Aug 2026· Discover Internet of Things· Vol 6· 0 citations· 40 references
TL;DR
This study presents a Quantum Machine Learning (QML)-based Intrusion Detection framework that uses Quantum Support Vector Machines (QSVM) to improve detection accuracy, adaptability, and computational efficiency in conceptual IoT Cloud-Enabled Smart City environments.
Abstract
The fast integration of Internet of Things (IoT) devices and cloud platforms has altered current smart cities, allowing for intelligent services and effective communication. However, the increased interconnectedness has broadened the attack surface, exposing systems to complex, evolving cyberattacks that standard Intrusion Detection Systems (IDSs) cannot adequately counter. Classical Machine Learning architectures have constraints in handling high-dimensional data, achieving scalability, maintaining performance, and adapting to dynamic attack behaviours. To find these problems, this study presents a Quantum Machine Learning (QML)-based Intrusion Detection framework that uses Quantum Support Vector Machines (QSVM) to improve detection accuracy, adaptability, and computational efficiency in conceptual IoT Cloud-Enabled Smart City environments. The proposed model was assessed through simulation-based evaluation on the CICDDoS2019 dataset using the DrDoS DNS subset and compared against conventional Machine Learning Models such as SVM, XGBoost, Random Forest, and RNN. The experimental results show an overall performance improvement of 99.28%, with our research delivering significantly higher detection accuracy and system adaptability, along with fewer false alarms and faster response times. These results demonstrate the efficiency of Quantum-enhanced Learning in protecting IoT-Cloud infrastructures in smart-city environments. The proposed QSVM framework was evaluated using a classical quantum simulation environment. Therefore, the reported findings represent simulation-based observations and should not be interpreted as evidence of practical quantum computational advantage or hardware-based validation.
The increasing deployment of Internet of Things (IoT) devices in smart city infrastructures has significantly expanded the network attack surface, making effective intrusion detection a critical security requirement. Traditional intrusion detection systems struggle to cope with the volume, heterogeneity, and dynamic behaviour of IoT network traffic, often resulting in high false alarm rates and missed attacks. This study investigates the effectiveness of supervised machine learning techniques for detecting cyberattacks in IoT-based smart city networks using the TON_IoT dataset. A progressive modelling approach is adopted, beginning with Logistic Regression as the baseline model, followed by Random Forest as an ensemble method, and culminating in an optimised XGBoost model. Preprocessing and feature engineering address dimensionality, feature representation, and the challenges associated with imbalanced IoT traffic distributions. Experimental results demonstrate that ensemble and boosting-based models significantly outperform linear approaches. Among the evaluated models, XGBoost achieves the highest detection performance, substantially reducing missed attacks while maintaining robust classification accuracy. The findings demonstrate that advanced ensemble learning combined with robust feature engineering provides a reliable and scalable solution for securing smart city IoT networks.
E. Okonta, Oluwaseun Bamgbose· ABC2: Journal of Architectur...· 0 citations
The rapid deployment of Internet of Things (IoT) devices across smart cities, healthcare systems, industrial automation, transportation networks, smart grids, and cyber-physical infrastructures has expanded the modern cyberattack surface. IoT devices are often constrained by limited processing capacity, memory, battery power, and communication bandwidth, making conventional security mechanisms difficult to deploy consistently at scale. Intrusion detection systems (IDSs) provide an important defensive layer; however, many machine-learning-based IDSs are developed under static assumptions and may experience performance degradation as traffic distributions evolve due to firmware changes, device onboarding, protocol updates, user behavior variation, or adaptive attacks. This paper presents a hybrid IDS framework that integrates supervised Random Forest classification, unsupervised Isolation Forest anomaly monitoring, and Kolmogorov–Smirnov (KS)-based concept drift monitoring. In the experimental pipeline, Isolation Forest is trained exclusively on benign traffic to ensure that the anomaly detector models normal behavior rather than an attack-dominated training distribution. The evaluation uses a large-scale chronologically sampled subset of the CICIoT2023 dataset containing 3,890,621 records while preserving the natural class distribution of 2.35% benign traffic and 97.65% attack traffic. The chronological 80/20 train/test split is established first at the file level, followed by systematic sampling within each split to reduce the risk of leakage across the evaluation boundary. On the 746,094-record test set, the proposed hybrid IDS achieved 99.73% accuracy, 99.89% precision, 99.83% recall, 99.86% F1-score, and a false positive rate of 4.77%. The corresponding confusion matrix contains TN = 16,683, FP = 836, FN = 1205, and TP = 727,370, yielding 95.23% specificity and 97.53% balanced accuracy. Standalone Random Forest marginally outperformed the hybrid model in raw accuracy and false positive rate; therefore, the contribution of the proposed framework is centered on deployment-oriented anomaly monitoring, drift awareness, and generalization rather than absolute superiority in static classification metrics. A leave-one-attack-family-out experiment withholding MITM-ArpSpoofing from training showed that the hybrid model detected 85.26% of the unseen attack-family samples, compared with 85.18% for Random Forest alone and 7.05% for Isolation Forest alone. These findings provide initial evidence of generalization to one held-out attack family but should not be interpreted as proof of broad zero-day detection capability. The framework is therefore positioned as a competitive IDS that combines supervised detection with anomaly monitoring and concept drift awareness for deployment-oriented IoT security.
