Home / Current Issue / Paper 1722957
Comparative Analysis of Machine Learning Techniques for Intrusion Detection In Nigerian IoT Networks: A Systematic Literature Review
Subject area: Science,Engineering and Technology · Area of research: Machine Learning
DOI: 10.64388/IREV10I3-1722957
Abstract
A large part of the increase in cyber threats to the network of Nigeria is the introduction of IoT devices in the areas of healthcare, smart homes, transportation, surveillance, banking, and business. These cyber threats include the likes of DDoS, malware injection, spoofing, unauthorized access. In this paper, we summarize a literature review and a comparative analysis of the techniques used in machine learning for intrusion detection in IoT networks, with a focus on their suitability for resource-constrained environments in Nigeria. PRISMA framework and Parsifal guided the process of reviewing and managing. Out of 850 records discovered on the different online platforms that are IEEE Xplore, Scopus, ScienceDirect, SpringerLink, and Google Scholar, the research documented 30 peer-reviewed studies which were published between 2021 and 2026 and included 30 papers for final synthesis. The most commonly used techniques in the IoT intrusion detection literature are Random Forest, Support Vector Machine, Decision Tree, K-Nearest Neighbors, Artificial Neural Networks, Convolutional Neural Networks (CNN), and Long ShortTerm Memory (LSTM) models. CNN and LSTM models usually had the highest reported detection scores, being about 96-99% in accuracy, precision, recall, and F1-score; however, their high computational and memory requirements limit their practical deployment on low-power IoT devices. Random Forest is evaluated as the best choice because of its appropriate overall balance in terms of reporting high accuracy statistics (95-99%) and also the moderate computational cost with the strong suitability rating for Nigeria's current IoT infrastructure. Decision Tree and KNN were also mentioned as lightweight alternatives, but they could stand lower performance compared to the complex attacks. The study declares that for Nigeria's IoT cybersecurity resilience to be effective, it is imperative to have accurate, lightweight, explainable, and context-aware intrusion detection model.
Keywords
Internet of Things, Intrusion Detection System, Machine Learning, Deep Learning, PRISMA, Random Forest, Resource-Constrained Environment, Nigeria
References
[1] M. A. Al-Garadi, A. Mohamed, A. K. Al-Ali, X. Du, I. Ali, and M. Guizani, “A survey of machine and deep learning methods for Internet of Things (IoT) security,” Ad Hoc Networks, Art. no. 101792, 2020, doi: 10.1016/j.adhoc.2019.101792.
[2] Khraisat and A. Alazab, “A critical review of intrusion detection systems in the Internet of Things: Techniques, deployment strategy, validation strategy, attacks, public datasets and challenges,” Cybersecurity, vol. 4, Art. no. 18, 2021, doi: 10.1186/s42400-021-00077-7.
[3] M. Almiani, A. AbuGhazleh, A. Al-Rahayfeh, S. Atiewi, and A. Razaque, “Deep recurrent neural network for IoT intrusion detection system,” Simulation Modelling Practice and Theory, vol. 101, Art. no. 102031, 2020, doi: 10.1016/j.simpat.2020.102031.
[4] E. Gyamfi and A. Jurcut, “Intrusion detection in Internet of Things systems: A review on design approaches leveraging multi-access edge computing, machine learning, and datasets,” Sensors, vol. 22, no. 10, Art. no. 3744, 2022, doi: 10.3390/s22103744.
[5] M. Sarhan, S. Layeghy, and M. Portmann, “Feature analysis for machine learning-based IoT intrusion detection,” arXiv:2108.12732, 2021.
[6] M. Sarhan, S. Layeghy, N. Moustafa, M. Gallagher, and M. Portmann, “Feature extraction for machine learning-based intrusion detection in IoT networks,” arXiv:2108.12722, 2021.
[7] W. W. Lo, S. Layeghy, M. Sarhan, M. Gallagher, and M. Portmann, “E-GraphSAGE: A graph neural network based intrusion detection system for IoT,” arXiv:2103.16329, 2021.
[8] M. Jouhari and M. Guizani, “Lightweight CNN-BiLSTM based intrusion detection systems for resource-constrained IoT devices,” in Proc. Int. Wireless Communications and Mobile Computing Conf. (IWCMC), 2024, pp. 1558–1563, doi: 10.1109/IWCMC61514.2024.10592352.
[9] H. Azzaoui, A. Boukhamla, P. Perazzo, M. Alazab, and V. Ravi, “A lightweight cooperative intrusion detection system for RPL-based IoT,” Wireless Personal Communications, vol. 134, pp. 2235–2258, 2024, doi: 10.1007/s11277-024-11009-2.
