Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Search Results (116)

Search Parameters:
Keywords = BOT-IOT

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
45 pages, 2288 KB  
Article
Calibration Granularity, Not Contamination: Diagnosing a TCN Anomaly Detector’s False Positive Advantage in Cross-Dataset IoT Traffic
by Muhammad Nouman, Muhsin Hassanu and Raja Ujjan
Future Internet 2026, 18(9), 447; https://doi.org/10.3390/fi18090447 - 24 Aug 2026
Viewed by 334
Abstract
We set out to fix a “contamination” problem in reconstruction-based Temporal Convolutional Network VAEs (TCN-VAEs) for cross-dataset IoT flow anomaly detection: when attack flows share an encoder window with benign flows, the shared latent code is allegedly distorted, inflating benign reconstruction error and [...] Read more.
We set out to fix a “contamination” problem in reconstruction-based Temporal Convolutional Network VAEs (TCN-VAEs) for cross-dataset IoT flow anomaly detection: when attack flows share an encoder window with benign flows, the shared latent code is allegedly distorted, inflating benign reconstruction error and producing false positive rates (FPRs) of 22–65% despite an ROC-AUC above 0.93. Our proposed fix, TCN-Pred, excludes the target flow from the encoder and scores it by next-flow prediction error, reducing FPR to 0.65–13%. We subjected this causal explanation to a battery of controlled ablations, holding architecture, decoder, loss, and thresholding fixed while varying one factor at a time. Each one falsified the original hypothesis: target inclusion/masking changes FPR by at most 0.001; context shuffling/reversing/zeroing changes it by at most 0.003; a context-blind constant-output predictor matches TCN-Pred’s FPR and F1 to three decimal places on all three datasets. The actual cause, confirmed on the original trained models with no retraining, is a scoring-granularity mismatch: the TCN-VAE threshold is calibrated from per-window errors averaged over 20 flows but applied to per-flow errors at evaluation (standard deviation 20× higher, measured ratio 4.46 against a predicted 4.47). Recalibrating the identical model at matching granularity drops FPR from 22.7/47.6/64.6% to 0.65/5.0/12.5% on BoT-IoT, IoT-23 and ToN-IoT, closing 89–97% of the reported FPR gap without changing a single model weight. We report this diagnostic chain, together with an attack-prevalence sensitivity analysis, sample-disjoint calibration, normality diagnostics, and label-free and redundancy-aware (mRMR) feature-selection benchmarks, as a methodology other work should apply before attributing fixed-threshold performance to architecture. The pipeline is supervised source-domain feature selection followed by benign-only detector training, not fully unsupervised, a distinction we quantify later in the paper. Investigating dataset representativeness, we found that all three provided files reduce to only ≈6000 genuinely distinct flows via an undocumented row-duplication procedure, causing 97.8% BoT-IoT train/test near-duplicate overlap; a leakage-free re-evaluation changes FPR by only 0.23 percentage points. We also found that the TLS-metadata columns are already transformed upstream of every available artefact, so the proportion of genuinely TLS-encrypted flows cannot be recovered, and we soften the paper’s encrypted-traffic framing accordingly. Full article
Show Figures

Figure 1

22 pages, 3571 KB  
Article
AER-DCWGAN: Adversarial Encoder-Regularized Dual-Conditional Wasserstein GAN for Imbalanced Network Intrusion Detection
by Mingqi Wang, Yu Yang, Minna Gao and Jinliang Yuan
Sensors 2026, 26(14), 4506; https://doi.org/10.3390/s26144506 - 15 Jul 2026
Viewed by 400
Abstract
Class imbalance remains a major obstacle to reliable network intrusion detection, particularly in Internet of Things (IoT) and sensor-network monitoring scenarios where rare attack categories are represented by only a small number of high-dimensional traffic samples. To improve minority-class augmentation, we propose an [...] Read more.
Class imbalance remains a major obstacle to reliable network intrusion detection, particularly in Internet of Things (IoT) and sensor-network monitoring scenarios where rare attack categories are represented by only a small number of high-dimensional traffic samples. To improve minority-class augmentation, we propose an adversarial encoder-regularized dual-conditional Wasserstein generative adversarial network (AER-DCWGAN), a class-aware latent-consistency framework operating in a normalized, feature-selected space. Unlike label-only conditional generation, AER-DCWGAN jointly models traffic features, latent codes, and class embeddings and is designed to encourage feature-, latent-, and label-conditioned consistency. The framework integrates a latent-code- and label-aware Wasserstein critic, encoder-guided reconstruction, adversarial prior alignment, and label-consistency filtering to reduce latent drifting and suppress semantically ambiguous generated samples. Experiments on NSL-KDD and CIC-IDS2017 show class-dependent effects rather than uniform improvement. On NSL-KDD, the Remote-to-Local (R2L) F1-score increases from 0.501 to 0.823, whereas the User-to-Root (U2R) F1-score increases only from 0.124 to 0.204 with a recall of 0.270, indicating that U2R detection remains weak. On CIC-IDS2017, Web Attack improves from 0.952 to 0.983, but Bot and PortScan decrease slightly from 0.828 to 0.817 and from 0.996 to 0.994, respectively. The improvement reported for Infiltration should also be interpreted cautiously because the test support is only seven samples. The controlled head-to-head comparison is restricted to the closely related WGAN-GP and AE-WGAN baselines, and the generated samples are evaluated and used only in the processed feature space; therefore, the study does not claim broad superiority over all imbalance-handling strategies or protocol-level validity of reconstructed raw traffic. Overall, AER-DCWGAN alleviates moderate class imbalance for several classes with sufficient representation, but it does not fully solve ultra-rare attack detection. Full article
Show Figures

