Skip to content
Open access

A Family-Aware Hierarchical XGBoost Framework for Efficient IoT Intrusion Detection

2026 · Computer Modeling in Engineering & Sciences · Vol 148, pp. 1-10 · 0 citations · 29 references

TL;DR

A family-aware hierarchical intrusion detection framework for attack-family prediction that first separates normal and attack traffic, then routes attack samples into empirically defined majority and minority attack-family branches, and finally performs branch-specific family classification.

Abstract

: Machine learning-based intrusion detection for Internet of Things (IoT) networks remains difficult because modern traffic is highly imbalanced and attack behaviors are heterogeneous. Evaluation pipelines can also overestimate performance when preprocessing is performed before train-test separation. We propose a family-aware hierarchical intrusion detection framework for attack-family prediction. The proposed approach first separates normal and attack traffic, then routes attack samples into empirically defined majority and minority attack-family branches, and finally performs branch-specific family classification. Within each cross-validation fold, training-label counts define the majority/minority routing branches, while scaling, weighting, model fitting, stage diagnostics, and metric computation remain fold-local. The final implementation uses XGBoost as the base learner in the hierarchical stages and compares it with flat LightGBM, XGBoost, Random Forest, Extra Trees, and stacking baselines under matched folds and metrics. On the CICIoT2023 30% stratified development split, the proposed approach achieved a Macro-F1 of 0.8380 and Weighted-F1 of 0.9940, performing close to the best flat Random Forest baseline while improving weak rare-family F1 scores for BruteForce and Web. On Edge-IIoTset, where the full processed dataset is used, the proposed approach achieved a Macro-F1 of 0.9456 and Weighted-F1 of 0.9494, outperforming all individual flat baselines and approaching the flat stacking ensemble. The hierarchy had lower inference time than the evaluated flat baselines under the workstation protocol.

Read PDF

Similar papers

Open access Aug 2026

A Correlation-Based Feature Selection and Weighted XGBoost Framework for Minority IoT Attack Detection

This study proposes a Correlation-Based Feature Selection (CFS)–Weighted XGBoost framework that combines redundancy-aware feature selection with an embedded class-weighted learning classifier to improve minority-attack detection.

M. Alnagdawi, Tariq Bishtawi, Ayman Ghaben · 0 citations
Open access Sep 2026

Hierarchical Expert-Routed Boosting with Probability Fusion for Multiclass Intrusion Detection in Edge-IoT and IIoT Networks

Findings indicate that attack-family information can provide useful complementary structure when fused with a strong flat boosting classifier, however, the evaluation is limited to Edge-IIoTset, and external validation on additional IoT/IIoT datasets is required in future work.

Fesih Keskin · 0 citations
Open access Aug 2026

An explainable hierarchical Fog–Cloud intrusion diagnosis framework for IoT ecosystems under imbalanced traffic conditions

The increasing heterogeneity and scale of Internet of Things (IoT) ecosystems have intensified cybersecurity challenges associated with highly imbalanced traffic distributions, evolving attack patterns, and resource-constrained deployment environments. Conventional cloud-centric intrusion detection systems often intr...

Ashutosh Shankhdhar, A. Sivakumaran, Nithya Rekha Sivakumar et al. · 0 citations
Open access Aug 2026

XP-IDS: an explainable hybrid CNN–XGBoost framework for IoT intrusion detection

The proposed accurate and interpretable framework shows strong potential as an edge-deployable security solution for safeguarding IoT devices and improving cyber resilience.

Prabhav Jain, Aashima Sharma, A. Noonia et al. · 0 citations
Open access Sep 2026

Intrusion detection in evolving internet of things environments using decentralized data systems

A hybrid IDS framework built on a stacking ensemble of four heterogeneous base classifiers, namely random forest, extreme gradient boosting, light gradient-boosting machine, and a shallow multi-layer perceptron (MLP), coupled with a PyTorch-based neural network meta-classifier, establishing that pairing meta-learning w...

Zobayer Alam, Arnab Bishakh Sarker, Jariatun Islam et al. · 0 citations
Open access Aug 2026

Explainable IoT Intrusion Detection Using Random Forest, SMOTE, and SHAP

Class imbalance in Internet of Things (IoT) Intrusion Detection System (IDS) datasets is a major challenge that degrades the detection performance on minority attacks and complicates model interpretability. This study investigates the performance of an IoT IDS based on Random Forest (RF) combined with the Synthetic Min...

Julfikar Mawansyah, Anik Nur Handayani, A. Wibawa et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.