International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1722603

1722603 Vol 5 · Issue 6 Download Paper

Lightweight Adaptive Intrusion Detection for Resource-Constrained IoT Networks Using Hybrid Machine Learning

S Gladson Oliver T Suguna C Aswini

Subject area: Science,Engineering and Technology  ·  Area of research: IoT Networks

Abstract

The rapid expansion of Internet of Things (IoT) systems has increased the number of resource-constrained devices exposed to network attacks. Conventional intrusion-detection systems often apply one computationally demanding classifier to every flow, which is inefficient for gateway and edge environments. This paper proposes a Lightweight Adaptive Intrusion Detection System (LA-IDS) that combines feature reduction, a low-cost Logistic Regression (LR) primary model, confidence-aware escalation, and a Random Forest (RF) secondary model. The framework is evaluated using the Bot-IoT dataset introduced in 2019. To avoid misleading results caused by the extreme attack dominance of Bot-IoT, controlled balanced subsets are constructed for binary and multiclass evaluation while the original attack taxonomy is preserved. Thirty-eight deployable candidate predictors are reduced to 16 using mutual information and tree-based importance. At the selected confidence threshold of 0.90, the reference binary benchmark obtains 98.93% accuracy, 98.75% precision, 99.11% recall, and 98.93% F1-score, with a false-positive rate of 1.26%. Only 35.7% of flows require RF inference. Average per-flow latency is consequently reduced from 1.54 ms for RF-only inference to 0.65 ms for LA-IDS, a reduction of approximately 57.8%. A four-class Bot-IoT experiment covering Normal, DDoS, DoS, and Reconnaissance traffic yields a macro F1-score of 98.30%. These results show that conditional hybrid inference can preserve strong detection performance while reducing average computational demand, making LA-IDS suitable for IoT gateways and edge-assisted security systems.

Keywords

internet of things, bot-iot, intrusion detection, lightweight machine learning, hybrid classification, random forest, adaptive inference, edge security.

How to cite this paper

S Gladson Oliver, T Suguna, C Aswini "Lightweight Adaptive Intrusion Detection for Resource-Constrained IoT Networks Using Hybrid Machine Learning" Iconic Research And Engineering Journals Volume 5 Issue 6 2021 Page 463-474
S Gladson Oliver, T Suguna, C Aswini "Lightweight Adaptive Intrusion Detection for Resource-Constrained IoT Networks Using Hybrid Machine Learning" Iconic Research And Engineering Journals, vol. 5, no. 6, Dec. 2021
S Gladson Oliver, T Suguna, C Aswini (2021). Lightweight Adaptive Intrusion Detection for Resource-Constrained IoT Networks Using Hybrid Machine Learning. Iconic Research And Engineering Journals, 5(6).
S Gladson Oliver, T Suguna, C Aswini "Lightweight Adaptive Intrusion Detection for Resource-Constrained IoT Networks Using Hybrid Machine Learning" Iconic Research And Engineering Journals, vol. 5, no. 6, Dec. 2021.
@article{1722603,
      author = {S Gladson Oliver, T Suguna, C Aswini},
      title = {Lightweight Adaptive Intrusion Detection for Resource-Constrained IoT Networks Using Hybrid Machine Learning},
      journal = {Iconic Research And Engineering Journals},
      year = {2021},
      volume = {5},
      number = {6},
      pages = {463-474},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1722603.pdf},
      abstract = {The rapid expansion of Internet of Things (IoT) systems has increased the number of resource-constrained devices exposed to network attacks. Conventional intrusion-detection systems often apply one computationally demanding classifier to every flow, which is inefficient for gateway and edge environments. This paper proposes a Lightweight Adaptive Intrusion Detection System (LA-IDS) that combines feature reduction, a low-cost Logistic Regression (LR) primary model, confidence-aware escalation, and a Random Forest (RF) secondary model. The framework is evaluated using the Bot-IoT dataset introduced in 2019. To avoid misleading results caused by the extreme attack dominance of Bot-IoT, controlled balanced subsets are constructed for binary and multiclass evaluation while the original attack taxonomy is preserved. Thirty-eight deployable candidate predictors are reduced to 16 using mutual information and tree-based importance. At the selected confidence threshold of 0.90, the reference binary benchmark obtains 98.93% accuracy, 98.75% precision, 99.11% recall, and 98.93% F1-score, with a false-positive rate of 1.26%. Only 35.7% of flows require RF inference. Average per-flow latency is consequently reduced from 1.54 ms for RF-only inference to 0.65 ms for LA-IDS, a reduction of approximately 57.8%. A four-class Bot-IoT experiment covering Normal, DDoS, DoS, and Reconnaissance traffic yields a macro F1-score of 98.30%. These results show that conditional hybrid inference can preserve strong detection performance while reducing average computational demand, making LA-IDS suitable for IoT gateways and edge-assisted security systems.},
      keywords = {internet of things, bot-iot, intrusion detection, lightweight machine learning, hybrid classification, random forest, adaptive inference, edge security.},
      month = {December},
  }