Performance Assessment of DL for Network Intrusion Detection on a Constrained IoT Device
Abstract
1. Introduction
- Insecure communication: data transmission by IoT devices may occur without adequate encryption, enabling attackers to intercept or manipulate communication [13].
- Lack of device identity management: the absence of robust Identity Management mechanisms complicates the verification of a device’s authenticity, creating potential security gaps in IoT networks.
- Insufficient authentication and authorization: many IoT devices lack strong authentication and authorization protocols, allowing unauthorized individuals to access sensitive data or control devices.
- Resource-constrained IDS design for IoT nodes: We propose an AI-based IDS specifically tailored for deployment on resource-constrained IoT devices, further validated on a STM32H7S78-DK board to address realistic embedded constraints.
- Comprehensive evaluation on a large-scale, highly imbalanced IoT dataset: The considered IDS is evaluated using the CICIoT2023 dataset, comprising over 46 M network traffic records collected from 105 IoT devices and featuring 34 distinct attack types (including DoS, DDoS, spoofing, brute-force, Mirai botnet attacks, etc.).
- Systematic handling of class imbalance: A hybrid data balancing strategy, combining random undersampling and random oversampling, is introduced to mitigate the severe imbalance between benign and malicious traffic traces, improving model generalization while avoiding excessive training time and overfitting.
- Multi-granularity attack classification analysis: Three dataset configurations—namely, binary (2-class), grouped (8-class), and fine-grained (34-class)—are considered, enabling a thorough analysis of the trade-offs between detection accuracy, computational cost, and deployability on a constrained hardware (HW).
- Feature selection driven by statistical relevance: A one-way ANOVA-based feature ranking is employed to identify and retain the most important features, reducing input dimensionality and computational complexity while preserving essential attack-related correlations.
- Bayesian optimization for HW-aware hyperparameter tuning: The performance of DL models is enhanced through BO, allowing an efficient exploration of the hyperparameter space while balancing accuracy and computational cost.
- End-to-end HW-aware evaluation and deployment: Models are evaluated in terms of Multiply–Accumulate operations (MACCs), RAM usage, and inference latency using the STM Cube.AI Analyzer, ensuring practical deployability on a constrained IoT board.
- Quantization-enabled efficiency enhancement: In order to reduce computational complexity and memory footprint, 8-bit integer quantization of weights and activations is applied, improving inference efficiency while maintaining competitive detection accuracy on the STM32H7S78-DK board.
2. Related Works
2.1. ML/DL Models for IoT NIDS on CICIoT2023
2.2. TinyML for Intrusion Detection
3. Vulnerabilities in IoT Architectures
3.1. IoT Layers
- Perception Layer: This layer, also known as sensing layer, corresponds to the lowest layer in an IoT architecture and consists of physical devices—such as sensors, actuators, and smart appliances—directly interacting with the environment to collect and process real-time data.
- Network Layer Inside an IoT domain, this layer manages the connectivity and the data transmission between IoT devices, gateways, and the higher layers, thus exploiting an ensemble of communication protocols (e.g., Zigbee, BLE, IEEE 802.11 Wi-Fi, LTE/5G cellular, LoRaWAN) to support seamless information transfer across the IoT ecosystem.
- Middleware Layer: This layer acts as an intermediate layer between network and application layers and provides essential services such as data filtering, aggregation, and protocol translation, thus ensuring interoperability and easing efficient management and deployment of IoT applications.
- Application Layer: This layer enables specific use cases by delivering services and insights to end-users and additional applications, in detail directly interfacing with the users and providing an ecosystem for the deployment of IoT applications (e.g., smart homes, healthcare, and industrial automation).
3.2. IoT Security Vulnerabilities
3.2.1. Active and Passive Attacks
- Active attack: it refers to a type of security attack wherein the attacker engages in direct communication with the intended target system or network. This attack involves the deliberate alteration or disruption of a network’s operations through the injection of malicious traffic or the execution of unauthorized commands.
- Passive attack: it is classified as a security attack wherein the attacker establishes an indirect connection with the target network and observes the communication occurring therein. In this case, an assailant would observe, intercept, or surreptitiously listen to data transfers without making any modifications or exerting any influence over the information, thus primarily aiming to illegally obtain access to sensitive or secret data or information without raising suspicion or detection.
3.2.2. Attacks to the Perception Layer
- Tampering: This attack aims at creating a direct physical connection with the IoT device and controlling its operational tasks, then involving HW manipulation (e.g., establishing connections with ports or interfaces on the device) or modifications to its settings [35].
- DoS: This attack foresees an attacker flooding the IoT sensors with an extraordinary volume of traffic or requests, leading to sensor overload, data loss, and service disruption [36].
- Jamming: This corresponds to a deliberate attack strategy disrupting or obstructing wireless communication signals, thus preventing information transmission [37].
- Fake node injection: This is one of the most severe attacks for an IoT device, since it features a malicious node to be injected into an IoT network to gain access to such network, then spreading misleading information across the network itself. Consequently, unauthorized nodes will enable an attacker to access the entire network.
- Sleep deprivation attack: This attack aims at affecting the energy source of (often battery-powered) sensor nodes. In fact, this attack keeps IoT nodes active by altering their sleep cycle—usually employed to minimize their energy consumption—and, consequently, their functionalities, quickly depleting and disrupting the overall IoT network [38].
3.2.3. Attacks to the Network Layer
- Routing attacks: This attack focuses on altering the routes established in the IoT network, thus aiming at transmitting data and messages to malicious intermediary nodes, or interfering with the network’s data transmission process.
- IP Spoofing: This attack features a malicious node posing as another device or changing the origin IP address inside the packets flowing inside the network itself to tamper with the IoT network and gain unauthorized access.
