A Survey of Machine Learning Approaches to IoT Security
Abstract
1. Introduction
| Year | Attack Name | Targeted Domain | Impact |
|---|---|---|---|
| 2020 | Mozi IoT botnet surge [20] | SOHO routers, DVRs, gateways | Large-scale DDoS capability; persistent infections across consumer IoT devices |
| 2021 | Verkada camera breach [11,21] | Cloud-managed security cameras (enterprise/industrial) | Access to 150 k live cameras; privacy exposure across hospitals, prisons, schools, firms |
| 2021 | Arcadyan router auth bypass (CVE-2021-20090) weaponized [22] | Home/SOHO routers (multiple brands using Arcadyan firmware) | Rapid global recruitment of routers into DDoS botnets days after disclosure |
| 2021–2022 | Hikvision camera RCE (CVE-2021-36260) exploited [23] | IP CCTV cameras | Camera takeover, lateral movement footholds, botnet growth in enterprise networks |
| 2022 | Viasat KA-SAT modem sabotage (“AcidRain”) [12] | Satellite broadband modems (consumer/industrial) | Tens of thousands modems disabled; 5800 wind turbines lost remote connectivity |
| 2023 | TP-Link Archer AX21 RCE (CVE-2023-1389) mass-exploited [5,6] | Home/SOHO Wi-Fi routers | Widespread router conscription, sustained DDoS firepower across multiple botnets into 2024 |
| 2023–2024 | Volt Typhoon & KV-botnet [10] | SOHO routers (Cisco/NETGEAR, often end-of-life) | Pre-positioning in critical infrastructure; U.S. takedown and notifications January 2024 |
| 2024 | AVTECH IP camera zero-day campaign [13] | IP cameras/NVRs (AVTECH) | Camera fleets co-opted into DDoS botnets; risk to critical environment organizations |
| 2025 | GeoVision EoL camera exploits (CVE-2024-6047, -11120) [14] | Legacy/EoL GeoVision IoT cameras | DDoS botnet expansion using abandoned devices with no vendor support |
2. Methodology
2.1. Search Strategy and Data Sources
- Database selectionA comprehensive literature search was conducted across five prominent academic databases selected for their comprehensive coverage of computer science, engineering and interdisciplinary IoT research:
- –
- MDPI (Multidisciplinary Digital Publishing Institute)
- –
- IEEE Xplore Digital Library
- –
- Nature Publishing Group
- –
- ScienceDirect
- –
- SpringerLink
- Temporal scopePublications from January 2023 to December 2025 (inclusive) were selected.
- Search keywordsThe search strategy employed Boolean combinations of the following keyword sets:
- –
- IoT security terms:
- *
- “Internet of Things” OR “IoT”
- *
- “security” OR “intrusion detection” OR “anomaly detection” OR “threat detection” OR “cybersecurity” OR “attack detection”
- –
- Machine learning terms:“machine learning” OR “deep learning” OR “neural network” OR “CNN” OR “LSTM” OR “random forest” OR “federated learning” OR “supervised learning” OR “unsupervised learning”
- –
- Domain-specific terms:“smart home” OR “smart city” OR “healthcare IoT” OR “industrial IoT” OR “IIoT”
- Initial resultsThe search queries yielded approximately 120,000 candidate publications across all databases. These were progressively filtered through a structured screening process; Table 2 documents the selection funnel.
2.2. Inclusion Criteria
- Publication date between 1 January 2023 and 31 December 2025
- Focus on ML/DL applications for IoT security (not general network security)
- Empirical evaluation on IoT-specific datasets or real-world deployments
- Full text availability in English or Romanian language
2.3. Exclusion Criteria
- Publications before 2023 or after 2025
- Studies focusing solely on non-IoT network environments
- Review papers without novel contributions
2.4. Data Extraction and Classification Framework
- Extracted attributes
- –
- ML technique taxonomy: supervised, unsupervised, reinforcement learning, federated learning, hybrid approaches
- –
- IoT application domain: smart home, smart city, healthcare IoT, industrial IoT
- –
- Addressed threats: DDoS, unauthorized access, malware, ransomware, data tampering
- –
- Performance metrics: accuracy, precision, recall, F1 score, inference latency, memory footprint
- –
- Deployment considerations: edge feasibility, privacy mechanisms, explainability
- Classification methodologyMachine learning techniques were categorized according to their implementation across different IoT domains, enabling systematic evaluation of domain-specific effectiveness.
2.5. Source Classification
2.6. Synthesis and Analysis Approach
- Quantitative synthesisAggregating performance metrics across similar approaches to identify the best-performing paradigms.
- Qualitative analysisExtracting common challenges, limitations, and future directions stated across multiple studies.
