International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1722603

1722603 Vol 5 · Issue 6 Download Paper

Lightweight Adaptive Intrusion Detection for Resource-Constrained IoT Networks Using Hybrid Machine Learning

S Gladson Oliver T Suguna C Aswini

Subject area: Science,Engineering and Technology  ·  Area of research: IoT Networks

DOI: https://doi.org/10.64388/IREV5I6-1722603

Abstract

The rapid expansion of Internet of Things (IoT) systems has increased the number of resource-constrained devices exposed to network attacks. Conventional intrusion-detection systems often apply one computationally demanding classifier to every flow, which is inefficient for gateway and edge environments. This paper proposes a Lightweight Adaptive Intrusion Detection System (LA-IDS) that combines feature reduction, a low-cost Logistic Regression (LR) primary model, confidence-aware escalation, and a Random Forest (RF) secondary model. The framework is evaluated using the Bot-IoT dataset introduced in 2019. To avoid misleading results caused by the extreme attack dominance of Bot-IoT, controlled balanced subsets are constructed for binary and multiclass evaluation while the original attack taxonomy is preserved. Thirty-eight deployable candidate predictors are reduced to 16 using mutual information and tree-based importance. At the selected confidence threshold of 0.90, the reference binary benchmark obtains 98.93% accuracy, 98.75% precision, 99.11% recall, and 98.93% F1-score, with a false-positive rate of 1.26%. Only 35.7% of flows require RF inference. Average per-flow latency is consequently reduced from 1.54 ms for RF-only inference to 0.65 ms for LA-IDS, a reduction of approximately 57.8%. A four-class Bot-IoT experiment covering Normal, DDoS, DoS, and Reconnaissance traffic yields a macro F1-score of 98.30%. These results show that conditional hybrid inference can preserve strong detection performance while reducing average computational demand, making LA-IDS suitable for IoT gateways and edge-assisted security systems.

Keywords

internet of things, bot-iot, intrusion detection, lightweight machine learning, hybrid classification, random forest, adaptive inference, edge security.

References

[1] N. Koroniotis, N. Moustafa, E. Sitnikova, and B. Turnbull, “Towards the development of realistic botnet dataset in the Internet of Things for network forensic analytics: Bot-IoT dataset,” Future Generation Computer Systems, vol. 100, pp. 779–796, 2019.

[2] N. Moustafa and J. Slay, “UNSW-NB15: A comprehensive data set for network intrusion detection systems,” in Proc. Military Communications and Information Systems Conference (MilCIS), 2015.

[3] Y. Meidan et al., “N-BaIoT: Network-based detection of IoT botnet attacks using deep autoencoders,” IEEE Pervasive Computing, vol. 17, no. 3, pp. 12–22, 2018.

[4] Y. Mirsky, T. Doitshman, Y. Elovici, and A. Shabtai, “Kitsune: An ensemble of autoencoders for online network intrusion detection,” in Proc. Network and Distributed System Security Symposium (NDSS), 2018.

[5] A. Khraisat, I. Gondal, P. Vamplew, and J. Kamruzzaman, “Survey of intrusion detection systems: Techniques, datasets and challenges,” Cybersecurity, vol. 2, 2019.

[6] M. Ring, S. Wunderlich, D. Scheuring, D. Landes, and A. Hotho, “A survey of network-based intrusion detection data sets,” Computers & Security, vol. 86, pp. 147–167, 2019.

[7] I. H. Sarker, “Machine learning: Algorithms, real-world applications and research directions,” SN Computer Science, vol. 2, 2021.

[8] L. Breiman, “Random forests,” Machine Learning, vol. 45, pp. 5–32, 2001.

[9] C. Cortes and V. Vapnik, “Support-vector networks,” Machine Learning, vol. 20, pp. 273–297, 1995.

[10] J. H. Friedman, “Greedy function approximation: A gradient boosting machine,” The Annals of Statistics, vol. 29, no. 5, pp. 1189–1232, 2001.

[11] F. Pedregosa et al., “Scikit-learn: Machine learning in Python,” Journal of Machine Learning Research, vol. 12, pp. 2825–2830, 2011.

[12] T. Fawcett, “An introduction to ROC analysis,” Pattern Recognition Letters, vol. 27, no. 8, pp. 861–874, 2006.

[13] J. Davis and M. Goadrich, “The relationship between Precision-Recall and ROC curves,” in Proc. 23rd International Conference on Machine Learning, 2006.

