Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

Search Results (93)

Search Parameters:
Keywords = ToNIoT

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
31 pages, 2374 KB  
Article
STAG-GuardNet: UAV-Assisted Spatio-Temporal Attack Graph Learning for Secure IoT Communication in Smart EV Charging Networks
by Abdulrahman A. Alshdadi
Sensors 2026, 26(18), 5898; https://doi.org/10.3390/s26185898 (registering DOI) - 17 Sep 2026
Viewed by 130
Abstract
Smart electric vehicle (EV) charging infrastructures are evolving into large-scale cyber-physical Internet of Things (IoT) systems that depend on distributed communication, real-time sensing, and spatially coordinated charging operations. However, their interconnected communication architecture exposes charging stations, EV communication links, and network gateways to [...] Read more.
Smart electric vehicle (EV) charging infrastructures are evolving into large-scale cyber-physical Internet of Things (IoT) systems that depend on distributed communication, real-time sensing, and spatially coordinated charging operations. However, their interconnected communication architecture exposes charging stations, EV communication links, and network gateways to coordinated distributed denial-of-service (DDoS) attacks. Existing intrusion detection approaches primarily rely on localized or static traffic analysis and therefore have limited capability to capture spatially distributed and temporally evolving attack behavior. This study proposes the Spatio-Temporal Attack Graph Guard Network (STAG-GuardNet), an unmanned aerial vehicle (UAV)-assisted spatio-temporal attack graph learning framework for DDoS detection and security monitoring in smart EV charging networks. The framework integrates spatiotemporal signal conditioning, telemetry-adaptive graph aggregation, temporal dependency learning, attack-memory encoding, and adaptive risk-aware attention to model coordinated cyber-physical attack behavior. UAV-assisted telemetry provides complementary spatial and wireless information on communication instability, signal variation, neighboring congestion, and distributed attack-related behavior. A Hybrid Hawk–Manta Adaptive Optimizer (HHMAO) is employed to improve hyperparameter selection and convergence stability under imbalanced, heterogeneous, and nonstationary traffic conditions. The framework is evaluated using a smart-city EV charging cybersecurity dataset and three benchmark IoT intrusion detection datasets, namely TON_IoT, Edge-IIoTset, and X-IIoTID. Experimental results show that STAG-GuardNet achieves 97.7% accuracy, a 97.7% weighted F1-score, and a 98.4% area under the receiver operating characteristic curve (AUC) on the primary dataset. The framework also maintains stable performance under noisy telemetry, missing observations, heterogeneous traffic distributions, and charging-node outages. These findings demonstrate the potential of STAG-GuardNet for resilient and spatially informed security monitoring in UAV-assisted IoT-enabled EV charging infrastructures. Full article
(This article belongs to the Special Issue Emerging Trends in Cybersecurity for Wireless Communication and IoT)
Show Figures

Figure 1

36 pages, 1772 KB  
Article
Robustness as a Tunable Design Objective for Lightweight IoT Intrusion Detection
by Xinzhu Dong and Zhihui Yang
Appl. Sci. 2026, 16(17), 8595; https://doi.org/10.3390/app16178595 - 28 Aug 2026
Viewed by 300
Abstract
Deep learning intrusion detectors for IoT networks are mostly evaluated on clean-data accuracy alone, leaving their behavior under perturbation unknown. This paper treats robustness as a tunable design parameter rather than an uncontrolled byproduct. The mechanism itself is not novel, since training with [...] Read more.
Deep learning intrusion detectors for IoT networks are mostly evaluated on clean-data accuracy alone, leaving their behavior under perturbation unknown. This paper treats robustness as a tunable design parameter rather than an uncontrolled byproduct. The mechanism itself is not novel, since training with additive input noise penalizes the norm of the input gradient. What is new is its quantified use as an operational control, where one training-time parameter sets a measurable robustness radius. On ToN-IoT and Edge-IIoTset, we evaluate a lightweight CNN-BiLSTM-Attention detector of about 200 K parameters with mutual-information feature selection. Under test-time Gaussian noise and projected gradient descent on modifiable continuous features, clean-data accuracy does not guarantee stability after deployment. A strong random forest, a high-accuracy deep model and a parameter-matched transformer all collapse under small perturbations, so the fragility belongs to the detection task rather than to any model family. Noise-aware training establishes a controllable radius matched to the expected deployment perturbation, retaining about 88 percent accuracy where baselines collapse. It costs clean-data attack recall, which a validation-calibrated threshold restores without reducing robustness, and gradient-free attacks confirm the robustness is genuine. Robustness should therefore be reported alongside accuracy and efficiency as a standard axis for IoT intrusion detection. Full article
Show Figures