3. IoT Security Landscape
3.1. Smart Home IoT
3.2. Smart City IoT
3.3. Healthcare IoT
3.4. Industrial IoT
3.5. Cross-Domain Comparison
4. ML Techniques for IoT Security
4.1. Classical ML Approaches
4.1.1. Supervised Learning
4.1.2. Unsupervised Learning
4.2. Reinforcement Learning
4.3. Deep Learning
4.3.1. Intrusion Detection
4.3.2. Malware Detection and Authentication
4.4. Federated Learning
5. Machine Learning Techniques for IoT Security: Comparative Analysis
- a technique-focused taxonomy accompanied by quantitative performance profiles across representative deployment scenarios
- synthesized comparative insights that elucidate when deep learning architectures justify their computational complexity, the divergence between federated learning’s theoretical promise and operational reality and the fundamental tension between model performance and interpretability, the explainability paradox
- an examination of persistent deployment challenges that impede the translation of laboratory results to production environments
5.1. Technical Taxonomy and Performance Overview
5.1.1. Classical Machine Learning
5.1.2. Deep Learning–Convolutional Neural Networks
5.1.3. Deep Learning–Recurrent Neural Networks
5.1.4. Deep Learning–Attention Mechanisms
5.1.5. Federated Learning
5.1.6. Hybrid and Ensemble Approaches
5.2. Critical Comparative Analysis
5.2.1. Deep Learning Complexity Under Theoretical and Practical Constraints
- Heterogeneous traffic patternsCNN architectures achieve up to 100% accuracy on device-specific datasets (individual smart home devices such as Philips baby monitors, GPS trackers and thermostats) [32] and 99.39% on single-device botnet telemetry [33], but degrade catastrophically to 72.31% on diverse, real-world IoT-23 traffic encompassing Mirai, Okiru and Torii botnet variants across 23 heterogeneous capture scenarios [62]. This performance degradation suggests deep learning benefits are dataset-specific rather than universal, with advantages concentrated in homogeneous deployments where CNNs can learn device-specific traffic fingerprints through spatial feature extraction. Classical ML demonstrates more consistent performance across heterogeneity: Random Forest maintains 99.39–99.88% accuracy across diverse datasets (NSL-KDD, BoTNeTIoT-L01, CICIoT2023) [26,35,49,59].
- Temporal attack sequencesRecurrent architectures (LSTM, GRU) capture multi-stage attacks unfolding over time reconnaissance, lateral movement, payload deployment—occurring in temporally separated phases that classical ML cannot model effectively. Hybrid CNN-GRU approaches achieve 99.39% accuracy on N-BaIoT [33], while GRU-CNN optimized via SUCMO achieves 98.71% on BoT-IoT [54], outperforming classical ML on attacks exhibiting strong temporal dependencies where feature-engineered approaches struggle to capture sequential patterns. However, for stationary threats without multi-stage temporal characteristics (brute-force authentication, isolated DDoS floods), classical ML matches or exceeds recurrent architecture performance without the computational overhead [35,49].
- Multi-objective securityHealthcare IoT requires simultaneous anomaly detection, integrity verification and access control, multiple security objectives that cannot be addressed through independent classical ML models owing to inconsistent alert thresholds and conflicting decision boundaries. Hybrid CNN-LSTM-VAE architectures achieve multi-objective security: anomaly detection (), integrity verification () and access control accuracy of 96.1% through unified frameworks coordinated by Trust-Aware Controllers [39]. Classical ML cannot provide this integrated multi-objective capability, justifying deep learning complexity for healthcare contexts.
- Scenario-method fit across IoT domains.
5.2.2. Federated Learning Between Theory and Practice
5.2.3. The Paradox of Explainability in Machine Learning Systems
5.3. Deployment Challenges
5.3.1. Resource Constraints and Computational Efficiency
5.3.2. Data Quality Challenges in the Presence of Class Imbalance and Heterogeneity
5.3.3. Privacy Preservation Under Regulatory Compliance Requirements
- differential privacy providing formal information leakage bounds rarely implemented despite being essential,
- secure aggregation preventing servers from observing individual client updates largely absent,
- homomorphic encryption enabling computation on encrypted gradients prohibitively expensive for resource-constrained IoT.
5.3.4. Scalability and Real-Time Processing
5.3.5. Dataset Limitations and Evaluation Methodology Gaps
- traffic captured in controlled laboratory environments rather than operational deployments, missing realistic background traffic, legitimate anomalies (firmware updates, user behavior changes) and adversarial evasion techniques employed against known detection systems,
- limited duration (days or weeks) versus operational deployments spanning months or years experiencing concept drift,
- artificial attack generation using penetration testing tools rather than genuine adversarial campaigns exhibiting sophisticated anti-forensic techniques [29]
5.3.6. Deployment and Maintenance Challenges
- Cross-study deployment readiness.