Figure 1

19 pages, 2604 KB  
Data Descriptor
A Pilot-Real-Calibrated Indoor Robotic IoT Benchmark Dataset for Edge-Assisted Mobile Robot Navigation and Anomaly Detection
by Burak Aggul
Data 2026, 11(7), 165; https://doi.org/10.3390/data11070165 - 4 Jul 2026
Cited by 1 | Viewed by 732
Abstract
Mobile robots used in edge-assisted Industrial Internet-of-Things (IIoT) settings generate coupled motion, LiDAR, edge-compute, and network telemetry. Public datasets that place these streams in one tabular format, with scenario labels suitable for machine-learning experiments, are still limited. This data descriptor presents a pilot-real-calibrated [...] Read more.
Mobile robots used in edge-assisted Industrial Internet-of-Things (IIoT) settings generate coupled motion, LiDAR, edge-compute, and network telemetry. Public datasets that place these streams in one tabular format, with scenario labels suitable for machine-learning experiments, are still limited. This data descriptor presents a pilot-real-calibrated indoor robotic IoT benchmark dataset with 120,000 records sampled at 2 Hz across nominal navigation and nine anomaly scenarios. The benchmark rows are generated from physically constrained simulation rules and are explicitly labeled as synthetic benchmark data. Real pilot evidence is included separately: ROS Noetic runs on a TurtleBot3 Burger, successful LD08 LiDAR bringup after resolving a driver mismatch, and NVIDIA Jetson Nano tegrastats logs under normal-navigation workloads. The calibrated file aligns normal-navigation LiDAR and edge-compute distributions with these pilot measurements while keeping the multi-scenario structure needed for controlled anomaly-detection experiments. The package includes CSV files, metadata, a data dictionary, validation reports, baseline scripts, ROS collection utilities, and a plan for future fully physical data collection. The complete dataset is openly available on Zenodo. Full article
(This article belongs to the Section Information Systems and Data Management)
Show Figures

Figure 1

43 pages, 4986 KB  
Article
Enhanced Data Security in Metadata-Governed Cloud IOT Using Optimized Provenance and Access Control Through MARShield, ThreshGuard and SentinelScheduler
by Abbi Kala, Mahalakshmi Guruvayur Suryanarayanan and Sendhilkumar Selvaradjou
Appl. Sci. 2026, 16(12), 6280; https://doi.org/10.3390/app16126280 - 22 Jun 2026
Viewed by 2493
Abstract
Manual data storage methods on various mobile devices, IoT devices, and traditional computing platforms still lack sufficient security governance due to the absence of a unified security framework. Unlike application controlled environments, manual storage locations such as file systems, removable media, and IoT [...] Read more.
Manual data storage methods on various mobile devices, IoT devices, and traditional computing platforms still lack sufficient security governance due to the absence of a unified security framework. Unlike application controlled environments, manual storage locations such as file systems, removable media, and IoT devices are highly susceptible to unauthorized access, misuse, and exfiltration. To address this problem, the paper proposes a security framework for manual storage systems using metadata, and the proposed framework includes three different algorithms, namely MARShield, ThreshGuard, and SentinelScheduler. These three algorithms operate together to ensure security for manual storage systems. MARShield is used for enforcing immutable metadata, multi-access rights based on tokens, and persistent source tracking by cryptographically securing provenance logs. ThreshGuard, on the other hand, enables the use of adaptive threshold-based misuse regulation and bottleneck-controlled serialized execution. SentinelScheduler optimizes the use of cryptography by incorporating trust-based application profiling and idle-time scheduling for heavy security operations. The proposed methodology is evaluated using a hybrid approach combining real-world datasets (CIC-IoT2023, TON-IoT, Bot-IoT and ISCX VPN non-VPN) and dataset-driven synthetic access pattern generation. Real datasets are used to model realistic IoT traffic behaviors, while additional synthetic scenarios are introduced to evaluate adaptability against evolving and previously unseen attack patterns. Network level features from these datasets are systematically transformed into storage-level access behaviors to evaluate metadata-driven access control. The experimental results indicate improved detection accuracy (94.6%), reduced false positive rate (4.3%), improved misuse control efficiency (92%) and scalability (94%). The proposed methodology for securing manual storage domains is scalable, adaptive, and portable, extending the security of applications and their associated domains. Full article
Show Figures

