A Lightweight Multi-Classification Intrusion Detection Model for Edge IoT Networks
Abstract
1. Introduction
- IoT network traffic data usually exhibits high dimensionality and strong feature correlation. If such data are directly fed into the detection model, redundant information will significantly increase computational burden and make the model prone to overfitting, which in turn degrades detection accuracy.
- Most deep learning-based intrusion detection models require substantial computational and storage resources. Given the resource-constrained nature of edge devices, models with large parameter sizes and high computational costs are difficult to deploy and run efficiently in practical edge environments.
- A hybrid feature extraction strategy: Aiming at the issues of high data dimensionality and feature redundancy in IoT network traffic, a hybrid feature selection method integrating variance filtering, mutual information, and correlation analysis is proposed. Firstly, variance filtering is used to quickly remove the information features with small variation amplitude and limited discrimination ability, thereby reducing the computational overhead of subsequent feature selection. Then, a feature selection objective function is constructed by combining mutual information and Pearson Correlation Coefficient to select the feature subset with high correlation to the category label and low feature redundancy.
- A lightweight intrusion detection model: A detection model was developed based on a temporal convolutional network (TCN), which effectively captures the long-term temporal dependency features of network traffic by leveraging its hierarchical causal convolution and dilated convolution structure. Meanwhile, residual connections are utilized to alleviate the vanishing gradient problem, making the model easy to train and converge. Compared with deep learning models, this method has a smaller parameter scale, faster convergence, and the ability to comprehensively extract sequence features, achieving good detection performance. It can be deployed on resource-constrained edge devices.
- Validation on the latest dataset: Experimental results on the Edge-IIoTset dataset show that the proposed hybrid feature selection method can significantly reduce feature dimensionality while still maintaining good detection performance. At the same time, compared with other models, TCN has an advantage in classification and detection performance, which verifies the effectiveness of the model.
2. Related Works
2.1. Feature Selection Methods for IoT Intrusion Detection
2.2. IoT Intrusion Detection Method Based on Deep Learning
3. Proposed Methodologies
3.1. Dataset Description
3.2. Dataset Preprocessing
3.2.1. Duplicate Row and Unnecessary Feature Removal
3.2.2. Dummy Encoding
3.2.3. Normalization
3.3. Hybrid Feature Selection Algorithm
3.3.1. Variance-Based Feature Selection
3.3.2. Mutual Information and Correlation-Based Feature Selection
3.3.3. mRMR-Based Feature Selection
3.3.4. Hybrid Feature Selection Method
| Algorithm 1 Hybrid Feature Selection Algorithm |
| Input: Feature set , class labels , Number of feature subsets: Output: The feature subset Step1. Initialization: set Step2. The variance filtering method is used to initially screen the original dataset, resulting in a new dataset Step3. Calculate for each feature in dataset Step4. Select the feature with the highest mutual information Step5. Set , , Step6. While do Calculate in (6) to find , , End For Step7. Return |
3.4. Intrusion Detection Framework Based on TCN
3.4.1. Causal Convolution
3.4.2. Dilated Convolution
3.4.3. Residual Connection
4. Experiments and Performance Evaluation