6. Domain-Specific Implementation Synthesis
6.1. Smart Homes
6.2. Smart Cities
6.3. Healthcare IoT
6.4. Industrial Internet of Things
7. Conclusions
7.1. Summary of Findings
7.2. Positioning Relative to Existing Surveys and Robustness of Conclusions
7.3. Open Challenges
7.4. Research Roadmap
7.5. Concluding Statement
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
Abbreviations
| ACK | Acknowledgment (TCP flag) |
| AWID3 | Aegean Wi-Fi Intrusion Dataset |
| BDT | Boosted Decision Tree |
| BiGRU-MHA | Bidirectional GRU with Multi-Head Attention |
| CCTV | Closed-Circuit Television |
| CVE | Common Vulnerabilities and Exposures |
| CNN-GRU | Convolutional Neural Network-Gated Recurrent Unit |
| CTGAN | Conditional Tabular Generative Adversarial Network |
| DBN | Deep Belief Network |
| DDoS | Distributed Denial of Service |
| DL | Deep Learning |
| DNN | Deep Neural Network |
| DoS | Denial of Service |
| DQN | Deep Q-Network |
| DRL | Deep Reinforcement Learning |
| ECG | Electrocardiogram |
| FL | Federated learning |
| GRU | Gated Recurrent Unit |
| HIPAA | Health Insurance Portability and Accountability Act |
| HVAC | Heating, Ventilation and Air Conditioning |
| IDS | Intrusion detection system |
| IIoT | Industrial Internet of Things |
| IP | Internet Protocol |
| IoT | Internet of Things |
| IWSO | Improved White Shark Optimization |
| LIME | Local Interpretable Model-agnostic Explanations |
| LSTM | Long Short-Term Memory |
| MITM | Man-in-the-Middle |
| ML | Machine learning |
| MQTT | Message Queuing Telemetry Transport |
| NFV | Network Functions Virtualization |
| OSNN | Optimized Single Neural Network |
| RL | Reinforcement Learning |
| SAPGAN | Self-Attention Progressive GAN |
| SCSO | Sand Cat Swarm Optimization |
| SDN | Software-Defined Networking |
| SHAP | SHapley Additive exPlanations |
| SMOTE | Synthetic Minority Over-sampling Technique |
| SOHO | Small Office/Home Office |
| SUCMO | Self-Upgraded Cat and Mouse Optimization |
| SVM | Support Vector Machine |
| SYN | Synchronize (TCP flag) |
| TAC | Trust-Aware Adaptive Controller |
| VAE | Variational Autoencoder |
| XAI | Explainable Artificial Intelligence |
References
- Iot-Analytics.com. Available online: https://iot-analytics.com/number-connected-iot-devices (accessed on 24 September 2025).
- Positive Technologies. Cyberthreats to Industrial IoT. ptsecurity.com. 2025. Available online: https://global.ptsecurity.com/en/research/analytics/cyberthreats-to-industrial-iot/ (accessed on 19 September 2025).
- Varonis. Ransomware Statistics, Data, Trends, and Facts [Updated 2026]. varonis.com. 2025. Available online: https://www.varonis.com/blog/ransomware-statistics (accessed on 23 January 2026).
- IBM. Cost of a Data Breach: The Industrial Sector. ibm.com. 2025. Available online: https://www.ibm.com/think/insights/cost-of-a-data-breach-industrial-sector (accessed on 23 January 2026).
- National Institute of Standards and Technology. CVE-2023-1389. National Vulnerability Database. 2023. Available online: https://nvd.nist.gov/vuln/detail/cve-2023-1389 (accessed on 20 September 2025).
- TP-Link. Statement on Archer AX21 Remote Code Execution Vulnerability. TP-Link Support. 2023. Available online: https://www.tp-link.com/us/support/faq/3643/ (accessed on 20 September 2025).
- Fierce Sensors. IoT Security Attacks Are Escalating-SonicWall Report. fiercesensors.com. 2024. Available online: https://www.fiercesensors.com/iot-wireless/iot-security-attacks-are-escalating-sonicwall-report (accessed on 24 January 2026).
- Fei, W.; Ohno, H.; Sampalli, S. A Systematic Review of IoT Security: Research Potential, Challenges, and Future Directions. ACM Comput. Surv. 2023, 56, 111. [Google Scholar] [CrossRef]
- Cobalt. Top 40 AI Cybersecurity Statistics. cobalt.io. 2024. Available online: https://www.cobalt.io/blog/top-40-ai-cybersecurity-statistics (accessed on 25 January 2026).
- Cybersecurity and Infrastructure Security Agency. PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. CISA Alert AA24-038A. 2024. Available online: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a (accessed on 24 September 2025).
- Knutson, J. Bloomberg: Hackers Breach 150,000 Cameras Tied to Hospitals, Prisons, Schools. Axios. 2021. Available online: https://www.axios.com/2021/03/09/hackers-breach-verkada-security-cameras (accessed on 26 September 2025).
- Guerrero-Saade, J.A.; van Amerongen, M. AcidRain: A Modem Wiper Rains Down on Europe. SentinelOne Labs. 2022. Available online: https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/ (accessed on 25 September 2025).
- Lefton, K.; Cashdollar, L.; Eliovich, A. Corona Mirai Botnet Spreads via Zero-Day. Akamai Security Research. 2024. Available online: https://www.akamai.com/blog/security-research/corona-mirai-botnet-infects-zero-day-sirt (accessed on 24 September 2025).
- Lefton, K. Here Comes Mirai: IoT Devices RSVP to Active Exploitation. Akamai Security Research. 2025. Available online: https://www.akamai.com/blog/security-research/active-exploitation-mirai-geovision-iot-botnet (accessed on 24 September 2025).
