Aug 2026· Cureus Journal of Computer Science· Vol 3· 0 citations· 15 references
TL;DR
This study proposes a hybrid machine learning-based intrusion detection and prevention framework for securing IoT networks that integrates Isolation Forest, Autoencoder, Extreme Gradient Boosting, and Bidirectional Long Short-Term Memory models within a stacked ensemble architecture to improve attack detection while reducing false-positive predictions.
Abstract
The rapid growth of Internet of Things (IoT) devices has significantly improved connectivity across smart environments. However, the resource-constrained nature of IoT devices and their limited built-in security mechanisms make them highly vulnerable to evolving cyberattacks. Traditional intrusion detection systems relying on signature-based or static rule sets are often ineffective against previously unseen attacks. This study proposes a hybrid machine learning-based intrusion detection and prevention framework for securing IoT networks. The framework integrates Isolation Forest, Autoencoder, Extreme Gradient Boosting, and Bidirectional Long Short-Term Memory models within a stacked ensemble architecture to improve attack detection while reducing false-positive predictions. The ensemble outputs are combined using a Logistic Regression meta-classifier to generate the final threat score. Experimental evaluation using the UNSW-NB15 dataset demonstrates that Extreme Gradient Boosting achieved the highest individual Receiver Operating Characteristic-Area Under the Curve score of 0.91, while the proposed framework further enhances detection robustness through ensemble learning and automated prevention. A Flask-based monitoring dashboard provides real-time visualization of detection results, blocked IP addresses, alerts, and system performance.
This study investigates the effectiveness of supervised machine learning techniques for detecting cyberattacks in IoT-based smart city networks using the TON_IoT dataset, finding that advanced ensemble learning combined with robust feature engineering provides a reliable and scalable solution for securing smart city IoT networks.
E. Okonta, Oluwaseun Bamgbose· ABC2: Journal of Architectur...· 0 citations
This paper introduces an innovative ML-based security paradigm that improves the attack detection accuracy by combining adaptive feature extraction techniques with a context-attentive hybrid mechanism and maximizes detection accuracy and computational efficiency.
P. P. Bairagi, Ashish Bagwari, Sailen Dutta Kalita et al.· international journal of eng...· 0 citations
The explosion of Internet of Things (IoT) deployment over the past decade has served as a foundational pillar for global digital transformation. However, the rapid expanding attack surface of IoT architectures often suffers from compromised security paradigms, rendering smart environments highly vulnerable to malicious exploitations. While traditional Intrusion Detection Systems (IDS) mitigate network threats, conventional datasets lack the granular, protocol-specific traffic anomalies characteristic of IoT environments. This research addresses this gap by developing an automated machine learning framework designed to differentiate reconnaissance and anomalous activities from baseline behaviors within smart home IoT infrastructures. Utilizing the Hacking and Countermeasure Research Lab (HCRL) dataset, we evaluate and contrast the efficacy of Naïve Bayes (NB) and Support Vector Machine (SVM) algorithms across varying data-split ratios. Experimental results indicate that while Naïve Bayes offers competitive computational recall in localized environments, the SVM classifier demonstrates superior robustness, achieving an accuracy threshold approaching 99.99% in isolating low-frequency reconnaissance attacks.
Traditional Internet of Things (IoT) security solutions often rely on heavy cloud-based or gateway-class infrastructure, which is frequently unsuitable for resource-limited hardware due to latency, power, and memory constraints. This paper proposed a resource-aware behavioral Intrusion Detection System (IDS) designed for highly constrained IoT devices. To address these challenges, the proposed system implements real-time application-layer monitoring on an ESP32 Microcontroller Unit (MCU) and utilizes an offline-trained logistic regression model for autonomous, on-device inference. The detection mechanism extracts behavioral features, such as request rates, failed authentication attempts, and invalid resource access within sliding time windows to estimate attack probabilities. Experimental evaluations under controlled scenarios involving flood, brute force, and scan attacks demonstrate that the system achieves high accuracy, precision, and recall. These findings indicate that effective cyber intrusion detection and local mitigation can be successfully executed directly on a single MCU while preserving stable runtime performance and minimal memory usage. Finally, this paper highlights the need for further optimizations to improve robustness and scalability.
Sofyan Bisher, Anas Fawaza, Tarek Mawed et al.· International Conference on...· 0 citations
A two-tier hybrid IDS that uses a Random Forest model for quick initial detection and a Neural Network for deeper analysis of suspicious traffic is proposed that provides a balanced and efficient solution that overcomes key limitations of existing IDS models and offers a pathway towards a more robust real-time IoT intrusion detection.
Research Paper, Wong Zoey, Yu Watanabe et al.· International Journal of Eme...· 0 citations
The rapid growth of the Internet of Things (IoT) has intensified cybersecurity risks while exposing the limitations of traditional security solutions in resource-constrained environments. Intrusion detection in IoT systems, therefore, requires reliable, real-time decision-making with minimal computational overhead. This paper presents a lightweight IoT security decision framework that combines entropy-guided feature selection with an adaptive ensemble-based intrusion detection strategy. The proposed approach employs an entropy–correlation (EnCor) feature selection pipeline to construct a compact and informative feature subset, reducing complexity while preserving discriminative security characteristics. Detection decisions are generated using a soft voting ensemble of complementary machine learning classifiers, supported by an adaptive fallback mechanism to improve reliability under diverse attack scenarios. The framework is specifically designed for edge- and gateway-level IoT deployment, avoiding the high latency and computational demands associated with deep learning and blockchain-based solutions. Experimental evaluation on the TON_IoT and CICIoT2023 datasets demonstrates high detection accuracy with low inference latency and reduced memory consumption. The results confirm that effective intrusion detection can be achieved without compromising practical deployment feasibility. Overall, the proposed framework establishes intrusion detection as an efficient and deployable security decision layer for real-world IoT environments.
Saif Wali Ali Alsudani, M. Feizi-Derakhshi· International Journal of Ele...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.