4.1. Experimental Environment
4.2. Hyperparameters for the Model’s Training
4.3. Performance Evaluation Metrics
4.4. Hybrid Feature Selection Algorithm Experiment
4.5. TCN Training Experiment Results
5. Discussion
6. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
Abbreviations
| IoT | Internet of Things |
| TCN | Temporal Convolutional Network |
| NIDS | Network Intrusion Detection System |
| CNN | Convolutional Neural Network |
| RNN | Recurrent Neural Network |
| LSTM | Long Short-Term Memory Network |
| MLP | Multilayer Perceptron |
| GRU | Gated Recurrent Unit |
| mRMR | Minimum Redundancy Maximum Relevance |
| IIoT | Industrial IoT |
| HTTP | HyperText Transfer Protocol |
| MQTT | Message Queuing Telemetry Transport |
| TCP | Transmission Control Protocol |
Appendix A
| S. No. | Feature Name | Protocol Layer | Datatype | Description |
|---|---|---|---|---|
| 1 | icmp.checksum | ICMP | Unsigned integer | Verifies the integrity of an ICMP message |
| 2 | icmp.seq_le | ICMP | Unsigned integer | Helps in identifying the order of sent packets |
| 3 | http.response | HTTP | Boolean | Indicates the status code and other information about the response to an HTTP request message |
| 4 | tcp.ack | TCP | Unsigned integer | Acknowledges receipt of a TCP segment or sequence of segments |
| 5 | tcp.ack_raw | TCP | Unsigned integer | The acknowledgment number in a TCP segment, used for acknowledging receipt of data |
| 6 | tcp.connection.rst | TCP | Label | A TCP flag used to indicate that a connection should be reset |
| 7 | tcp.connection.syn | TCP | Label | A TCP flag used to initiate a connection |
| 8 | udp.stream | UDP | Unsigned integer | A sequence of UDP packets between two hosts |
| 9 | dns.qry.name | DNS | Character string | The domain name queried in a DNS request |
| 10 | http.request.method-0 | HTTP | Character string | Specifies the HTTP method used in HTTP request message |
| 11 | http.request.method-GET | HTTP | Character string | Specifies the HTTP method used in HTTP request message |
| 12 | http.request.method-POST | HTTP | Character string | Specifies the HTTP method used in HTTP request message |
| 13 | http.referer-0 | HTTP | Character string | Indicates the URL of the webpage that led to the current request |
| 14 | http.request.version-0 | HTTP | Character string | Specifies the version of HTTP used in an HTTP request message |
| 15 | dns.qry.name.len-0.0 | DNS | Unsigned integer | The length of the domain name queried in a DNS request |
| 16 | mqtt.conack.flags-0.0 | MQTT | Unsigned integer | Flags used in an MQTTconnection acknowledgement message |
| 17 | mqtt.protoname-0.0 | MQTT | Unsigned integer | The name of the MQTT protocol used in an MQTT message |
| 18 | mqtt.topic-0.0 | MQTT | Character string | The topic published or subscribed to in an MQTT message |
References
- Alotaibi, B. A survey on industrial Internet of Things security: Requirements, attacks, AI-based solutions, and edge computing opportunities. Sensors 2023, 23, 7470. [Google Scholar] [CrossRef]
- Kumar, M.; Kumar, A.; Verma, S.; Bhattacharya, P.; Ghimire, D.; Kim, S.-H.; Hosen, A.S.M.S. Healthcare Internet of Things (H-IoT): Current trends, future prospects, applications, challenges, and security issues. Electronics 2023, 12, 2050. [Google Scholar] [CrossRef]
- Omrany, H.; Al-Obaidi, K.M.; Hossain, M.; Alduais, N.A.M.; Al-Duais, H.S.; Ghaffarianhoseini, A. IoT-enabled smart cities: A hybrid systematic analysis of key research areas, challenges, and recommendations for future direction. Discov. Cities 2024, 1, 2. [Google Scholar] [CrossRef]