Figure 1

19 pages, 631 KB  
Article
Proactive DoS and DDoS Attack Detection Through Behavior-Based Threat Intelligence
by Orieb Abualghanam, Malik Al-Essa, Wesam Almobaideen, Mohammad Qatawneh and Ahmad Sami Al-Shamayleh
Electronics 2026, 15(12), 2559; https://doi.org/10.3390/electronics15122559 - 10 Jun 2026
Cited by 1 | Viewed by 459
Abstract
The rapid growth of cyberattacks necessitates the development of more sophisticated detection techniques. DoS and DDoS are well-known harmful attacks that affect organizations. This paper proposes a proactive, behavior-based DoS and DDoS detection framework that integrates threat intelligence and machine learning to analyze [...] Read more.
The rapid growth of cyberattacks necessitates the development of more sophisticated detection techniques. DoS and DDoS are well-known harmful attacks that affect organizations. This paper proposes a proactive, behavior-based DoS and DDoS detection framework that integrates threat intelligence and machine learning to analyze attack behavior and enhance early detection. XGBoost is used to train the proposed model and evaluate feature importance. The evaluation of the proposed model and the generated rules is conducted using three different datasets: CICIoT2023, BoT-IoT, and Edge-IIoT. Experimental results demonstrate high detection performance, achieving up to 99.98% accuracy and 99.89% F1-score, while maintaining low false positive rates across diverse datasets. Integrating threat intelligence into SIEM has been evaluated using two datasets, DDoS-AT-2022 and CIC-DDoS2019. The rule-based detection technique enhances detection rates and mitigates false positives. Moreover, the proposed framework enhances detection accuracy. Full article
Show Figures

Figure 1

27 pages, 1800 KB  
Article
TLS-Aware Anomaly Detection for Encrypted IoT Traffic Using a β-Variational Autoencoder with ANOVA–Mutual Information Feature Selection
by Muhammad Nouman, Raja Ujjan and Muhsin Hassanu
Future Internet 2026, 18(6), 310; https://doi.org/10.3390/fi18060310 - 8 Jun 2026
Cited by 1 | Viewed by 758
Abstract
The rapid growth of the Internet of Things (IoT) has increased dependency on Transport Layer Security (TLS) for securing device communications, enhancing confidentiality while reducing the visibility required by traditional intrusion detection systems. As payload inspection becomes impractical in encrypted environments, anomaly detection [...] Read more.
The rapid growth of the Internet of Things (IoT) has increased dependency on Transport Layer Security (TLS) for securing device communications, enhancing confidentiality while reducing the visibility required by traditional intrusion detection systems. As payload inspection becomes impractical in encrypted environments, anomaly detection must instead rely on flow-level statistics and TLS metadata. This is challenging because IoT traffic is heterogeneous, non-stationary, and distributionally inconsistent across datasets, while many existing studies rely on single-dataset evaluation and therefore provide limited evidence of real-world generalisation. We introduce a TLS-aware anomaly detection framework that combines a β-Variational Autoencoder (β-VAE) with a hybrid ANOVA–Mutual Information (ANOVA–MI) feature-selection pipeline. The incremental contribution lies not in the individual use of these components, but in their integrated application to encrypted IoT anomaly detection under strict cross-dataset evaluation, where feature filtering, probabilistic latent regularisation, and threshold transferability are jointly examined without retraining or recalibration on target datasets. The framework models benign encrypted IoT traffic using probabilistic latent representations and identifies anomalies through reconstruction-error-based scoring. Network flows from the BoT-IoT, IoT-23, and ToN-IoT datasets were processed using Zeek and CICFlowMeter to construct a unified metadata feature space incorporating flow statistics and TLS attributes such as JA3 and JA3S fingerprints. The model was trained on benign BoT-IoT traffic and evaluated in both in-dataset and cross-dataset scenarios. The model achieves strong in-dataset performance on BoT-IoT (ROC-AUC 0.9996; F1 0.9922) and retains robust anomaly-ranking and threshold-based detection capability under cross-dataset domain shift (IoT-23: ROC-AUC 0.9882, F1 0.9422; ToN-IoT: ROC-AUC 0.9465, F1 0.8732). A comparative evaluation against deterministic autoencoders and classical baselines further indicates that the proposed β-VAE achieves stronger cross-dataset anomaly-ranking performance than the compared methods. These findings support the suitability of probabilistic latent modelling for privacy-preserving anomaly detection in encrypted IoT environments. Full article
(This article belongs to the Section Cybersecurity)
Show Figures