Figure 1

31 pages, 1338 KB  
Article
XAI-Driven Intrusion Detection for Internet of Things Networks
by Awatif Alqahtani, Fatimah Alakeel and Lujain Abuhaimed
Sensors 2026, 26(17), 5437; https://doi.org/10.3390/s26175437 - 28 Aug 2026
Viewed by 449
Abstract
Systems that can reliably detect intrusion are increasingly in demand as the scale and heterogeneity of Internet of Things (IoT) networks rise. However, when strong tabular models are employed as a benchmark, it is not clear whether the complexity of ensembling actually pays [...] Read more.
Systems that can reliably detect intrusion are increasingly in demand as the scale and heterogeneity of Internet of Things (IoT) networks rise. However, when strong tabular models are employed as a benchmark, it is not clear whether the complexity of ensembling actually pays off. The aim of this work is to systematically assess the reliability and accuracy of soft-voting ensembles across three benchmark datasets (CICIoT2023, TON_IoT, and Edge-IIoTset), applying a leakage-free protocol with twice-repeated stratified 10-fold cross-validation. Ensembles of varying sizes and compositions were benchmarked against Decision Tree, KNN, Random Forest, LightGBM, XGBoost, and CatBoost and the results revealed that ensemble complexity did not lead to a consistent increase in performance. For example, SoftVote-2 increased macro-F1 over LightGBM on CICIoT2023 from 0.8506 to 0.8563, whereas LightGBM remained superior on TON_IoT and Edge-IIoTset. A leakage analysis demonstrated that resampling before data partitioning increased accuracy by around 8 percentage points and macro-F1 by 14 to 17 percentage points. To assess the trade-off between performance and complexity, training time, inference latency, memory, and model size were all evaluated, and LIME and SHAP were also assessed for explanation stability, local fidelity, and attribution agreement. XAI-guided feature selection showed that the 15 most important features retained 98.4–99.4% of the original macro-F1 and decreased inference latency by up to 38%. The results indicate that the value of ensemble complexity varies by dataset and should be weighed against its computational cost. The main contribution of this study is a leakage-aware and explainability-informed framework that can be used to judge when ensemble complexity yields genuine predictive and practical benefits for the detection of IoT intrusion. Full article
(This article belongs to the Section Internet of Things)
Show Figures

Figure 1

25 pages, 7874 KB  
Article
A Three-Stage Federated Distillation Framework for Robust Intrusion Detection in Heterogeneous IoT/Edge Networks
by Xudong Yang, Ziyi Lin, Qiuyan Li, Yuanxiang Dong, Zhenyu Zhang, Zhenzhou Jing and Xuyao Lu
Electronics 2026, 15(17), 3810; https://doi.org/10.3390/electronics15173810 - 25 Aug 2026
Viewed by 295
Abstract
Internet of Things(IoT)/edge intrusion-detection systems operate on distributed traffic and system-state data whose distributions vary across gateways, services, and attack conditions. We study a server-assisted federated setting in which a teacher reference is fitted from a permitted server-accessible training pool and explicitly distinguish [...] Read more.
Internet of Things(IoT)/edge intrusion-detection systems operate on distributed traffic and system-state data whose distributions vary across gateways, services, and attack conditions. We study a server-assisted federated setting in which a teacher reference is fitted from a permitted server-accessible training pool and explicitly distinguish this simulation assumption from fully decentralized deployment. The proposed framework evaluates progressive local training through boundary stabilization, confidence-weighted decision distillation, representation alignment, and validation-quality-aware aggregation. The evaluation uses a leakage-controlled protocol: server and client validation subsets are held out before federated training, update quality and early stopping use validation data only, and the final-test split is evaluated once. Results on NSL-KDD, CIC-IDS2017, Edge-IIoTset, and the ToN-IoT network dataset show competitive primary performance and stronger robustness in several severe label-skew settings. On the Telemetry of Things(ToN-IoT) with Dirichlet alpha = 0.1, the proposed method achieves 91.46 ± 5.54 F1, compared with 53.73 ± 49.00 for FedAvg and 53.77 ± 48.92 for FedProx. The results do not establish universal superiority or a universally optimal stage order: competing methods remain stronger in selected stable and attack-shift settings. The framework is therefore presented as a bounded, server-assisted robustness-oriented training strategy for heterogeneous IoT/edge intrusion detection. Full article
(This article belongs to the Special Issue IoT Sensing and Generalization)
Show Figures

