International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1722957

1722957 Vol 10 · Issue 3 Download Paper

Comparative Analysis of Machine Learning Techniques for Intrusion Detection In Nigerian IoT Networks: A Systematic Literature Review

Ojima Gabriella Ob’lama Eru, Akwuma Nathaniel Ahiaba, Solomon Ridwan Kolapo Kureve, Stephanie Nguhemen

Subject area: Science,Engineering and Technology  ·  Area of research: Machine Learning

DOI: https://doi.org/10.64388/IREV10I3-1722957

Abstract

A large part of the increase in cyber threats to the network of Nigeria is the introduction of IoT devices in the areas of healthcare, smart homes, transportation, surveillance, banking, and business. These cyber threats include the likes of DDoS, malware injection, spoofing, unauthorized access. In this paper, we summarize a literature review and a comparative analysis of the techniques used in machine learning for intrusion detection in IoT networks, with a focus on their suitability for resource-constrained environments in Nigeria. PRISMA framework and Parsifal guided the process of reviewing and managing. Out of 850 records discovered on the different online platforms that are IEEE Xplore, Scopus, ScienceDirect, SpringerLink, and Google Scholar, the research documented 30 peer-reviewed studies which were published between 2021 and 2026 and included 30 papers for final synthesis. The most commonly used techniques in the IoT intrusion detection literature are Random Forest, Support Vector Machine, Decision Tree, K-Nearest Neighbors, Artificial Neural Networks, Convolutional Neural Networks (CNN), and Long ShortTerm Memory (LSTM) models. CNN and LSTM models usually had the highest reported detection scores, being about 96-99% in accuracy, precision, recall, and F1-score; however, their high computational and memory requirements limit their practical deployment on low-power IoT devices. Random Forest is evaluated as the best choice because of its appropriate overall balance in terms of reporting high accuracy statistics (95-99%) and also the moderate computational cost with the strong suitability rating for Nigeria's current IoT infrastructure. Decision Tree and KNN were also mentioned as lightweight alternatives, but they could stand lower performance compared to the complex attacks. The study declares that for Nigeria's IoT cybersecurity resilience to be effective, it is imperative to have accurate, lightweight, explainable, and context-aware intrusion detection model.

Keywords

Internet of Things, Intrusion Detection System, Machine Learning, Deep Learning, PRISMA, Random Forest, Resource-Constrained Environment, Nigeria