- Sybil attack: This attack foresees that the attacker will try to access the network by using a phony identity, in turn also activating fake nodes as normal devices within the network and impairing the network’s operation by creating incorrect and/or large amounts of information [39].
- Traffic analysis attack: This attack targets to analyze and intercept data packets exchanged intra IoT nodes, as well as between IoT devices and remote entities, in order to extract valuable information.
3.2.4. Attacks to the Middleware Layer
- Man-in-the-Middle (MITM) attack: This attack foresees the ability of an unauthorized entity to intercept (and potentially manipulate) the communication occurring between IoT devices.
- Malwares: Threats like viruses, Trojan horses, and malware represent a (sub-)set of tools used by attackers to access (in an unauthorized way) undisclosed and private information, with data theft happening by exploiting executable codes (often developed in machine language).
- DoS attack: This class of intrusion foresees an attacker overwhelming the IoT network with a heavy amount of requests, thus resulting in the network’s congestion due to excessive traffic. As a result, IoT devices deplete energy and resources, thus preventing the user from accessing his/her data.
3.2.5. Attacks to the Application Layer
- Cross-Site Scripting (XSS): In this type of attack, the attacker adds harmful scripts to be run (at run-time) into the IoT node’s command-line or Web interfaces, thus compromising its responsiveness as well as the user’s protected information.
- SQL injection: This attack occurs when the attacker succeeds in manipulating the input parameters used in an SQL query and in executing such malicious SQL queries into the target database.
- Sniffing attack: This attack involves the ability of the attacker to successfully collect and monitor the data traffic between IoT devices and the services at the application layer, thus handling and controlling them without any authorized permission.
4. Proposed Model
4.1. Dataset
4.1.1. Data Balancing
4.1.2. Data Normalization
4.1.3. Feature Selection
- 2-class dataset: rst count, urg count, Variance, Flow duration, Std, Radius, Covariance, Header Length, Max, ack flag number, AVG, Magnitude, HTTPS, Tot size.
- 8-class dataset: Variance, RST count, URG count, Std, Radius, Magnitude, AVG, Tot size, Max, Min, Covariance, Protocol type, Flow duration, Header Length, Tot sum, ack flag number.
- 34-class dataset: ICMP, fin flag number, Protocol Type, Variance, Header Length, syn flag number, rst count, Magnitude, AVG, Radius, Std, urg count, Min, Tot size, Max, Covariance, rst flag number, syn count, flow duration, TCP, psh flag number, Tot sum, UDP, fin count, ack flag number, ack count.
4.2. Hyperparammeter Optimization
4.3. Model Training
4.3.1. SimpleRNN
4.3.2. Long Short-Term Memory (LSTM)
4.3.3. Gated Recurrent Unit (GRU) and Bidirectional GRU
4.3.4. Multi-Layer Perceptron (MLP)
4.3.5. 1-Dimensional CNN (1D-CNN)
4.3.6. Temporal Convolutional Network (TCN)
4.4. Evaluation Metrics
4.4.1. Accuracy
4.4.2. Precision
4.4.3. Recall
4.4.4. F1-Score
4.4.5. Matthews Correlation Coefficient (MCC)
4.4.6. Cohen’s Kappa Coefficient
4.4.7. Receiver Operating Characteristic (ROC) Curve and Area Under Curve (AUC)
4.5. Model Complexity
5. Results
- The selected performance metrics are: accuracy , precision , recall , F1-Score , MCC , and Cohen’s Kappa Coefficient .
- The selected complexity evaluation metrics are: number of MACCs, RAM usage, and inference time.
5.1. Network Traffic Classification Performance
5.2. Post-Training Quantization (PTQ)
5.3. Accuracy-Computational Complexity Trade-Off
5.3.1. Metrics Normalization
5.3.2. Efficiency Score Computation
5.3.3. Trade-Off Score
5.4. Deployment on Resource-Constrained Devices
- smul_f32_f32 performs a scalar multiplication between two FP32 values;
- op_f32_f32 represents a generic operation—such as addition, activation, or normalization—applied to FP32 data;
- smul_s8_s8 and op_s8_s8 perform, adopting signed INT8 data types, the same operations operated by MACCs 1 and 2;
- smul_s8_f32 and smul_f32_s8 perform conversions from signed INT8 to FP32 and vice versa.
- As indicated by the operations’ breakdown, the bulk of the computation still relies on FP32 multiplications (namely, ), with several conversion layers having to be added before and after convolutional and element-wise operations (e.g., and ).
- Each additional layer requires temporary buffers to store intermediate activations in both FP32 and INT8 formats: this drastically increases the RAM consumption at runtime, and in the worst case, the device has insufficient internal RAM, temporary buffers have to be stored into external RAM, and the performance degrades much more.
- Each quantized layer needs to store its scale and zero-point parameters for proper rescaling between quantized tensors: this results in the need to add metadata that partially hinders the expected flash memory reduction. Moreover, as discussed for RAM, in the case of insufficient internal flash memory, an external memory should be used, further degrading the performance.
5.5. Quantized Models Accuracy-Computational Complexity Trade-Off
5.6. Limitations of the Proposed Work
- Quantization support for complex architectures: While MLP models can be fully quantized to INT8 with minimal impact on performance, TCN architectures suffer from incomplete quantization due to the presence of dilated convolutions and dynamic padding. This leads to increased RAM usage (up to ) and inference time (up to ) despite significant reductions in model size.
- Trade-off between accuracy and computational efficiency: Although quantization reduces model size and flash usage, the accuracy of fully quantized MLP models decreases slightly (average drop ), highlighting the trade-off between resource efficiency and detection performance, in particular for multi-class () scenarios.
