Skip to content
Open access

Machine Learning-Based Intrusion Detection for Smart City Internet of Things Networks

Aug 2026 · ABC2: Journal of Architecture, Building, Construction, and Cities · 0 citations · 56 references

TL;DR

This study investigates the effectiveness of supervised machine learning techniques for detecting cyberattacks in IoT-based smart city networks using the TON_IoT dataset, finding that advanced ensemble learning combined with robust feature engineering provides a reliable and scalable solution for securing smart city IoT networks.

Abstract

The increasing deployment of Internet of Things (IoT) devices in smart city infrastructures has significantly expanded the network attack surface, making effective intrusion detection a critical security requirement. Traditional intrusion detection systems struggle to cope with the volume, heterogeneity, and dynamic behaviour of IoT network traffic, often resulting in high false alarm rates and missed attacks. This study investigates the effectiveness of supervised machine learning techniques for detecting cyberattacks in IoT-based smart city networks using the TON_IoT dataset. A progressive modelling approach is adopted, beginning with Logistic Regression as the baseline model, followed by Random Forest as an ensemble method, and culminating in an optimised XGBoost model. Preprocessing and feature engineering address dimensionality, feature representation, and the challenges associated with imbalanced IoT traffic distributions. Experimental results demonstrate that ensemble and boosting-based models significantly outperform linear approaches. Among the evaluated models, XGBoost achieves the highest detection performance, substantially reducing missed attacks while maintaining robust classification accuracy. The findings demonstrate that advanced ensemble learning combined with robust feature engineering provides a reliable and scalable solution for securing smart city IoT networks.

Read PDF

Similar papers

Open access Aug 2026

Multiclass Cyber Attack Classification in Smart Home IoT Networks Using Ensemble Machine Learning with the ML-EdgeIIoT Dataset

With the rapid adoption of smart home solutions and related technologies, edge computing has emerged as a key enabler by offering low-latency data processing, increased efficiency and improved scalability. However, this integration in IoT systems introduces complex security challenges in smart home edge environments, increasingly susceptible to cyber threats such as denial-of-service (DoS), malware injection, passive surveillance, and unauthorized access. This paper investigates intelligent intrusion detection and attack classification strategies specifically designed for smart home edge systems. Using the comprehensive ML-EdgeIIoT dataset, this study designs and evaluates a machine learning-based intrusion detection framework for multiclass classification of eight categories of IoT network attacks, namely Backdoor, MITM, DDoS, Ransomware, Password Attack, SQL Injection, Prob-attacks, and Normal traffic while minimizing false positives and false negatives. The framework incorporates data cleaning, correlation- and feature importance-based feature selection, hyperparameter optimization using gridsearchCV, model training, and ensemble learning. A set of machine learning models comprising Artificial Neural Network, Balanced Random Forest, K-Nearest Neighbours, Random Forest, and Logistic Regression was implemented and comparatively evaluated. Two ensemble techniques were subsequently developed using the three best-performing classifiers: (1) a stacking ensemble with Logistic Regression as the meta-learner and (2) a Top-3 majority voting ensemble. Model performance was evaluated using accuracy, precision, recall, F1-score, confusion matrix, and ROC-AUC. Robustness and generalization of the individual machine learning models were assessed through stratified 10-fold cross-validation for the three best-performing classifiers. The Top-3 voting ensemble subsequently achieved the highest performance on the independent test set, with accuracy of 99.24%, average precision of 98.75%, recall of 99.00%, and an F1-score of 99.00% for all attack classes, while reducing misclassification compared with individual classifiers. The findings of this study significantly enhance the understanding of smart home edge computing security, which will pave the way for more robust and intelligent threat detection frameworks.

