Skip to content
Open access

LLM-Integrated Anomaly Detection for IoT Networks: Framework Structure

Aug 2026 · Baghdad Science Journal · 0 citations

TL;DR

A machine learning-based framework to tackle issues in traditional systems in traditional systems is introduced by combining large language models (LLMs) and is effective in identifying possible threats as well as filling the semantic gap.

Abstract

Internet of Things (IoT) devices are vulnerable to zero-day attacks because most of them have weak or no inherent security due to the resource constraints of the devices. This weakness underscores the growing need for anomaly-based intrusion detection systems tailored to IoT networks. Nevertheless, general anomaly detection traditionally has a high number of false positives that drain analysts' time. Also, a semantic difference exists between the system's results and the operators' interpretations. We introduce a machine learning-based framework to tackle these issues in traditional systems in this paper by combining large language models (LLMs). Our model is effective in identifying possible threats as well as filling the semantic gap. The framework uses isolation forests to detect anomalies and random forests to measure device integrity. To further improve the assessment of anomalies and increase interpretability, system insights are further refined using GPT-4o mini, an LLM. The model gives statistical summaries of the IoT traffic, a risk score, and an explanation in easy language, which is easy to understand and therefore makes the process of decision-making easier. Such a novel system reduces the reliance on dedicated network operators and allows non-technical users to better understand and act on the results of the system.

Read PDF

Similar papers

Open access Jul 2026

A Two-Tier Hybrid Intrusion Detection System for IoT Networks

A two-tier hybrid IDS that uses a Random Forest model for quick initial detection and a Neural Network for deeper analysis of suspicious traffic is proposed that provides a balanced and efficient solution that overcomes key limitations of existing IDS models and offers a pathway towards a more robust real-time IoT intrusion detection.

Research Paper, Wong Zoey, Yu Watanabe et al. · 0 citations
Open access Aug 2026

Explainable Deep Learning Intrusion Detection Framework for Securing IoT Environment

A new explainable hybrid IDS architecture for IoT environments named XABiL-IDS (Explainable Attention-based Bi LSTM-Intrusion Detection System) in response to this challenge, which uses a robust hybrid architecture to detect attacks effectively.

Ravi Patni, Gurvinder Singh · 0 citations

Anomaly Detection Based on Behavior Feature Correlation for IoT Systems

The approach models inter-device state correlations using a heterogeneous graph structure and partitions behavior patterns through iterative community detection and automated semantic annotation, and represents normal behavior by embedding and clustering of state sequences.

Yifan Lu, Qixiao Lin, Jian Mao et al. · 0 citations
Open access Aug 2026

Detecting and Preventing Cyberattacks in Internet of Things (IoT) Systems

This study proposes a hybrid machine learning-based intrusion detection and prevention framework for securing IoT networks that integrates Isolation Forest, Autoencoder, Extreme Gradient Boosting, and Bidirectional Long Short-Term Memory models within a stacked ensemble architecture to improve attack detection while reducing false-positive predictions.

Ruthwik Palem, Likhith Reddy Peketi, Vanathi M et al. · 0 citations
Open access 2026

From IoT Vulnerabilities to Intrusion Detection: An Explainable Vulnerability-Aware Machine Learning Framework for Smart Home IoT Security

The swift deployment of IoT-based smart home appliances has increased the attack surface for the smart environment and exposed it to attacks like botnet command-and-control communications, brute force attacks, denial-of-service attacks, and web-based attacks. Even though the Intrusion Detection Systems (IDSs) that use Machine Learning (ML) algorithms achieve a very high detection rate, most existing solutions focus on predictive performance but lack the ability to link detected attacks to the corresponding vulnerabilities in the Internet of Things (IoT). In this paper, an interpretable vulnerability-aware ML-based approach is presented to solve this problem through the integration of vulnerability classes of IoT, attack classes, network flow attributes, and ML features into one interpretation model. The proposed method uses leakage-aware pre-processing, addressing class imbalance, and compares Random Forest, XGBoost, and soft voting ensemble ML techniques using the CSE-CIC-IDS2018 dataset. Experimental outcomes indicate that XGBoost outperforms the other approaches in terms of performance, with an accuracy of 98.22%, precision of 99.69%, F1-score of 95.36%, ROC-AUC of 99.07%, and only 760 false alarms, which is approximately 19× lower number of false positives compared to Random Forest while keeping a similar level of detection efficiency. In addition to numeric assessment of the approach performance, the suggested model provides the vulnerability-oriented interpretation module that establishes mapping between prominent network flow attributes and possible IoT vulnerability states and attacks. Therefore, the integration of an interpretable vulnerability reasoning component into a high-performing tree-based machine learning algorithm proves to be effective for smart home IoT intrusion detection.

Huda Aldawghan, Mounir Frikha · 0 citations
Open access Sep 2026

AI-Driven Vulnerability Management Framework for the Internet of Things

This rapid growth of IoT has changed the landscape of today’s digital world by allowing devices to communicate effectively, especially in different fields like healthcare, smart cities, industrial control, and defense. Despite its advantages, IoT introduces significant security challenges due to device heterogeneity, constrained computational resources, and weak security architectures, making it highly vulnerable to cyber threats. Traditional vulnerability management approaches, including rule-based intrusion detection systems and signature-based scanning, have proven inadequate in addressing the dynamic and large-scale nature of IoT environments, as they are largely reactive and incapable of detecting novel attack patterns. This study proposes an AI driven vulnerability management framework that integrates anomaly detection techniques using machine learning to enhance proactive threat identification and mitigation in IoT ecosystems. The framework leverages publicly available datasets such as Bot-IoT, CIC-IoT, and UNSW NB15 to train and evaluate models capable of distinguishing between normal and malicious network behaviors. Various machine learning algorithms, including supervised and unsupervised techniques, were implemented and assessed using performance metrics such as accuracy, precision, recall, F1-score and false positive rate. The results demonstrate that AI based models significantly outperform traditional methods in detecting previously unseen threats, achieving high detection accuracy and reduced false positives. The proposed framework integrates anomaly detection into a structured vulnerability management lifecycle encompassing identification, prioritization and remediation of vulnerabilities. Generally, the study provides a scalable and adaptive solution for improving IoT security, reducing system vulnerabilities, and enhancing resilience against evolving cyber threats, with potential for future real-world deployment across critical sectors.

Daniel Nafisatu Mshelbila · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.