- Scope of the evaluation: The study focuses on a single constrained platform (STM32H7S78-DK) and FP32-to-INT8 quantization schemes. Results may differ on alternative HW platforms, bit-widths, or DL frameworks, limiting the generality of the deployment conclusions.
6. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
Abbreviations
| 1D-CNN | One-dimensional Convolutional Neural Network |
| AUC | Area Under Curve |
| DDoS | Distributed DoS |
| DL | Deep Learning |
| DNN | Deep Neural Network |
| DoS | Denial of Service |
| DT | Decision Tree |
| FFN | FeedForward Network |
| FL | Federated Learning |
| GRU | Gated Recurrent Unit |
| HPO | Hyper-Parameter Optimization |
| IDS | Intrusion Detection System |
| IoT | Internet of Things |
| LGBM | Light Gradient Boosting Machine |
| LSTM | Long Short-Term Memory |
| MACC | Multiply–ACCumulate operation |
| MCC | Matthews Correlation Coefficient |
| MITM | Man-in-the-Middle |
| ML | Machine Learning |
| MLP | Multi-Layer Perceptron |
| NLP | Natural Language Processing |
| PTQ | Post-Training Quantization |
| ReLU | REctified Linear Unit |
| RF | Random Forest |
| ROC | Receiver Operating Characteristic |
| SDN | Software-Defined Networking |
| SGD | Stochastic Gradient Descent |
| SimpleRNN | Simple Recurrent Neural Network |
| SMOTE | Synthetic Minority Oversampling Technique |
| SVM | Support Vector Machine |
| TCN | Temporal Convolutional Network |
| TFlite | TensorFlow Lite |
| XSS | Cross-Site Scripting |
Appendix A. Confusion Matrices of the Considered DL Models

| Class | Label | Class | Label |
|---|---|---|---|
| Attack | 0 | Benign | 1 |

| Class | Label | Class | Label | Class | Label |
|---|---|---|---|---|---|
| Benign | 0 | DoS | 3 | Spoofing | 6 |
| Brute Force | 1 | Mirai | 4 | Web-based | 7 |
| DDoS | 2 | Reconnaissance | 5 |






| Class | Label | Class | Label | Class | Label |
|---|---|---|---|---|---|
| Benign | 0 | DDoS-SynonymousIP Flood | 12 | Mirai-greeth flood | 23 |
| Backdoor Malware | 1 | DDoS-TCP Flood | 13 | Mirai-greip flood | 24 |
| Browser Hijacking | 2 | DDoS-UDP Flood | 14 | Mirai-udpplain | 25 |
| Command Injection | 3 | DDoS-UDP Fragmentation | 15 | Recon-Host Discovery | 26 |
| DDoS-ACK Fragmentation | 4 | DNS Spoofing | 16 | Recon-OS Scan | 27 |
| DDoS-HTTP Flood | 5 | Dictionary Brute Force | 17 | Recon-Ping Sweep | 28 |
| DDoS-ICMP Flood | 6 | DoS-HTTP Flood | 18 | Recon-Port Scan | 29 |
| DDoS-ICMP Fragmentation | 7 | DoS-SYN Flood | 19 | SQL Injection | 30 |
| DDoS-PSHACK Flood | 8 | DoS-TCP Flood | 20 | Uploading Attack | 31 |
| DDoS-RSTFIN Flood | 9 | DoS-UDP Flood | 21 | Vulnerability Scan | 32 |
| DDoS-SYN Flood | 10 | MITMArp Spoofing | 22 | XSS | 33 |
| DDoS-SlowLoris | 11 |
References
- Rejeb, A.; Suhaiza, Z.; Rejeb, K.; Seuring, S.; Treiblmaier, H. The Internet of Things and the Circular Economy: A Systematic Literature Review and Research Agenda. J. Clean. Prod. 2022, 350, 131439. [Google Scholar] [CrossRef] [Scilit]
- Hirsch, C.; Davoli, L.; Grosu, R.; Ferrari, G. DynGATT: A Dynamic GATT-based Data Synchronization Protocol for BLE Networks. Comput. Netw. 2023, 222, 109560. [Google Scholar] [CrossRef] [Scilit]
- Davoli, L.; Belli, L.; Cilfone, A.; Ferrari, G. Integration of Wi-Fi Mobile Nodes in a Web of Things Testbed. ICT Express 2016, 2, 95–99. [Google Scholar] [CrossRef] [Scilit]
- Pagliari, E.; Davoli, L.; Ferrari, G. Harnessing Communication Heterogeneity: Architectural Design, Analytical Modeling, and Performance Evaluation of an IoT Multi-Interface Gateway. IEEE Internet Things J. 2024, 11, 8030–8051. [Google Scholar] [CrossRef] [Scilit]
- Premalatha, B.; Prakasam, P. A Review on FoG Computing in 5G Wireless Technologies: Research Challenges, Issues and Solutions. Wirel. Pers. Commun. 2024, 134, 2455–2484. [Google Scholar] [CrossRef] [Scilit]
- Salsano, S.; Veltri, L.; Davoli, L.; Ventre, P.L.; Siracusano, G. PMSR–Poor Man’s Segment Routing, a Minimalistic Approach to Segment Routing and a Traffic Engineering Use Case. In Proceedings of the 2016 IEEE/IFIP Network Operations and Management Symposium (NOMS), Istanbul, Turkey, 25–29 April 2016; pp. 598–604. [Google Scholar] [CrossRef] [Scilit]
- Zikria, Y.B.; Ali, R.; Afzal, M.K.; Kim, S.W. Next-Generation Internet of Things (IoT): Opportunities, Challenges, and Solutions. Sensors 2021, 21, 1174. [Google Scholar] [CrossRef] [Scilit]
- Belli, L.; Cirani, S.; Davoli, L.; Ferrari, G.; Melegari, L.; Picone, M. Applying Security to a Big Stream Cloud Architecture for the Internet of Things. Int. J. Distrib. Syst. Technol. (IJDST) 2016, 7, 37–58. [Google Scholar] [CrossRef] [Scilit]