Figure 1

45 pages, 2288 KB  
Article
Calibration Granularity, Not Contamination: Diagnosing a TCN Anomaly Detector’s False Positive Advantage in Cross-Dataset IoT Traffic
by Muhammad Nouman, Muhsin Hassanu and Raja Ujjan
Future Internet 2026, 18(9), 447; https://doi.org/10.3390/fi18090447 - 24 Aug 2026
Viewed by 400
Abstract
We set out to fix a “contamination” problem in reconstruction-based Temporal Convolutional Network VAEs (TCN-VAEs) for cross-dataset IoT flow anomaly detection: when attack flows share an encoder window with benign flows, the shared latent code is allegedly distorted, inflating benign reconstruction error and [...] Read more.
We set out to fix a “contamination” problem in reconstruction-based Temporal Convolutional Network VAEs (TCN-VAEs) for cross-dataset IoT flow anomaly detection: when attack flows share an encoder window with benign flows, the shared latent code is allegedly distorted, inflating benign reconstruction error and producing false positive rates (FPRs) of 22–65% despite an ROC-AUC above 0.93. Our proposed fix, TCN-Pred, excludes the target flow from the encoder and scores it by next-flow prediction error, reducing FPR to 0.65–13%. We subjected this causal explanation to a battery of controlled ablations, holding architecture, decoder, loss, and thresholding fixed while varying one factor at a time. Each one falsified the original hypothesis: target inclusion/masking changes FPR by at most 0.001; context shuffling/reversing/zeroing changes it by at most 0.003; a context-blind constant-output predictor matches TCN-Pred’s FPR and F1 to three decimal places on all three datasets. The actual cause, confirmed on the original trained models with no retraining, is a scoring-granularity mismatch: the TCN-VAE threshold is calibrated from per-window errors averaged over 20 flows but applied to per-flow errors at evaluation (standard deviation 20× higher, measured ratio 4.46 against a predicted 4.47). Recalibrating the identical model at matching granularity drops FPR from 22.7/47.6/64.6% to 0.65/5.0/12.5% on BoT-IoT, IoT-23 and ToN-IoT, closing 89–97% of the reported FPR gap without changing a single model weight. We report this diagnostic chain, together with an attack-prevalence sensitivity analysis, sample-disjoint calibration, normality diagnostics, and label-free and redundancy-aware (mRMR) feature-selection benchmarks, as a methodology other work should apply before attributing fixed-threshold performance to architecture. The pipeline is supervised source-domain feature selection followed by benign-only detector training, not fully unsupervised, a distinction we quantify later in the paper. Investigating dataset representativeness, we found that all three provided files reduce to only ≈6000 genuinely distinct flows via an undocumented row-duplication procedure, causing 97.8% BoT-IoT train/test near-duplicate overlap; a leakage-free re-evaluation changes FPR by only 0.23 percentage points. We also found that the TLS-metadata columns are already transformed upstream of every available artefact, so the proportion of genuinely TLS-encrypted flows cannot be recovered, and we soften the paper’s encrypted-traffic framing accordingly. Full article
Show Figures

Figure 1

32 pages, 6300 KB  
Article
An Autonomous AI-Driven Framework for Adaptive Cyber Deception with Real-Time Threat Detection and Behaviour-Based Attribution
by Muhammad Shahzad, Muhsin Hassanu Saleh and Raja Ujjan
Computers 2026, 15(7), 462; https://doi.org/10.3390/computers15070462 - 21 Jul 2026
Viewed by 801
Abstract
Contemporary cyber threats increasingly employ multi-stage and behaviourally adaptive strategies that challenge static intrusion detection and non-adaptive deception mechanisms. Existing approaches typically treat threat detection, deception deployment, and adversarial attribution as separate functions, limiting timely response and underusing the behavioural evidence generated during [...] Read more.
Contemporary cyber threats increasingly employ multi-stage and behaviourally adaptive strategies that challenge static intrusion detection and non-adaptive deception mechanisms. Existing approaches typically treat threat detection, deception deployment, and adversarial attribution as separate functions, limiting timely response and underusing the behavioural evidence generated during attacker interaction. This study develops and evaluates a theory-informed computational and operational framework for autonomous cyber deception. The principal research artefact is a reusable closed-loop architecture rather than a single predictive model: it specifies the interacting components, interfaces, data and control flows, decision rules, and feedback mechanisms that connect detection, deception, telemetry, and attribution. Methodologically, the study follows an engineering design-and-evaluation approach comprising problem and requirement identification from the literature, architectural synthesis, component-level mathematical modelling, prototype implementation, and controlled cyber-range evaluation. In this context, modelling refers to the distinct computational models embedded within the framework: a hybrid detection model combining supervised classification, anomaly detection, and temporal sequence analysis; a Markov Decision Process and reinforcement-learning policy model for selecting and reconfiguring deception actions under engagement, intelligence-gain, resource, and containment objectives; and similarity-based and Bayesian attribution models for estimating MITRE ATT&CK techniques from incomplete behavioural evidence. The component models were developed offline using the NSL-KDD, CICIDS2017, UNSW-NB15, and ToN-IoT datasets, while the integrated prototype was evaluated separately in a controlled enterprise-like cyber range using reconnaissance, brute-force, exploitation, and multi-stage attack scenarios. The reported classification metrics were calculated from the labelled cyber-range evaluation events, not by pooling the four benchmark datasets. On this integrated cyber-range evaluation set, the system achieved 95.4% detection accuracy, 93.6% precision, 94.7% recall, and a 94.1% F1-score, with a mean detection latency of 85 ms. It also achieved 100% honeypot deployment reliability, 92% dynamic reconfiguration success, 88% fingerprinting resistance, and attacker engagement durations of up to 280 s. The attribution component demonstrated end-to-end generation of ATT&CK-aligned technique hypotheses from deception-derived telemetry; however, the present archived evaluation does not support per-technique or baseline-comparative performance claims. These findings show that specialised models and operational services can be coordinated within a unified adaptive defence process, while also identifying the additional class-level and ablation evidence required for rigorous attribution validation. Full article
(This article belongs to the Special Issue Next-Generation Cyber Defense: AI, Automation and Adaptive Security)
Show Figures

