Previous Article in Journal
Secure Programming and Secure Design in DevSecOps: A Literature-Based Conceptual Synthesis
Previous Article in Special Issue
Cognitive Network Intrusion Detection Systems: Anomaly and Malware Detection for Zero-Day Attack Resilience
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
This is an early access version, the complete PDF, HTML, and XML versions will be available soon.
Systematic Review

Machine Learning Applications for IoT Intrusion Detection: Network Dependencies, Dataset Limitations, and Regulatory Compliance—A Systematic Review

1
Faculty of Engineering and IT, University of Technology Sydney (UTS), Ultimo, NSW 2007, Australia
2
Faculty of Computing and Information, Al-Baha University (BU), Alaqiq 65779, Saudi Arabia
*
Author to whom correspondence should be addressed.
Network 2026, 6(3), 76; https://doi.org/10.3390/network6030076
Submission received: 15 July 2026 / Revised: 29 August 2026 / Accepted: 4 September 2026 / Published: 10 September 2026

Abstract

Background: Internet of Things (IoT) deployments face complex network dependencies and persistent data limitations that constrain machine learning (ML) intrusion detection systems (IDS). Objective: To synthesise peer-reviewed machine learning IDS research for IoT, focusing on dependency-driven failure propagation and chronic data scarcity, positioned against 2024–2025 EU regulatory requirements (NIS2, the Cyber Resilience Act). Eligibility criteria: Peer-reviewed empirical studies proposing or evaluating a machine learning or deep learning IoT intrusion detection method published in English from January 2018 (limited pre-2018 exceptions for seminal works). Information sources: IEEE Xplore, SpringerLink, Elsevier ScienceDirect, Scopus, Web of Science, and Google Scholar, searched on 12 February 2025. Risk of bias: Each candidate was scored against four criteria (objectives clarity, methodological soundness, reproducibility, IoT-security relevance); studies scoring at least 3 out of 4 were retained. Screening and scoring were performed by one reviewer, with a second reviewer independently checking 20 percent of records. Synthesis methods: Narrative thematic synthesis; heterogeneous metrics and incompatible datasets across studies precluded quantitative meta-analysis. Included studies: Of 427 records identified, 52 studies initially met inclusion criteria; a post hoc independently validated reconstruction of individual QA1–QA4 scores subsequently found that six did not meet the threshold or topical eligibility criteria, yielding a final 46-study corpus. Main findings: Generative adversarial networks (GANs) dominate dataset augmentation work, graph-based communication analysis addresses dependency modelling, and methods based on transformers or federated learning emerge from 2023 onward. Certainty of evidence: No formal grading (GRADE) applies to this narrative synthesis. Confidence in the corpus composition is high, following independent QA1–QA4 validation, while confidence in the thematic findings is moderate given single-reviewer screening and judgment-based classification. Conclusions: We identify three recurring gaps: real-time detection under resource constraints, dependency-aware detection, and regulatory compliance. Closing these gaps requires detection methods that treat IoT security as a networked and regulated system rather than an isolated device classification problem. Registration: Open Science Framework, 10.17605/OSF.IO/NMAK4 (registered retrospectively). No external funding supported this review.
Keywords: IoT security; intrusion detection systems; machine learning; complex network dependencies; data scarcity; regulatory compliance IoT security; intrusion detection systems; machine learning; complex network dependencies; data scarcity; regulatory compliance

Share and Cite

MDPI and ACS Style

Alzahrani, M.; Nanda, P.; Mohanty, M.; Zegil, F.E. Machine Learning Applications for IoT Intrusion Detection: Network Dependencies, Dataset Limitations, and Regulatory Compliance—A Systematic Review. Network 2026, 6, 76. https://doi.org/10.3390/network6030076

AMA Style

Alzahrani M, Nanda P, Mohanty M, Zegil FE. Machine Learning Applications for IoT Intrusion Detection: Network Dependencies, Dataset Limitations, and Regulatory Compliance—A Systematic Review. Network. 2026; 6(3):76. https://doi.org/10.3390/network6030076

Chicago/Turabian Style

Alzahrani, Majed, Priyadarsi Nanda, Manoranjan Mohanty, and Farag El Zegil. 2026. "Machine Learning Applications for IoT Intrusion Detection: Network Dependencies, Dataset Limitations, and Regulatory Compliance—A Systematic Review" Network 6, no. 3: 76. https://doi.org/10.3390/network6030076

APA Style

Alzahrani, M., Nanda, P., Mohanty, M., & Zegil, F. E. (2026). Machine Learning Applications for IoT Intrusion Detection: Network Dependencies, Dataset Limitations, and Regulatory Compliance—A Systematic Review. Network, 6(3), 76. https://doi.org/10.3390/network6030076

Article Metrics

Back to TopTop