- Heidari, A.; Jabraeil Jamali, M.A. Internet of Things Intrusion Detection Systems: A Comprehensive Review and Future Directions. Clust. Comput. 2022, 26, 3753–3780. [Google Scholar] [CrossRef] [Scilit]
- Jiang, X.; Lora, M.; Chattopadhyay, S. An Experimental Analysis of Security Vulnerabilities in Industrial IoT Devices. ACM Trans. Internet Technol. 2020, 20, 16. [Google Scholar] [CrossRef] [Scilit]
- Bertino, E.; Islam, N. Botnets and Internet of Things Security. Computer 2017, 50, 76–79. [Google Scholar] [CrossRef] [Scilit]
- Khan, M.A.; Salah, K. IoT Security: Review, Blockchain Solutions, and Open Challenges. Future Gener. Comput. Syst. 2018, 82, 395–411. [Google Scholar] [CrossRef] [Scilit]
- Davoli, L.; Protskaya, Y.; Veltri, L. An Anonymization Protocol for the Internet of Things. In Proceedings of the 2017 International Symposium on Wireless Communication Systems (ISWCS), Bologna, Italy, 28–31 August 2017; pp. 459–464. [Google Scholar] [CrossRef] [Scilit]
- Asharf, J.; Moustafa, N.; Khurshid, H.; Debie, E.; Haider, W.; Wahab, A. A Review of Intrusion Detection Systems Using Machine and Deep Learning in Internet of Things: Challenges, Solutions and Future Directions. Electronics 2020, 9, 1177. [Google Scholar] [CrossRef] [Scilit]
- Neto, E.C.P.; Dadkhah, S.; Ferreira, R.; Zohourian, A.; Lu, R.; Ghorbani, A.A. CICIoT2023: A Real-Time Dataset and Benchmark for Large-Scale Attacks in IoT Environment. Sensors 2023, 23, 5941. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- STMicroelectronics. Discovery Kit with STM32H7S7L8 MCU. Available online: https://www.st.com/en/evaluation-tools/stm32h7s78-dk.html (accessed on 1 January 2026).
- Abbas, S.; Bouazzi, I.; Ojo, S.; Al Hejaili, A.; Sampedro, G.A.; Almadhor, A.; Gregus, M. Evaluating Deep Learning Variants for Cyber-Attacks Detection and Multi-Class Classification in IoT Networks. Peerj Comput. Sci. 2024, 10, e1793. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Abbas, S.; Al Hejaili, A.; Sampedro, G.A.; Abisado, M.; Almadhor, A.S.; Shahzad, T.; Ouahada, K. A Novel Federated Edge Learning Approach for Detecting Cyberattacks in IoT Infrastructures. IEEE Access 2023, 11, 112189–112198. [Google Scholar] [CrossRef] [Scilit]
- Vajrobol, V.; Gupta, B.B.; Gaurav, A.; Chuang, H.M. Adversarial Learning for Mirai Botnet Detection based on Long Short-Term Memory and XGBoost. Int. J. Cogn. Comput. Eng. 2024, 5, 153–160. [Google Scholar] [CrossRef] [Scilit]
- Gharaibeh, H.; Aljaidi, M.; Nasayreh, A.; Al-Na’amneh, Q.; Jaradat, A.S.; Samara, G.; Al Mamlook, R.E. Deep Feature Extraction Framework Based on DNN for Enhancing Mirai Attachment Classification in Machine Learning. In Proceedings of the 2023 2nd International Engineering Conference on Electrical, Energy, and Artificial Intelligence (EICEEAI), Zarqa, Jordan, 27–28 December 2023; pp. 1–5. [Google Scholar] [CrossRef] [Scilit]
- Becerra-Suarez, F.L.; Tuesta-Monteza, V.A.; Mejia-Cabrera, H.I.; Arcila-Diaz, J. Performance Evaluation of Deep Learning Models for Classifying Cybersecurity Attacks in IoT Networks. Informatics 2024, 11, 32. [Google Scholar] [CrossRef] [Scilit]
- Aguru, A.D.; Erukala, S.B. A Lightweight Multi-Vector DDoS Detection Framework for IoT-enabled Mobile Health Informatics Systems using Deep Learning. Inf. Sci. 2024, 662, 120209. [Google Scholar] [CrossRef] [Scilit]
- Kumar, A.G.; Rastogi, A.; Ranga, V. Evaluation of Different Machine Learning Classifiers on New IoT Dataset CICIoT2023. In Proceedings of the 2024 International Conference on Intelligent Systems for Cybersecurity (ISCS), Gurugram, India, 3–4 May 2024; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
- Diab, A.; Chehade, A.; Ragusa, E.; Gastaldo, P.; Zunino, R.; Baghdadi, A.; Rizk, M. Intrusion Detection on Resource-Constrained IoT Devices with Hardware-Aware ML and DL. arXiv 2025, arXiv:2512.02272. [Google Scholar]
- Saxe, J.; Berlin, K. Deep Neural Network based Malware Detection using Two Dimensional Binary Program Features. In Proceedings of the 2015 10th International Conference on Malicious and Unwanted Software (MALWARE), Fajardo, PR, USA, 20–22 October 2015; pp. 11–20. [Google Scholar] [CrossRef] [Scilit]
- The Imbalanced-Learn Developers. RandomOverSampler. Available online: https://imbalanced-learn.org/stable/references/generated/imblearn.over_sampling.RandomOverSampler.html (accessed on 1 January 2026).