References

[5] -

[9] . Table 2 consolidates the performance ranges reported in the project and combines them with the review- based computational-cost and Nigerian-suitability ratings. The ranges are descriptive values reported by heterogeneous studies; they should not be read as estimates from a common dataset or experimental protocol. Table 2: Comparative Performance and Deployment Suitability Technique Reported Ranges (%) Cost Nigeria Fit Random Forest Acc 95-99 P 94-99 R 94-98 F1 94-98 Moderate Very High SVM Acc 90-97 P 89-96 R 88-95 F1 89-95 Moderate Moderate Decision Tree Acc 88-95 P 87-94 R 86-93 F1 87-93 Low High KNN Acc 85-94 P 84-93 R 83-92 F1 84-92 Low High CNN Acc 96-99 P 95-99 R 95-99 F1 95-99 High Low Technique Reported Ranges (%) Cost Nigeria Fit LSTM Acc 96-99 P 95-99 R 95-99 F1 95-99 Very High Low Note: Acc = accuracy; P = precision; R = recall. Values are descriptive author-reported ranges from heterogeneous studies and are not pooled estimates. CNN and LSTM scored the most fantastic forecast ranges in the reporting of 96-99 which were dedicated to the partnering of four fundamental metrics. Their positive link is the same as local feature patterns where they learn and temporal dependencies that they model are of CNNs and LSTMs, respectively. Nevertheless, the same architectures were allocated high computational costs due to the requirements of larger memory, more training time, and more inference capacity. The bad quality of the model does not necessarily mean that it fails, and we can make it with uncompressed models on powerful gateways, edge servers, fog nodes, or any cloud infrastructure but not on low-energy end devices. Random Forest reported an accuracy rate of 95-99%, precision of 94-99%, recall of 94-98%, and F1-score of 94-98% with moderate computational cost. This configuration produced the strongest overall suitability rating. The model is relatively impervious to the impact of noisy and nonlinear data; it supports the analysis of importance of feature, and it can be installed or updated on the hardware of the gateway class. However, its major drawbacks are the memory growth that arise from large ensembles and the requirement of calibrating the class weights and thresholds for targeted class imbalances. SVM does pretty good; however, Random Forest runs the show, and it is ideal for situations where the feature spaces are very high and the control training samples are enough. Despite its technical features, big data traffic through nonlinear kernels is often cited as the explanation for the increased cost of training and inference. Decision Tree and KNN were lower on the performance scale, but they were rated the highest on the suitability scale. A small tree is both understandable and cheap to run, while KNN is easy to implement; yet KNN keeps the training examples, and its prediction cost increases with the dataset size. Hence, they are best seen as lightweight baselines, edge filters, or hierarchical construction parts rather than the first choice of detectors against complex attacks. Figure 3 depicts a descriptive midpoint composite created from the ranges in Table 2. The visualization brings out the central tradeoff: CNN and LSTM have the regular highest midpoint; Random Forest follows closely, and the Decision Tree and KNN, which are lighter weight methods, offer some performance in return for a lower resource demand. Although the composite is only for comparative purposes, it does not serve as a substitute for the dataset-specific evaluation. Figure 3: Descriptive midpoint composite of reported performance ranges Evidence points towards a tiered architecture for Nigeria deployment. Only critical sensors should be deployed on low power devices, which rely on basic preprocessing. To begin, an edge or gateway node can conduct feature extraction and implement either Random Forest or a super-small Decision Tree algorithm for consistent performance monitoring. Unlike cheaper models, more advanced CNN or LSTM can be deployed based on whether the network traffic is unclear; the attacks are complex, or the analysis is done periodically. Through this fragmentation, the device accesses a deep detector only when needed while saving energy and communication. The choice of the model should always be associated with operational controls. The feature set should be trimmed down as much as possible while maintaining recall; the models should be tested with realistic class imbalance; false positives and detection latency should be included in the report alongside the accuracy; and the threshold should be configured to the environment. Other things are the explainable outputs, the versioned models, the drift monitoring, the secure update channels, and the analyst feedback needed to build the trust and the performance. If data cannot be centralized, federated or privacy-preserving learning can be looked at, albeit its communications cost must be assessed and its susceptibility to poisoned updates evaluated before deployment. There are four main flaws in the review. Firstly, the review depended upon third-party data and did not carry out experiments on its own. Secondly, the dataset's differences, feature engineering, binary or multiclass framing, and metric calculation were causes of the restrictions of the direct comparison. Thirdly, no realtime deployment was run on a Nigerian IoT testbed, the kind of field assessment that's usually carried out was not done, which leaves the appropriateness ratings as reasoned assessments against defined resource criteria. Fourthly, the little number of Nigeria-specific studies has undermined the country's case for an extensive adoption of the research work done in other countries. Due to these constraints, local data collection followed by operational validation is an imperative and should be the topmost priority for further research. V. CONCLUSION This systematic literature review compared machine learning techniques for intrusion detection in IoT networks and evaluated their practicality for resourceconstrained environments relevant to Nigeria. The evidence showed that CNN and LSTM models generally produced the highest reported detection ranges, but their resource demands limit direct use on many low-power devices. When it comes to the overall performance of a given algorithm in terms of accuracy, robustness, interpretability, and moderate computational cost, Random Forest is the one that stands out. Decision Tree and KNN, as expected, were the lightweight alternatives, but SVM brought to the table strong classification at a cost of more variable scalability. The most straightforward and efficient way to deploy the models is not just to use a single algorithm but to have a proper hierarchical context-aware structure in place. While optimized deep models are set aside for capable gateways or cloud-driven analysis, lightweight preprocessing, and classical models continuously operate on the edge. Using IoT, Nigerian companies must consider models that reflect the actual local traffic, the prevalence of realistic attacks, the required latency, memory, energy consumption, and false-positive rates rather than just the benchmark accuracy results. Future studies must revolve around the creation of genuine Nigerian IoT datasets; conducting validation of models on actual devices and gateways; developing the most compact hybrid architectures; exploring explainable artificial intelligence; and studying federated and edgecomputing approaches. Advancement in these sections may help tread IoT from the current high benchmark scores towards reasonably priced, scalable, and dependable cybersecurity protection in real operational environments. REFERENCES

[1] M. A. Al-Garadi, A. Mohamed, A. K. Al-Ali, X. Du, I. Ali, and M. Guizani, “A survey of machine and deep learning methods for Internet of Things (IoT) security,” Ad Hoc Networks, Art. no. 101792, 2020, 10.1016/j.adhoc.2019.101792.