Figure 1

29 pages, 16650 KB  
Article
Cognitive Detection at Big-Data Scale: A CNN-LSTM-DQN Framework with Prioritized Experience Replay for Cross-Attack-Family Generalization and Multi-Seed Initialization Sensitivity Analysis
by Rushendra, Kalamullah Ramli, Prima Dewi Purnamasari, Teddy Surya Gunawan and Muhammad Salman
Big Data Cogn. Comput. 2026, 10(7), 239; https://doi.org/10.3390/bdcc10070239 - 16 Jul 2026
Cited by 1 | Viewed by 587
Abstract
Real-world IoT network security generates traffic at big-data scale with extreme class imbalance, temporal non-stationarity, and continuously evolving attack strategies that overwhelm static supervised classifiers. This paper presents a cognitive computing framework for network intrusion detection: a CNN–LSTM–DQN architecture with Prioritized Experience Replay [...] Read more.
Real-world IoT network security generates traffic at big-data scale with extreme class imbalance, temporal non-stationarity, and continuously evolving attack strategies that overwhelm static supervised classifiers. This paper presents a cognitive computing framework for network intrusion detection: a CNN–LSTM–DQN architecture with Prioritized Experience Replay (PER) evaluated on a 5,000,000-flow naturalistic sample of the TON_IoT Processed_Network dataset (4,000,000 training/1,000,000 temporally held-out test flows; 94.5% attack ratio) under a strict temporal split. The cognitive agent optimizes detection decisions using an Alerts per Million Flows (ARMF)-aware reward function that encodes both alert-fatigue cost and missed-attack penalty. We conduct a cross-attack-family generalization study: the methodology—architecture template, reward design, and hyperparameter calibration—is inherited from a framework previously validated on CSE-CIC-IDS2018, re-instantiated and retrained on the structurally different TON_IoT environment, and compared against the previously published benchmark. Initialization sensitivity is characterized across five independent random seeds using paired Wilcoxon signed-rank and t-tests. Across the five seeds, the proposed X2 model attains recall 0.833 ± 0.306 and F1 0.874 ± 0.241 (mean ± sample SD), versus the supervised X1 baseline at 0.858 ± 0.178 and 0.912 ± 0.116; the best-performing seed (42) achieves 97.52% accuracy, 98.02% attack recall, 99.46% precision, and 98.73% F1-score on 1,000,000 held-out XSS flows—an attack family entirely absent from training—with temporal stability variances of 4.63 × 10−7 (recall) and 1.38 × 10−7 (F1). The X2 advantage observed among the four stable seeds is not statistically demonstrated at n = 5 (statistical power ≈ 5.1%); the initialization-sensitivity finding itself, including one degenerate alert-suppression seed, is reported as a primary contribution. A formal, exactly additive ARMF decomposition distinguishes the detected-attack (structural) component (99.46%) from the model-induced false-positive component (0.54%), and we report a multi-seed, ARMF-aware cognitive IDS evaluation on naturalistic TON_IoT traffic under an unseen-attack-family test condition that, to the best of our knowledge, has not been reported in the surveyed RL-based NIDS literature. Full article
Show Figures

Graphical abstract

20 pages, 2773 KB  
Article
Trust-Aware Contrastive Meta-Aggregation Federated Learning for Intrusion Detection in the Internet of Things
by Alanoud A. Aljuaid
Symmetry 2026, 18(7), 1188; https://doi.org/10.3390/sym18071188 - 14 Jul 2026
Viewed by 512
Abstract
The Internet of Things (IoT) has increased the cyber-attack surface by bringing together a variety of different devices, sensors, and services in critical digital infrastructure. Federated learning (FL) is a solution that enables local devices to train together without sharing raw traffic data; [...] Read more.
The Internet of Things (IoT) has increased the cyber-attack surface by bringing together a variety of different devices, sensors, and services in critical digital infrastructure. Federated learning (FL) is a solution that enables local devices to train together without sharing raw traffic data; thus, it can be used for intrusion detection without compromising privacy. Nevertheless, traditional FL aggregation techniques are still susceptible to non-IID client distributions, data imbalance, unreliable local updates, and poor representation learning approaches. This study introduces a novel method, called Trust-Aware Contrastive Federated Learning for IoT intrusion detection, TACMA Fed. The framework extends AMAFed and combines trust-aware client scoring, aggregation based on similarity of updates, supervised contrastive representation learning, adaptive focal–Dice loss, and rare-class-aware weighting into a lightweight 1D convolutional model. The ten simulated IoT clients and the non-IID Dirichlet partition are used in experiments with the ToN-IoT train_test_network dataset. TACMA Fed achieves an accuracy of 0.9957, an F1 score of 0.9937, an ROC-AUC of 0.9991, a PR-AUC of 0.9997, and a false-positive rate of 0.0087. Robustness analysis also shows stability parameters in the presence of Gaussian noise and feature masking, as well as varying levels of client heterogeneity. The outcomes of these experiments prove that, in the context of federated IDS (FIDS) for a heterogeneous IoT network, the integration of trust-aware aggregation with contrastive representation learning and imbalance-aware optimization can enhance performance. Full article
(This article belongs to the Section A: Computer Science)
Show Figures

