Aug 2026· Journal of Intelligent Informatics, Networking, and Cybersecurity· 0 citations
TL;DR
An offensive-defensive system based on Deep Reinforcement Learning (DRL) algorithms is proposed, which outperform several state-of-the-art machine learning approaches in the literature, revealing that the systematic incorporation of accurate data engineering and reinforcement learning frameworks generates a field-tested security barrier that offers an expedient reaction to counteract multifaceted threats to IoT networks.
Abstract
Breach rates and unparalleled vulnerabilities are a constant feature of the cyber landscape these days, and the increasing complexity of the proliferation of Internet of Things (IoT) nodes is to be expected. With these challenges, the conventional intrusion detection systems (IDS) are proven to be unable to deal with the extensive and varied data streams. Such systems can be fundamentally attributed to the classical nature of these systems, which are lacking in flexibility to analyze traffic in real-time and thus have no proactive capabilities of identifying patterns of unknown attacks. Considering these technical barriers, in this paper, an offensive-defensive system based on Deep Reinforcement Learning (DRL) algorithms is proposed. The novelty of the proposed method is the unique synergic combination of mathematical feature engineering and a dynamically changing Deep Q-Network (DQN) agent, dynamically adapting to changing traffic patterns. A comprehensive four-stage data preparation pipeline was designed and tested on the benchmark CICIoT2023 dataset, prior to the training phase. To reduce the dimensionality, non-influential features of the network were eliminated using entropy and the Synthetic Minority Over-Sampling Technique (SMOTE) was applied to address the statistical imbalance between the classes. It was tested under strict experimental conditions, with an 80:20 train/test split, on a set of 231,250 samples, before an isolated test set of 46,250 samples. This organization's initiation led to a stable mathematical context of the DQN agent, which can better formulate inferential policies to enable it to make real-time directional choices, including blocking or passing packets, by optimization of the reward function, which is ideally consistent with the concepts of zero-trust architecture. At the experimental level, the suggested framework proved to be highly efficient in its operation, with a total accuracy of 98.74%, a precision rate of 99.80%, a recall rate of 98.93%, and an F1-score of 99.37%. These numerical metrics outperform several state-of-the-art machine learning approaches in the literature, revealing that the systematic incorporation of accurate data engineering and reinforcement learning frameworks generates a field-tested security barrier that offers an expedient reaction to counteract multifaceted threats to IoT networks.
The review reveals that the most used algorithm for DRL-based IDS is Deep Q-Network (DQN), appearing in 8 studies (30.8%), and the most frequently targeted attacks are DoS, DDoS, Backdoors, Mirai, Reconnaissance, Scan, and Torii.
Maryam Omar Abdullah Sawad, S. Abdulkadir, H. Alhussian et al.· Computer Modeling in Enginee...· 0 citations
LSTM had good detection for frequent attacks and slow-changing patterns, which shows its capacity in learning long-lasting dependencies, which shows its capacity in learning long-lasting dependencies.
Jawad Hussain Awan, Misbah Safdar, Muhammad Ayaz Shirazi et al.· Italian National Conference...· 0 citations
A new explainable hybrid IDS architecture for IoT environments named XABiL-IDS (Explainable Attention-based Bi LSTM-Intrusion Detection System) in response to this challenge, which uses a robust hybrid architecture to detect attacks effectively.
Ravi Patni, Gurvinder Singh· International journal of com...· 0 citations
The framework introduces CNN–BiLSTM deep learning networks to represent traffic in a spatiotemporal manner and adopts ensemble machine learning classifiers to enhance the robustness of traffic detection and its interpretability, to enhance the robustness of traffic detection and its interpretability.
Ramesh N. S. V. S. C. Sripada, A. Bhavani, Kiran B. Malagi et al.· Discover Computing· 0 citations
Experimental results demonstrate that the proposed AI-driven IDS achieves superior performance compared to existing approaches, highlighting its potential as a robust and efficient solution for securing IoT environments against emerging cyber threats.
N. G, Sujatha S. R., Sushmitha J et al.· Genetics and Molecular Resea...· 0 citations
A hybrid deep learning (DL)-based anomaly detection model is presented for IoT cybersecurity that achieves superior performance in terms of accuracy, precision, recall, and F1-score compared to conventional DL techniques.
P. Palpandi, B. Sakthivel, M. Ponnrajakumari et al.· International Journal of Inf...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.