- Thapa, S.; Poudel, S.; Abouyoussef, M. TinyML-Enabled Intrusion Detection for Securing Electric Vehicle Supply Equipment (EVSE). In Proceedings of the 2025 1st International Conference on Secure IoT, Assured and Trusted Computing (SATC), Dayton, OH, USA, 25–27 February 2025; pp. 1–5. [Google Scholar] [CrossRef] [Scilit]
- Buedi, E.D.; Ghorbani, A.A.; Dadkhah, S.; Ferreira, R.L. Enhancing EV Charging Station Security Using a Multi-dimensional Dataset: CICEVSE2024. In Proceedings of the Data and Applications Security and Privacy XXXVIII, San Jose, CA, USA, 15–17 July 2024; pp. 171–190. [Google Scholar] [CrossRef] [Scilit]
- Arcot, S.; Masum, M.; Kader, M.S.; Saha, A.; Chowdhury, M. TinyML for Cybersecurity: Deploying Optimized Deep Learning Models for On-Device Threat Detection on Resource-Constrained Devices. In Proceedings of the 2024 IEEE International Conference on Big Data (BigData), Washington, DC, USA, 15–18 December 2024; pp. 5542–5550. [Google Scholar] [CrossRef] [Scilit]
- Wang, W.; Zhu, M.; Zeng, X.; Ye, X.; Sheng, Y. Malware Traffic Classification using Convolutional Neural Network for Representation Learning. In Proceedings of the 2017 International Conference on Information Networking (ICOIN), Da Nang, Vietnam, 11–13 January 2017; pp. 712–717. [Google Scholar] [CrossRef] [Scilit]
- Ke, G.; Meng, Q.; Finley, T.; Wang, T.; Chen, W.; Ma, W.; Ye, Q.; Liu, T.Y. LightGBM: A Highly Efficient Gradient Boosting Decision Tree. In Proceedings of the 31st International Conference on Neural Information Processing Systems, Long Beach, CA, USA, 4–9 December 2017; pp. 3149–3157. [Google Scholar] [CrossRef]
- Ferrag, M.A.; Friha, O.; Hamouda, D.; Maglaras, L.; Janicke, H. Edge-IIoTset: A New Comprehensive Realistic Cyber Security Dataset of IoT and IIoT Applications for Centralized and Federated Learning. IEEE Access 2022, 10, 40281–40306. [Google Scholar] [CrossRef] [Scilit]
- Sharma, A.; Rani, S.; Shabaz, M. An Optimized Stacking-Based TinyML Model for Attack Detection in IoT Networks. PLoS ONE 2025, 20, e0329227. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Booij, T.M.; Chiscop, I.; Meeuwissen, E.; Moustafa, N.; Den Hartog, F.T. ToN_IoT: The Role of Heterogeneity and the Need for Standardization of Features and Attack Types in IoT Network Intrusion Data Sets. IEEE Internet Things J. 2022, 9, 485–496. [Google Scholar] [CrossRef] [Scilit]
- Sengupta, J.; Ruj, S.; Das Bit, S. A Comprehensive Survey on Attacks, Security Issues and Blockchain Solutions for IoT and IIoT. J. Netw. Comput. Appl. 2020, 149, 102481. [Google Scholar] [CrossRef] [Scilit]
- Syed, N.F.; Baig, Z.; Ibrahim, A.; Valli, C. Denial of Service Attack Detection through Machine Learning for the IoT. J. Inf. Telecommun. 2020, 4, 482–503. [Google Scholar] [CrossRef] [Scilit]
- Pirayesh, H.; Kheirkhah Sangdeh, P.; Zeng, H. Securing ZigBee Communications Against Constant Jamming Attack Using Neural Network. IEEE Internet Things J. 2021, 8, 4957–4968. [Google Scholar] [CrossRef] [Scilit]
- Balueva, A.; Desnitsky, V.; Ushakov, I. Approach to Detection of Denial-of-Sleep Attacks in Wireless Sensor Networks on the Base of Machine Learning. In Studies in Computational Intelligence; Springer International Publishing: Berlin/Heidelberg, Germany, 2019; pp. 350–355. [Google Scholar] [CrossRef] [Scilit]
- Yan, J.; Jiang, T.; Lin, L.; Wu, Z.; Ye, X.; Tian, M.; Wang, Y. A Novel Sybil Attack Detection Scheme in Mobile IoT based on Collaborate Edge Computing. EURASIP J. Wirel. Commun. Netw. 2023, 2023, 25. [Google Scholar] [CrossRef] [Scilit]
- The Imbalanced-Learn Developers. RandomUnderSampler. Available online: https://imbalanced-learn.org/stable/references/generated/imblearn.under_sampling.RandomUnderSampler.html (accessed on 1 January 2026).
- Scikit-Learn. PowerTransformer. Available online: https://scikit-learn.org/stable/modules/generated/sklearn.preprocessing.PowerTransformer.html (accessed on 1 January 2026).
- SciPy Core Developer. One-Way ANOVA Tests. Available online: https://docs.scipy.org/doc/scipy/reference/generated/scipy.stats.f_oneway.html (accessed on 1 January 2026).
- Keras Google Group. KerasTuner. Available online: https://keras.io/keras_tuner/ (accessed on 1 January 2026).
