Skip to content
Conference

HMCTI: A Hierarchical Multi-Context Threat Intelligence Framework for Proactive Cyberattack Detection in IoT Environments

Jul 2026 · International Conference on Computer, Information and Telecommunication Systems · pp. 1-8 · 0 citations · 21 references

Abstract

The rapid growth of Internet of Things (IoT) networks has increased their exposure to cyber threats, while existing Intrusion Detection Systems (IDS) remain largely reactive and resource-intensive. This paper proposes a HMCTI Framework for proactive cyberattack detection in IoT environments. The framework distributes threat intelligence across Edge, Fog, and Cloud layers, integrating behavioral drift analysis, flow-level features, and device-context information to identify attacks at their early stages. By combining lightweight anomaly detection, context-aware threat analysis, and multi-layer threat correlation, HMCTI enhances detection capability while maintaining scalability and efficiency. Experimental evaluation using the CICIoT2023 dataset assesses detection accuracy, Detection Lead Time (DLT), and resource overhead. The proposed framework provides a scalable and proactive approach for early cyberattack detection in next-generation IoT networks.

View source

Similar papers

Conference Open access 2026

Hierarchical Temporal Evidence Fusion for Intrusion Detection in Edge-Fog-Cloud IoT Architectures

: The hierarchical and heterogeneous nature of Internet of Things (IoT) architectures, spanning edge, fog, and cloud layers, makes intrusion detection particularly challenging, as each layer provides only a partial view of the system. Traditional intrusion detection systems (IDS) often fail to identify coordinated and distributed attacks from fragmented observations. This paper proposes HTEF-IDS, a hierarchical intrusion detection framework that combines LSTM-based temporal modeling with Dempster–Shafer evidence fusion to infer a global security state from distributed observations. Local detections are progressively aggregated across layers, while a feedback mechanism dynamically adjusts detection sensitivity according to the inferred threat level. Experiments conducted on the CIC IoT-DIAD 2024 dataset show that the proposed framework improves detection performance, reduces false positives, and effectively identifies distributed attack patterns that are not observable at a single layer.

Myria Bouhaddi, Farah Sadok · 0 citations
Open access Aug 2026

Detecting and Preventing Cyberattacks in Internet of Things (IoT) Systems

This study proposes a hybrid machine learning-based intrusion detection and prevention framework for securing IoT networks that integrates Isolation Forest, Autoencoder, Extreme Gradient Boosting, and Bidirectional Long Short-Term Memory models within a stacked ensemble architecture to improve attack detection while reducing false-positive predictions.

Ruthwik Palem, Likhith Reddy Peketi, Vanathi M et al. · 0 citations
Open access 2026

A Lightweight Language-Model-Driven Agentic Framework for Intrusion Prediction, Detection, and Mitigation in 6G-Enabled IoT Networks

The extensive deployment of Internet of Things (IoT) devices in emerging 6G-enabled environments, characterized by massive connectivity, distributed edge intelligence, and ultra-low-latency communication, allows cyber threats to evade detection until malicious activities manifest. Conventional intrusion detection systems remain fundamentally reactive, identifying threats only after suspicious patterns become observable in network traffic, which hinders both proactive threat anticipation and timely mitigation. To address these limitations, this paper proposes a role-based multi-agent cybersecurity framework for 6G-enabled IoT networks that enables proactive intrusion prediction, real-time detection, and knowledge-driven threat mitigation. The framework establishes a coordinated defense loop composed of three specialized agents: (i) a prediction agent that leverages Small Language Models (SLMs) to model packet-level temporal dependencies and proactively forecast malicious traffic sequences, (ii) a detection agent that performs real-time traffic classification using a lightweight gradient boosting model suitable for low-latency edge environments, and (iii) a knowledge graph-driven mitigation agent that maps detected threats to corresponding defensive countermeasures. Extensive evaluation on the CICIoT2023 dataset demonstrates the effectiveness of the proposed framework, achieving 98.24% accuracy in proactive packet-level detection using forecasted packets and 99.94% accuracy in real-time flow-based detection. The proposed framework combines structured multi-agent coordination, low-latency inference, and knowledge-driven response, making it a promising step toward scalable and intelligent cybersecurity management in 6G-enabled IoT networks.