Figure 1

30 pages, 6331 KB  
Article
Lightweight Malicious Traffic Detection Model for Edge Scenarios: Co-Optimization of Detection Accuracy and Computational Overhead
by Wanjia Li, Guanjie Wang, Xiang Meng, Hongyu Sun and Yanhua Dong
Electronics 2026, 15(14), 3083; https://doi.org/10.3390/electronics15143083 - 13 Jul 2026
Viewed by 449
Abstract
With the widespread deployment of IoT devices, deploying efficient network traffic classification models on resource-constrained edge nodes is critical for real-time boundary security. However, traditional lightweight models primarily rely on macro-level structural pruning, which often sacrifices crucial feature extraction capabilities when handling complex [...] Read more.
With the widespread deployment of IoT devices, deploying efficient network traffic classification models on resource-constrained edge nodes is critical for real-time boundary security. However, traditional lightweight models primarily rely on macro-level structural pruning, which often sacrifices crucial feature extraction capabilities when handling complex heterogeneous traffic, leading to a severe imbalance between parameter compression and detection accuracy. To overcome this bottleneck, we propose TinyFlowNet, an ultra-lightweight multi-module fusion architecture. To prevent the parameter explosion inherent in combining CNN, LSTM, and Transformer modules, TinyFlowNet innovatively adopts an extreme operator-level reconstruction strategy. By introducing debiased computations, affine-free normalization, and a customized micro-self-attention mechanism, it comprehensively strips away underlying redundant parameters. Simultaneously, an integrated parameter-free regularization mechanism is introduced to compensate for the representational capacity lost under this extreme compression, ensuring robust spatio-temporal feature fusion. Comprehensive evaluations on the custom X-IDS-20 balanced dataset alongside the complex CICDarknet2020 and ToN_IoT public datasets demonstrate that TinyFlowNet achieves exceptional accuracies of 95.31 percent, 99.53 percent, and 97.13 percent, respectively. Furthermore, it exhibits formidable robustness against extreme class imbalances by securing a peak Matthews Correlation Coefficient of 0.9465 and an outstanding PR-AUC of 0.9834, all while strictly confining the parameter count to merely 74,600. Crucially, actual on-device hardware profiling on a commercial edge device corroborates its deployment viability, exhibiting a minimal dynamic memory footprint of 8.26 MB, an average inference latency of 0.79 ms, and a processing throughput exceeding 1200 FPS. Compared to a standard heavy Hybrid CNN-LSTM-Transformer baseline, TinyFlowNet achieves superior detection accuracy while drastically reducing the parameter footprint by over 99.3% and computational FLOPs by 95.8%. Furthermore, against mainstream lightweight benchmarks like DistilBERT and heavy baselines such as LSTM, TinyFlowNet reduces parameters by 61.4% to 94% while simultaneously achieving absolute accuracy leaps and accelerating inference speed by nearly 4× over MobileNetV2, establishing a highly efficient new paradigm for intelligent edge defense. Full article
Show Figures