- Popoola, O.; Rodrigues, M.; Marchang, J.; Shenfield, A.; Ikpehai, A.; Popoola, J. A critical literature review of security and privacy in smart home healthcare schemes adopting IoT & blockchain: Problems, challenges and solutions. Blockchain Res. Appl. 2024, 5, 100178. [Google Scholar]
- Kumar, S.; Kumar, D.; Dangi, R.; Choudhary, G.; Dragoni, N.; You, I. A review of lightweight security and privacy for resource-constrained IoT devices. Comput. Mater. Contin. 2024, 78, 31–63. [Google Scholar] [CrossRef]
- Chen, K.; Zhang, S.; Li, Z.; Zhang, Y.; Deng, Q.; Ray, S.; Jin, Y. Internet-of-things security and vulnerabilities: Taxonomy, challenges, and practice. J. Hardw. Syst. Secur. 2018, 2, 97–110. [Google Scholar] [CrossRef]
- Khraisat, A.; Gondal, I.; Vamplew, P.; Kamruzzaman, J. Survey of intrusion detection systems: Techniques, datasets and challenges. Cybersecurity 2019, 2, 20. [Google Scholar] [CrossRef]
- Ahmad, M.; Riaz, Q.; Zeeshan, M.; Tahir, H.; Haider, S.A.; Khan, M.S. Intrusion detection in internet of things using supervised machine learning based on application and transport layer features using UNSW-NB15 data-set. EURASIP J. Wirel. Commun. Netw. 2021, 2021, 10. [Google Scholar] [CrossRef]
- Chinnasamy, R.; Subramanian, M.; Easwaramoorthy, S.V.; Cho, J. Deep learning-driven methods for network-based intrusion detection systems: A systematic review. ICT Express 2025, 11, 181–215. [Google Scholar] [CrossRef]
- Gyamfi, E.; Jurcut, A. Intrusion detection in internet of things systems: A review on design approaches leveraging multi-access edge computing, machine learning, and datasets. Sensors 2022, 22, 3744. [Google Scholar] [CrossRef]
- Pudjihartono, N.; Fadason, T.; Kempa-Liehr, A.W.; O’SUllivan, J.M. A review of feature selection methods for machine learning-based disease risk prediction. Front. Bioinform. 2022, 2, 927312. [Google Scholar] [CrossRef]
- Omuya, E.O.; Okeyo, G.O.; Kimwele, M.W. Feature selection for classification using principal component analysis and information gain. Expert Syst. Appl. 2021, 174, 114765. [Google Scholar] [CrossRef]
- Alhassan, S.; Abdul-Salaam, G.; Micheal, A.; Missah, Y.M.; Ganaa, E.D.; Shirazu, A.S. CFS-AE: Correlation-based Feature Selection and Autoencoder for Improved Intrusion Detection System Performance. J. Internet Serv. Inf. Secur. 2024, 14, 104–120. [Google Scholar] [CrossRef]
- Devaraju, S.; Ramakrishnan, S.; Jawahar, S.; Soni, D.; Somasundaram, A. Entropy-based feature selection for network intrusion detection systems. In Methods, Implementation, and Application of Cyber Security Intelligence and Analytics; IGI Global Scientific Publishing: Hershey, PA, USA, 2022; pp. 201–225. [Google Scholar]
- Xie, S.; Zhang, Y.; Lv, D.; Chen, X.; Lu, J.; Liu, J. A new improved maximal relevance and minimal redundancy method based on feature subset. J. Supercomput. 2022, 79, 3157. [Google Scholar] [CrossRef] [PubMed]
- Rahman, M.M.; Al Shakil, S.; Mustakim, M.R. A survey on intrusion detection system in IoT networks. Cyber Secur. Appl. 2025, 3, 100082. [Google Scholar] [CrossRef]
- Huang, H.; Wang, P.; Pei, J.; Wang, J.; Alexanian, S.; Niyato, D. Deep learning advancements in anomaly detection: A comprehensive survey. IEEE Internet Things J. 2025, 12, 44318–44342. [Google Scholar] [CrossRef]
- Ullah, I.; Mahmoud, Q.H. Design and development of RNN anomaly detection model for IoT networks. IEEE Access 2022, 10, 62722–62750. [Google Scholar] [CrossRef]
- Elshewey, A.M.; Abbas, S.; Osman, A.M.; Aldakheel, E.A.; Fouad, Y. DDoS classification of network traffic in software defined networking SDN using a hybrid convolutional and gated recurrent neural network. Sci. Rep. 2025, 15, 29122. [Google Scholar] [CrossRef] [PubMed]