- Keras Google Group. ReLU layer. Available online: https://keras.io/api/layers/activation_layers/relu/ (accessed on 1 January 2026).
- Keras Google Group. Layer Activation Functions—Softmax. Available online: https://keras.io/api/layers/activations/#softmax-function (accessed on 1 January 2026).
- Alsadi, N.; Gadsden, S.A.; Yawney, J. Intelligent Estimation: A Review of Theory, Applications, and Recent Advances. Digit. Signal Processing 2023, 135, 103966. [Google Scholar] [CrossRef] [Scilit]
- Zhang, J.; Man, K. Time Series Prediction using RNN in Multi-Dimension Embedding Phase Space. In Proceedings of the 1998 IEEE International Conference on Systems, Man, and Cybernetics (SMC), San Diego, CA, USA, 11–14 October 1998; Volume 2, pp. 1868–1873. [Google Scholar] [CrossRef] [Scilit]
- Al-Selwi, S.M.; Hassan, M.F.; Abdulkadir, S.J.; Muneer, A. LSTM Inefficiency in Long-Term Dependencies Regression Problems. J. Adv. Res. Appl. Sci. Eng. Technol. 2023, 30, 16–31. [Google Scholar] [CrossRef] [Scilit]
- Khandelwal, S.; Lecouteux, B.; Besacier, L. Comparing GRU and LSTM for Automatic Speech Recognition; Research Report; LIG: Saint-Martin-d’Hères, France, 2016; Available online: https://hal.science/hal-01633254 (accessed on 1 January 2026).
- Kurt, I.; Ture, M.; Kurum, A.T. Comparing Performances of Logistic Regression, Classification and Regression Tree, and Neural Networks for Predicting Coronary Artery Disease. Expert Syst. Appl. 2008, 34, 366–374. [Google Scholar] [CrossRef] [Scilit]
- Zhao, B.; Lu, H.; Chen, S.; Liu, J.; Wu, D. Convolutional Neural Networks for Time Series Classification. J. Syst. Eng. Electron. 2017, 28, 162–169. [Google Scholar] [CrossRef] [Scilit]
- Mazinani, A.; Davoli, L.; Ferrari, G. Deep Learning Algorithms for Cryptocurrency Price Prediction: A Comparative Analysis. Distrib. Ledger Technol. Res. Pract. 2025, 4, 1–38. [Google Scholar] [CrossRef] [Scilit]
- McHugh, M.L. Interrater Reliability: The Kappa Statistic. Biochem. Medica 2012, 22, 276–282. [Google Scholar] [CrossRef] [Scilit]
- Abadi, M.; Agarwal, A.; Barham, P.; Brevdo, E.; Chen, Z.; Citro, C.; Corrado, G.S.; Davis, A.; Dean, J.; Devin, M.; et al. TensorFlow: Large-Scale Machine Learning on Heterogeneous Distributed Systems. arXiv 2016, arXiv:1603.04467. [Google Scholar] [CrossRef] [Scilit]
- Wu, J.; Leng, C.; Wang, Y.; Hu, Q.; Cheng, J. Quantized Convolutional Neural Networks for Mobile Devices. In Proceedings of the 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Los Alamitos, CA, USA, 27–30 June 2016; pp. 4820–4828. [Google Scholar] [CrossRef] [Scilit]
- Mazinani, A.; Davoli, L.; Pau, D.P.; Ferrari, G. Air Quality Estimation with Embedded AI-Based Prediction Algorithms. In Proceedings of the 2023 International Conference on Information Technology Research and Innovation (ICITRI), Jakarta, Indonesia, 16 August 2023; pp. 87–92. [Google Scholar] [CrossRef] [Scilit]
- STMicroelectronics. STM32Cube.AI (X-CUBE-AI v10.0)—Free AI Model Optimizer for STM32. Available online: https://stm32ai.st.com/stm32-cube-ai (accessed on 1 January 2026).
- Burrello, A.; Dequino, A.; Pagliari, D.J.; Conti, F.; Zanghieri, M.; Macii, E.; Benini, L.; Poncino, M. TCN Mapping Optimization for Ultra-Low Power Time-Series Edge Inference. In Proceedings of the 2021 IEEE/ACM International Symposium on Low Power Electronics and Design (ISLPED), Newport Beach, CA, USA, 5–7 August 2021; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]







| Ref. | Model (s) | Feature Selection | Data Balancing | Hyperparameter Tuning | IoT Deployability Assessment | Quantization |
|---|---|---|---|---|---|---|
| [17] | RNN | ✗ | ✗ | ✗ | ✗ | ✗ |
| [15] | RF | ✗ | ✗ | ✗ | ✗ | ✗ |
| [18] | Federated Learning | ✗ | ✓ | ✗ | ✗ | ✗ |
| [19] | LSTM+XGBoost | ✗ | ✗ | ✗ | ✗ | ✗ |
| [20] | DNN+LGBM | ✗ | ✗ | ✗ | ✗ | ✗ |
| [21] | CNN | ✓ | ✗ | ✗ | ✗ | ✗ |
| [22] | Modified GRU | ✓ | ✗ | ✗ | ✗ | ✗ |
| [23] | RF | ✗ | ✗ | ✗ | ✗ | ✗ |
| [24] | 1D-CNN | ✓ | ✗ | ✓ | ✓ | ✗ |
| Proposed Model | TCN | ✓ | ✓ | ✓ | ✓ | ✓ |
| Layer | Attack Type | Description |
|---|---|---|
| Perception Layer | Tampering | Physically accessing and controlling IoT HW or altering settings. |
| DoS | Overwhelming IoT sensors with traffic, causing data loss and service disruption. | |
| Jamming | Interfering with wireless communication (e.g., Wi-Fi, Bluetooth), blocking data transmission. | |
| Fake node injection | Adding unauthorized nodes to spread false information across the network. | |
| Sleep deprivation | Keeping sensor nodes active to deplete battery power and disrupt network operations. | |
