Jul 2026· Frontiers in Big Data· Vol 9· 1 citation· 94 references
Medicine
TL;DR
This study presents future directions for dataset design aligned with the requirements of next-generation IDSs by highlighting digital twin-based IIoT environments, edge-cloud collaborative data generation, sequential traffic modeling, and explainability-oriented annotations that can ensure robust, trustworthy, and deployment-ready IDS solutions.
Abstract
The rapid growth of IoT and IIoT expands the cyber-attack surface of interconnected and safety-critical systems, and, as such, IDSs have become a fundamental security mechanism. Although very impressive results have been reported for machine learning and deep learning-based IDS in benchmark datasets, these gains often do not generalize to real-world deployments owing to dataset design limitations, realism deficits, and evaluation biases, rather than inherent flaws in detection algorithms, which can lead to significant vulnerabilities in actual operational environments. This study presents a dataset-centric review of widely used intrusion detection datasets from the IIoT, IoT, and traditional network domains. A unified taxonomy differentiates datasets based on the domain context, traffic representation, protocol semantics, and attack modeling assumptions. Based on a common analytical framework, each dataset was reviewed regarding its realism, coverage of the threats, class imbalance, temporal continuity, and modern ML/DL-based evaluation of the IDS. The cross-dataset analysis conducted in this study shows that, in addition to the fact that model architecture and feature engineering play a major role, several studies indicate that the simplicity of the datasets, the class imbalance, and the repetitive attack patterns as well as the evaluation methods can affect accuracy of the IDS. This work further underlines the remaining gaps, such as zero-day and adaptive attacks, limited encrypted traffic, weak temporal evolution, poor support for federated learning, and sparse annotations for explainable IDSs. Finally, this study presents future directions for dataset design aligned with the requirements of next-generation IDSs by highlighting digital twin-based IIoT environments, edge-cloud collaborative data generation, sequential traffic modeling, and explainability-oriented annotations that can ensure robust, trustworthy, and deployment-ready IDS solutions.
The rapid proliferation of Internet of Things (IoT) devices across critical domains including healthcare, smart cities, industrial control systems, and intelligent transportation has fundamentally transformed the cybersecurity threat landscape. The inherent characteristics of IoT environments, namely resource-constrained devices, heterogeneous architectures, and large-scale deployment, render traditional Intrusion Detection Systems (IDS) inadequate for the sophisticated and evolving attack vectors targeting these networks. Deep learning (DL) has emerged as a compelling paradigm for next-generation IoT IDS, offering automated feature extraction, temporal pattern recognition, and adaptive threat detection capabilities that address the limitations of conventional approaches.
This paper provides a thorough and systematic review of the existing DL methods for IoT intrusion detection. The paper explore the IoT architectural paradigms, outline a four layered taxonomy for types of IoT attacks across its three primary layers Perception, Network and Application as well as Adversarial Machine Learning attacks, and systematically review seven classes of DL architectures Convolutional Neural Networks (CNN), Long Short-Term Memory (LSTM) networks, Gated Recurrent Units (GRU), Autoencoders, Generative Adversarial Networks (GAN), models based on Transformer architecture and Federated Learning frameworks. In a comparative review of forty peer-reviewed studies, we demonstrate that hybrid DL models provide excellent detection performance (99-100% classification accuracy on benchmark datasets) as well as practical viability for deployment with privacy-preserving Federated Learning for large-scale data. The study additionally highlights five enduring challenges class imbalance, adversarial vulnerability, zero-day detection limitations, computational constraints and the absence of standardized benchmarking protocols that together account for the gap between performance benchmarks and real-world deployment efficacy. It outlines future research avenues targeting on five key axes with a particular focus in the integration of Explainable AI (XAI), lightweight edge-deployable architectures, and adversarial robustness mechanisms. This survey identifies a structured reference to advance the state of IoT intrusion detection from research to operationally viable and deployable systems.
