Skip to content

A Lightweight Bounded-Residual DAE for Mitigating Adaptive Attacks on IoT Intrusion Detection Systems

Sep 2026 · International Symposium on Networks, Computers and Communications · pp. 1-7 · 0 citations · 21 references

Abstract

Machine-learning intrusion detection has strengthened protection in Internet of Things (IoT) networks, but it also creates a new attack surface: small, deliberately chosen changes to flow features can make malicious traffic appear benign. Classifier hardening retrains the detector, while existing non-invasive schemes can add auxiliary detection, multiple reconstructors or iterative inference. We present a lightweight bounded-residual denoising autoencoder (DAE) that operates as an input purifier before a frozen feed-forward neural network. The 220-parameter DAE learns to preserve clean benign and malicious records while reconstructing adversarial records towards their clean counterparts; a validation-selected residual strength prevents excessive correction of unperturbed traffic. The pipeline is evaluated across three seeds on BoT-IoT and CICIDS2017 under adaptive white-box FGSM and multi-restart PGD, with PGD adversarial training included as a classifier-modifying comparator. On sealed BoT-IoT test data, the DAE reduced FGSM and PGD attack success rates on a fixed malicious cohort by 36.45% and 32.20%, while clean accuracy changed from 90.75% to 89.72%. On CICIDS2017, reductions were 25.01% and 5.72%, with accuracy changing from 83.28% to 82.91%. The findings support the compact pre-filter as a partial mitigation when retraining is not practical, but not as a universal defence.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.