- Alfahaid, A.; Alalwany, E.; Almars, A.M.; Alharbi, F.; Atlam, E.; Mahgoub, I. Machine Learning-Based Security Solutions for IoT Networks: A Comprehensive Survey. Sensors 2025, 25, 3341. [Google Scholar] [CrossRef]
- Alwahedi, F.; Aldhaheri, A.; Ferrag, M.A.; Battah, A.; Tihanyi, N. Machine learning techniques for IoT security: Current research and future vision with generative AI and large language models. Internet Things-Cyber-Phys. Syst. 2024, 4, 167–185. [Google Scholar] [CrossRef]
- Ali, H.A.S.; Rani, V.J. Machine Learning for Internet of Things (IoT) Security: A Comprehensive Survey. Int. J. Comput. Netw. Appl. (IJCNA) 2024, 11, 617–659. [Google Scholar] [CrossRef]
- Hernandez-Ramos, J.L.; Karopoulos, G.; Chatzoglou, E.; Kouliaridis, V.; Marmol, E.; Gonzalez-Vidal, A.; Kambourakis, G. Intrusion Detection Based on Federated Learning: A Systematic Review. Acm Comput. Surv. 2025, 57, 309. [Google Scholar] [CrossRef]
- El-Sofany, H.; El-Seoud, S.A.; Karam, O.H.; Bouallegue, B. Using machine learning algorithms to enhance IoT system security. Sci. Rep. 2024, 14, 12077. [Google Scholar] [CrossRef]
- McMillen, D.; Gao, W.; DeBeck, C. IBM X-Force Threat Intelligence. A New Botnet Attack Just Mozied Into Town. ibm.com. Available online: https://www.ibm.com/think/x-force/botnet-attack-mozi-mozied-into-town (accessed on 24 September 2025).
- Randolph, K.; Hunt, M. 2021 Security Incident Report (Version 1.2). Verkada Inc. 2021. Available online: https://docs.verkada.com/docs/Security_Incident_Report_Version1.2.pdf (accessed on 7 May 2026).
- Bakhshi, T.; Ghita, B.; Kuzminykh, I. A Review of IoT Firmware Vulnerabilities and Auditing Techniques. Sensors 2024, 24, 708. [Google Scholar] [CrossRef]
- Watchful IP. Unauthenticated Remote Code Execution (RCE) Vulnerability in Hikvision IP Camera/NVR Firmware (CVE-2021-36260). watchfulip.github.io. 2024. Available online: https://watchfulip.github.io/2021/09/18/Hikvision-IP-Camera-Unauthenticated-RCE.html (accessed on 24 September 2025).
- Zia, M.F.; Siddiqua, M.; Ouameur, M.A.; Bagaa, M.; Al Turjman, F. Securing the Future: A Survey on Smart Home Security in IoT-Integrated Smart Cities. Adv. Netw. 2025, 12, 1–18. [Google Scholar] [CrossRef]
- Abdullahi, S.M.; Lazarova-Molnar, S. On the adoption and deployment of secure and privacy-preserving IIoT in smart manufacturing: A comprehensive guide with recent advances. Int. J. Inf. Secur. 2025, 24, 53. [Google Scholar] [CrossRef]
- Khan, M.M.; Alkhathami, M. Anomaly detection in IoT-based healthcare: Machine learning for enhanced security. Sci. Rep. 2024, 14, 5872. [Google Scholar] [CrossRef] [PubMed]
- Kołaczek, G. Internet of Things (IoT) Technologies in Cybersecurity: Challenges and Opportunities. Appl. Sci. 2025, 15, 2935. [Google Scholar] [CrossRef]
- Khan, M.S.; Phoummalayvane, A.; Akl, R. Unleashing the Power of IoT: A Comprehensive Review of IoT Applications and Future Prospects in Healthcare, Agriculture, Smart Homes, Smart Cities and Industry 4.0. Sensors 2023, 23, 7194. [Google Scholar] [CrossRef]
- Neto, E.C.P.; Dadkhah, S.; Ferreira, R.; Zohourian, A.; Lu, R.; Ghorbani, A.A. CICIoT2023: A Real-Time Dataset and Benchmark for Large-Scale Attacks in IoT Environment. Sensors 2023, 23, 5941. [Google Scholar] [CrossRef]
- Hasan, T.; Tasnim, S. Real-time explainable IoT security with machine learning and CTGAN-enhanced detection for resource-constrained devices. Ad Hoc Netw. 2025, 178, 103937. [Google Scholar] [CrossRef]
- Albanbay, N.; Tursynbek, Y.; Graffi, K.; Uskenbayeva, R.; Kalpeyeva, Z.; Abilkaiyr, Z.; Ayapov, Y. Federated Learning-Based Intrusion Detection in IoT Networks: Performance Evaluation and Data Scaling Study. J. Sens. Actuator Netw. 2025, 14, 78. [Google Scholar] [CrossRef]
- Alabbadi, A.; Bajaber, F. An Intrusion Detection System over the IoT Data Streams Using eXplainable Artificial Intelligence (XAI). Sensors 2025, 25, 847. [Google Scholar] [CrossRef]
- Wang, Z.; Huang, H.; Du, R.; Li, X.; Yuan, G. IoT Intrusion Detection Model based on CNN-GRU. Front. Comput. Intell. Syst. 2023, 4, 90–95. [Google Scholar] [CrossRef]
- Karakaya, A. A Hybrid Approach for IoT Security: Combining Ensemble Learning with Fuzzy Logic. Sensors 2025, 25, 5668. [Google Scholar] [CrossRef]
- Nawaz, M.; Tahira, S.; Shah, D.; Ali, S.; Tahir, M. Lightweight machine learning framework for efficient DDoS attack detection in IoT networks. Sci. Rep. 2025, 15, 24961. [Google Scholar] [CrossRef] [PubMed]
- Thabit, F.; Can, O.; Abdaljlil, S.; Alkhzaimi, H.A. Enhanced an Intrusion Detection System for IoT networks through machine learning techniques: An examination utilizing the AWID dataset. Cogent Eng. 2024, 11, 2378603. [Google Scholar] [CrossRef]
- Segarra, J. IoT Smart City Trends 2025. soracom.io. 2024. Available online: https://soracom.io/blog/iot-smart-city-trends-2025/ (accessed on 12 February 2026).
