The proposed accurate and interpretable framework shows strong potential as an edge-deployable security solution for safeguarding IoT devices and improving cyber resilience.
Abstract
The rapid growth of IoT-enabled technologies and interconnected smart devices has significantly increased security risks associated with poorly protected and resource-constrained IoT environments. Efficient anomaly detection mechanisms can help mitigate these threats by analyzing network traffic and identifying abnormal activities. However, such mechanisms must also preserve user privacy and maintain scalability for deployment on low-power edge devices. This paper presents
XP-IDS
: a hybrid deep gradient boosting framework for intrusion detection in IoT networks. Using the
CIC IoT-DIAD 2024
dataset,
XP-IDS
learns from three categories of handcrafted features: (i) strategic-based features that capture high-level protocol semantics and flow behavior, (ii) time-based features that represent sequential relationships and traffic evolution over time, and (iii) IP-based features that characterize packet-flow communication among IoT endpoints. Feature representations extracted through stacked Convolutional Neural Networks are subsequently forwarded to an Extreme Gradient Boosting classifier for final prediction. In addition, SHapley Additive exPlanation (SHAP) is utilized to provide interpretability for model decisions and to identify overall feature importance, thereby enhancing transparency and privacy-aware analysis. Extensive experimental evaluation demonstrates that the proposed framework achieves strong detection accuracy across several common attack categories while outperforming multiple baseline approaches. The proposed accurate and interpretable framework shows strong potential as an edge-deployable security solution for safeguarding IoT devices and improving cyber resilience.
The results indicate that the proposed CNN–LSTM framework is suitable for near-real-time IIoT intrusion detection where low false alarms, calibrated confidence, temporal stability, and lightweight deployment are critical.
Mushtaq Ali, Imad Ullah· Majestic International Journ...· 3 citations· ⚡1
A Hybrid Convolutional Neural Network–Long Short-Term Memory (CNN–LSTM) model for effective IoT malware detection is proposed, which enhances detection capability for both known and zero-day attacks.
MI-IDS is presented, a hybrid Convolutional Neural Network–Bidirectional Long Short-Term Memory (CNN-BiLSTM) ensemble deployed on a two-tier edge-cloud framework that integrates reservoir-sampling-based incremental learning and SHAP explainability under a single experimentally validated pipeline.
Manjot Kaur, Kedar Nath Singh, Alpana Suman et al.· Discover Internet of Things· 0 citations
A new explainable hybrid IDS architecture for IoT environments named XABiL-IDS (Explainable Attention-based Bi LSTM-Intrusion Detection System) in response to this challenge, which uses a robust hybrid architecture to detect attacks effectively.
Ravi Patni, Gurvinder Singh· International journal of com...· 0 citations
Recent networks have a remote larger attack surface owing to the quick spread of Internet of Things (IoT) strategies, which for effective and instantaneous Intrusion Detection Systems (IDS). Deep-IDS, a real-time Deep Learning (DL) IDS intended for IoT nodes with limited resources, is presented in this work. The raw ne...
D. Sameera, M. Sreenivasu, Aruna Kommu· International Conference on...· 0 citations
The framework introduces CNN–BiLSTM deep learning networks to represent traffic in a spatiotemporal manner and adopts ensemble machine learning classifiers to enhance the robustness of traffic detection and its interpretability, to enhance the robustness of traffic detection and its interpretability.
Ramesh N. S. V. S. C. Sripada, A. Bhavani, Kiran B. Malagi et al.· Discover Computing· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.