Graphical abstract

30 pages, 7038 KB  
Article
Distributional Drift in IoT Intrusion Detection Systems: Implications for Cross-Dataset Generalisation
by Kazım Kıvanç Eren, Kerem Küçük, Radhwan A. A. Saleh, Mehmet Zeki Konyar, Olympia M. Hardy and Sajjad Ahmad Khan
Electronics 2026, 15(11), 2307; https://doi.org/10.3390/electronics15112307 - 26 May 2026
Viewed by 688
Abstract
The rapid expansion of Internet of Things (IoT) technologies has highlighted the need for reliable intrusion detection systems (IDSs), yet the majority of existing studies rely on single-dataset evaluations, raising concerns about their real-world generalisation capability. This study addresses this limitation by systematically [...] Read more.
The rapid expansion of Internet of Things (IoT) technologies has highlighted the need for reliable intrusion detection systems (IDSs), yet the majority of existing studies rely on single-dataset evaluations, raising concerns about their real-world generalisation capability. This study addresses this limitation by systematically investigating distributional shift across heterogeneous IoT intrusion detection datasets and their impact on model behaviour. To achieve this, a unified feature space is constructed using BoT-IoT, ToN-IoT, and UNSW-NB15 datasets, followed by a comprehensive preprocessing pipeline including attack class alignment, distribution-preserving sampling for class imbalance, and feature selection based on cross-dataset feature value propagation analysis. Furthermore, feature-specific transformations and correlation-based dimensionality reduction are applied to enhance statistical consistency and model stability. To simulate realistic deployment scenarios, models are trained on combinations of datasets and evaluated on unseen datasets. The results reveal that distributional inconsistencies and dataset-specific feature biases significantly degrade cross-dataset performance, despite strong within-dataset results. The proposed framework provides a systematic understanding of feature-level behaviour across datasets, identifying both stable and bias-prone features. These findings highlight the necessity of distribution-aware preprocessing and feature analysis for developing robust and generalisable IoT intrusion detection systems. Full article
Show Figures

Figure 1

30 pages, 4078 KB  
Article
Benchmarking and Cross-Dataset Evaluation of AI-Based Intrusion Detection Systems for Smart City IoT Networks
by Ahlam Alghamdi and Samia Dardouri
Computers 2026, 15(6), 340; https://doi.org/10.3390/computers15060340 - 26 May 2026
Viewed by 973
Abstract
The rapid expansion of Internet of Things (IoT) infrastructures in smart city environments has increased the demand for reliable intrusion detection systems (IDS). However, many existing studies rely on single-dataset evaluations and inconsistent experimental settings, which can lead to overly optimistic performance estimates. [...] Read more.
The rapid expansion of Internet of Things (IoT) infrastructures in smart city environments has increased the demand for reliable intrusion detection systems (IDS). However, many existing studies rely on single-dataset evaluations and inconsistent experimental settings, which can lead to overly optimistic performance estimates. In this study, we propose a standardized benchmarking framework for evaluating artificial intelligence-based IDS across heterogeneous IoT datasets, including CIC-IoT 2023, BoT-IoT, and N-BaIoT. Multiple classical machine learning and deep learning models are evaluated under a unified preprocessing pipeline and a consistent evaluation protocol. A hybrid CNN–BiLSTM–Attention architecture is also implemented as a reference model within this framework. While several models achieve near-perfect performance under intra-dataset evaluation, cross-dataset experiments reveal substantial performance degradation and unstable metric behavior under distribution shifts. These results highlight the limitations of dataset-specific optimization and emphasize the necessity of cross-dataset validation for realistic IoT intrusion detection evaluation. All experiments are conducted under a binary intrusion detection setting (benign vs. attack) to enable consistent comparison across datasets. Consequently, the reported results reflect binary detection performance and do not capture attack-type discrimination. Full article
(This article belongs to the Section ICT Infrastructures for Cybersecurity)
Show Figures