- Sun, S.; Sharma, P.; Nwodo, K.; Stavrou, A.; Wang, H. FedMADE: Robust Federated Learning for Intrusion Detection in IoT Networks Using a Dynamic Aggregation Method. arXiv 2024, arXiv:2408.07152. [Google Scholar]
- Naik, N.; Surendranath, N.; Raju, S.A.B.; Madduri, C.; Dasari, N.; Shukla, V.K.; Patil, V. Hybrid deep learning-enabled framework for enhancing security, data integrity and operational performance in Healthcare Internet of Things (H-IoT) environments. Sci. Rep. 2025, 15, 31039. [Google Scholar] [CrossRef]
- Karunamurthy, A.; Vijayan, K.; Kshirsagar, P.R.; Tan, K.T. An optimal federated learning-based intrusion detection for IoT environment. Sci. Rep. 2025, 15, 8696. [Google Scholar] [CrossRef]
- Rathi, B.; Thapaswi, S.; Kambhampati, M.; Jain, V.; Akshay, P.; Pandey, T.N.; Pradhan, S.K. Realizing the potential of Internet of Things (IoT) in Industrial applications. Discov. Internet Things 2025, 5, 45. [Google Scholar] [CrossRef]
- rinf.tech. Available online: https://www.rinf.tech/industrial-iot-iiot-trends-2024-and-the-future-path/ (accessed on 27 September 2025).
- Grandviewresearch.com. Available online: https://www.grandviewresearch.com/industry-analysis/us-industrial-internet-of-things-market-report (accessed on 27 September 2025).
- Soori, M.; Arezoo, B.; Dastres, R. Internet of Things for Smart Factories in Industry 4.0, A Review. Internet Things-Cyber-Phys. Syst. 2023, 3, 192–204. [Google Scholar] [CrossRef]
- Ubisense.com. Available online: https://ubisense.com/industrial-iot-what-to-expect-in-2024/ (accessed on 19 September 2025).
- Al-Hawawreh, M.; Alazab, M.; Ferrag, M.A.; Hossain, M.S. Securing the Industrial Internet of Things against Ransomware Attacks: A Comprehensive Analysis of the Emerging Threat Landscape and Detection Mechanisms. J. Netw. Comput. Appl. 2024, 223, 103809. [Google Scholar] [CrossRef]
- Rehman, Z.; Tariq, N.; Moqurrab, S.; Yoo, J.; Srivastava, G. Machine learning and internet of things applications in enterprise architectures: Solutions, challenges and open issues. Expert Syst. 2023, 41, e13467. [Google Scholar] [CrossRef]
- Tadj, T.; Arablouei, R.; Dedeoglu, V. On Evaluating IoT Data Trust via Machine Learning. Future Internet 2023, 15, 309. [Google Scholar] [CrossRef]
- Alve, S.R.; Mahmud, M.Z.; Islam, S.; Chowdhury, M.A.; Islam, J. Resource-Efficient Machine Learning Approaches for Multi-Class Threat Detection in IoT Environments. In Proceedings of the 2025 International Conference on Quantum Photonics, Artificial Intelligence and Networking (QPAIN), Rangpur, Bangladesh, 31 July–2 August 2025; IEEE: New York, NY, USA, 2025; pp. 1–6. [Google Scholar] [CrossRef]
- Ahmed, S.F.; Alam, M.S.B.; Hoque, M.; Lameesa, A.; Afrin, S.; Farah, T.; Kabir, M.; Shafiullah, G.M.; Muyeen, S.M. Industrial Internet of Things enabled technologies, challenges and future directions. Comput. Electr. Eng. 2023, 110, 108847. [Google Scholar] [CrossRef]
- Devine, M.; Ardakani, S.P.; Al-Khafajiy, M.; James, Y. Federated Machine Learning to Enable Intrusion Detection Systems in IoT Networks. Electronics 2025, 14, 1176. [Google Scholar] [CrossRef]
- Aljabri, J. Attack resilient IoT security framework using multi head attention based representation learning with improved white shark optimization algorithm. Sci. Rep. 2025, 15, 14255. [Google Scholar] [CrossRef]
- Alabbadi, A.; Bajaber, F. X-FuseRLSTM: A Cross-Domain Explainable Intrusion Detection Framework in IoT Using the Attention-Guided Dual-Path Feature Fusion and Residual LSTM. Sensors 2025, 25, 3693. [Google Scholar] [CrossRef]
- Sagu, A.; Gill, N.S.; Gulia, P.; Alduaiji, N.; Shukla, P.K.; Shah, M.A. Advances to IoT security using a GRU-CNN deep learning model trained on SUCMO algorithm. Sci. Rep. 2025, 15, 16485. [Google Scholar] [CrossRef]
- Karthikeyan, M.; Manimegalai, D.; RajaGopal, K. Firefly algorithm based WSN-IoT security enhancement with machine learning for intrusion detection. Sci. Rep. 2024, 14, 231. [Google Scholar] [CrossRef]
- Shi, L.; Yang, Q.; Gao, L.; Ge, H. An ensemble system for machine learning IoT intrusion detection based on enhanced artificial hummingbird algorithm. J. Supercomput. 2024, 81, 110. [Google Scholar] [CrossRef]