[2] Khraisat and A. Alazab, “A critical review of intrusion detection systems in the Internet of Things: Techniques, deployment strategy, validation strategy, attacks, public datasets and challenges,” Cybersecurity, vol. 4, Art. no. 18, 2021, 7.

[3] M. Almiani, A. AbuGhazleh, A. Al-Rahayfeh, S. Atiewi, and A. Razaque, “Deep recurrent neural network for IoT intrusion detection system,” Simulation Modelling Practice and Theory, vol. 101, Art. no. 102031, 2020, 10.1016/j.simpat.2020.102031.

[4] E. Gyamfi and A. Jurcut, “Intrusion detection in Internet of Things systems: A review on design approaches leveraging multi-access edge computing, machine learning, and datasets,” Sensors, vol. 22, no. 10, Art. no. 3744, 2022,

[5] M. Sarhan, S. Layeghy, and M. Portmann, “Feature analysis for machine learning-based IoT intrusion detection,” arXiv:2108.12732, 2021.

[6] M. Sarhan, S. Layeghy, N. Moustafa, M. Gallagher, and M. Portmann, “Feature extraction for machine learning-based intrusion detection in IoT networks,” arXiv:2108.12722, 2021.

[7] W. W. Lo, S. Layeghy, M. Sarhan, M. Gallagher, and M. Portmann, “E-GraphSAGE: A graph neural network based intrusion detection system for IoT,” arXiv:2103.16329, 2021.

[8] M. Jouhari and M. Guizani, “Lightweight CNN-BiLSTM based intrusion detection systems for resource-constrained IoT devices,” in Proc. Int. Wireless Communications and Mobile Computing Conf. (IWCMC), 2024, pp. 1558–1563, 10.1109/IWCMC61514.2024.10592352.

[9] H. Azzaoui, A. Boukhamla, P. Perazzo, M. Alazab, and V. Ravi, “A lightweight cooperative intrusion detection system for RPL-based IoT,” Wireless Personal Communications, vol. 134, pp. 2235–2258, 2024, A. H. Ali et al., “Unveiling machine learning strategies and considerations in intrusion detection systems: A comprehensive survey,” Frontiers in Computer Science, vol. 6, Art. no. 1387354, 2024, 10.3389/fcomp.2024.1387354.

[10] Pinto, L. C. Herrera, Y. Donoso, and J. A. Gutierrez, “Survey on intrusion detection systems based on machine learning techniques for the protection of critical infrastructure,” Sensors, vol. 23, no. 5, Art. no. 2415, 2023,

[11] L. Breiman, “Random forests,” Machine Learning, vol. 45, no. 1, pp. 5–32, 2001, 10.1023/A:1010933404324.

[12] Cortes and V. Vapnik, “Support-vector networks,” Machine Learning, vol. 20, no. 3, pp. 273 –297, 1995, 10.1007/BF00994018.

[13] M. Sokolova and G. Lapalme, “A systematic analysis of performance measures for classification tasks,” Information Processing and Management, vol. 45, no. 4, pp. 427–437, 2009,

[14] M. J. Page et al., “The PRISMA 2020 statement: An updated guideline for reporting systematic reviews,” BMJ, vol. 372, Art. no. n71, 2021,

[15] Kitchenham and S. Charters, Guidelines for Performing Systematic Literature Reviews in Software Engineering, EBSE Technical Report EBSE-2007-01, Keele University and Durham University, 2007.

[16] Okoli, “A guide to conducting a standalone systematic literature review,” Communications of the Association for Information Systems, vol. 37, pp. 879–910, 2015,

[17] N. Moustafa and J. Slay, “UNSW-NB15: A comprehensive data set for network intrusion detection systems,” in Proc. Military Communications and Information Systems Conf. (MilCIS), 2015, pp. 1–6, 10.1109/MilCIS.2015.7348942.