Figure 1

27 pages, 695 KB  
Article
A Drift-Aware Human-in-the-Loop Edge AI Agent for Wireless IoMT Sensor-Network Intrusion Detection Under Cross-Corpus Shift
by Abdulaziz Saleh Alajaji
Electronics 2026, 15(14), 3015; https://doi.org/10.3390/electronics15143015 - 9 Jul 2026
Viewed by 424
Abstract
Wireless sensor networks underpin the Internet of Medical Things (IoMT), where connected medical devices and wearable body-area sensors stream patient telemetry across hospital networks, and securing this traffic is safety-critical. Machine learning intrusion-detection systems for the IoMT are usually evaluated within a single [...] Read more.
Wireless sensor networks underpin the Internet of Medical Things (IoMT), where connected medical devices and wearable body-area sensors stream patient telemetry across hospital networks, and securing this traffic is safety-critical. Machine learning intrusion-detection systems for the IoMT are usually evaluated within a single public dataset, where they report near-perfect detection scores; whether that accuracy predicts performance in a different hospital has not been measured systematically. We frame the deployed detector as a lightweight human-in-the-loop edge AI agent that observes local traffic, asks an analyst to label a small set of representative flows, trains a tiny model on-premises, and monitors the traffic distribution for drift. Using cross-corpus shift across four public datasets, comprising three sensor-network corpora (WUSTL-EHMS-2020, CIC-IoMT-2024, TON-IoT) and an unrelated enterprise-network corpus, as a reproducible stand-in for cross-hospital deployment, we find the shift is near its theoretical maximum on all twelve transfer directions, that unlabeled domain-adaptation methods collapse on the hardest medical-telemetry targets, and that external pretraining adds no measurable benefit once training schedules are matched, consistent with a domain-adaptation error bound that the measured divergence renders vacuous. The same 1206-parameter network trained from scratch on ten to fifty locally labeled flows matches or exceeds every transfer alternative across all four corpora; on the six sensor-network transfer directions it also outperforms larger and classical local models. A closed-loop evaluation on simulated drifting streams shows the calibrated trigger detects drift within two 500-flow windows at under one false alarm per hundred stationary windows, retraining restores accuracy, and the agent tolerates ten percent analyst error for about five F1 points; we also map the detector’s exposure to white-box evasion and targeted label poisoning. Full article
(This article belongs to the Section Networks)
Show Figures

Figure 1

20 pages, 1225 KB  
Article
Lightweight Machine Learning Intrusion Detection for IoT/IIoT Networks: Quantisation Strategies and Physical Deployment on Resource-Constrained Microcontrollers
by Emanuele Pio De Bernardis, Oleksandr Kuznetsov, Marco Arnesano, Polatova Zhansaya and Madina Sydykova
Electronics 2026, 15(13), 2869; https://doi.org/10.3390/electronics15132869 - 1 Jul 2026
Viewed by 716
Abstract
Intrusion detection in IoT and IIoT networks must operate under tight resource constraints, yet most published machine learning-based IDS solutions report accuracy on held-out data without addressing whether the trained model can actually run on the target hardware. We address this gap with [...] Read more.
Intrusion detection in IoT and IIoT networks must operate under tight resource constraints, yet most published machine learning-based IDS solutions report accuracy on held-out data without addressing whether the trained model can actually run on the target hardware. We address this gap with an end-to-end study spanning dataset preprocessing, model training, INT8 quantisation, and physical execution on two real microcontrollers. Five supervised classifiers—Logistic Regression, Decision Tree (depth 5), Random Forest, XGBoost, and LightGBM—plus an MLP deep learning baseline are evaluated on binary and ten-class intrusion detection tasks using the TON_IoT network dataset. A 5-fold stratified cross-validation confirms stable performance across splits, with LightGBM reaching F1=0.9993±0.0001. Models are then exported through three quantisation pipelines: m2cgen C code generation for the two lightest classifiers, TensorFlow Lite Micro full-integer INT8 for the MLP (9.34× size reduction to 13.03 KB), and a custom post-training INT8 binary format for XGBoost and LightGBM (18.91× compression for LightGBM to 73.85 KB). All five quantised models are deployed to an Arduino Mega 2560 (ATmega2560, 16 MHz, 8 KB SRAM) and an ESP32-C3 SuperMini (RISC-V, 160 MHz, 400 KB SRAM) and benchmarked on physical hardware across 500 timed inferences per model (250 per input class), with firmware predictions confirmed to match the Python 3.11 float model on both test vectors. The Decision Tree achieves 5.6 µs inference on the ESP32-C3; LightGBM INT8 (F1=0.9992) provides the best accuracy–size trade-off among ensemble models. Cross-platform comparison reveals that the RISC-V device is 5.8–7.8× faster than the 8-bit AVR for identical model code. A cross-domain evaluation using CIC-IoT-Dataset2023 identifies large normalised distribution shifts (up to δ=5.95 in packet asymmetry), quantifying the generalisation gap that remains an open challenge. Full article
Show Figures

