2026· Computer Modeling in Engineering & Sciences· Vol 148, pp. 1-10· 0 citations· 29 references
TL;DR
A family-aware hierarchical intrusion detection framework for attack-family prediction that first separates normal and attack traffic, then routes attack samples into empirically defined majority and minority attack-family branches, and finally performs branch-specific family classification.
Abstract
: Machine learning-based intrusion detection for Internet of Things (IoT) networks remains difficult because modern traffic is highly imbalanced and attack behaviors are heterogeneous. Evaluation pipelines can also overestimate performance when preprocessing is performed before train-test separation. We propose a family-aware hierarchical intrusion detection framework for attack-family prediction. The proposed approach first separates normal and attack traffic, then routes attack samples into empirically defined majority and minority attack-family branches, and finally performs branch-specific family classification. Within each cross-validation fold, training-label counts define the majority/minority routing branches, while scaling, weighting, model fitting, stage diagnostics, and metric computation remain fold-local. The final implementation uses XGBoost as the base learner in the hierarchical stages and compares it with flat LightGBM, XGBoost, Random Forest, Extra Trees, and stacking baselines under matched folds and metrics. On the CICIoT2023 30% stratified development split, the proposed approach achieved a Macro-F1 of 0.8380 and Weighted-F1 of 0.9940, performing close to the best flat Random Forest baseline while improving weak rare-family F1 scores for BruteForce and Web. On Edge-IIoTset, where the full processed dataset is used, the proposed approach achieved a Macro-F1 of 0.9456 and Weighted-F1 of 0.9494, outperforming all individual flat baselines and approaching the flat stacking ensemble. The hierarchy had lower inference time than the evaluated flat baselines under the workstation protocol.
This study proposes a Correlation-Based Feature Selection (CFS)–Weighted XGBoost framework that combines redundancy-aware feature selection with an embedded class-weighted learning classifier to improve minority-attack detection.
M. Alnagdawi, Tariq Bishtawi, Ayman Ghaben· Journal of Intelligent Decis...· 0 citations
Findings indicate that attack-family information can provide useful complementary structure when fused with a strong flat boosting classifier, however, the evaluation is limited to Edge-IIoTset, and external validation on additional IoT/IIoT datasets is required in future work.
Fesih Keskin· Black Sea Journal of Enginee...· 0 citations
The increasing heterogeneity and scale of Internet of Things (IoT) ecosystems have intensified cybersecurity challenges associated with highly imbalanced traffic distributions, evolving attack patterns, and resource-constrained deployment environments. Conventional cloud-centric intrusion detection systems often intr...
Ashutosh Shankhdhar, A. Sivakumaran, Nithya Rekha Sivakumar et al.· Scientific Reports· 0 citations
The proposed accurate and interpretable framework shows strong potential as an edge-deployable security solution for safeguarding IoT devices and improving cyber resilience.
Prabhav Jain, Aashima Sharma, A. Noonia et al.· Scientific Reports· 0 citations
A hybrid IDS framework built on a stacking ensemble of four heterogeneous base classifiers, namely random forest, extreme gradient boosting, light gradient-boosting machine, and a shallow multi-layer perceptron (MLP), coupled with a PyTorch-based neural network meta-classifier, establishing that pairing meta-learning w...
Zobayer Alam, Arnab Bishakh Sarker, Jariatun Islam et al.· International Journal of Adv...· 0 citations
Class imbalance in Internet of Things (IoT) Intrusion Detection System (IDS) datasets is a major challenge that degrades the detection performance on minority attacks and complicates model interpretability. This study investigates the performance of an IoT IDS based on Random Forest (RF) combined with the Synthetic Min...
Julfikar Mawansyah, Anik Nur Handayani, A. Wibawa et al.· Jurnal Elektronika dan Telek...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.