Skip to content
Conference

Evaluation of Neural Network Architectures for Intrusion Detection in Resource-Constrained Embedded Network Systems

Jul 2026 · International Conference on Ubiquitous and Future Networks · pp. 911-916 · 0 citations · 13 references

Abstract

Deploying effective intrusion detection systems (IDS) on resource-constrained embedded hardware demands models that maximise threat recall under severe class imbalance and tight computational budgets. This paper presents a systematic, multi-cycle experimental study comparing neural network architectures—multi-layer perceptrons (MLPs) of varying depth, a long short-term memory (LSTM) network, and classical machine-learning baselines (Random Forest, XGBoost)—for binary classification of network traffic in an embedded testbed environment. Three findings distinguish our work. First, we show that temporal holdout splitting consistently outperforms k-fold cross-validation for network traffic data because random fold assignment violates the temporal autocorrelation structure of network flows, inflating k-fold recall estimates by 4–7 percentage points. Second, we demonstrate that removing four machine-specific identifiers (source/destination IP addresses and port numbers) improves recall by approximately 20 percentage points—a larger gain than any architectural change evaluated. Third, despite its theoretical suitability for sequential data, the LSTM underperforms the optimised MLP ($26.7\%$ vs. $50.7\%$ recall) on this small, imbalanced dataset, while classical tree-based methods achieve competitive recall with substantially lower inference cost. These results provide concrete, empirically grounded guidelines for IDS practitioners targeting embedded deployment, and highlight systematic evaluation pitfalls that are widespread in the network-security literature.

View source

Similar papers

Open access Aug 2026

Performance and Structural Symmetry Evaluation of Machine Learning-Driven Intrusion Detection Systems in Software-Defined Networks

This paper evaluates an ultra-compact five-feature polling scheme (F1–F5) designed to preserve statistical symmetry between control-plane monitoring and telemetry overhead within a dynamic Mininet–Ryu testbed and reveals that tree-based ensembles consistently outperform deep learning approaches.

Rohan Giri, Abdussalam Salama, Reza Saatchi et al. · 0 citations
Open access Aug 2026

An enhanced multi-model ensemble learning architecture for robust network intrusion detection

An Enhanced Multi-Model Ensemble Network Intrusion Detection System (EME-NIDS), a deep meta-learning system that combines five different heterogeneous learning paradigms, including Convolutional Neural Networks, Dense Neural Networks, Transformers, XGBoost, and Random Forests is introduced.

Dwarsala Sireesha, Kakelli Anil Kumar · 0 citations
Conference Jul 2026

Resource-Constrained CAN Intrusion Detection with Distilled Decision Trees

Controller Area Network (CAN) is the dominant in-vehicle bus, yet its broadcast design and absent authentication leave it exposed to injection and spoofing attacks. Existing deep-learning intrusion detection systems achieve strong accuracy but depend on ML inference frameworks incompatible with the resource budgets of...

Amirmasoud Pourmiri, Ali Eslami, Sergio A. Salinas Monroy · 0 citations
Open access Jul 2026

Optimized Fast-Learning Network Model With SMOTE for University Network Intrusion Detection Systems

An OFLN by addition of PSO to perform automated hyperparameter optimization and MAML to enable high-speed adaptation to new and previously seen attacks is proposed, which is more effective than baseline ensemble models in detection accuracy, resistance to class imbalance and training efficiency.

Robert Wamusi, Guma Ali, Taban Habibu · 0 citations
Open access Aug 2026

Reservoir computing for network intrusion classification

Network Intrusion Detection Systems (NIDS) play a critical role in securing IoT environments, where resource constraints demand lightweight yet effective solutions. While Convolutional Neural Network (CNN) and Long Short-Term Memory (LSTM) networks are widely adopted as benchmarks for intrusion detection, their high co...

Khorshed Alam, Mahbubul Haq Bhuiyan, Mohammad Ashraful Hoque et al. · 0 citations
Open access Aug 2026

Explainable Machine Learning for DDoS Attack Detection with Physical Network Validation

Distributed Denial-of-Service (DDoS) attacks remain one of the most disruptive threats to network infrastructure, yet many machine learning (ML)-based detection studies report only offline benchmark performance without verifying whether that performance holds under real network conditions. This study evaluates two expl...

Muhammad Azzam Anshori, R. Amri · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.