Figure 1

32 pages, 4538 KB  
Article
Handling Imbalanced IoMT Network Data for Intrusion Detection via PCA and One-Class SVM
by Eren Gencturk, Beste Ustubioglu and Guzin Ulutas
Appl. Sci. 2026, 16(10), 4701; https://doi.org/10.3390/app16104701 - 9 May 2026
Viewed by 781
Abstract
The Internet of Medical Things (IoMT) has become integral to modern healthcare, yet its always-connected and resource-constrained nature enlarges the attack surface and complicates timely intrusion detection. This study presents a deployment-oriented, two-stage anomaly-detection pipeline. First, Principal Component Analysis (PCA) is employed to [...] Read more.
The Internet of Medical Things (IoMT) has become integral to modern healthcare, yet its always-connected and resource-constrained nature enlarges the attack surface and complicates timely intrusion detection. This study presents a deployment-oriented, two-stage anomaly-detection pipeline. First, Principal Component Analysis (PCA) is employed to reduce the dimensionality of network traffic data, capturing the most significant variance. Subsequently, a One-Class Support Vector Machine (OC-SVM) is trained exclusively on these principal components of normal traffic. This approach prioritizes computational efficiency for resource-constrained IoMT devices while maintaining high model robustness. By modeling the principal components of normal behavior, our method achieves state-of-the-art performance across diverse attack families. We adopt a uniform protocol across four public IoMT corpora—BoT-IoT, CICIoMT2024, ECU-IoHT, and IoMT-TrafficData. The model’s hyperparameters, including the optimal number of principal components determined by explained variance, are tuned via randomized search. Despite using no attack labels during training, the proposed PCA-enhanced detector achieves state-of-the-art performance across diverse attack families: on BoT-IoT we obtain 99.92% F1-score (99.84% accuracy), on CICIoMT2024 we obtain 99.88% F1-score (99.77% accuracy), on ECU-IoHT 99.25% F1-score (98.58% accuracy), and on IoMT-TrafficData 99.19% F1-score (98.66% accuracy). The compact model size, enabled by PCA, makes the approach highly amenable to edge or gateway deployment in clinical networks, while the normal-only training paradigm improves robustness to zero-day threats. The results demonstrate that modeling the principal components of routine network behavior is a highly effective and efficient strategy for reliable, low-latency threat detection in realistic IoMT settings. Full article
(This article belongs to the Special Issue Advances in Cyber Security)
Show Figures

Figure 1

32 pages, 9370 KB  
Article
Evaluation of Explainable Artificial Intelligence in IoT Intrusion Detection Systems Under DeepFool Adversarial Conditions
by Jorge Munilla and Rana M. Khammas
Sensors 2026, 26(10), 2924; https://doi.org/10.3390/s26102924 - 7 May 2026
Cited by 1 | Viewed by 620
Abstract
As IoT systems complexity grows, transparent and trustworthy machine-learning intrusion detection systems are crucial. Post hoc explainable AI methods, such as SHAP and LIME, are the most widely used ways to explain how models work, but the degree to which these methods are [...] Read more.
As IoT systems complexity grows, transparent and trustworthy machine-learning intrusion detection systems are crucial. Post hoc explainable AI methods, such as SHAP and LIME, are the most widely used ways to explain how models work, but the degree to which these methods are robust to adversarial conditioning is understudied. In this paper, we propose to create a unified system of evaluating explanation fidelity by using three metrics: sparsity, completeness, and robustness based on minimally distorting DeepFool input perturbations. Our study benchmarks SHAP and LIME across three datasets (BoT-IoT, Edge-IIoT, and N-BaIoT) using four classifiers: CNN, DNN, LSTM, and RF. Our results demonstrate a consistent trade-off: SHAP achieves stronger feature alignment and higher completeness under attack, whereas LIME exhibits greater rank stability in terms of top-k feature overlap. However, LIME also produces more spurious attributions and offers less explanatory power than SHAP, especially in the presence of synthetic features. Our findings reveal that high model accuracy does not guarantee that the provided explanation is also high-fidelity. This investigation highlights the necessity for robustness-aware XAI in cybersecurity and provides reproducible parameters to guide the adoption of XAI in adversarial environments. Full article
(This article belongs to the Special Issue Privacy and Cybersecurity in IoT-Based Applications)
Show Figures

