Skip to content
Open access

A Lightweight Security Decision Framework for IoT Intrusion Detection Using Entropy-Guided Feature Integrity and Adaptive Ensemble Learning

Saif Wali Ali Alsudani M. Feizi-Derakhshi
Jul 2026 · International Journal of Electronics and Communication Engineering · Vol 13, pp. 134-144 · 0 citations · 37 references

TL;DR

This paper presents a lightweight IoT security decision framework that combines entropy-guided feature selection with an adaptive ensemble-based intrusion detection strategy, establishing intrusion detection as an efficient and deployable security decision layer for real-world IoT environments.

Abstract

The rapid growth of the Internet of Things (IoT) has intensified cybersecurity risks while exposing the limitations of traditional security solutions in resource-constrained environments. Intrusion detection in IoT systems, therefore, requires reliable, real-time decision-making with minimal computational overhead. This paper presents a lightweight IoT security decision framework that combines entropy-guided feature selection with an adaptive ensemble-based intrusion detection strategy. The proposed approach employs an entropy–correlation (EnCor) feature selection pipeline to construct a compact and informative feature subset, reducing complexity while preserving discriminative security characteristics. Detection decisions are generated using a soft voting ensemble of complementary machine learning classifiers, supported by an adaptive fallback mechanism to improve reliability under diverse attack scenarios. The framework is specifically designed for edge- and gateway-level IoT deployment, avoiding the high latency and computational demands associated with deep learning and blockchain-based solutions. Experimental evaluation on the TON_IoT and CICIoT2023 datasets demonstrates high detection accuracy with low inference latency and reduced memory consumption. The results confirm that effective intrusion detection can be achieved without compromising practical deployment feasibility. Overall, the proposed framework establishes intrusion detection as an efficient and deployable security decision layer for real-world IoT environments.

Read PDF

Similar papers

Open access Aug 2026

Adaptive Machine Learning Framework for Real-Time Cyber-Attack Detection and Prevention in IoT Networks

This paper introduces an innovative ML-based security paradigm that improves the attack detection accuracy by combining adaptive feature extraction techniques with a context-attentive hybrid mechanism and maximizes detection accuracy and computational efficiency.

P. P. Bairagi, Ashish Bagwari, Sailen Dutta Kalita et al. · 0 citations
Open access Aug 2026

Detecting and Preventing Cyberattacks in Internet of Things (IoT) Systems

This study proposes a hybrid machine learning-based intrusion detection and prevention framework for securing IoT networks that integrates Isolation Forest, Autoencoder, Extreme Gradient Boosting, and Bidirectional Long Short-Term Memory models within a stacked ensemble architecture to improve attack detection while reducing false-positive predictions.

Ruthwik Palem, Likhith Reddy Peketi, Vanathi M et al. · 0 citations
Open access Aug 2026

Design and Implementation of a Lightweight Adaptive Machine Learning Framework for Real-Time DDoS Mitigation in Resource-Constrained IoT Devices

The results verify the framework's ability to provide low latency and correct DDoS mitigation directly on the IoT devices, which can be considered a feasible solution to achieve resilience improvement of critical IoT deployments in health care, industrial automation, and smart cities.

Selvi T, Jayaganesh J · 0 citations
Open access 2026

From IoT Vulnerabilities to Intrusion Detection: An Explainable Vulnerability-Aware Machine Learning Framework for Smart Home IoT Security

The swift deployment of IoT-based smart home appliances has increased the attack surface for the smart environment and exposed it to attacks like botnet command-and-control communications, brute force attacks, denial-of-service attacks, and web-based attacks. Even though the Intrusion Detection Systems (IDSs) that use Machine Learning (ML) algorithms achieve a very high detection rate, most existing solutions focus on predictive performance but lack the ability to link detected attacks to the corresponding vulnerabilities in the Internet of Things (IoT). In this paper, an interpretable vulnerability-aware ML-based approach is presented to solve this problem through the integration of vulnerability classes of IoT, attack classes, network flow attributes, and ML features into one interpretation model. The proposed method uses leakage-aware pre-processing, addressing class imbalance, and compares Random Forest, XGBoost, and soft voting ensemble ML techniques using the CSE-CIC-IDS2018 dataset. Experimental outcomes indicate that XGBoost outperforms the other approaches in terms of performance, with an accuracy of 98.22%, precision of 99.69%, F1-score of 95.36%, ROC-AUC of 99.07%, and only 760 false alarms, which is approximately 19× lower number of false positives compared to Random Forest while keeping a similar level of detection efficiency. In addition to numeric assessment of the approach performance, the suggested model provides the vulnerability-oriented interpretation module that establishes mapping between prominent network flow attributes and possible IoT vulnerability states and attacks. Therefore, the integration of an interpretable vulnerability reasoning component into a high-performing tree-based machine learning algorithm proves to be effective for smart home IoT intrusion detection.

Huda Aldawghan, Mounir Frikha · 0 citations
Open access Sep 2026

AI-Driven Vulnerability Management Framework for the Internet of Things

This rapid growth of IoT has changed the landscape of today’s digital world by allowing devices to communicate effectively, especially in different fields like healthcare, smart cities, industrial control, and defense. Despite its advantages, IoT introduces significant security challenges due to device heterogeneity, constrained computational resources, and weak security architectures, making it highly vulnerable to cyber threats. Traditional vulnerability management approaches, including rule-based intrusion detection systems and signature-based scanning, have proven inadequate in addressing the dynamic and large-scale nature of IoT environments, as they are largely reactive and incapable of detecting novel attack patterns. This study proposes an AI driven vulnerability management framework that integrates anomaly detection techniques using machine learning to enhance proactive threat identification and mitigation in IoT ecosystems. The framework leverages publicly available datasets such as Bot-IoT, CIC-IoT, and UNSW NB15 to train and evaluate models capable of distinguishing between normal and malicious network behaviors. Various machine learning algorithms, including supervised and unsupervised techniques, were implemented and assessed using performance metrics such as accuracy, precision, recall, F1-score and false positive rate. The results demonstrate that AI based models significantly outperform traditional methods in detecting previously unseen threats, achieving high detection accuracy and reduced false positives. The proposed framework integrates anomaly detection into a structured vulnerability management lifecycle encompassing identification, prioritization and remediation of vulnerabilities. Generally, the study provides a scalable and adaptive solution for improving IoT security, reducing system vulnerabilities, and enhancing resilience against evolving cyber threats, with potential for future real-world deployment across critical sectors.

Daniel Nafisatu Mshelbila · 0 citations
Open access Aug 2026

Multiclass Cyber Attack Classification in Smart Home IoT Networks Using Ensemble Machine Learning with the ML-EdgeIIoT Dataset

A machine learning-based intrusion detection framework for multiclass classification of eight categories of IoT network attacks, namely Backdoor, MITM, DDoS, Ransomware, Password Attack, SQL Injection, Prob-attacks, and Normal traffic is designed and evaluated while minimizing false positives and false negatives.

Abhay Kumar Ray, Rupak Sharma, Sunil Kumar Pandey · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.