Aug 2026· International journal of computer information systems and industrial management applications· 0 citations
TL;DR
The results verify the framework's ability to provide low latency and correct DDoS mitigation directly on the IoT devices, which can be considered a feasible solution to achieve resilience improvement of critical IoT deployments in health care, industrial automation, and smart cities.
Abstract
The rapid expansion of the Internet of Things (IoT) has raised additional concerns about security, and there was a major risk of Distributed Denial-of-Service (DDoS) attacks because the IoT devices have limited computation, memory, and energy capabilities. Traditional intrusion detection methods, which are at times contrived to support a high capacity, are incompetent at these limitations, delaying detections, having too many false alarms, and also compromising the system performance. This study offers a resource-efficient, adaptive machine learning system that was suitable to be used in the operation of DDoS attacks in resource-confined IoT settings. The technique combines the hybrid feature selection algorithms based on mutual information gain and recursive feature elimination to construct a more compact and high-utility feature set together with the optimization of the lightweight classifiers, including stochastic gradient descent and shallow decision trees. The concept drift was solved by an online incremental learning mechanism that guarantees long-term trend detection over time against changing patterns of attacks. The evaluation of the benchmark datasets (CICDDoS2019, BoT-IoT, TON_IoT) using experimental evaluation on a heterogeneous testbed IoT and assessing both security metrics and resource efficiency was researched. The model suggested had a precision of 0.973, a recall of 0.959, an F1-score of 0.966, and an average decrease of malicious traffic by 93 percent at the expense of legitimacy throughput. Latency was decreased to 2.6 seconds when detecting high-intensity attacks, and the CPU and memory usage continued to be less than 35 percent and 70 percent of the device capacity, respectively. A better result in terms of accuracy, response time, false positive rates, and not using resource budgets was witnessed when compared to baseline models through comparative analysis. The results verify the framework's ability to provide low latency and correct DDoS mitigation directly on the IoT devices, which can be considered a feasible solution to achieve resilience improvement of critical IoT deployments in health care, industrial automation, and smart cities.
This paper introduces an innovative ML-based security paradigm that improves the attack detection accuracy by combining adaptive feature extraction techniques with a context-attentive hybrid mechanism and maximizes detection accuracy and computational efficiency.
P. P. Bairagi, Ashish Bagwari, Sailen Dutta Kalita et al.· international journal of eng...· 0 citations
Besides having high detection rates, the proposed BGL-RID model also achieves the highest efficiency ratio across different datasets, showing that it is robust and scalable, with minimal computation and memory requirements, suggesting its potential suitability for resource-constrained IoT applications.
Mohd Zain Khan, Mahfooz Alam, Irfan Alam et al.· Scientific Reports· 0 citations
The majority of assaults in heterogeneous networks are detected by intrusion detection systems (IDS). Cyberattack kinds that seriously harm networks are difficult for conventional IDSs to detect. The majority of existing solutions rely on deep learning models, which have a significant computational and energy overhead that limits their use in IoT environments with limited resources. A lightweight IDS based on ML is proposed in this research as a solution to this difficulty. Predicting the behavior of network traffic is achieved using ToN-IoT data and a tailored preprocessing pipeline. The voting-based ensemble classifier is built through the combination of models of RF and LightGBM to enhance the stability of the classification. The standard performance measures that are utilized to evaluate the proposed approach include accuracy, precision, recall, F1score, false alarm rates, and ROC analysis. The experimental findings indicate that RF achieve 99.81% accuracy, LGBM achieve 99.83%, and the ensemble model has a high accuracy of 99.99% with very low false alarms. Comparative evaluation with traditional ML and DL models demonstrates improved detection reliability with reduced computational overhead. These results prove that the suggested architecture is both computationally efficient and practically applicable to IoT settings with limited resources. However, direct hardware-level energy measurements are required to fully quantify the energy-saving characteristics of the proposed IDS.
Abhinay Kumar Reddy Seella, Rupesh Shirke, Vijay Kumar Kasuba et al.· International Conference on...· 0 citations
The proliferation of Internet of Things (IoT) networks in smart homes, healthcare, industrial systems, and critical infrastructure has greatly extended the attack surface, and the deep learning models that are best suited to detecting these attacks are challenging to deploy on resource-limited edge devices, difficult to trust because they are black-box, and difficult to maintain effectively because traffic and attack distributions are evolving over time. Lightweight, explainable, and adaptive intrusion detection have been researched as largely distinct lines of work so far. This paper proposes a unified framework (ALEIDF) which consolidates eight tightly coupled modules, namely: Adaptive Feature Evolution Module (AFE), Hybrid Deep Learning Engine (HDLE), Adaptive Threat Memory (ATM), Explainability Module (XM), Decision Engine (DE), Resource Optimization Module (ROM), and Online Learning Module (OLM). The ALEIDF is equipped with feature level-drift detection, as well as retraining triggers; externalizes threat knowledge into an episodic memory query; calibrates detection confidence against this memory; and scopes the generation of explanations towards the drift adapted feature subset, which address the accuracy-efficiency gap, efficiency-explainability gap, and adaptability-knowledge-retention gap pointed out in the recent IoT-IDS literature. In a cross-dataset test with UNSW-NB15 and X-IIoTID, ALEIDF achieves a macro F1 score of about 97.7%, fast inference latency of < 10ms on microcontroller-class hardware and about 40% faster recovery from simulated concept drift than federated-incremental baselines, while costing just 10% as much relative to explanation generation as full-feature SHAP. Having identified joint integration of efficiency, explainability and adaptability as an open field in recent surveys regarding IoT network security research, ALEIDF is well positioned to further this integration.
Sally Hamdi, Hussein M. Farhood, M. Mohammed· International Journal of Com...· 0 citations
This study proposes a hybrid machine learning-based intrusion detection and prevention framework for securing IoT networks that integrates Isolation Forest, Autoencoder, Extreme Gradient Boosting, and Bidirectional Long Short-Term Memory models within a stacked ensemble architecture to improve attack detection while reducing false-positive predictions.
Ruthwik Palem, Likhith Reddy Peketi, Vanathi M et al.· Cureus Journal of Computer S...· 0 citations
The rapid propagation of Internet of Things (IoT) devices has significantly expanded the cyber-attack surface, particularly in essential infrastructure sectors such as energy, water, and healthcare. Machine learning (ML) based intrusion detection systems (IDS) offer a promising defense, but their real-world deployment is often hindered by data imbalance, lack of interpretability, and computational demands. In this paper, we introduce a lightweight ensemble approach, which integrates XGBoost and LightGBM using a soft-voting method. The system is evaluated on the IDSAI dataset after eliminating duplicates, resulting in 693,116 unique samples with a natural class imbalance. The preprocessing phase includes data cleansing and data scaling. The results indicate that the proposed ensemble achieves 99.95% accuracy, 99.95% F1-score, and a perfect AUC of 1.0 on a test set of 207,935 samples. Training completes in under 8 seconds on a standard CPU. The feature importance (gain) highlights delta_time; packet inter-arrival time, as the most significant feature, followed by source/destination ports. SHapley Additive exPlanations (SHAP) analysis provides local explanations, revealing that high inter-arrival times push predictions toward malicious—likely due to slow scanning or burst-and-pause attack patterns. All code and the trained model are publicly available to facilitate reproducibility1.
Nooruddine F. Assarwie, F. Alqasemi, Tasnim M. Al-Khawlani et al.· 2026 6th International Confe...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.