How to cite this paper

Ojima Gabriella Ob’lama, Eru, Akwuma Nathaniel, Ahiaba, Solomon, Ridwan Kolapo, Kureve, Stephanie Nguhemen "Comparative Analysis of Machine Learning Techniques for Intrusion Detection In Nigerian IoT Networks: A Systematic Literature Review" Iconic Research And Engineering Journals Volume 10 Issue 3 2026 Page 1557-1565 https://doi.org/10.64388/IREV10I3-1722957
Ojima Gabriella Ob’lama, Eru, Akwuma Nathaniel, Ahiaba, Solomon, Ridwan Kolapo, Kureve, Stephanie Nguhemen "Comparative Analysis of Machine Learning Techniques for Intrusion Detection In Nigerian IoT Networks: A Systematic Literature Review" Iconic Research And Engineering Journals, vol. 10, no. 3, Sep. 2026, doi: https://doi.org/10.64388/IREV10I3-1722957
Ojima Gabriella Ob’lama, Eru, Akwuma Nathaniel, Ahiaba, Solomon, Ridwan Kolapo, Kureve, Stephanie Nguhemen (2026). Comparative Analysis of Machine Learning Techniques for Intrusion Detection In Nigerian IoT Networks: A Systematic Literature Review. Iconic Research And Engineering Journals, 10(3). doi: https://doi.org/10.64388/IREV10I3-1722957
Ojima Gabriella Ob’lama, Eru, Akwuma Nathaniel, Ahiaba, Solomon, Ridwan Kolapo, Kureve, Stephanie Nguhemen "Comparative Analysis of Machine Learning Techniques for Intrusion Detection In Nigerian IoT Networks: A Systematic Literature Review" Iconic Research And Engineering Journals, vol. 10, no. 3, Sep. 2026. Crossref, https://doi.org/10.64388/IREV10I3-1722957
@article{1722957,
      author = {Ojima Gabriella Ob’lama, Eru, Akwuma Nathaniel, Ahiaba, Solomon, Ridwan Kolapo, Kureve, Stephanie Nguhemen },
      title = {Comparative Analysis of Machine Learning Techniques for Intrusion Detection In Nigerian IoT Networks: A Systematic Literature Review},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {10},
      number = {3},
      pages = {1557-1565},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1722957.pdf},
      abstract = {A large part of the increase in cyber threats to the network of Nigeria is the introduction of IoT devices in the areas of healthcare, smart homes, transportation, surveillance, banking, and business. These cyber threats include the likes of DDoS, malware injection, spoofing, unauthorized access. In this paper, we summarize a literature review and a comparative analysis of the techniques used in machine learning for intrusion detection in IoT networks, with a focus on their suitability for resource-constrained environments in Nigeria.  PRISMA framework and Parsifal guided the process of reviewing and managing. Out of 850 records discovered on the different online platforms that are IEEE Xplore, Scopus, ScienceDirect, SpringerLink, and Google Scholar, the research documented 30 peer-reviewed studies which were published between 2021 and 2026 and included 30 papers for final synthesis. The most commonly used techniques in the IoT intrusion detection literature are Random Forest, Support Vector Machine, Decision Tree, K-Nearest Neighbors, Artificial Neural Networks,  Convolutional Neural Networks (CNN), and Long ShortTerm Memory (LSTM) models. CNN and LSTM models usually had the highest reported detection scores, being about 96-99% in accuracy, precision, recall, and F1-score; however, their high computational and memory requirements limit their practical deployment on low-power IoT devices. Random Forest is evaluated as the best choice because of its appropriate overall balance in terms of reporting high accuracy statistics (95-99%) and also the moderate computational cost with the strong suitability rating for Nigeria's current IoT infrastructure. Decision Tree and KNN were also mentioned as lightweight alternatives, but they could stand lower performance compared to the complex attacks. The study declares that for Nigeria's IoT cybersecurity resilience to be effective, it is imperative to have accurate, lightweight, explainable, and context-aware intrusion detection model.},
      keywords = {Internet of Things, Intrusion Detection System, Machine Learning, Deep Learning, PRISMA, Random Forest, Resource-Constrained Environment, Nigeria},
      month = {September},
      doi = {https://doi.org/10.64388/IREV10I3-1722957}
  }