- Kilichev, D.; Turimov, D.; Kim, W. Next–Generation Intrusion Detection for IoT EVCS: Integrating CNN, LSTM and GRU Models. Mathematics 2024, 12, 571. [Google Scholar] [CrossRef]
- Kantharaju, V.; Suresh, H.; Niranjanamurthy, M.; Ansarullah, S.I.; Amin, F.; Alabrah, A. Machine learning based intrusion detection framework for detecting security attacks in internet of things. Sci. Rep. 2024, 14, 30275. [Google Scholar] [CrossRef]
- Mahmud, M.Z.; Islam, S.; Alve, S.R.; Jubayer Pial, A. Optimized IoT Intrusion Detection using Machine Learning Technique. In Proceedings of the 2024 IEEE 3rd International Conference on Robotics, Automation, Artificial-Intelligence and Internet-of-Things (RAAICON), Dhaka, Bangladesh, 29–30 November 2024; IEEE: New York, NY, USA, 2024; pp. 167–172. [Google Scholar] [CrossRef]
- Harahsheh, K.; Chen, C.-H. A survey of using machine learning in IoT security and the challenges faced by researchers. Informatica 2023, 47, 1–54. [Google Scholar] [CrossRef]
- Mienye, I.D.; Swart, T.G. A Comprehensive Review of Deep Learning: Architectures, Recent Advances and Applications. Information 2024, 15, 755. [Google Scholar] [CrossRef]
- Amine, M.S.; Nada, F.A.; Hosny, K.M. Improved model for intrusion detection in the Internet of Things. Sci. Rep. 2025, 15, 21547. [Google Scholar] [CrossRef]
- Alsubaei, F.S. Smart deep learning model for enhanced IoT intrusion detection. Sci. Rep. 2025, 15, 20577. [Google Scholar] [CrossRef] [PubMed]
- Lazzarini, R.; Tianfield, H.; Charissis, V. Federated Learning for IoT Intrusion Detection. AI 2023, 4, 509–530. [Google Scholar] [CrossRef]
- Hector, I.; Panjanathan, R. Predictive maintenance in Industry 4.0: A survey of planning models and machine learning techniques. Peerj Comput. Sci. 2024, 10, e2016. [Google Scholar] [CrossRef]
- Ucar, A.; Karakose, M.; Kırımça, N. Artificial Intelligence for Predictive Maintenance Applications: Key Components, Trustworthiness and Future Trends. Appl. Sci. 2024, 14, 898. [Google Scholar] [CrossRef]
- Yousuf, M.; Alsuwian, T.; Amin, A.A.; Fareed, S.; Hamza, M. IoT-based health monitoring and fault detection of industrial AC induction motor for efficient predictive maintenance. Meas. Control 2024, 57, 1146–1160. [Google Scholar] [CrossRef]

| Screening Stage | Papers Remaining | Action/Exclusion Reason |
|---|---|---|
| Initial database search | ∼120,000 | MDPI: ∼12,000; IEEE Xplore: ∼48,000; Nature: ∼9000; ScienceDirect: ∼28,000; SpringerLink: ∼23,000. Searches run independently per database using identical keyword sets; duplicate records arising from cross-indexing removed at the deduplication stage |
| Date filter (January 2023–December 2025) | ∼9500 | Excluded publications outside the 2023–2025 window |
| Deduplication | ∼7200 | Removed duplicate records appearing across multiple databases |
| Title and abstract screening | ∼420 | Retained only papers addressing ML/DL methods for IoT security; excluded generic network security or non-IoT studies |
| Full-text eligibility assessment | ∼90 | Applied inclusion/exclusion criteria (see Section 2.2 and Section 2.3); excluded review papers without novel contributions and studies lacking empirical evaluation on IoT-specific datasets |
| Final included papers | 40 | Primary research studies covering at least one of the four IoT domains (smart home, smart city, healthcare IoT, industrial IoT) with quantified ML performance metrics |
| Domain | Study | ML Approach | Acc. | FPR | Latency | Resource/Energy | Dataset |
|---|---|---|---|---|---|---|---|
| Smart home | Hasan [30] | RF + CTGAN augmentation | 97–100% | N/R | 0.01–0.57 s | 2.73–1510 kB | CICIoT2023 |
| Smart home | Nawaz [35] | XGBoost + feature selection | 99.88% | N/R | N/R | 41 → 18 features | CICIoT2023 |
| Smart home | Wang [33] | CNN-GRU hybrid | 99.39% | N/R | 8 ms/sample | N/R | Custom IoT |
| Smart home | Karakaya [34] | Hybrid classical ML | >99% | N/R | N/R | N/R | NSL-KDD/CIC |
| Smart home | Alabbadi [32] | 1-D CNN + XAI (LIME) | up to 100% | N/R | N/R | N/R | IoT-specific |
| Smart city | Albanbay [31] | Federated CNN (10–150 clients) | 94–98% | N/R | 1.4 ms/sample | RPi 5 (<72 °C) | CICIoT2023 |