Mohammed Gharkan, Mustafa I. Hussien Al-Janabi, Obaid Salim· Al-Noor Journal of Engineeri...· 0 citations
Most modern networks depend on Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) as core defense system against an increasingly expanding number of cyber threats. This is the reason why research effort over the years has concentrated on improving these systems, while attention is now been directed at the network settings in which they are tested. In this paper, we systematically review the IDS/IPS literature and discuss the evaluation environments and benchmark datasets used to evaluate detection performance, e.g., KDD Cup 99, NSL-KDD, UNSW-NB15, CICIDS2017, and Bot-IoT. The analysis shows that the popular datasets like the KDD Cup 99 are still in widespread use despite their known limitations, such as duplicate records and attack profiles that do not reflect modern threats. Nevertheless, the adoption of other recent datasets such as CICIDS2017 and Bot-IoT that capture more realistic traffic, and include IoT-specific scenarios, is still modest compared to their older counterparts. The review also shows that experiments are mostly based on artificial and not operational traffic and are mostly limited to laboratory and not production settings, thus limiting the external validity of reported results. Taken together, these observations establish a persistent discrepancy between benchmark settings and the realities of operational networks. The paper ends with practical recommendations to assist researchers and practitioners to choose evaluation environments to enhance the realism, dependability and transferability of IDS/IPS solutions.
G. N. Edegbe, E. Enoyoze, Ijegwa David Acheme et al.· FUDMA Journal of Sciences· 0 citations
Internet of Things (IoT) intrusion detection is frequently reported as a near-solved classification problem, yet operational deployments remain vulnerable to class imbalance, distribution shift, dataset leakage, poor probability calibration, unstable explanations, and cross-network failure. This review synthesizes 28 verified sources spanning benchmark datasets, adaptive learning, generalization, explainable artificial intelligence, imbalance handling, ensemble models, probability quality, and review methodology. It develops a unified taxonomy in which data integrity, model intelligence, temporal resilience, human trust, and evaluation rigor are treated as interdependent design requirements. Mathematical foundations are provided for class-weighted risk, macro-averaged performance, Matthews correlation coefficient, calibration error, drift detection, soft voting, and additive explanations. Major findings are that random record splits can materially overstate readiness; accuracy alone obscures minority-class failure; oversampling must be confined to training folds; post-hoc explanations need stability tests; and drift adaptation requires governance, not only retraining. A reproducibility case study using an audited RT-IoT2022 copy illustrates how index leakage, duplicates, conflicting labels, and extreme skew can coexist with apparently excellent scores. The review concludes with an evidence-driven architecture and a research agenda for device-aware evaluation, calibrated uncertainty, explanation monitoring, and safe rollback. The article is intended as both a critical survey and a practical blueprint for thesis-level experimental work.
Aanchal Khare· IJAICET - International Jour...· 0 citations
LSTM had good detection for frequent attacks and slow-changing patterns, which shows its capacity in learning long-lasting dependencies, which shows its capacity in learning long-lasting dependencies.
Jawad Hussain Awan, Misbah Safdar, Muhammad Ayaz Shirazi et al.· Italian National Conference...· 0 citations
The results demonstrate the effectiveness of the proposed Tiny-IDS in accurately identifying Mirai botnet attacks on IoT devices along with a minimal memory footprint and low inference time, while also emphasizing the need for IoT-specific evaluation frameworks to support the development of robust and lightweight IDS.
Shyam Bahadur, Sudhanshu Kumar Jha, Rajkumar Singh Rathore et al.· IEEE Open Journal of the Com...· 0 citations
This review paper critically examines the integration of Artificial Intelligence (AI) and Machine Learning (ML) techniques to enhance information security within Cloud-IoT networks, focusing on hybrid Deep Learning models (CNN-LSTM), predictive analytics, and automated threat response mechanisms.
R. Saravanakumar, V.Anuratha, M.Elamparithi· International journal of com...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.