Figure 1

31 pages, 7250 KB  
Article
Enhancing IoT Network Security: A BPSO-Optimized Attention-GRU Deep Learning Framework for Intrusion Detection
by Abdallah Elayan and Michel Kadoch
Computers 2026, 15(5), 266; https://doi.org/10.3390/computers15050266 - 23 Apr 2026
Cited by 1 | Viewed by 570
Abstract
The exponential expansion of computer networks, alongside the rapid development of the Internet of Things (IoT), has significantly increased the volume and complexity of transmitted data, emphasizing the need for robust network security measures to secure sensitive data and prevent unauthorized access or [...] Read more.
The exponential expansion of computer networks, alongside the rapid development of the Internet of Things (IoT), has significantly increased the volume and complexity of transmitted data, emphasizing the need for robust network security measures to secure sensitive data and prevent unauthorized access or breaches. Intrusion Detection Systems (IDSs) have emerged as a vital tool for protecting networks and IoT environments from threats. Various IDSs have been proposed in the literature; however, the lack of optimal feature learning, computational efficiency, and reliance on obsolete datasets poses significant challenges, limiting their effectiveness against evolving cyber threats. Moreover, traditional IDSs struggle to efficiently manage the high-dimensional and imbalanced nature of IoT network traffic data. To address these challenges, this research proposes a hybrid deep learning (DL)-based IDS integrating Binary Particle Swarm Optimization (BPSO), MultiHead Attention mechanisms (MHA), and a deep Gated Recurrent Unit (GRU) architecture, improving detection effectiveness while reducing computational overhead. Our proposed approach also utilizes a Target Sampling strategy to balance class distributions, enhancing the model’s ability to accurately identify minority attacks. The BPSO algorithm is employed to identify the most influential features from the high-dimensional network traffic datasets, enhancing model interpretability and supporting more efficient learning. This optimized feature subset is then fed into a GRU-based DL architecture augmented with MHA, which performs sequence processing and attention-based learning for intrusion detection. The performance of the proposed model is evaluated utilizing the BoT-IoT and the CIC-IDS2017 benchmark datasets, ensuring a comprehensive assessment of anomaly detection capabilities. Extensive experimental results demonstrate the superior performance of the proposed model, achieving a recall of 98.42% and 99.76%, with F1-score of 98.94% and 99.76% for binary classification and a recall of 99.79% and 98.69%, with F1-score of 99.89% and 98.04% for multiclass classification on the BoT-IoT and CIC-IDS2017 datasets, respectively, highlighting the effectiveness of our model in enhancing threat detection for computer networks and IoT environments in comparison to recent state-of-the-art IDSs. Full article
Show Figures

Figure 1

23 pages, 352 KB  
Article
Performance Comparison of Python-Based Complex Event Processing Engines for IoT Intrusion Detection: Faust Versus Streamz
by Maryam Abbasi, Filipe Cardoso, Paulo Váz, José Silva, Filipe Sá and Pedro Martins
Computers 2026, 15(3), 200; https://doi.org/10.3390/computers15030200 - 23 Mar 2026
Viewed by 1480
Abstract
The proliferation of Internet of Things (IoT) devices has intensified the need for efficient real-time anomaly and intrusion detection, making the selection of an appropriate Complex Event Processing (CEP) engine a critical architectural decision for security-aware data pipelines. Python-based CEP frameworks offer compelling [...] Read more.
The proliferation of Internet of Things (IoT) devices has intensified the need for efficient real-time anomaly and intrusion detection, making the selection of an appropriate Complex Event Processing (CEP) engine a critical architectural decision for security-aware data pipelines. Python-based CEP frameworks offer compelling advantages through the seamless integration with data science and machine learning ecosystems; however, rigorous comparative evaluations of such frameworks under realistic IoT security workloads remain absent from the literature. This study presents the first systematic comparative evaluation of Faust and Streamz—two Python-native CEP engines representing fundamentally different architectural philosophies—specifically in the context of IoT network intrusion detection. Faust was selected for its actor-based stateful processing model with native Kafka integration and distributed table support, while Streamz was selected for its reactive, lightweight pipeline design targeting high-throughput stateless processing, making them representative of the two dominant paradigms in Python stream processing. Although both engines target different application niches, their performance characteristics under realistic CEP workloads have never been rigorously compared, leaving practitioners without empirical guidance. The primary evaluation employs an IoT network intrusion dataset comprising 583,485 events from 83 heterogeneous devices. To assess whether the observed performance characteristics are specific to this single dataset or generalize across different workload profiles, a secondary IoT-adjacent benchmark is included: the PaySim financial transaction dataset (6.4 million records), selected because its event schema, fraud-pattern temporal structure, and volume differ substantially from the intrusion dataset, providing a stress test for cross-workload robustness rather than a claim of domain equivalence. We acknowledge the reviewer’s valid point that a second IoT-specific intrusion dataset (such as TON_IoT or Bot-IoT) would constitute a more directly comparable validation; this is identified as a priority for future work. The load levels used in scalability experiments (up to 5000 events per second) intentionally exceed the dataset’s natural rate to stress-test each engine’s architectural ceiling and identify saturation thresholds relevant to large-scale or multi-sensor IoT deployments. We conducted controlled experiments with comprehensive statistical analysis. Our results demonstrate that Streamz achieves superior throughput at 4450 events per second with 89% efficiency and minimal resource consumption (40 MB memory, 12 ms median latency), while Faust provides robust intrusion pattern detection with 93–98% accuracy and stable, predictable resource utilization (1.4% CPU standard deviation). A multi-framework comparison including Apache Kafka Streams and offline scikit-learn baselines confirms that Faust achieves detection quality competitive with JVM-based alternatives (Faust: 96.2%; Kafka Streams: 96.8%; absolute difference of 0.6 percentage points, not statistically significant at p=0.318) while retaining the Python ecosystem advantages. Statistical analysis confirms significant performance differences across all metrics (p<0.001, Cohen’s d>0.8). Critical scalability thresholds are identified: Streamz maintains efficiency above 95% up to 3500 events per second, while Faust degrades beyond 2500 events per second. These findings provide IoT security engineers and system architects with actionable, empirically grounded guidance for CEP engine selection, establish reproducible benchmarking methodology applicable to future Python-based stream processing evaluations, and advance theoretical understanding of the accuracy–throughput trade-off in stateful versus stateless Python CEP architectures. Full article
(This article belongs to the Section Internet of Things (IoT) and Industrial IoT)
Show Figures