Figure 1

21 pages, 3311 KB  
Article
A Hybrid CNN–LSTM Model for IoT Intrusion Detection: A Robustness Analysis Across Datasets
by Amir Muhammad Hafiz Othman, Mohd Faizal Ab Razak, Ahmad Firdaus, Hamid Tahaei and Mehdi Gheisari
Future Internet 2026, 18(7), 345; https://doi.org/10.3390/fi18070345 - 30 Jun 2026
Viewed by 644
Abstract
The rapid growth of Internet of Things (IoT) devices has led to security concerns due to increasing IoT attacks. Traditional intrusion detection systems (IDS) struggle to effectively detect attacks due to the evolving nature of threats and heterogeneous traffic patterns. Therefore, this study [...] Read more.
The rapid growth of Internet of Things (IoT) devices has led to security concerns due to increasing IoT attacks. Traditional intrusion detection systems (IDS) struggle to effectively detect attacks due to the evolving nature of threats and heterogeneous traffic patterns. Therefore, this study presents a structured and reproducible intrusion detection approach that integrates preprocessing and deep learning-based classification for binary detection in IoT networks. The datasets used are ToN_IoT and UNSW-NB15 datasets, which contain IoT network traffic data. This study deploys a meta-heuristic algorithm called Gray Wolf Optimizer (GWO) for feature selection. SMOTE is used for balancing the class sample, and MinMax and standard normalization for data scaling during preprocessing. A comparative analysis is performed across multiple deep learning models, including Convolutional Neural Network–Long Short-Term Memory (CNN–LSTM), Multi-Layer Perceptron (MLP), Deep Neural Network (DNN), Convolutional Neural Network (CNN), and Recurrent Neural Network (RNN). Results show that the CNN–LSTM model demonstrates strong performance consistency across datasets, achieving 99.68% and 92.05% accuracy on ToN_IoT and UNSW-NB15, respectively. Threshold sensitivity analysis reveals key detection and false-positive trade-offs for edge IDS. Through extensive performance evaluation and sensitivity analysis, this study highlights the importance of combining preprocessing, model evaluation, and threshold analysis for reliable IoT intrusion detection. Full article
(This article belongs to the Special Issue Security and Privacy Issues in the Internet of Cloud—2nd Edition)
Show Figures

Figure 1

43 pages, 4986 KB  
Article
Enhanced Data Security in Metadata-Governed Cloud IOT Using Optimized Provenance and Access Control Through MARShield, ThreshGuard and SentinelScheduler
by Abbi Kala, Mahalakshmi Guruvayur Suryanarayanan and Sendhilkumar Selvaradjou
Appl. Sci. 2026, 16(12), 6280; https://doi.org/10.3390/app16126280 - 22 Jun 2026
Viewed by 2781
Abstract
Manual data storage methods on various mobile devices, IoT devices, and traditional computing platforms still lack sufficient security governance due to the absence of a unified security framework. Unlike application controlled environments, manual storage locations such as file systems, removable media, and IoT [...] Read more.
Manual data storage methods on various mobile devices, IoT devices, and traditional computing platforms still lack sufficient security governance due to the absence of a unified security framework. Unlike application controlled environments, manual storage locations such as file systems, removable media, and IoT devices are highly susceptible to unauthorized access, misuse, and exfiltration. To address this problem, the paper proposes a security framework for manual storage systems using metadata, and the proposed framework includes three different algorithms, namely MARShield, ThreshGuard, and SentinelScheduler. These three algorithms operate together to ensure security for manual storage systems. MARShield is used for enforcing immutable metadata, multi-access rights based on tokens, and persistent source tracking by cryptographically securing provenance logs. ThreshGuard, on the other hand, enables the use of adaptive threshold-based misuse regulation and bottleneck-controlled serialized execution. SentinelScheduler optimizes the use of cryptography by incorporating trust-based application profiling and idle-time scheduling for heavy security operations. The proposed methodology is evaluated using a hybrid approach combining real-world datasets (CIC-IoT2023, TON-IoT, Bot-IoT and ISCX VPN non-VPN) and dataset-driven synthetic access pattern generation. Real datasets are used to model realistic IoT traffic behaviors, while additional synthetic scenarios are introduced to evaluate adaptability against evolving and previously unseen attack patterns. Network level features from these datasets are systematically transformed into storage-level access behaviors to evaluate metadata-driven access control. The experimental results indicate improved detection accuracy (94.6%), reduced false positive rate (4.3%), improved misuse control efficiency (92%) and scalability (94%). The proposed methodology for securing manual storage domains is scalable, adaptive, and portable, extending the security of applications and their associated domains. Full article
Show Figures

