build ml intrusion detectors

Design, implement, and evaluate machine‑learning based intrusion detection systems that analyze network and IoT traffic to detect, classify, and flag malicious behavior at packet or flow granularity. This includes feature engineering for protocol‑specific flows, selecting and training ML models or anomaly detectors, and optimizing inference and deployment under resource constraints typical of network and embedded/edge devices.

buildmlintrusiondetectors

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
-0.08
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Recommended Survey Paper

Quick overview of the field
View more

Must-Read Papers

Most classic and influential ideas
View more

Existing machine learning (ML) and deep learning (DL) intrusion detection systems (IDS) for IoT edge environments lack empirical, multi-dimensional evaluation of performance–energy trade-offs under realistic workloads. Method: This study conducts the first systematic measurement of CPU utilization, energy consumption, and inference latency of ML/DL-IDS on real edge platforms under both benign and adversarial network traffic, while investigating the impact of software-defined networking (SDN) on dynamic resource orchestration and detection efficacy. We integrate SDN-based centralized control, real-time traffic emulation, multi-dimensional system monitoring, and ANOVA-based statistical validation. Results: Under attack, ML-IDS exhibits 47% higher average CPU utilization and 39% increased energy consumption; SDN reduces detection latency by 22% but incurs 8–15% control-plane overhead; DL models improve accuracy by 6.2% yet double inference energy cost. The work establishes empirical performance–energy trade-off patterns and SDN-mediated optimization mechanisms, providing foundational insights for designing lightweight, energy-aware edge security architectures.

Analyzing SDN integration effects on intrusion detection efficiencyAssessing energy and CPU impact of edge-deployed IDS solutionsEvaluating ML-based IDS performance in IoT under cyber threats

To address the declining performance of traditional intrusion detection systems (IDS) in dynamic, large-scale, resource-constrained IoT environments—exacerbated by increasing encrypted traffic—this paper proposes an adaptive IDS framework integrating classical machine learning (e.g., Random Forest, SVM), deep learning (e.g., LSTM, CNN, autoencoders), and generative AI/large language models. This is the first systematic integration of multi-paradigm models to jointly optimize detection accuracy, computational efficiency, and model interpretability. Experimental results demonstrate that the proposed framework significantly reduces false positive rates, enhances detection of zero-day attacks and encrypted malicious traffic, achieves high classification accuracy with real-time responsiveness under stringent resource constraints, and incorporates built-in privacy-preserving mechanisms and ethical compliance safeguards.

Addressing dynamic IoT network challenges in IDSEnhancing IoT security with ML/DL-based intrusion detectionEvaluating ML techniques for real-world IoT applications

Revisiting Network Traffic Analysis: Compatible network flows for ML models

Nov 11, 2025
JV
João Vitorino
🏛️ GECAD | ISEP | Polytechnic of Porto

In IoT network attack detection, feature inconsistency across heterogeneous flow exporters undermines model generalization and robustness. Method: This paper proposes a feature-consistency framework based on raw PCAP reprocessing: leveraging the HERA tool to uniformly parse and perform fine-grained flow labeling on Bot-IoT, IoT-23, and CICIoT23 datasets, thereby extracting standardized, exporter-agnostic features; subsequently, a Bagging–gradient-boosted decision tree ensemble is employed for modeling. Results: Experiments demonstrate significant improvements in cross-dataset detection accuracy and stability, validating that low-level traffic reconstruction and feature standardization critically enhance ML model robustness. The core contribution lies in unifying the feature generation pipeline at the PCAP source—bypassing heterogeneous flow exporters—thereby effectively mitigating dataset shift and evaluation bias.

Complex IoT network traffic patterns are difficult to accurately represent for attack detectionExisting cybersecurity datasets lack compatibility for trustworthy ML model evaluationNetwork traffic flow exporters create inconsistent features affecting ML model generalization

To address escalating security vulnerabilities and the challenge of detecting diverse attack types in large-scale Internet of Things (IoT) networks, this paper proposes a hybrid machine learning intrusion detection system (IDS) based on an ensemble voting mechanism. The method innovatively integrates Random Forest, XGBoost, K-Nearest Neighbors (KNN), and AdaBoost into a scalable ensemble architecture, leveraging a weighted voting strategy to enhance robustness and multi-class attack discrimination. Comprehensive evaluation on the real-world IoT-23 dataset demonstrates that the proposed approach consistently outperforms individual baseline models in both binary and multi-class intrusion detection tasks, achieving average improvements of 5.2–8.7% in accuracy and F1-score. Notably, it exhibits superior detection capability against sophisticated threats—including Advanced Persistent Threats (APTs), Distributed Denial-of-Service (DDoS) attacks, and malicious scanning. The implementation is open-sourced and designed for practical deployment in resource-constrained IoT environments.