Alaeddine Diaf, A. A. Korba, W. Jaafar et al. · 0 citations
Open access Sep 2026

AI-Driven Vulnerability Management Framework for the Internet of Things

This rapid growth of IoT has changed the landscape of today’s digital world by allowing devices to communicate effectively, especially in different fields like healthcare, smart cities, industrial control, and defense. Despite its advantages, IoT introduces significant security challenges due to device heterogeneity, constrained computational resources, and weak security architectures, making it highly vulnerable to cyber threats. Traditional vulnerability management approaches, including rule-based intrusion detection systems and signature-based scanning, have proven inadequate in addressing the dynamic and large-scale nature of IoT environments, as they are largely reactive and incapable of detecting novel attack patterns. This study proposes an AI driven vulnerability management framework that integrates anomaly detection techniques using machine learning to enhance proactive threat identification and mitigation in IoT ecosystems. The framework leverages publicly available datasets such as Bot-IoT, CIC-IoT, and UNSW NB15 to train and evaluate models capable of distinguishing between normal and malicious network behaviors. Various machine learning algorithms, including supervised and unsupervised techniques, were implemented and assessed using performance metrics such as accuracy, precision, recall, F1-score and false positive rate. The results demonstrate that AI based models significantly outperform traditional methods in detecting previously unseen threats, achieving high detection accuracy and reduced false positives. The proposed framework integrates anomaly detection into a structured vulnerability management lifecycle encompassing identification, prioritization and remediation of vulnerabilities. Generally, the study provides a scalable and adaptive solution for improving IoT security, reducing system vulnerabilities, and enhancing resilience against evolving cyber threats, with potential for future real-world deployment across critical sectors.

Daniel Nafisatu Mshelbila · 0 citations
Open access Aug 2026

Adaptive Machine Learning Framework for Real-Time Cyber-Attack Detection and Prevention in IoT Networks

This paper introduces an innovative ML-based security paradigm that improves the attack detection accuracy by combining adaptive feature extraction techniques with a context-attentive hybrid mechanism and maximizes detection accuracy and computational efficiency.

P. P. Bairagi, Ashish Bagwari, Sailen Dutta Kalita et al. · 0 citations
Open access Aug 2026

Adaptive Threat Intelligence Framework for Real-Time Cyberattack Detection Using Behavior-Based Analytics

The rapid growth of interconnected digital infrastructures, cloud computing environments, Internet of Things devices, and enterprise networking systems has significantly increased the frequency, complexity, and sophistication of cyberattacks targeting organizational information assets. Traditional cybersecurity mechanisms based primarily on signature detection and static rule-based monitoring are becoming increasingly ineffective against modern attack strategies such as zero-day exploits, advanced persistent threats, insider attacks, ransomware campaigns, and polymorphic malware. In this context, adaptive threat intelligence frameworks integrated with behavior-based analytics have emerged as a promising approach for enhancing real-time cyberattack detection and proactive security response capabilities. This research investigates the design and implementation of an adaptive threat intelligence framework capable of identifying malicious activities through continuous behavioral analysis, anomaly detection, and dynamic threat assessment techniques. The study focuses on how behavioral analytics can improve cybersecurity resilience by monitoring user activities, network communication patterns, system interactions, application behavior, and endpoint activities to identify deviations from established normal operational baselines. Unlike traditional detection approaches that depend heavily on predefined signatures, behavior-based analytics enables the identification of previously unknown threats and evolving attack vectors through machine learning algorithms, predictive analytics, and intelligent pattern recognition models. The proposed framework integrates adaptive learning mechanisms that continuously update threat intelligence repositories based on real-time attack behaviors, thereby improving detection accuracy and minimizing response delays. The research further examines the role of artificial intelligence, big data analytics, and automated incident response systems in strengthening cyber defense infrastructures across enterprise environments. In addition to operational advantages, the study critically evaluates challenges associated with implementing adaptive threat intelligence systems, including false-positive generation, data privacy concerns, computational complexity, adversarial machine learning attacks, scalability limitations, and integration difficulties within heterogeneous network architectures. The research methodology incorporates quantitative analysis, simulated attack scenarios, case study evaluations, and expert assessments to measure the effectiveness of behavior-based threat detection techniques in identifying malicious activities across dynamic cybersecurity environments. Findings from the study indicate that adaptive threat intelligence frameworks significantly enhance threat visibility, accelerate incident response, reduce detection latency, and improve organizational preparedness against sophisticated cyber threats when compared to conventional security monitoring systems. The research also emphasizes the importance of continuous learning models, human oversight, ethical cybersecurity governance, and secure data management practices to ensure sustainable and reliable implementation of intelligent threat detection systems. The study concludes that behavior-based adaptive cybersecurity frameworks represent a critical advancement in modern cyber defense strategies by enabling organizations to detect, analyze, and respond to emerging cyber threats in real time while maintaining operational continuity, information security, and digital infrastructure resilience in increasingly hostile cyber environments.

S. Tamilselvi · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.