Figure 1

22 pages, 3598 KB  
Article
Fractional Tchebichef-ResNet-SE: A Hybrid Deep Learning Framework Integrating Fractional Tchebichef Moments with Attention Mechanisms for Enhanced IoT Intrusion Detection
by Islam S. Fathi, Ahmed R. El-Saeed, Mohammed Tawfik and Gaber Hassan
Fractal Fract. 2026, 10(3), 172; https://doi.org/10.3390/fractalfract10030172 - 5 Mar 2026
Cited by 1 | Viewed by 883
Abstract
The Internet of Things (IoT) faces critical security challenges stemming from resource-constrained devices and inadequate intrusion detection capabilities. Traditional machine learning approaches struggle with high-dimensional network traffic data due to the curse of dimensionality, severe class imbalance between benign and malicious traffic, and [...] Read more.
The Internet of Things (IoT) faces critical security challenges stemming from resource-constrained devices and inadequate intrusion detection capabilities. Traditional machine learning approaches struggle with high-dimensional network traffic data due to the curse of dimensionality, severe class imbalance between benign and malicious traffic, and dependence on manual feature engineering that fails to capture complex non-linear attack patterns. Although deep neural networks offer automatic feature extraction, they suffer from two fundamental limitations: the degradation problem, where increasing network depth paradoxically raises training error rather than improving performance, and uniform channel weighting, which prevents the network from adaptively emphasizing attack-relevant features while suppressing irrelevant noise. This research proposes a novel hybrid framework integrating Fractional Tchebichef moment-based feature preprocessing with deep Residual Networks enhanced by Squeeze-and-Excitation (ResNet-SE) attention mechanisms. Fractional Tchebichef moments provide compact, noise-resistant representations by operating directly in the discrete domain, eliminating discretization errors inherent in continuous moment approaches. Network traffic features are transformed into 232 × 232 moment-based matrices capturing discriminative patterns across multiple scales. Comprehensive evaluation on Bot-IoT and Leopard Mobile IoT datasets demonstrates superior performance, achieving 99.78% accuracy and a 99.37% F1-score, substantially outperforming K-Nearest Neighbors (84.7%), Support Vector Machines (87.5%), and baseline CNNs (99.3%). Ablation studies confirm synergistic contributions, with residual connections contributing 0.18% and SE attention adding 0.14% improvements. Cross-dataset evaluation achieves 96.34% and 97.12% accuracy on UNSW-NB15 and IoT-Bot datasets without retraining, while the framework processes 127.9 samples per second across diverse attack taxonomies. Full article
(This article belongs to the Section Optimization, Big Data, and AI/ML)
Show Figures

