Skip to content
Open access

Sequential submodular feature-sample selection for lightweight and update-efficient IoT intrusion detection

Aug 2026 · Scientific Reports · Vol 16 · 0 citations · 34 references
Medicine

TL;DR

The Sequential Submodular Feature-Sample Selection (SSFSS) framework is proposed, a theoretically grounded approach that sequentially optimizes the feature and sample spaces to reduce training cost while preserving detection fidelity, and is positioned as an efficient update-aware preprocessing framework whose measured speedups and RAM consumption motivate deployment on resource-constrained edge hardware.

Abstract

The exponential expansion of the Internet of Things (IoT) has created a complex threat landscape that challenges traditional intrusion detection systems (IDS), particularly on edge devices with stringent computational and memory budgets. Beyond lightweight inference, practical IoT security increasingly requires on-device learning and frequent retraining so that models can adapt to evolving traffic patterns and emerging attacks; however, repeatedly training on high-dimensional data and large traffic corpora remains prohibitively expensive for resource-constrained devices. Existing lightweight IDS solutions often treat dimensionality reduction and data pruning as isolated tasks, leading to suboptimal representations and a lack of theoretical guarantees. To address this, we propose the Sequential Submodular Feature-Sample Selection (SSFSS) framework, a theoretically grounded approach that sequentially optimizes the feature and sample spaces to reduce training cost while preserving detection fidelity. First, we introduce Label-Aware Coreset Greedy-Based Feature Selection (LA-CGFS), which formulates feature selection as a label-conditioned facility location problem. This stage maximizes coverage across class manifolds, preserving discriminative power for minority attack classes without relying on synthetic oversampling. Second, we employ a geometry-aware coreset selection strategy that minimizes geometric coverage error in the reduced feature space. By leveraging the submodular property of diminishing returns, SSFSS provides a proven \documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$(1-1/e)$$\end{document} approximation guarantee to the optimal subset. Extensive evaluation on the RT-IoT2022, Edge-IIoTset, and CICIoT2023 datasets demonstrates that SSFSS reduces the feature space to 20 features and the training set to as little as 5% of the original samples, achieving average training speedups of up to \documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$70\times $$\end{document} and up to a 96% reduction in peak training RAM; even when the one-time coreset-construction cost is included, the end-to-end pipeline remains faster than a single full-data fit. Across four differentiable empirical-risk-minimization classifiers (kernel logistic regression, kernel SVM, kernel ridge, and softmax regression), the best reduced model retains 97.5–99.5% accuracy at \documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$10\%$$\end{document} budget, and the weighted coreset improves macro-F1 and balanced accuracy on the imbalanced benchmarks. Supported by the reported results, we position the proposed SSFSS framework as an efficient update-aware preprocessing framework whose measured speedups and RAM consumption motivate deployment on resource-constrained edge hardware.

Read PDF

Similar papers

Sep 2026

DAFF: Deployment-Aware Feature Fusion for Efficient TinyML-Based Intrusion Detection in IoT

Tiny Machine Learning (TinyML) enables on-device inference for resource-constrained IoT systems, yet most intrusion detection approaches focus primarily on classification accuracy while overlooking deployment constraints such as latency, memory footprint, and energy consumption. This paper presents a system-level TinyM...

A. G. M. F. H. Akanda, Baris Aksanli · 0 citations
Aug 2026

FedSE-1DSqueezeNet: a lightweight federated intrusion detection system for Internet of Things

FedSE-1DSqueezeNet is proposed, a lightweight federated IDS tailored for resource-constrained IoT environments, designed to optimize feature extraction efficiency under strict resource constraints and achieves detection accuracy exceeding that of state-of-the-art models.

Qi Zhou, Xuechun Mao, Ying Chen · 0 citations
Oct 2026

Lightweight IoT Intrusion Detection via Curriculum Knowledge Distillation

The rapid development of Internet of Things (IoT) systems brings severe security challenges, as edge devices are restricted by limited computing and memory resources. Existing intrusion detection methods either deliver high accuracy at the expense of heavy computation, or cannot maintain stable performance under resour...

Guangfu Wu, Yue-Hong Xu, Dao-Jing He et al. · 0 citations
#federated learning Open access Sep 2026

EdgeSecure: A Heterogeneous Federated Learning Framework for Lightweight Malware Detection in Resource-Constrained IoT Networks

The rapid expansion of Internet of Things (IoT) devices has intensified security challenges, particularly malware attacks that continue to grow in sophistication while operating under strict resource constraints. Conventional centralized machine learning–based malware detection approaches face significant limitations i...

Baraa I. Farhan · 0 citations
Open access 2026

An Explainable Ensemble Feature Selection Framework for Enhanced IoT Edge Attack Detection

An explainable hybrid feature-selection framework (X-EFS) that combines multiple feature reduction techniques via a multi-expert system module, then uses the MDA metric to select the most important features, ensuring high performance and explainability.

Minh Trọng Hoàng, Le Thi Trang Linh, Hoang Minh Nguyen et al. · 0 citations
Open access Aug 2026

Design and Implementation of a Lightweight Adaptive Machine Learning Framework for Real-Time DDoS Mitigation in Resource-Constrained IoT Devices

The results verify the framework's ability to provide low latency and correct DDoS mitigation directly on the IoT devices, which can be considered a feasible solution to achieve resilience improvement of critical IoT deployments in health care, industrial automation, and smart cities.

Selvi T, Jayaganesh J · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.