Skip to content
Review Open access

Deep Learning-Based Intrusion Detection in IoT: A Comprehensive Review of Architectures, Attacks, Challenges, and Future Directions

Sep 2026 · Al-Noor Journal of Engineering Management and Computer Science · pp. 115-141 · 0 citations · 84 references

TL;DR

In a comparative review of forty peer-reviewed studies, it is demonstrated that hybrid DL models provide excellent detection performance (99-100% classification accuracy on benchmark datasets) as well as practical viability for deployment with privacy-preserving Federated Learning for large-scale data.

Abstract

The rapid proliferation of Internet of Things (IoT) devices across critical domains including healthcare, smart cities, industrial control systems, and intelligent transportation has fundamentally transformed the cybersecurity threat landscape. The inherent characteristics of IoT environments, namely resource-constrained devices, heterogeneous architectures, and large-scale deployment, render traditional Intrusion Detection Systems (IDS) inadequate for the sophisticated and evolving attack vectors targeting these networks. Deep learning (DL) has emerged as a compelling paradigm for next-generation IoT IDS, offering automated feature extraction, temporal pattern recognition, and adaptive threat detection capabilities that address the limitations of conventional approaches. This paper provides a thorough and systematic review of the existing DL methods for IoT intrusion detection. The paper explore the IoT architectural paradigms, outline a four layered taxonomy for types of IoT attacks across its three primary layers Perception, Network and Application as well as Adversarial Machine Learning attacks, and systematically review seven classes of DL architectures Convolutional Neural Networks (CNN), Long Short-Term Memory (LSTM) networks, Gated Recurrent Units (GRU), Autoencoders, Generative Adversarial Networks (GAN), models based on Transformer architecture and Federated Learning frameworks. In a comparative review of forty peer-reviewed studies, we demonstrate that hybrid DL models provide excellent detection performance (99-100% classification accuracy on benchmark datasets) as well as practical viability for deployment with privacy-preserving Federated Learning for large-scale data. The study additionally highlights five enduring challenges class imbalance, adversarial vulnerability, zero-day detection limitations, computational constraints and the absence of standardized benchmarking protocols that together account for the gap between performance benchmarks and real-world deployment efficacy. It outlines future research avenues targeting on five key axes with a particular focus in the integration of Explainable AI (XAI), lightweight edge-deployable architectures, and adversarial robustness mechanisms. This survey identifies a structured reference to advance the state of IoT intrusion detection from research to operationally viable and deployable systems.

Read PDF

Similar papers

Open access Aug 2026

Cross-Domain Deep Transfer Learning Framework for Intrusion Detection in Data-Constrained and Resource-Limited IoT Environments

Experimental results demonstrate that the proposed DTL framework outperforms conventional DL-based IDS models, achieving improvements in accuracy, recall, F1-score, and area under the receiver operating characteristic curve (AUC).

I. Mohammed, Imad Mahgoub · 0 citations
Open access Sep 2026

AI-Driven Vulnerability Management Framework for the Internet of Things

This rapid growth of IoT has changed the landscape of today’s digital world by allowing devices to communicate effectively, especially in different fields like healthcare, smart cities, industrial control, and defense. Despite its advantages, IoT introduces significant security challenges due to device heterogeneity...

Daniel Nafisatu Mshelbila · 0 citations
Review Open access Aug 2026

AI-ENHANCED INFORMATION SECURITY FRAMEWORKS FOR CLOUD-ENABLED IOT NETWORKS: A COMPREHENSIVE REVIEW

This review paper critically examines the integration of Artificial Intelligence (AI) and Machine Learning (ML) techniques to enhance information security within Cloud-IoT networks, focusing on hybrid Deep Learning models (CNN-LSTM), predictive analytics, and automated threat response mechanisms.

R. Saravanakumar, V.Anuratha, M.Elamparithi · 0 citations
Open access Sep 2026

Fog computing deep learning-based intrusion detection model for IOT network security

The rapid expansion of Internet of Things (IoT) communications across fog networks has led to a significant increase in security concerns and cyber threats due to the multiplicity and diversity of violations and security vulnerabilities. Due to inadequate security, a large number of IoT devices are vulnerable to malwar...

Karar Falah Sailan, Mohsen Nik Ray · 0 citations
#federated learning Review Open access Oct 2026

Intelligent defense at the edge: a comprehensive survey of federated learning, TinyML and explainable AI for intrusion detection in IoT and IIoT ecosystems

The proliferation of Internet of Things (IoT) and Industrial Internet of Things (IIoT) technologies has fundamentally transformed contemporary computing infrastructures by interconnecting large heterogeneous devices, sensors, embedded systems, and cyber-physical platforms. These ecosystems support diverse applications...

S. S. Kumar, M. Jerlin · 0 citations
Open access Aug 2026

HybridML CyberShield for explainable proactive intrusion detection in enterprise and IoT networks

The framework introduces CNN–BiLSTM deep learning networks to represent traffic in a spatiotemporal manner and adopts ensemble machine learning classifiers to enhance the robustness of traffic detection and its interpretability, to enhance the robustness of traffic detection and its interpretability.

Ramesh N. S. V. S. C. Sripada, A. Bhavani, Kiran B. Malagi et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.