Score
Design, implement, and evaluate machine‑learning based intrusion detection systems that analyze network and IoT traffic to detect, classify, and flag malicious behavior at packet or flow granularity. This includes feature engineering for protocol‑specific flows, selecting and training ML models or anomaly detectors, and optimizing inference and deployment under resource constraints typical of network and embedded/edge devices.
This study addresses critical challenges in machine learning–based intrusion detection systems (IDS): dataset bias, misaligned evaluation metrics, and poor model generalizability. We conduct a systematic empirical analysis by performing the first large-scale, cross-classifier benchmark—evaluating ten mainstream classifiers (e.g., SVM, RF, XGBoost, ANN) across five widely used IDS datasets (KDDCUP’99, NSL-KDD, UNSW-NB15, CIC-IDS2017, CSE-CIC-IDS2018). Leveraging bibliometric analysis and tabular meta-analysis—including attack-type coverage, F1-score, and accuracy—we identify structural deficiencies in these datasets concerning attack representativeness, feature discriminability, and evaluation consistency. Based on these findings, we propose a dynamic dataset construction paradigm grounded in real-world network traffic characteristics. This paradigm supports the development of lightweight, highly generalizable next-generation IDS models. Our work delivers a reproducible methodological framework and practical guidelines for robust, evidence-based IDS research.
Existing machine learning (ML) and deep learning (DL) intrusion detection systems (IDS) for IoT edge environments lack empirical, multi-dimensional evaluation of performance–energy trade-offs under realistic workloads. Method: This study conducts the first systematic measurement of CPU utilization, energy consumption, and inference latency of ML/DL-IDS on real edge platforms under both benign and adversarial network traffic, while investigating the impact of software-defined networking (SDN) on dynamic resource orchestration and detection efficacy. We integrate SDN-based centralized control, real-time traffic emulation, multi-dimensional system monitoring, and ANOVA-based statistical validation. Results: Under attack, ML-IDS exhibits 47% higher average CPU utilization and 39% increased energy consumption; SDN reduces detection latency by 22% but incurs 8–15% control-plane overhead; DL models improve accuracy by 6.2% yet double inference energy cost. The work establishes empirical performance–energy trade-off patterns and SDN-mediated optimization mechanisms, providing foundational insights for designing lightweight, energy-aware edge security architectures.
To address the declining performance of traditional intrusion detection systems (IDS) in dynamic, large-scale, resource-constrained IoT environments—exacerbated by increasing encrypted traffic—this paper proposes an adaptive IDS framework integrating classical machine learning (e.g., Random Forest, SVM), deep learning (e.g., LSTM, CNN, autoencoders), and generative AI/large language models. This is the first systematic integration of multi-paradigm models to jointly optimize detection accuracy, computational efficiency, and model interpretability. Experimental results demonstrate that the proposed framework significantly reduces false positive rates, enhances detection of zero-day attacks and encrypted malicious traffic, achieves high classification accuracy with real-time responsiveness under stringent resource constraints, and incorporates built-in privacy-preserving mechanisms and ethical compliance safeguards.
In IoT network attack detection, feature inconsistency across heterogeneous flow exporters undermines model generalization and robustness. Method: This paper proposes a feature-consistency framework based on raw PCAP reprocessing: leveraging the HERA tool to uniformly parse and perform fine-grained flow labeling on Bot-IoT, IoT-23, and CICIoT23 datasets, thereby extracting standardized, exporter-agnostic features; subsequently, a Bagging–gradient-boosted decision tree ensemble is employed for modeling. Results: Experiments demonstrate significant improvements in cross-dataset detection accuracy and stability, validating that low-level traffic reconstruction and feature standardization critically enhance ML model robustness. The core contribution lies in unifying the feature generation pipeline at the PCAP source—bypassing heterogeneous flow exporters—thereby effectively mitigating dataset shift and evaluation bias.