Combine multiple ML models for robustnessEvaluate hybrid models on IoT-23 datasetImprove IoT intrusion detection accuracy

This work addresses the vulnerability of existing IoT intrusion detection systems (IDS) to black-box adversarial attacks under real-world deployment constraints, a challenge often overlooked in prior research. The authors propose a practical black-box adversarial attack method that generates highly stealthy adversarial traffic without access to internal model information, effectively exposing the fragility of mainstream IoT IDS. To counter this threat, they also design a lightweight defense mechanism that significantly enhances system robustness against such attacks. Experimental results demonstrate that the proposed attack achieves high success rates in realistic settings, while the defense effectively identifies the majority of adversarial samples and outperforms existing approaches in both efficacy and efficiency, thereby bridging the critical gap between theoretical security research and practical deployment requirements.

adversarial attacksblack-box attacksevasion attacks

Latest Papers

What's happening recently
View more

This study investigates the robustness of artificial intelligence in two critical security tasks: network intrusion detection and identification of side-channel information leakage in cryptographic implementations. To address performance degradation under distribution shifts and unknown traffic scenarios, we systematically evaluate multiple machine learning approaches on the NSL-KDD and CIC-IDS datasets. Our results demonstrate that models achieve near-perfect detection accuracy in stable environments but suffer significant performance drops under distributional shifts. Furthermore, AI methods effectively identify feature patterns consistent with side-channel leakage, confirming their potential for security analysis of cryptographic implementations. This work provides an empirical foundation and methodological insights for enhancing the generalization capabilities of AI-driven security systems.

AI robustnesscryptographic leakageintrusion detection

The growth of networked and IoT systems has intensified cyber-security threats and exposed the limits of traditional signature-based intrusion detection. Although machine-learning-based intrusion detection systems often report strong benchmark performance, high ac- curacy within a single dataset does not necessarily guarantee reliable performance in unseen network environments. This study investigates the generalisation capability of supervised machine learning models for intrusion detection using UNSW-NB15 and TON_IoT. Random Forest, Logistic Regression, and Naive Bayes were evaluated under same-dataset and cross-dataset settings. Random Forest achieved the strongest same dataset performance, with 95.08% accuracy on UNSW-NB15 and 99.79% on TON_IoT, but performance dropped sharply in cross-dataset testing. When trained on UNSW-NB15 and tested on TON_IoT or vice versa, below 40% accuracy. These results reveal a significant generalisation gap in intrusion detection. We connect this challenge to affective computing and human-centric AI, where behavioural signal analysis, anomaly detection, domain shift, and context-sensitive modelling are also central. This framing highlights the need for adaptive, generalisable cyber-security models that can operate across changing network and IoT environments.

cyber-securitydomain shiftgeneralisation

This work addresses the challenge of securing resource-constrained Internet of Things (IoT) devices against prevalent threats such as denial-of-service and man-in-the-middle attacks. To this end, the authors propose a lightweight intrusion detection approach tailored for microcontrollers, which integrates an optimized decision tree with a compact neural network to achieve high-accuracy, real-time detection under stringent memory and computational constraints. Experimental evaluation in heterogeneous IoT environments demonstrates that the proposed method attains detection accuracies of 99% using the decision tree component and 96% with the neural network component, substantially outperforming existing solutions. The approach effectively balances security assurance with deployment efficiency and hardware limitations, offering a practical defense mechanism for low-resource IoT deployments.

cyber threatsintrusion detectionIoT security

This work addresses the challenge of achieving both high accuracy and robustness in intrusion detection under dynamic traffic conditions in Software-Defined Networking (SDN) environments, where conventional security mechanisms often fall short. Fixed machine learning models are particularly susceptible to overfitting or underfitting, leading to performance degradation. To overcome these limitations, the paper proposes an adaptive machine learning framework tailored for SDN, which integrates multiple algorithms within the controller and dynamically selects the optimal model based on real-time traffic characteristics and type-specific metrics. The framework further incorporates automated hyperparameter tuning to enhance model adaptability. Experimental results demonstrate that this approach significantly improves detection performance and generalization capability across diverse network conditions, effectively mitigating model mismatch and thereby strengthening both system security and operational feasibility.

Dynamic Algorithm SelectionIntrusion DetectionMachine Learning

Hot Scholars

KD

Kishor Datta Gupta

Assistant Professor of Computer Science, Clark Atlanta University | Senior Member, IEEE
Physics Guided Neural NetworkPhysics Informed Machine LearningContext-Aware Machine learning
KW

Kawser Wazed Nafi

PhD Student, University of Saskatchewan
Multi-Lang. Soft. Dev.AI4SEBig-Data in SEIoT Sec.
MA

Mohsen Amini Salehi

Associate Professor of Computer Science and Engineering, University of North Texas
Cloud and Edge Computing
DI

Dong In Kim

Sungkyunkwan University (SKKU)
Wireless CommunicationsInternet of ThingsWireless Power TransferConnected Intelligence
XS

Xiyu Shi

Institute for Digital Technologies, Loughborough University London
Speech signal processmobile and wireless communicationnetwork securityInternet of things