| Network Layer | Routing attacks | Altering network paths to redirect data to malicious nodes or disrupt communication. |
| IP spoofing | Using falsified IP addresses to impersonate trusted devices. | |
| Sybil attack | Creating fake identities to generate incorrect data and disrupt network functionality. | |
| Traffic analysis | Intercepting data packets to extract valuable information. | |
| Middleware Layer | MitM | Intercepting and potentially manipulating communication between IoT devices and middleware. |
| Malware | Using malicious software like viruses or Trojans to access sensitive information. | |
| DoS | Overloading the network with data, consuming resources and preventing legitimate access. | |
| Application Layer | XSS | Embedding malicious scripts into an IoT platform interface, compromising data and device functionality. |
| SQL injection | Executing unauthorized SQL commands by altering input data in database queries. | |
| Sniffing attack | Monitoring data traffic between IoT devices and application services without permission. |
| Feature | Description | Feature | Description |
|---|---|---|---|
| ts | Timestamp | SMTP | Indicates if the app. layer protocol is SMTP |
| flow duration | Duration of the packet’s flow | SSH | Indicates if the app. layer protocol is SSH |
| Header Length | Header length | IRC | Indicates if the app. layer protocol is IRC |
| Protocol Type | IP, UDP, TCP, IGMP, ICMP, Unknown (Integers) | TCP | Indicates if the transport layer protocol is TCP |
| Duration | Time-to-Live (TTL) | UDP | Indicates if the transport layer protocol is UDP |
| Rate | Rate of packet transmission in a flow | DHCP | Indicates if the app. layer protocol is DHCP |
| Srate | Rate of outbound packets transmission in a flow | ARP | Indicates if the link layer protocol is ARP |
| Drate | Rate of inbound packets transmission in a flow | ICMP | Indicates if the network layer protocol is ICMP |
| fin flag number | % of packets with FIN flags in the window | IPv | Indicates if the network layer protocol is IP |
| syn flag number | % of packets with SIN flags in the window | LLC | Indicates if the link layer protocol is LLC |
| rst flag number | % of packets with RST flags in the window | Tot sum | Summation of packets lengths in flow |
| psh flag number | % of packets with PSH flags in the window | Min | Minimum packet length in the flow |
| ack flag number | % of packets with ACK flags in the window | Max | Maximum packet length in the flow |
| ece flag number | % of packets with ECE flags in the window | AVG | Average packet length in the flow |
| cwr flag number | % of packets with CWR flags in the window | Std | Standard deviation of packet length in the flow |
| ack count | No. of packets with ACK flag set in the same flow | Tot size | Packet’s length |
| syn count | No. of packets with SYN flag set in the same flow | IAT | The time difference with the previous packet |
| fin count | No. of packets with FIN flag set in the same flow | Number | No. of packets in the flow |
| urg count | No. of packets with URG flag set in the same flow | Magnitude | (Average of the lengths of incoming packets in the flow + average of the lengths of outgoing packets in the flow)0.5 |
| rst count | No. of packets with RST flag set in the same flow | Radius | (Variance of the lengths of incoming packets in the flow + variance of the lengths of outgoing packets in the flow)0.5 |
| HTTP | Indicates if the app. layer protocol is HTTP | Covariance | Covariance of the lengths of incoming and outgoing packets |
| HTTPS | Indicates if the app. layer protocol is HTTPS | Variance | Variance of the lengths of incoming packets in the flow/ variance of the lengths of outgoing packets in the flow |
| DNS | Indicates if the app. layer protocol is DNS | Weight | No. of incoming packets × No. of outgoing packets |
| Telnet | Indicates if the app. layer protocol is Telnet | ||
| Dataset | Samples No. | ||
|---|---|---|---|
| Classes () | Classes () | Classes () | |
| Malicious | DDoS | ACK_Fragmentation | |
| HTTP_Flood | 2360 | ||
| ICMP_Flood | |||
| ICMP_Fragmentation | |||
| PSHACK_Flood | |||
| RSTFINFlood | |||
| SYN_Flood | |||
| SlowLoris | 1928 | ||
| SynonymousIP_Flood | |||
| TCP_Flood | |||
| UDP_Flood | |||
| UDP_Fragmentation | |||
| DoS | HTTP_Flood | 5930 | |
| SYN_Flood | |||
| TCP_Flood | |||
| UDP_Flood | |||
| Mirai | greeth_flood | ||
| greip_flood | |||
| udpplain | |||
| Spoofing | DNS_Spoofing | ||
| MITM-ArpSpoofing | |||
| Recon | HostDiscovery | ||
| OSScan | 8172 | ||
| PingSweep | 149 | ||
