Skip to content
Open access

Adversarial Machine Learning for Detection of Zero-Day Attacks on IoT Networks

Jul 2026 · AL-Yarmouk Journal · 0 citations

Abstract

The Internet of Things (IoT) has dramatically expanded global connectivity, with billions of heterogeneous devices generating massive volumes of network traffic. This growth has significantly enlarged the attack surface for cyber threats, particularly synthetic unknown attacks that exploit vulnerabilities not yet captured in existing signature databases. Traditional intrusion detection systems (IDS), which rely on known attack signatures, fail to detect such novel threats. This study proposes a comprehensive Adversarial Machine Learning (AML) framework designed to detect synthetic unknown attacks in IoT networks through the integration of three complementary techniques: Generative Adversarial Networks (GANs) for synthesizing realistic attack samples, Adversarial Autoencoders (AAEs) for robust low-dimensional feature extraction, and Deep Neural Networks (DNNs) for real-time anomaly classification. The framework was evaluated on a controlled synthetic IoT dataset comprising 250,000 traffic samples. Results demonstrate detection accuracy of 94.8%, precision of 93.1%, recall of 92.7%, and F1-score of 92.9%, substantially outperforming signature-based IDS (63.5%), SVM (87.2%), and Random Forest (90.1%). The framework maintained detection rates of 90.2%, 87.5%, and 85.3% under FGSM, PGD, and Carlini-Wagner adversarial perturbations, respectively. Scalability testing across datasets up to 4 million samples confirmed sustained performance with inference latency below 0.021 seconds per sample. The proposed framework represents a scalable, adversarially resilient approach to IoT intrusion detection, with limitations regarding real-world generalization openly acknowledged.

Read PDF

Similar papers

Open access Aug 2026

A Hybrid Deep Autoencoders and Random Forest Framework for False Data Injection Attack Detection in Industrial Internet of Things Networks

A hybrid detection framework is proposed that integrates a Random Forest classifier with an unsupervised anomaly detection model based on a deep autoencoder combined through a Logistic Regression metaclassifier that addresses the gap in single-model detectors that either rely on fixed decision boundaries that struggle with gradually evolving stealthy FDIA patterns or on anomaly detection that lacks strong discriminative power in separating subtle adversarial deviations from normal operational variability.

A. Albarrak, Fuad A. Ghaleb, Sultan Noman Qasem et al. · 0 citations
Open access Jul 2026

Deep Q learning algorithm for detecting DDoS attacks on IoT devices

A deep Q-learning (DQL) framework that integrates K-means clustering directly into the RL action space, enabling adaptive state representation and improved generalization to unseen traffic patterns is proposed.

Lana Kamla Ahmed, Kayhan Zrar Ghafoor · 0 citations
Open access Aug 2026

Security Analysis of IoT Traffic Classification Systems Under Adversarial Machine Learning Attacks

A constraint-aware adversarially robust Internet of Things (IoT) traffic classification system with protocol validity, device behavior consistency, and manifold-aware training and evaluation is presented, demonstrating improved robustness, realism, and deployability compared to existing approaches.

Chenxuan Li, Xinyi Zhang · 0 citations
Review Jul 2026

Generative AI and Federated Learning for Intrusion Detection Systems: A Survey

This survey provides a structured review of generative AI and FL techniques for IDS and categorizes generative AI applications in IDS according to model families and task objectives, covering autoencoder-based models, Generative Adversarial Networks (GANs), diffusion models, and Large Language Models (LLMs).

Jiefei Liu, A. S. Tayeen, Pratyay Kumar et al. · 1 citation
Open access Jun 2026

Intelligent MITM Attack Detection Systems Using Ensemble Learning for IoT Network Security

Across all five algorithms, boosting methods showed a small but consistent advantage over bagging methods, and detection was effective for every MITM technique considered, with SSL stripping proving the most difficult to identify.

Yasser AbdelSatar, Fatma El-Zahraa Mohamed, Shimaa AbdelNasser et al. · 0 citations
Open access Aug 2026

Adversarial Transferability in AI-based Network Intrusion Detection: A Comparative Study of ANN and CNN Models

Experimental results indicate that CNN-based NIDS are more vulnerable to adversarial attacks than ANN-based models, with adversarial examples successfully transferring across architectures, highlighting the critical risks associated with adversarial transferability.

Aasim Zafar, Shazra Wali, Sheikh Burhan Ul Haque · 0 citations