Figure 1

27 pages, 2849 KB  
Systematic Review
Intrusion Detection in Fog Computing: A Systematic Review of Security Advances and Challenges
by Nyashadzashe Tamuka, Topside Ehleketani Mathonsi, Thomas Otieno Olwal, Solly Maswikaneng, Tonderai Muchenje and Tshimangadzo Mavin Tshilongamulenzhe
Computers 2026, 15(3), 169; https://doi.org/10.3390/computers15030169 - 5 Mar 2026
Cited by 2 | Viewed by 1830
Abstract
Fog computing extends cloud services to the network edge to support low-latency IoT applications. However, since fog environments are distributed and resource-constrained, intrusion detection systems must be adapted to defend against cyberattacks while keeping computation and communication overhead minimal. This systematic review presents [...] Read more.
Fog computing extends cloud services to the network edge to support low-latency IoT applications. However, since fog environments are distributed and resource-constrained, intrusion detection systems must be adapted to defend against cyberattacks while keeping computation and communication overhead minimal. This systematic review presents research on intrusion detection systems (IDSs) for fog computing and synthesizes advances and research gaps. The study was guided by the “Preferred-Reporting-Items for-Systematic-Reviews-and-Meta-Analyses” (PRISMA) framework. Scopus and Web of Science were searched in the title field using TITLE/TI = (“intrusion detection” AND “fog computing”) for 2021–2025. The inclusion criteria were (i) 2021–2025 publications, (ii) journal or conference papers, (iii) English language, and (iv) open access availability; duplicates were removed programmatically using a DOI-first key with a title, year, and author alternative. The search identified 8560 records, of which 4905 were unique and included for qualitative grouping and bibliometric synthesis. Metadata (year, venue, authors, affiliations, keywords, and citations) were extracted and analyzed in Python to compute trends and collaboration. Intrusion detection systems in fog networks were categorized into traditional/signature-based, machine learning, deep learning, and hybrid/ensemble. Hybrid and DL approaches reported accuracy ranging from 95 to 99% on benchmark datasets (such as NSL-KDD, UNSW-NB15, CIC-IDS2017, KDD99, BoT-IoT). Notable bottlenecks included computational load relative to real-time latency on resource-constrained nodes, elevated false-positive rates for anomaly detection under concept drift, limited generalization to unseen attacks, privacy risks from centralizing data, and limited real-world validation. Bibliometric analyses highlighted the field’s concentration in fast-turnaround, open-access journals such as IEEE Access and Sensors, as well as a small number of highly collaborative author clusters, alongside dominant terms such as “learning,” “federated,” “ensemble,” “lightweight,” and “explainability.” Emerging directions include federated and distributed training to preserve privacy, as well as online/continual learning adaptation. Future work should consist of real-world evaluation of fog networks, ultra-lightweight yet adaptive hybrid IDS, self-learning, and secure cooperative frameworks. These insights help researchers select appropriate IDS models for fog networks. Full article
Show Figures

Figure 1

25 pages, 633 KB  
Article
Lightweight LSTM-Based Homogeneous Transfer Learning for Efficient On-Device IoT Intrusion Detection
by Amjad Gamlo, Sanaa Sharaf and Rania Molla
Future Internet 2026, 18(3), 133; https://doi.org/10.3390/fi18030133 - 4 Mar 2026
Cited by 1 | Viewed by 1097
Abstract
The emergence of the Internet of Things (IoT) has introduced major security challenges. Deep learning models have shown strong potential for intrusion detection. However, they often require large datasets and high computational resources. In contrast, IoT environments are resource-constrained and lack sufficient labeled [...] Read more.
The emergence of the Internet of Things (IoT) has introduced major security challenges. Deep learning models have shown strong potential for intrusion detection. However, they often require large datasets and high computational resources. In contrast, IoT environments are resource-constrained and lack sufficient labeled data. This paper proposes a lightweight intrusion detection approach based on Long Short-Term Memory (LSTM) networks and homogeneous transfer deep learning. The model is first trained on a subset of the BoT-IoT dataset as a source domain. It is then fine-tuned on a disjoint subset containing a rare attack type. This setup represents adaptation to unseen attack behaviors within the same environment. By freezing earlier layers and fine-tuning only the final layers, the method reduces training overhead while preserving performance. This is important to meet the IoT requirement for frequent, lightweight model updates on resource-constrained devices. The proposed model achieved 99.9% accuracy, a macro F1-score of 0.96, and a 47.8% reduction in training time compared to training from scratch. Extensive experiments confirm that it maintains balanced detection across both common and rare classes. Full article
Show Figures

Figure 1

Back to TopTop