| PortScan | 6640 | ||
| VulnerabilityScan | 3059 | ||
| Web | SQLInjection | 429 | |
| CommandInjection | 404 | ||
| BrowserHijacking | 453 | ||
| XSS | 302 | ||
| Uploading_Attack | 105 | ||
| Backdoor_Malware | 283 | ||
| BruteForce | DictionaryBruteForce | 1045 | |
| Benign | |||
| Class | % |
|---|---|
| Benign | |
| Malicious |
| Class | % | Class | % |
|---|---|---|---|
| DDoS | Recon | ||
| DoS | Web | ||
| Mirai | BruteForce | ||
| Spoofing | Benign |
| Class | % | Class | % |
|---|---|---|---|
| DDoS-ICMP_Flood | DDoS-ACK_Fragmentation | ||
| DDoS-UDP_Flood | DNS_Spoofing | ||
| DDoS-TCP_Flood | Recon-HostDiscovery | ||
| DDoS-PSHACK_Flood | |||
| DDoS-SYN_Flood | Recon-PortScan | ||
| DDoS-RSTFINFlood | DoS-HTTP_Flood | ||
| DDoS-SynonymousIP_Flood | VulnerabilityScan | ||
| DoS-UDP_Flood | DDoS-HTTP_Flood | ||
| DoS-TCP_Flood | DDoS-SlowLoris | ||
| DoS-SYN_Flood | DictionaryBruteForce | ||
| Benign | BrowserHijacking | ||
| Mirai-greeth_flood | CommandInjection | ||
| Mirai-udpplain | SqlInjection | ||
| Mirai-greip_flood | XSS | ||
| DDoS-ICMP_Fragmentation | Backdoor_Malware | ||
| MITM-ArpSpoofing | Recon-PingSweep | ||
| DDoS-UDP_Fragmentation | Uploading_Attack |
| Model Type | Hyperparamater | Range | |
|---|---|---|---|
| Generic Parameter | Learning Rate | [, ] | |
| Batch Normalization | [True, False] | ||
| Activation Function | [tanh, relu] | ||
| Model-specific Parameter | RNN | No. Layers | [1, 2] (step = 1) |
| Layer Units | [64, 512] (step = 16) | ||
| Dropout Value | [, ] (step = ) | ||
| Dense Units | [324, 256] (step = 16) | ||
| CNN | Convolutional Filters | [32, 256] (step = 32) | |
| Kernel Size | [3, 5, 7] | ||
| Pool Size | [2, 4] (step = 1) | ||
| Dilatation Rate | [2, 4, 8] | ||
| Model | MACC Complexity [num.] | RAM Usage [KiB] | Inference Time [ms] | ||||||
|---|---|---|---|---|---|---|---|---|---|
| LSTM | |||||||||
| GRU | |||||||||
| RNN | |||||||||
| CNN | |||||||||
| TCN | |||||||||
| MLP | |||||||||
| Model | ROC-AUC | ||||||
|---|---|---|---|---|---|---|---|
| LSTM | |||||||
| GRU | |||||||
| RNN | |||||||
| CNN | |||||||
| TCN | |||||||
| MLP |
| Model | ROC-AUC | ||||||
|---|---|---|---|---|---|---|---|
| LSTM | |||||||
| GRU | |||||||
| RNN | |||||||
| CNN | |||||||
| TCN | |||||||
| MLP |
| Model | ROC-AUC | ||||||
|---|---|---|---|---|---|---|---|
| LSTM | |||||||
| GRU | |||||||
| RNN | |||||||
| CNN | |||||||
| TCN | |||||||
| MLP |
| Model | MACC Complexity [num.] | RAM Usage [KiB] | Inference Time [ms] | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| TCN | ||||||||||||
| MLP | ||||||||||||
| Model | (%) | MACC (%) | RAM (%) | Inference Time (%) | Flash (%) | Model Size (%) | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| TCN | − | − | − | + | + | + | + | + | + | + | + | + | + | + | − | − | − | − |
| MLP | − | − | − | − | − | − | + | + | + | − | − | − | − | − | − | − | − | − |
| Model | MACC | Flash Size [MB] | Model Size [MB] | ||||
|---|---|---|---|---|---|---|---|
| FP32 | INT8 | FP32 | INT8 | FP32 | INT8 | ||
| TCN | 2 | smul_f32_f32 op_f32_f32 2270 | smul_s8_s8 290 smul_s8_f32 smul_f32_f32 smul_f32_s8 1024 op_s8_s8 | ||||
| TCN | 8 | smul_f32_f32 op_f32_f32 2360 | smul_s8_s8 872 smul_s8_f32 10,848 smul_f32_f32 281,600 smul_f32_s8 1024 op_s8_s8 824 | ||||
| TCN | 34 | smul_f32_f32 op_f32_f32 2846 | smul_s8_s8 6754 smul_s8_f32 smul_f32_f32 smul_f32_s8 1216 op_s8_s8 1310 | ||||
| MLP | 2 | smul_f32_f32 op_f32_f32 862 | smul_s8_s8 op_s8_s8 30 | ||||
| MLP | 8 | smul_f32_f32 op_f32_f32 1160 | smul_s8_s8 op_s8_s8 120 | ||||
| MLP | 34 | smul_f32_f32 op_f32_f32 1550 | smul_s8_s8 op_s8_s8 510 | ||||
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Mazinani, A.; Antonucci, D.; Davoli, L.; Ferrari, G. Performance Assessment of DL for Network Intrusion Detection on a Constrained IoT Device. Future Internet 2026, 18, 34. https://doi.org/10.3390/fi18010034
Mazinani A, Antonucci D, Davoli L, Ferrari G. Performance Assessment of DL for Network Intrusion Detection on a Constrained IoT Device. Future Internet. 2026; 18(1):34. https://doi.org/10.3390/fi18010034
Chicago/Turabian StyleMazinani, Armin, Daniele Antonucci, Luca Davoli, and Gianluigi Ferrari. 2026. "Performance Assessment of DL for Network Intrusion Detection on a Constrained IoT Device" Future Internet 18, no. 1: 34. https://doi.org/10.3390/fi18010034
APA StyleMazinani, A., Antonucci, D., Davoli, L., & Ferrari, G. (2026). Performance Assessment of DL for Network Intrusion Detection on a Constrained IoT Device. Future Internet, 18(1), 34. https://doi.org/10.3390/fi18010034

