Machine learning approaches for intrusion Detection in IOT networks

محتوى المقالة الرئيسي

Assistant Lecturer. Ahmed Ridha Khudhur

الملخص

Internet of Things (IoT) technologies have introduced a new complexity in the network environment and made it larger, leading to the demand for accurate, robust and interpretable Intrusion Detection System (IDS). This study presents a machine-learning framework for multi-class IoT intrusion detection system (IDS) with the CICIoT2023 dataset. The proposed framework can solve the problems of severe class imbalance, multi-class classification, data leakage and model interpretability. The initial categories in the attack were merged into nine significant classes, then the data was preprocessed, oversampled with the SMOTE technique, and selected using the Random Forest technique. To guarantee reliable model evaluation, feature selection and SMOTE were integrated into a stratified five-fold cross-validation loop, and only performed on the training set of each fold. Logistic Regression, Decision Tree, Random Forest, XGBoost, LightGBM, CatBoost and HistGradientBoosting were comparatively assessed. In order to select the best model that performs well on the cross validation set, the model with the best Macro F1-scores of 0.9350 ± 0.0100 was chosen, which happened to be XGBoost, followed by Balanced Accuracy of 0.9400. The independent test set yielded 99.40% accuracy, 83.38% Balanced Accuracy, 80.25% Macro F1-score and 99.40% Weighted F1-score for the proposed model. The results of the per class analysis exhibited F1-scores of 1.00 for DDoS, DoS, and Mirai, while the extremely rare Brute Force and Other classes were not as successful, with F1 scores of 0.42 and 0.47, respectively. To make the model as transparent as possible, the SHAP analysis was performed, which identified the characteristics of flow duration and traffic-rate as the most influential features, including Rate, Srate and Drate. The results show that the proposed framework achieves good overall detection rate and presents a leakage-aware and interpretable multi-class IoT intrusion detection solution. The results also demonstrate the ongoing challenge of identifying very rare categories in attacks, suggesting the need for more sophisticated minority class learning strategies.

تفاصيل المقالة

كيفية الاقتباس
Khudhur, A. L. A. R. . (2026). Machine learning approaches for intrusion Detection in IOT networks. مجلة الشرق الأوسط للعلوم الإنسانية والثقافية, 6(3), 812–792. https://doi.org/10.56961/mejhss.v6i3.1740
القسم
المقالات