on...· 0 citations
An OFLN by addition of PSO to perform automated hyperparameter optimization and MAML to enable high-speed adaptation to new and previously seen attacks is proposed, which is more effective than baseline ensemble models in detection accuracy, resistance to class imbalance and training efficiency.
Network Intrusion Detection Systems (NIDS) play a critical role in securing IoT environments, where resource constraints demand lightweight yet effective solutions. While Convolutional Neural Network (CNN) and Long Short-Term Memory (LSTM) networks are widely adopted as benchmarks for intrusion detection, their high co...
Khorshed Alam, Mahbubul Haq Bhuiyan, Mohammad Ashraful Hoque et al.· PLoS ONE· 0 citations
Distributed Denial-of-Service (DDoS) attacks remain one of the most disruptive threats to network infrastructure, yet many machine learning (ML)-based detection studies report only offline benchmark performance without verifying whether that performance holds under real network conditions. This study evaluates two expl...
Muhammad Azzam Anshori, R. Amri· Journal of Computer Science...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.