Figure 1

27 pages, 1800 KB  
Article
TLS-Aware Anomaly Detection for Encrypted IoT Traffic Using a β-Variational Autoencoder with ANOVA–Mutual Information Feature Selection
by Muhammad Nouman, Raja Ujjan and Muhsin Hassanu
Future Internet 2026, 18(6), 310; https://doi.org/10.3390/fi18060310 - 8 Jun 2026
Cited by 1 | Viewed by 835
Abstract
The rapid growth of the Internet of Things (IoT) has increased dependency on Transport Layer Security (TLS) for securing device communications, enhancing confidentiality while reducing the visibility required by traditional intrusion detection systems. As payload inspection becomes impractical in encrypted environments, anomaly detection [...] Read more.
The rapid growth of the Internet of Things (IoT) has increased dependency on Transport Layer Security (TLS) for securing device communications, enhancing confidentiality while reducing the visibility required by traditional intrusion detection systems. As payload inspection becomes impractical in encrypted environments, anomaly detection must instead rely on flow-level statistics and TLS metadata. This is challenging because IoT traffic is heterogeneous, non-stationary, and distributionally inconsistent across datasets, while many existing studies rely on single-dataset evaluation and therefore provide limited evidence of real-world generalisation. We introduce a TLS-aware anomaly detection framework that combines a β-Variational Autoencoder (β-VAE) with a hybrid ANOVA–Mutual Information (ANOVA–MI) feature-selection pipeline. The incremental contribution lies not in the individual use of these components, but in their integrated application to encrypted IoT anomaly detection under strict cross-dataset evaluation, where feature filtering, probabilistic latent regularisation, and threshold transferability are jointly examined without retraining or recalibration on target datasets. The framework models benign encrypted IoT traffic using probabilistic latent representations and identifies anomalies through reconstruction-error-based scoring. Network flows from the BoT-IoT, IoT-23, and ToN-IoT datasets were processed using Zeek and CICFlowMeter to construct a unified metadata feature space incorporating flow statistics and TLS attributes such as JA3 and JA3S fingerprints. The model was trained on benign BoT-IoT traffic and evaluated in both in-dataset and cross-dataset scenarios. The model achieves strong in-dataset performance on BoT-IoT (ROC-AUC 0.9996; F1 0.9922) and retains robust anomaly-ranking and threshold-based detection capability under cross-dataset domain shift (IoT-23: ROC-AUC 0.9882, F1 0.9422; ToN-IoT: ROC-AUC 0.9465, F1 0.8732). A comparative evaluation against deterministic autoencoders and classical baselines further indicates that the proposed β-VAE achieves stronger cross-dataset anomaly-ranking performance than the compared methods. These findings support the suitability of probabilistic latent modelling for privacy-preserving anomaly detection in encrypted IoT environments. Full article
(This article belongs to the Section Cybersecurity)
Show Figures

Graphical abstract

53 pages, 3701 KB  
Article
Closed-Set Heterogeneous Domain Adaptation for IoT Intrusion Detection: An Anchor-Based Benchmark Across Single- and Multi-Source Transfer
by Mohammad Chizari, Qublai Khan Ali Mirza, Abu Alam and Hassan Chizari
Sensors 2026, 26(11), 3610; https://doi.org/10.3390/s26113610 - 5 Jun 2026
Viewed by 580
Abstract
Closed-set heterogeneous domain adaptation (HDA) for Internet of Things (IoT) intrusion detection aims to transfer detection capabilities across environments that differ in devices, telemetry, feature schemas, attack implementations, label taxonomies, and target supervision availability. Although recent HDA methods report strong performance, their deployment [...] Read more.
Closed-set heterogeneous domain adaptation (HDA) for Internet of Things (IoT) intrusion detection aims to transfer detection capabilities across environments that differ in devices, telemetry, feature schemas, attack implementations, label taxonomies, and target supervision availability. Although recent HDA methods report strong performance, their deployment meaning is often unclear because improvements over a weak source-only baseline do not show how much target supervision headroom has been recovered or whether adaptation is preferable to direct target-side labelling under the same budget. This paper presents a controlled, anchor-based benchmark for closed-set HDA in IoT intrusion detection. Edge-IIoTset is used as the main fixed target dataset, with transfer from CICIDS2017, UNSW-NB15, CICIDS2017 + UNSW-NB15, and CICIDS2017 + NSL-KDD under single-source and multi-source settings. The benchmark defines fixed resolved contexts, Intersection and Union representation contracts, a five-class closed-set label contract, leakage-safe preprocessing, and an anchor ladder consisting of source-only, correlation alignment (CORAL), matched-budget target-only, and oracle target-only references. Geometric Graph Alignment (GGA) and the Joint Semantic Transfer Network (JSTN) are evaluated as the primary selected native single-source semi-supervised HDA (SS-HDA) and multi-source semi-supervised HDA (MS-HDA) exemplars, while the Prototype-Matching Graph Network (PMGN) and Conditional Weighting Adversarial Network (CWAN) provide 1:10 method coverage checks. Each method–context–ratio configuration is evaluated across twenty fixed seeds, and DA-versus-target-only differences are tested using paired seed-level statistical evidence. A compact second-target confirmatory experiment using ToN-IoT assesses whether the qualitative headroom recovery and same-budget deployment patterns remain visible under a different IoT/IIoT target. The results show that primary native HDA can recover substantial source-only-to-oracle headroom, but not uniformly. At the 1:10 labelled target ratio, GGA recovers 0.6330.835 of the available headroom across C1–C4, while JSTN recovers 0.7760.897 in the contemporary-source MS-HDA family and 0.8720.926 in the mixed-vintage family. Same-budget comparisons show that DA is deployment-competitive only in some contexts; in others, direct target-side supervised learning is stronger. The benchmark therefore shows that closed-set HDA should be evaluated as target-conditioned, context-resolved evidence rather than as a pooled method leaderboard. Full article
(This article belongs to the Special Issue Recent Advances in IoT Multi Sensors)
Show Figures

Figure 1

Back to TopTop