[14] R. Sommer and V. Paxson, “Outside the closed world: On using machine learning for network intrusion detection,” in Proc. IEEE Symposium on Security and Privacy, 2010.

[15] M. Roesch, “Snort: Lightweight intrusion detection for networks,” in Proc. 13th USENIX Conference on System Administration, 1999.

[16] N. Moustafa, “A new distributed architecture for evaluating AI-based security systems at the edge: Network TON_IoT datasets,” Sustainable Cities and Society, vol. 72, 2021.

[17] M. A. Ferrag, L. Maglaras, S. Moschoyiannis, and H. Janicke, “Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study,” Journal of Information Security and Applications, 2020.

[18] M. Tavallaee, E. Bagheri, W. Lu, and A. A. Ghorbani, “A detailed analysis of the KDD CUP 99 data set,” in Proc. IEEE Symposium on Computational Intelligence for Security and Defense Applications, 2009.

[19] V. Chandola, A. Banerjee, and V. Kumar, “Anomaly detection: A survey,” ACM Computing Surveys, vol. 41, no. 3, 2009.

How to cite this paper

S Gladson Oliver, T Suguna, C Aswini "Lightweight Adaptive Intrusion Detection for Resource-Constrained IoT Networks Using Hybrid Machine Learning" Iconic Research And Engineering Journals Volume 5 Issue 6 2021 Page 463-474 https://doi.org/10.64388/IREV5I6-1722603
S Gladson Oliver, T Suguna, C Aswini "Lightweight Adaptive Intrusion Detection for Resource-Constrained IoT Networks Using Hybrid Machine Learning" Iconic Research And Engineering Journals, vol. 5, no. 6, Dec. 2021, doi: https://doi.org/10.64388/IREV5I6-1722603
S Gladson Oliver, T Suguna, C Aswini (2021). Lightweight Adaptive Intrusion Detection for Resource-Constrained IoT Networks Using Hybrid Machine Learning. Iconic Research And Engineering Journals, 5(6). doi: https://doi.org/10.64388/IREV5I6-1722603
S Gladson Oliver, T Suguna, C Aswini "Lightweight Adaptive Intrusion Detection for Resource-Constrained IoT Networks Using Hybrid Machine Learning" Iconic Research And Engineering Journals, vol. 5, no. 6, Dec. 2021. Crossref, https://doi.org/10.64388/IREV5I6-1722603
@article{1722603,
      author = {S Gladson Oliver, T Suguna, C Aswini},
      title = {Lightweight Adaptive Intrusion Detection for Resource-Constrained IoT Networks Using Hybrid Machine Learning},
      journal = {Iconic Research And Engineering Journals},
      year = {2021},
      volume = {5},
      number = {6},
      pages = {463-474},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1722603.pdf},
      abstract = {The rapid expansion of Internet of Things (IoT) systems has increased the number of resource-constrained devices exposed to network attacks. Conventional intrusion-detection systems often apply one computationally demanding classifier to every flow, which is inefficient for gateway and edge environments. This paper proposes a Lightweight Adaptive Intrusion Detection System (LA-IDS) that combines feature reduction, a low-cost Logistic Regression (LR) primary model, confidence-aware escalation, and a Random Forest (RF) secondary model. The framework is evaluated using the Bot-IoT dataset introduced in 2019. To avoid misleading results caused by the extreme attack dominance of Bot-IoT, controlled balanced subsets are constructed for binary and multiclass evaluation while the original attack taxonomy is preserved. Thirty-eight deployable candidate predictors are reduced to 16 using mutual information and tree-based importance. At the selected confidence threshold of 0.90, the reference binary benchmark obtains 98.93% accuracy, 98.75% precision, 99.11% recall, and 98.93% F1-score, with a false-positive rate of 1.26%. Only 35.7% of flows require RF inference. Average per-flow latency is consequently reduced from 1.54 ms for RF-only inference to 0.65 ms for LA-IDS, a reduction of approximately 57.8%. A four-class Bot-IoT experiment covering Normal, DDoS, DoS, and Reconnaissance traffic yields a macro F1-score of 98.30%. These results show that conditional hybrid inference can preserve strong detection performance while reducing average computational demand, making LA-IDS suitable for IoT gateways and edge-assisted security systems.},
      keywords = {internet of things, bot-iot, intrusion detection, lightweight machine learning, hybrid classification, random forest, adaptive inference, edge security.},
      month = {December},
      doi = {https://doi.org/10.64388/IREV5I6-1722603}
  }