Skip to content
Open access

Intelligent Detection Method for In-the-Wild Exploit Attacks in Distributed IoT Networks

Aug 2026 · ICST Transactions on Scalable Information Systems · 0 citations · 31 references

Abstract

INTRODUCTION: In distributed IoT networks, massive devices, edge nodes and cloud platforms exchange data via open protocols, making device exploit attacks a severe threat to business continuity, data security and cross-domain propagation. Existing rule-based methods fail to balance real-time performance, accuracy and attack localization against rapidly mutating, obfuscated and large-scale in-the-wild exploits.

Objectives

To address the above limitations, this paper aims to propose an intelligent detection method integrating hybrid deep learning and open-source intelligence correlation for distributed IoT systems.

Methods

First, HTTP packet preprocessing extracts suspected attack samples to mitigate extreme class imbalance. Second, a BERT-CNN coupled model classifies suspicious packets automatically. Finally, attack vector regression correlation with public vulnerabilities, PoCs and threat intelligence realizes accurate 1Day/NDay attack identification.

Results

Experiments show the method achieves over 99.99% accuracy and 99.98% F1-score on real datasets. The IoT_Exploits_Founder system discovered 13 new in-the-wild exploits within one month in real environment. This study also supplements quantitative comparisons with representative methods, online deployment measurements of latency, memory overhead and throughput, and ablation studies for the attack-vector regression threshold and feature weights.

Conclusion

The proposed method provides effective support for AI-driven security monitoring in distributed IoT systems, with strong real-time edge applicability and robustness.

Read PDF