Abhay Kumar Ray, Rupak Sharma, Sunil Kumar Pandey · 0 citations
Open access Aug 2026

Quantum machine learning-based intrusion detection system for IoT cloud-enabled smart city environments

This study presents a Quantum Machine Learning (QML)-based Intrusion Detection framework that uses Quantum Support Vector Machines (QSVM) to improve detection accuracy, adaptability, and computational efficiency in conceptual IoT Cloud-Enabled Smart City environments.

Sukanya. Pondavakam, S. Singh, Himanshu Gupta · 0 citations
Open access Aug 2026

Automated Network Intrusion Detection for Internet of Things Security Enhancements

As interconnected devices increasingly transmit personal and sensitive data, security attacks are becoming more sophisticated and prevalent, highlighting the critical need for effective security solutions in Internet of Things (IoT) environments. An automated Network Intrusion Detection (NID) system plays a vital role in notifying system administrators of security breaches, acting as an efficient tool for protecting IoT networks from various threats. This study utilizes the UNSW-NB 15 dataset to enhance intrusion detection accuracy by addressing performance challenges and class imbalances within the data. We employ a combination of feature selection techniques, including Filter Method, Wrapper Method, and an Embedded approach using Lasso and Random Forest with Recursive Feature Elimination (RFE), alongside Pearson Correlation Coefficient (PCC). To tackle class imbalance, we apply the Synthetic Minority Over-sampling Technique (SOMTE). Various algorithms are implemented, including Random Forest, Decision Tree, AdaBoost, Bernoulli Naive Bayes, K-Nearest Neighbors, and Logistic Regression. Notably, the Stacking Classifier, which combines Boosted Decision Trees, Bagging with Random Forest, and LightGBM, demonstrates high performance in accurately detecting intrusions, significantly improving detection rates and reducing false alarms.

Rangu Shashidhar, M. Raju · 1 citation
Open access Sep 2026

Machine Learning-Based Anomaly Detection for Traffic in IoT-Enabled Transportation Networks

The rapid proliferation of Internet of Things (IoT) devices and their integration into increasingly interconnected applications have substantially expanded the attack surface of modern networked systems. The heterogeneous nature and high volume of IoT traffic make timely and reliable identification of malicious activities increasingly important for maintaining the security and resilience of IoT-enabled environments. This study investigates the effectiveness of maching learning approaches for supervised malicious traffic classification in IoT networks using the ACI-IoT-2023 dataset. A comparative experimental study is conducted across binary and eleven-class classification tasks to examine the capability of different learning approaches to distinguish benign and malicious traffic and identify diverse attack categories. The results demonstrate strong classification performance across the evaluated approaches, with XGBoost achieving the highest ROC-AUC in binary classification and the Decision Tree delivering the best overall performance in eleven-class classification. Further analysis of feature importance identifies several flow-level features that contribute substantially to classification performance. Overall, the findings demonstrate the effectiveness of machine learning-based approaches for accurate and efficient malicious traffic classification in IoT networks.

Connor Gladish, Molly Corgan, J. Moss et al. · 0 citations
Open access Aug 2026

Hybrid Intrusion Detection System with Real-Time Concept Drift Detection for Enhanced IoT Security

A hybrid IDS framework that integrates supervised Random Forest classification, unsupervised Isolation Forest anomaly monitoring, and Kolmogorov–Smirnov (KS)-based concept drift monitoring is presented, providing initial evidence of generalization to one held-out attack family but should not be interpreted as proof of broad zero-day detection capability.

Muath A. Obaidat, Meryem Abouali, Aneeza Shakeel · 0 citations
Open access Aug 2026

Detecting and Preventing Cyberattacks in Internet of Things (IoT) Systems

This study proposes a hybrid machine learning-based intrusion detection and prevention framework for securing IoT networks that integrates Isolation Forest, Autoencoder, Extreme Gradient Boosting, and Bidirectional Long Short-Term Memory models within a stacked ensemble architecture to improve attack detection while reducing false-positive predictions.

Ruthwik Palem, Likhith Reddy Peketi, Vanathi M et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.