- Kodyš, M.; Lu, Z.; Fok, K.W.; Thing, V.L. Intrusion detection in internet of things using convolutional neural networks. In Proceedings of the 2021 18th International Conference on Privacy, Security and Trust (PST), Virtual, 13–15 December 2021; IEEE: Washington, DC, USA, 2021; pp. 1–10. [Google Scholar]
- Lopes, I.O.; Zou, D.; Abdulqadder, I.H.; Akbar, S.; Li, Z.; Ruambo, F.; Pereira, W. Network intrusion detection based on the temporal convolutional model. Comput. Secur. 2023, 135, 103465. [Google Scholar] [CrossRef]
- Nazre, R.; Budke, R.; Oak, O.; Sawant, S.; Joshi, A. A temporal convolutional network-based approach for network intrusion detection. In Proceedings of the 2024 International Conference on Integrated Intelligence and Communication Systems (ICIICS), Karnataka, India, 22–23 November 2024; IEEE: Washington, DC, USA, 2024; pp. 1–6. [Google Scholar]
- He, P.; Zhang, H.; Feng, Y.; Sakurai, K. A design of network attack detection using causal and non-causal temporal convolutional network. In Proceedings of the International Conference on Science of Cyber Security, Melbourne, Australia, 11–14 July 2023; Springer Nature: Cham, Switzerland, 2023; pp. 513–523. [Google Scholar]
- Ferrag, M.A.; Friha, O.; Hamouda, D.; Maglaras, L.; Janicke, H. Edge-IIoTset: A new comprehensive realistic cyber security dataset of IoT and IIoT applications for centralized and federated learning. IEEE Access 2022, 10, 40281–40306. [Google Scholar] [CrossRef]
- Latif, S.; Boulila, W.; Koubaa, A.; Zou, Z.; Ahmad, J. Dtl-ids: An optimized intrusion detection framework using deep transfer learning and genetic algorithm. J. Netw. Comput. Appl. 2024, 221, 103784. [Google Scholar] [CrossRef]
- Bolikulov, F.; Nasimov, R.; Rashidov, A.; Akhmedov, F.; Cho, Y.-I. Effective methods of categorical data encoding for artificial intelligence algorithms. Mathematics 2024, 12, 2553. [Google Scholar] [CrossRef]
- Peng, H.; Long, F.; Ding, C. Feature selection based on mutual information criteria of max-dependency, max-relevance, and min-redundancy. IEEE Trans. Pattern Anal. Mach. Intell. 2005, 27, 1226–1238. [Google Scholar] [CrossRef]
- Coelho, F.; Braga, A.P.; Verleysen, M. A mutual information estimator for continuous and discrete variables applied to feature selection and classification problems. Int. J. Comput. Intell. Syst. 2016, 9, 726–733. [Google Scholar] [CrossRef]
- Ambusaidi, M.A.; He, X.; Nanda, P.; Tan, Z. Building an intrusion detection system using a filter-based feature selection algorithm. IEEE Trans. Comput. 2016, 65, 2986–2998. [Google Scholar] [CrossRef]
- Saadouni, R.; Khacha, A.; Harbi, Y.; Gherbi, C.; Harous, S.; Aliouat, Z. Secure IIoT networks with hybrid CNN-GRU model using Edge-IIoTset. In Proceedings of the 2023 15th International Conference on Innovations in Information Technology (IIT), Al Ain, United Arab Emirates, 14–15 November 2023; IEEE: Washington, DC, USA, 2023; pp. 150–155. [Google Scholar]
- Khacha, A.; Saadouni, R.; Harbi, Y.; Aliouat, Z. Hybrid Deep Learning-based Intrusion Detection System for Industrial Internet of Things. In Proceedings of the 2022 5th International Symposium on Informatics and its Applications (ISIA), M’sila, Algeria, 29–30 November 2022; pp. 1–6. [Google Scholar]
- Sasi, T.; Lashkari, A.H.; Lu, R.; Xiong, P.; Iqbal, S. An efficient self attention-based 1D-CNN-LSTM network for IoT attack detection and identification using network traffic. J. Inf. Intell. 2024, 3, 375–400. [Google Scholar] [CrossRef]
- Gueriani, A.; Kheddar, H.; Mazari, A.C.; Ghanem, M.C. A robust cross-domain IDS using BiGRU-LSTM-attention for medical and industrial IoT security. ICT Express, 2025; in press. [Google Scholar]










| Parameters | Value |