| Smart city | Sun [38] | FedMADE (dynamic agg.) | 0.981 | N/R | +4.7% overhead | N/R | CICIDS |
| Smart city | El-Sofany [19] | SVM/classical ML | 94–96% | N/R | N/R | N/R | NSL-KDD |
| Smart city | Rehman [47] | Ensemble ML | ∼97% | N/R | N/R | N/R | Enterprise IoT |
| Healthcare | Naik [39] | CNN-LSTM-VAE + TAC | 0.943 | 3.7% | <160 ms | RPi 5/Jetson Nano | H-IoT |
| Healthcare | Khan [26] | Autoencoder anomaly | >95% | N/R | N/R | N/R | General IoT |
| Healthcare | Karunamurthy [40] | Federated Learning IDS | ∼96% | N/R | N/R | Distributed edge | CIC/custom |
| Industrial | Aljabri [52] | BiGRU + Multi-Head Attention | 98.28–99.74% | N/R | 5.06 s/sample | N/R | CICIDS2018 |
| Industrial | Kilichev [57] | CNN-LSTM-GRU IDS | >98% | N/R | 14,800 s training | GPU only | EVCS |
| Industrial | Kantharaju [58] | SAPGAN/scalable ML | 97–99% | N/R | Real-time capable | N/R | IIoT traffic |
| Industrial | Karthikeyan [55] | Firefly-optimized ensemble | 99.34% | N/R | N/R | N/R | NSL-KDD |
| Industrial | Sagu [54] | GRU-CNN + SUCMO | 96.65–99.1% | N/R | N/R | N/R | UNSW/BoT-IoT |
| Focus Area | Primary Threats | Security Requirements | Optimal ML Paradigm | Accuracy Range | Reported FPR/Latency | Limitations | Key Studies |
|---|---|---|---|---|---|---|---|
| Smart home | DDoS (botnet recruitment), unauthorized access (brute-force), IoT-to-IoT attacks |
| Classical ML (RF, XGBoost) + XAI (SHAP/LIME) | 97–100% | FPR: N/R Latency: 0.01–0.57 s Model: 2.73–1510 kB | Limited to known attacks; cross-device validation gaps | [30,33,35] |
| Smart city | DDoS (infrastructure disruption), large-scale attacks, unauthorized access |
| Federated CNN with robust aggregation (FedMADE) | 94–98% | FPR: N/R Latency: 1.4 ms/sample (RPi 5) | FL maturity gap (22/104 use actual libraries); artificial partitioning | [18,31,38] |
| Healthcare IoT | Data tampering (vital signs), unauthorized device access, DDoS (monitoring disruption) |
| Hybrid CNN-LSTM-VAE + Trust-Aware Controller + XAI | 94–99% ( 0.928–0.943) | FPR: 3.7% [39] Latency: edge-feasible (RPi 5, Jetson Nano) | Medical dataset scarcity; FL privacy proofs absent | [26,39,40] |
| Industrial IoT | APT (19% of breaches), ransomware (24-day downtime), SQL injection, XSS |
| Attention-based (BiGRU-MHA) or Ensemble (CNN-LSTM-GRU) with metaheuristic optimization | 98–100% | FPR: N/R Latency: N/R (training: ∼14,800 s for full ensemble [57]) | OT network validation gap; no reported FPR in most studies | [52,57,58] |
| Technique | Category | Accuracy Range | Training Cost | Inference Latency | Edge Suitable | Key Application |
|---|---|---|---|---|---|---|
| Random Forest | Classical | 99.55–99.88% | Low (32 s) | Low | Yes | DDoS detection [35] |
| Decision Tree | Classical | 99.56% | Low | Very low | Yes | Resource-constrained IDS [49] |
| SVM | Classical | 99.34% | Medium | Medium | Partial | WSN intrusion detection [55] |
| Federated SVM | Classical/FL | Comparable to RF | Low | Low | Partial | Distributed IoT IDS [51] |
| 1-D CNN | Deep | 72–100% | Medium | 0.01–0.57 s | Yes | Traffic classification [32] |
| CNN-GRU | Deep/Hybrid | 99.39% | High | 8 ms | Yes | Smart home IDS [33] |
| CNN-LSTM-GRU | Deep/Hybrid | 96.90–100% | Very high (14,800 s) | Low | GPU only | Multi-class IDS [57] |
| BiGRU-MHA | Deep/Attention | 98.28% | High | 5.06 s | No | IIoT security [52] |
| GRU-CNN+SUCMO | Deep/Hybrid | 96.65% | High | Medium | Partial | IoT anomaly detection [54] |
| Federated CNN | Deep/FL | 94–98% | Medium | 1.4 ms | Yes | Smart city IDS [31] |
| FedMADE | Deep/FL | +71% minority | Medium | +4.7% overhead | Yes | Imbalanced FL-IDS [38] |
| CTGAN+RF | Hybrid | 97–100% | Medium | 0.01–0.57 s | Yes | Augmented IDS [30] |
| SAPGAN | Hybrid/GAN | +18–30% over CNN | Very high | High | No | Data augmentation [58] |
| Dataset | Year | Attack Types | Environment | Used by | Known Limitations |
|---|---|---|---|---|---|
| NSL-KDD | 2009 | DoS, Probe, R2L, U2R | Wired enterprise network | [18,54] | Outdated attacks; no IoT protocols; wired only |
| UNSW-NB15 | 2015 | 9 attack families (Fuzzers, Exploits, etc.) | Synthetic + real network traffic | [54] | Limited IoT relevance; no device heterogeneity |