To address escalating security vulnerabilities and the challenge of detecting diverse attack types in large-scale Internet of Things (IoT) networks, this paper proposes a hybrid machine learning intrusion detection system (IDS) based on an ensemble voting mechanism. The method innovatively integrates Random Forest, XGBoost, K-Nearest Neighbors (KNN), and AdaBoost into a scalable ensemble architecture, leveraging a weighted voting strategy to enhance robustness and multi-class attack discrimination. Comprehensive evaluation on the real-world IoT-23 dataset demonstrates that the proposed approach consistently outperforms individual baseline models in both binary and multi-class intrusion detection tasks, achieving average improvements of 5.2–8.7% in accuracy and F1-score. Notably, it exhibits superior detection capability against sophisticated threats—including Advanced Persistent Threats (APTs), Distributed Denial-of-Service (DDoS) attacks, and malicious scanning. The implementation is open-sourced and designed for practical deployment in resource-constrained IoT environments.
This work addresses the vulnerability of existing IoT intrusion detection systems (IDS) to black-box adversarial attacks under real-world deployment constraints, a challenge often overlooked in prior research. The authors propose a practical black-box adversarial attack method that generates highly stealthy adversarial traffic without access to internal model information, effectively exposing the fragility of mainstream IoT IDS. To counter this threat, they also design a lightweight defense mechanism that significantly enhances system robustness against such attacks. Experimental results demonstrate that the proposed attack achieves high success rates in realistic settings, while the defense effectively identifies the majority of adversarial samples and outperforms existing approaches in both efficacy and efficiency, thereby bridging the critical gap between theoretical security research and practical deployment requirements.
This study investigates the robustness of artificial intelligence in two critical security tasks: network intrusion detection and identification of side-channel information leakage in cryptographic implementations. To address performance degradation under distribution shifts and unknown traffic scenarios, we systematically evaluate multiple machine learning approaches on the NSL-KDD and CIC-IDS datasets. Our results demonstrate that models achieve near-perfect detection accuracy in stable environments but suffer significant performance drops under distributional shifts. Furthermore, AI methods effectively identify feature patterns consistent with side-channel leakage, confirming their potential for security analysis of cryptographic implementations. This work provides an empirical foundation and methodological insights for enhancing the generalization capabilities of AI-driven security systems.
The growth of networked and IoT systems has intensified cyber-security threats and exposed the limits of traditional signature-based intrusion detection. Although machine-learning-based intrusion detection systems often report strong benchmark performance, high ac- curacy within a single dataset does not necessarily guarantee reliable performance in unseen network environments. This study investigates the generalisation capability of supervised machine learning models for intrusion detection using UNSW-NB15 and TON_IoT. Random Forest, Logistic Regression, and Naive Bayes were evaluated under same-dataset and cross-dataset settings. Random Forest achieved the strongest same dataset performance, with 95.08% accuracy on UNSW-NB15 and 99.79% on TON_IoT, but performance dropped sharply in cross-dataset testing. When trained on UNSW-NB15 and tested on TON_IoT or vice versa, below 40% accuracy. These results reveal a significant generalisation gap in intrusion detection. We connect this challenge to affective computing and human-centric AI, where behavioural signal analysis, anomaly detection, domain shift, and context-sensitive modelling are also central. This framing highlights the need for adaptive, generalisable cyber-security models that can operate across changing network and IoT environments.
This work addresses the challenge of securing resource-constrained Internet of Things (IoT) devices against prevalent threats such as denial-of-service and man-in-the-middle attacks. To this end, the authors propose a lightweight intrusion detection approach tailored for microcontrollers, which integrates an optimized decision tree with a compact neural network to achieve high-accuracy, real-time detection under stringent memory and computational constraints. Experimental evaluation in heterogeneous IoT environments demonstrates that the proposed method attains detection accuracies of 99% using the decision tree component and 96% with the neural network component, substantially outperforming existing solutions. The approach effectively balances security assurance with deployment efficiency and hardware limitations, offering a practical defense mechanism for low-resource IoT deployments.
This work addresses the challenge of achieving both high accuracy and robustness in intrusion detection under dynamic traffic conditions in Software-Defined Networking (SDN) environments, where conventional security mechanisms often fall short. Fixed machine learning models are particularly susceptible to overfitting or underfitting, leading to performance degradation. To overcome these limitations, the paper proposes an adaptive machine learning framework tailored for SDN, which integrates multiple algorithms within the controller and dynamically selects the optimal model based on real-time traffic characteristics and type-specific metrics. The framework further incorporates automated hyperparameter tuning to enhance model adaptability. Experimental results demonstrate that this approach significantly improves detection performance and generalization capability across diverse network conditions, effectively mitigating model mismatch and thereby strengthening both system security and operational feasibility.