[10] H. Ali et al., “Unveiling machine learning strategies and considerations in intrusion detection systems: A comprehensive survey,” Frontiers in Computer Science, vol. 6, Art. no. 1387354, 2024, doi: 10.3389/fcomp.2024.1387354.
[11] Pinto, L. C. Herrera, Y. Donoso, and J. A. Gutierrez, “Survey on intrusion detection systems based on machine learning techniques for the protection of critical infrastructure,” Sensors, vol. 23, no. 5, Art. no. 2415, 2023, doi: 10.3390/s23052415.
[12] L. Breiman, “Random forests,” Machine Learning, vol. 45, no. 1, pp. 5–32, 2001, doi: 10.1023/A:1010933404324.
[13] Cortes and V. Vapnik, “Support-vector networks,” Machine Learning, vol. 20, no. 3, pp. 273–297, 1995, doi: 10.1007/BF00994018.
[14] M. Sokolova and G. Lapalme, “A systematic analysis of performance measures for classification tasks,” Information Processing and Management, vol. 45, no. 4, pp. 427–437, 2009, doi: 10.1016/j.ipm.2009.03.002.
[15] M. J. Page et al., “The PRISMA 2020 statement: An updated guideline for reporting systematic reviews,” BMJ, vol. 372, Art. no. n71, 2021, doi: 10.1136/bmj.n71.
[16] Kitchenham and S. Charters, Guidelines for Performing Systematic Literature Reviews in Software Engineering, EBSE Technical Report EBSE-2007-01, Keele University and Durham University, 2007.
[17] Okoli, “A guide to conducting a standalone systematic literature review,” Communications of the Association for Information Systems, vol. 37, pp. 879–910, 2015, doi: 10.17705/1CAIS.03743.
[18] N. Moustafa and J. Slay, “UNSW-NB15: A comprehensive data set for network intrusion detection systems,” in Proc. Military Communications and Information Systems Conf. (MilCIS), 2015, pp. 1–6, doi: 10.1109/MilCIS.2015.7348942.
How to cite this paper
@article{1722957,
author = {Ojima Gabriella Ob’lama, Eru, Akwuma Nathaniel, Ahiaba, Solomon, Ridwan Kolapo, Kureve, Stephanie Nguhemen },
title = {Comparative Analysis of Machine Learning Techniques for Intrusion Detection In Nigerian IoT Networks: A Systematic Literature Review},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {3},
pages = {1557-1565},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1722957.pdf},
abstract = {A large part of the increase in cyber threats to the network of Nigeria is the introduction of IoT devices in the areas of healthcare, smart homes, transportation, surveillance, banking, and business. These cyber threats include the likes of DDoS, malware injection, spoofing, unauthorized access. In this paper, we summarize a literature review and a comparative analysis of the techniques used in machine learning for intrusion detection in IoT networks, with a focus on their suitability for resource-constrained environments in Nigeria. PRISMA framework and Parsifal guided the process of reviewing and managing. Out of 850 records discovered on the different online platforms that are IEEE Xplore, Scopus, ScienceDirect, SpringerLink, and Google Scholar, the research documented 30 peer-reviewed studies which were published between 2021 and 2026 and included 30 papers for final synthesis. The most commonly used techniques in the IoT intrusion detection literature are Random Forest, Support Vector Machine, Decision Tree, K-Nearest Neighbors, Artificial Neural Networks, Convolutional Neural Networks (CNN), and Long ShortTerm Memory (LSTM) models. CNN and LSTM models usually had the highest reported detection scores, being about 96-99% in accuracy, precision, recall, and F1-score; however, their high computational and memory requirements limit their practical deployment on low-power IoT devices. Random Forest is evaluated as the best choice because of its appropriate overall balance in terms of reporting high accuracy statistics (95-99%) and also the moderate computational cost with the strong suitability rating for Nigeria's current IoT infrastructure. Decision Tree and KNN were also mentioned as lightweight alternatives, but they could stand lower performance compared to the complex attacks. The study declares that for Nigeria's IoT cybersecurity resilience to be effective, it is imperative to have accurate, lightweight, explainable, and context-aware intrusion detection model.},
keywords = {Internet of Things, Intrusion Detection System, Machine Learning, Deep Learning, PRISMA, Random Forest, Resource-Constrained Environment, Nigeria},
month = {September},
doi = {https://doi.org/10.64388/IREV10I3-1722957}
}