Muath A. Obaidat, Meryem Abouali, Aneeza Shakeel· Italian National Conference...· 0 citations
The exponentially increasing number of IoT devices and their corresponding cloud infrastructures increases the attack surface․ Classic rule-based schemes and cryptographic solutions are not well adapted to dynamic‚ heterogeneous‚ distributed‚ and resource-constrained IoT-cloud infrastructures․ Artificial intelligence (AI) based techniques such as machine learning (ML)‚ deep learning (DL) and federated learning (FL)‚ considered as a new model for intrusion detection systems (IDS) to assess the threats in real time and respond to the threats effectively in the dynamic environment․ This paper thoroughly reviews the state-of-the-art AI-based IDS in a layer-wise manner which consists of IoT and cloud stacks․ It categorizes popular cyber-attacks associated with each layer (perception‚ network‚ transport‚ processing and application) and correlate the attacks to machine learning classifiers (SVM‚ KNN‚ Random Forest‚ CNN‚ RNN/LSTM‚ Autoencoder) at shallow and deep learning levels․ The research incorporates federated IDS‚ graph neural networks‚ transformer architecture and explainable artificial intelligence as models of machine learning and further discusses prominent research issues (data scarcity‚ adversarial robustness‚ latency‚ transferability) and the future direction of next-generation IoT-cloud security․
A. Anitha, A. R, Arpita Nath Boruah et al.· International journal of com...· 0 citations
The rapid growth of Internet of Things (IoT) devices has significantly improved connectivity across smart environments. However, the resource-constrained nature of IoT devices and their limited built-in security mechanisms make them highly vulnerable to evolving cyberattacks. Traditional intrusion detection systems relying on signature-based or static rule sets are often ineffective against previously unseen attacks. This study proposes a hybrid machine learning-based intrusion detection and prevention framework for securing IoT networks. The framework integrates Isolation Forest, Autoencoder, Extreme Gradient Boosting, and Bidirectional Long Short-Term Memory models within a stacked ensemble architecture to improve attack detection while reducing false-positive predictions. The ensemble outputs are combined using a Logistic Regression meta-classifier to generate the final threat score. Experimental evaluation using the UNSW-NB15 dataset demonstrates that Extreme Gradient Boosting achieved the highest individual Receiver Operating Characteristic-Area Under the Curve score of 0.91, while the proposed framework further enhances detection robustness through ensemble learning and automated prevention. A Flask-based monitoring dashboard provides real-time visualization of detection results, blocked IP addresses, alerts, and system performance.
Ruthwik Palem, Likhith Reddy Peketi, Vanathi M et al.· Cureus Journal of Computer S...· 0 citations
The growing usage of Internet of Things gadgets has facilitated smart environments including automated homes, smart lighting systems, and smart industrial applications. In spite of these advantages, the IoT devices are frequently not well secured because of their poor computing power and compact architecture. This makes them very susceptible to cyberattacks that may cripple the functionality of their devices, interfere with network processes or reveal confidential information. The identification of malicious activity on the IoT networks has thus become a key challenge to cybersecurity. This paper has discussed a machine learning-driven intrusion detection system that aims to detect attacks on IoT devices. An actual IoT system based on ESP32 microcontrollers and a smart bulb was used to create network traffic both in the regular operation environment and in the simulated attack environment. To enhance the efficiency of the model, the data obtained on the traffic was subjected to various preprocessing steps such as data cleaning, feature encoding, normalization and feature selection. Local Outlier Factor (LOF) based anomaly detection method was employed to determine abnormal network behavior with a random forest classifier used to determine the category of attack. The system is constantly watching the IoT traffic and sends automatic email notifications in case of suspicious activity. The outcomes of the experiment suggest that machine learning methods can be successfully used to differentiate between legitimate and malicious network behavior, which can be used as a viable solution to enhance the security and surveillance of IoT-based systems. The proposed system achieved an accuracy of 88.22%, precision of 90.41%, recall of 85.51%, and an F1-score of 87.89%, demonstrating effective detection of malicious IoT network activity.
P. Praveen, K. Sridhar, B. Rao et al.· International journal of com...· 0 citations
With the rapid adoption of smart home solutions and related technologies, edge computing has emerged as a key enabler by offering low-latency data processing, increased efficiency and improved scalability. However, this integration in IoT systems introduces complex security challenges in smart home edge environments, increasingly susceptible to cyber threats such as denial-of-service (DoS), malware injection, passive surveillance, and unauthorized access. This paper investigates intelligent intrusion detection and attack classification strategies specifically designed for smart home edge systems. Using the comprehensive ML-EdgeIIoT dataset, this study designs and evaluates a machine learning-based intrusion detection framework for multiclass classification of eight categories of IoT network attacks, namely Backdoor, MITM, DDoS, Ransomware, Password Attack, SQL Injection, Prob-attacks, and Normal traffic while minimizing false positives and false negatives. The framework incorporates data cleaning, correlation- and feature importance-based feature selection, hyperparameter optimization using gridsearchCV, model training, and ensemble learning. A set of machine learning models comprising Artificial Neural Network, Balanced Random Forest, K-Nearest Neighbours, Random Forest, and Logistic Regression was implemented and comparatively evaluated. Two ensemble techniques were subsequently developed using the three best-performing classifiers: (1) a stacking ensemble with Logistic Regression as the meta-learner and (2) a Top-3 majority voting ensemble. Model performance was evaluated using accuracy, precision, recall, F1-score, confusion matrix, and ROC-AUC. Robustness and generalization of the individual machine learning models were assessed through stratified 10-fold cross-validation for the three best-performing classifiers. The Top-3 voting ensemble subsequently achieved the highest performance on the independent test set, with accuracy of 99.24%, average precision of 98.75%, recall of 99.00%, and an F1-score of 99.00% for all attack classes, while reducing misclassification compared with individual classifiers. The findings of this study significantly enhance the understanding of smart home edge computing security, which will pave the way for more robust and intelligent threat detection frameworks.
Abhay Kumar Ray, Rupak Sharma, Sunil Kumar Pandey· International Journal of Wir...· 0 citations