| BoT-IoT | 2019 | DDoS, DoS, recon, information theft | Simulated IoT network | [54] | Synthetic traffic; limited device types |
| IoT-23 | 2020 | Mirai, Okiru, Torii botnet variants | Real IoT malware captures | [62] | 23 capture scenarios; limited attack diversity |
| TON_IoT | 2020 | 9 attack types | IoT/IIoT testbed with telemetry | [53] | Telemetry + network; moderate scale |
| AWID3 | 2021 | Wi-Fi specific (deauth, evil twin) | 802.11 wireless network | [36] | Single protocol (Wi-Fi); no multi-protocol IoT |
| Edge-IIoTset | 2022 | 14 attack types (DDoS, injection, etc.) | IoT/IIoT edge devices | [52,57] | Laboratory environment; no operational OT traffic |
| CICIoT2023 | 2023 | 33 attack types across 7 categories | 105 real IoT devices | [29,31,38] | Controlled lab; limited duration; no concept drift |
| Study | Domain | Scalability | Energy Efficiency | Real-Time Feasibility | Evidence Basis |
|---|---|---|---|---|---|
| Albanbay [31] | Smart city | H (150 clients tested) | H (<72 °C, RPi 5) | H (1.4 ms/sample) | Hardware-validated FL |
| Sun [38] | Smart city | M (63 simulated clients) | NV | M (+4.7% overhead) | Sim-only partition |
| El-Sofany [19] | Smart city | NV | NV | NV | SDN/NFV concept |
| Naik [39] | Healthcare | NV (single-device study) | M (60% size cut) | H (<160 ms) | Edge-deployed RPi/Jetson |
| Khan [26] | Healthcare | NV | NV | NV | Lab-only autoencoder |
| Karunamurthy [40] | Healthcare | M (FL distributed) | NV | NV | Distributed-edge claim |
| Hasan [30] | Smart home | NV | M (compact 2.73 kB) | H (0.01–0.57 s) | Edge-feasible profile |
| Nawaz [35] | Smart home | NV | H (32 s training, 18 features) | H (low-cost RF inference) | Resource-profiled |
| Wang [33] | Smart home | NV | M (8 ms suggests low cost) | H (8 ms/sample) | Latency only |
| Aljabri [52] | Industrial | NV | L (5.06 s/sample) | L (5.06 s/sample) | Lab-only |
| Kilichev [57] | Industrial | NV | L (14,800 s training) | M (binary inference fast) | GPU only |
| Sagu [54] | Industrial | NV | NV | NV | Static benchmark |
| Domain | Predominant Paradigm | Representative Accuracy Range | Primary Deployability Constraint | Core Performance–Deployability Trade-Off |
|---|---|---|---|---|
| Smart home | Classical ML + XAI (SHAP/LIME) | 97.2–100% | Computational resources (model size 2.73–1510 kB) | Smallest models enable edge deployment but sacrifice F1 on minority classes; explainability adds minimal overhead |
| Smart city | Federated Learning (SVM, CNN, dynamic aggregation) |
| Communication overhead, data heterogeneity, non-IID distribution | Privacy preservation versus accuracy on minority attack classes; lightweight CNN offers best accuracy-efficiency trade-off on real hardware (RPi 5) |
| Healthcare IoT | Hybrid multi-objective DL (CNN+LSTM+VAE) | 94.3–99.55% | Regulatory compliance, real-time requirements, multi-objective optimization | Feature reduction preserves accuracy while cutting latency; edge deployment (RPi, Jetson Nano) feasible but requires architectural complexity |
| Industrial IoT | Attention + ensemble + metaheuristic optimization | 98.28–99.74% | Adversarial robustness, generalizability across datasets | Metaheuristic feature selection reduces input dimensionality (to 4–9 features) while maintaining >98% accuracy; attention mechanisms add robustness but increase model complexity |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Georgian, I.; Zamfirel, T.A.; Goga, N.; Crăciunescu, R. A Survey of Machine Learning Approaches to IoT Security. Algorithms 2026, 19, 384. https://doi.org/10.3390/a19050384
Georgian I, Zamfirel TA, Goga N, Crăciunescu R. A Survey of Machine Learning Approaches to IoT Security. Algorithms. 2026; 19(5):384. https://doi.org/10.3390/a19050384
Chicago/Turabian StyleGeorgian, Iosef, Teșulă Adrian Zamfirel, Nicolae Goga, and Răzvan Crăciunescu. 2026. "A Survey of Machine Learning Approaches to IoT Security" Algorithms 19, no. 5: 384. https://doi.org/10.3390/a19050384
APA StyleGeorgian, I., Zamfirel, T. A., Goga, N., & Crăciunescu, R. (2026). A Survey of Machine Learning Approaches to IoT Security. Algorithms, 19(5), 384. https://doi.org/10.3390/a19050384