|---|---|
| Learning rate | 0.001 |
| Optimizer | Adam |
| Activation function | PReLU |
| Epochs | 50 |
| Batch_size | 128 |
| Dilation factor | 8 |
| Loss function | Categorical_crossentropy |
| Feature Selection Methods | Accuracy (%) | Precision (%) | Recall (%) | F1 (%) | Model Parameters (KB) |
|---|---|---|---|---|---|
| 6 | 0.79 | 0.75 | 0.79 | 0.76 | 14.25 |
| 12 | 89.75 | 90.65 | 90.65 | 89.27 | 15 |
| 16 | 92.35 | 92.37 | 92.35 | 91.52 | 15.5 |
| 18 | 93.55 | 92.95 | 93.55 | 92.67 | 15.75 |
| 20 | 93.66 | 93.16 | 93.66 | 92.78 | 16 |
| 22 | 93.79 | 93.33 | 93.79 | 93.13 | 16.25 |
| All features | 94.24 | 93.77 | 94.24 | 93.71 | 25.37 |
| Accuracy (%) | Precision (%) | Recall (%) | F1 (%) | Model Parameters (KB) | ||
|---|---|---|---|---|---|---|
| 2 | 1 | 92.18 | 92.74 | 93.18 | 91.71 | 9 |
| 2 | 2 | 93.20 | 92.20 | 93.20 | 92.21 | 13 |
| 2 | 4 | 93.19 | 92.13 | 93.19 | 92.29 | 21 |
| 4 | 1 | 93.14 | 93.02 | 93.14 | 91.69 | 12.37 |
| 4 | 2 | 93.14 | 92.62 | 93.14 | 92.16 | 18.37 |
| 4 | 4 | 93.12 | 92.60 | 93.12 | 91.69 | 30.37 |
| 8 | 1 | 93.55 | 92.95 | 93.55 | 92.67 | 15.75 |
| 8 | 2 | 93.24 | 92.51 | 93.24 | 92.43 | 23.75 |
| 8 | 4 | 93.16 | 92.08 | 93.16 | 92.27 | 39.75 |
| 16 | 1 | 93.25 | 92.56 | 93.25 | 92.21 | 19.12 |
| 16 | 2 | 93.28 | 92.52 | 93.28 | 92.48 | 29.12 |
| 16 | 4 | 93.21 | 92.42 | 93.21 | 92.35 | 49.12 |
| Methods | Acc. (%) | Pr (%) | Rc (%) | F1 (%) | Model Parameters (KB) | Memory Usage (MB) | Inference Time (s/inst) |
|---|---|---|---|---|---|---|---|
| RNN | 92.80 | 91.31 | 92.80 | 91.80 | 24.56 | 72.77 | 0.001216 |
| LSTM | 91.40 | 89.39 | 91.40 | 89.68 | 27.43 | 73.37 | 0.001390 |
| CNN-GRU [30] | 93.04 | 92.28 | 93.04 | 92.20 | 22.37 | 40.30 | 0.001699 |
| CNN-LSTM [31] | 92.71 | 91.13 | 92.71 | 91.57 | 29 | 103.18 | 0.001413 |
| CNN-LSTM-ResNet-SA [32] | 92.68 | 91.93 | 92.68 | 91.57 | 25.06 | 107.87 | 0.001568 |
| BiGRU-MHA-LSTM [33] | 93.09 | 92.19 | 93.09 | 92.86 | 39.93 | 78.22 | 0.005740 |
| TCN | 93.79 | 93.33 | 93.79 | 93.13 | 16.25 | 39.48 | 0.000852 |
| Precision | Recall | F1 Score | Support | |
|---|---|---|---|---|
| Backdoor | 0.95 | 0.98 | 0.96 | 7193 |
| DDoS_HTTP | 0.71 | 0.98 | 0.82 | 14,540 |
| DDoS_ICMP | 0.99 | 0.99 | 0.99 | 20,217 |
| DDoS_TCP | 0.71 | 0.99 | 0.83 | 15,035 |
| DDoS_UDP | 0.99 | 1.00 | 0.99 | 36,523 |
| Fingerprinting | 0.80 | 0.39 | 0.52 | 250 |
| MITM | 1.00 | 1.00 | 1.00 | 101 |
| Normal | 1.00 | 1.00 | 1.00 | 409,327 |
| Password | 0.41 | 0.77 | 0.55 | 15,050 |
| Port_Scanning | 0.00 | 0.00 | 0.00 | 5987 |
| Ransomware | 0.99 | 0.87 | 0.93 | 2892 |
| SQL_injection | 0.46 | 0.20 | 0.28 | 15,141 |
| Uploading | 0.59 | 0.34 | 0.43 | 11,033 |
| Vulnerability_scanner | 0.93 | 0.84 | 0.88 | 15,040 |
| XSS | 0.86 | 0.01 | 0.02 | 4535 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Gao, W.; Wang, M.; Pei, Y.; Li, F.; Wang, C. A Lightweight Multi-Classification Intrusion Detection Model for Edge IoT Networks. Electronics 2026, 15, 938. https://doi.org/10.3390/electronics15050938
Gao W, Wang M, Pei Y, Li F, Wang C. A Lightweight Multi-Classification Intrusion Detection Model for Edge IoT Networks. Electronics. 2026; 15(5):938. https://doi.org/10.3390/electronics15050938
Chicago/Turabian StyleGao, Wei, Mingyue Wang, Yadong Pei, Fangwei Li, and Chaonan Wang. 2026. "A Lightweight Multi-Classification Intrusion Detection Model for Edge IoT Networks" Electronics 15, no. 5: 938. https://doi.org/10.3390/electronics15050938
APA StyleGao, W., Wang, M., Pei, Y., Li, F., & Wang, C. (2026). A Lightweight Multi-Classification Intrusion Detection Model for Edge IoT Networks. Electronics, 15(5), 938. https://doi.org/10.3390/electronics15050938

