Home / Current Issue / Paper 1722603
Lightweight Adaptive Intrusion Detection for Resource-Constrained IoT Networks Using Hybrid Machine Learning
Subject area: Science,Engineering and Technology · Area of research: IoT Networks
Abstract
The rapid expansion of Internet of Things (IoT) systems has increased the number of resource-constrained devices exposed to network attacks. Conventional intrusion-detection systems often apply one computationally demanding classifier to every flow, which is inefficient for gateway and edge environments. This paper proposes a Lightweight Adaptive Intrusion Detection System (LA-IDS) that combines feature reduction, a low-cost Logistic Regression (LR) primary model, confidence-aware escalation, and a Random Forest (RF) secondary model. The framework is evaluated using the Bot-IoT dataset introduced in 2019. To avoid misleading results caused by the extreme attack dominance of Bot-IoT, controlled balanced subsets are constructed for binary and multiclass evaluation while the original attack taxonomy is preserved. Thirty-eight deployable candidate predictors are reduced to 16 using mutual information and tree-based importance. At the selected confidence threshold of 0.90, the reference binary benchmark obtains 98.93% accuracy, 98.75% precision, 99.11% recall, and 98.93% F1-score, with a false-positive rate of 1.26%. Only 35.7% of flows require RF inference. Average per-flow latency is consequently reduced from 1.54 ms for RF-only inference to 0.65 ms for LA-IDS, a reduction of approximately 57.8%. A four-class Bot-IoT experiment covering Normal, DDoS, DoS, and Reconnaissance traffic yields a macro F1-score of 98.30%. These results show that conditional hybrid inference can preserve strong detection performance while reducing average computational demand, making LA-IDS suitable for IoT gateways and edge-assisted security systems.
Keywords
internet of things, bot-iot, intrusion detection, lightweight machine learning, hybrid classification, random forest, adaptive inference, edge security.
How to cite this paper
@article{1722603,
author = {S Gladson Oliver, T Suguna, C Aswini},
title = {Lightweight Adaptive Intrusion Detection for Resource-Constrained IoT Networks Using Hybrid Machine Learning},
journal = {Iconic Research And Engineering Journals},
year = {2021},
volume = {5},
number = {6},
pages = {463-474},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1722603.pdf},
abstract = {The rapid expansion of Internet of Things (IoT) systems has increased the number of resource-constrained devices exposed to network attacks. Conventional intrusion-detection systems often apply one computationally demanding classifier to every flow, which is inefficient for gateway and edge environments. This paper proposes a Lightweight Adaptive Intrusion Detection System (LA-IDS) that combines feature reduction, a low-cost Logistic Regression (LR) primary model, confidence-aware escalation, and a Random Forest (RF) secondary model. The framework is evaluated using the Bot-IoT dataset introduced in 2019. To avoid misleading results caused by the extreme attack dominance of Bot-IoT, controlled balanced subsets are constructed for binary and multiclass evaluation while the original attack taxonomy is preserved. Thirty-eight deployable candidate predictors are reduced to 16 using mutual information and tree-based importance. At the selected confidence threshold of 0.90, the reference binary benchmark obtains 98.93% accuracy, 98.75% precision, 99.11% recall, and 98.93% F1-score, with a false-positive rate of 1.26%. Only 35.7% of flows require RF inference. Average per-flow latency is consequently reduced from 1.54 ms for RF-only inference to 0.65 ms for LA-IDS, a reduction of approximately 57.8%. A four-class Bot-IoT experiment covering Normal, DDoS, DoS, and Reconnaissance traffic yields a macro F1-score of 98.30%. These results show that conditional hybrid inference can preserve strong detection performance while reducing average computational demand, making LA-IDS suitable for IoT gateways and edge-assisted security systems.},
keywords = {internet of things, bot-iot, intrusion detection, lightweight machine learning, hybrid classification, random forest, adaptive inference, edge security.},
month = {December},
}