An IDS that integrates federated learning with Double Deep Q-Network (DDQN), a deep reinforcement learning algorithm, designed for large-scale MQTT-based IoT networks is proposed and validated for robustness against adversarial attacks and adaptability to evolving attack patterns.
This work proposes a novel multiclass intrusion detection system using FL at the subnetwork level using various machine learning models, including Artificial Neural Networks, Convolutional Neural Networks, and Long Short-Term Memory to build an effective IoT IDS.
Mamta Rawat, Manan Suri, Gaurav Singal· Wireless personal communicat...· 0 citations
The results show a success in implementing a real time, scalable, privacy-preserving, and adaptive IDS in large-scale IoT deployments through intelligent workload distribution between edge and cloud layers.
Chidera Winifred John, Eduediuyai Ekerete Dan, P. Asuquo et al.· E3S Web of Conferences· 0 citations
: The increasing complexity and heterogeneity of cyberattacks targeting Internet of Things (IoT) environments, driven by the diversity of interconnected nodes and communication channels, necessitate the development of more advanced and intelligent cyber defence techniques. However, the most effective methods are Machine Learning (ML)-based and Deep Learning (DL)-based intrusion detection systems (IDS), which perform well but still face significant limitations and challenges. To address these issues, Deep Reinforcement Learning (DRL) has been proposed in recent years to automatically resolve the issues by detecting attacks in IoT environments. Therefore, this Systematic Literature Review (SLR) presents an up-to-date review by analyzing the existing studies on DRL-based IDS models that detect intrusions in IoT networks. To achieve this goal, this review focuses on and scrutinizes scientific journals and articles extracted from 2020 to 2026 across multiple databases, identifying 267 articles. A systematic mapping procedure was then carried out using Rayyan and Mendeley to screen the articles based on nine well-defined inclusion and exclusion criteria covering publication year, language, publication type, full-text availability, explicit use of DRL techniques, relevance to IoT attack detection, minimum page count, duplication, and open access, which collectively reduced the pool to 26 high-quality studies. The majority of excluded articles 241 in total were removed primarily because they did not explicitly employ DRL techniques in an IoT intrusion detection context, were duplicate records, or did not meet the minimum quality thresholds defined in the eligibility assessment. The review reveals that the most used algorithm for DRL-based IDS is Deep Q-Network (DQN), appearing in 8 studies (30.8%). Three studies utilized feature selection methods, including LightGBM and Mutual Information Feature Selection (MIFS), and the most frequently targeted attacks are DoS, DDoS, Backdoors, Mirai, Reconnaissance, Scan, and Torii. Finally, this research highlights the open issues and challenges for future research in DRL-based IDS models, to enhance IoT network security.
Maryam Omar Abdullah Sawad, S. Abdulkadir, H. Alhussian et al.· Computer Modeling in Enginee...· 0 citations
Breach rates and unparalleled vulnerabilities are a constant feature of the cyber landscape these days, and the increasing complexity of the proliferation of Internet of Things (IoT) nodes is to be expected. With these challenges, the conventional intrusion detection systems (IDS) are proven to be unable to deal with the extensive and varied data streams. Such systems can be fundamentally attributed to the classical nature of these systems, which are lacking in flexibility to analyze traffic in real-time and thus have no proactive capabilities of identifying patterns of unknown attacks. Considering these technical barriers, in this paper, an offensive-defensive system based on Deep Reinforcement Learning (DRL) algorithms is proposed. The novelty of the proposed method is the unique synergic combination of mathematical feature engineering and a dynamically changing Deep Q-Network (DQN) agent, dynamically adapting to changing traffic patterns. A comprehensive four-stage data preparation pipeline was designed and tested on the benchmark CICIoT2023 dataset, prior to the training phase. To reduce the dimensionality, non-influential features of the network were eliminated using entropy and the Synthetic Minority Over-Sampling Technique (SMOTE) was applied to address the statistical imbalance between the classes. It was tested under strict experimental conditions, with an 80:20 train/test split, on a set of 231,250 samples, before an isolated test set of 46,250 samples. This organization's initiation led to a stable mathematical context of the DQN agent, which can better formulate inferential policies to enable it to make real-time directional choices, including blocking or passing packets, by optimization of the reward function, which is ideally consistent with the concepts of zero-trust architecture. At the experimental level, the suggested framework proved to be highly efficient in its operation, with a total accuracy of 98.74%, a precision rate of 99.80%, a recall rate of 98.93%, and an F1-score of 99.37%. These numerical metrics outperform several state-of-the-art machine learning approaches in the literature, revealing that the systematic incorporation of accurate data engineering and reinforcement learning frameworks generates a field-tested security barrier that offers an expedient reaction to counteract multifaceted threats to IoT networks.
Hawraa A. Habeeb, M. Manaa· Journal of Intelligent Infor...· 0 citations
Modern networks are becoming increasingly complex as the number of interconnections grows and the number of Internet of Things (IoT) devices rapidly increases, making it possible for complex cyberattacks, including zero-day attacks, distributed denial-of-service (DDoS) attacks, and advanced persistent threats (APTs), to take root. Current traditional IDSs and individual machine learning/deep learning methods have drawbacks, including limited ability to learn from new attacks, high false alarm rates, limited interpretability, and scalability issues. These constraints hinder their usefulness in enterprise-level and IoT-based cybersecurity applications. To overcome these challenges, this paper introduces HybridML-CyberShield, a hybrid machine learning system designed for proactive cyber threat intelligence and intrusion detection. The framework introduces CNN–BiLSTM deep learning networks to represent traffic in a spatiotemporal manner and adopts ensemble machine learning classifiers, such as Random Forest, Support Vector Machine, and Gradient Boosting, to enhance the robustness of traffic detection and its interpretability. A Proactive Threat Scoring Mechanism (PTSM) is added to prioritise threats based on attack probability, attack severity, and confidence, enabling adaptive incident response prioritisation. Additionally, SHAP and LIME models also provide both global and local interpretability, resulting in greater transparency and analyst trust. Experimental evaluation across various benchmark cybersecurity datasets shows that HybridML-CyberShield achieves up to 98.4% accuracy on the CICIDS2017 dataset, with strong F1-scores, AUC-ROC values, and fewer false-positive alerts. The proposed architecture is scalable, transparent and almost real-time for enterprise and IoT cybersecurity monitoring environments.
Ramesh N. S. V. S. C. Sripada, A. Bhavani, Kiran B. Malagi et al.· Discover Computing· 0 citations
Wireless Sensor Networks (WSNs) play a crucial role in various applications, but their vulnerability to malicious nodes and data breaches hinders their full potential. Traditional security methods often struggle to keep pace with evolving attack patterns and can introduce privacy concerns. This research proposes a novel framework for anomaly detection in WSNs that leverages federated deep learning and prioritizes real-time adaptation and data privacy. Sensor nodes collaboratively train adaptive deep learning models to identify anomalies in real-time, enabling continuous learning and response to evolving threats. Partial Homomorphic Encryption (PHE) safeguards sensitive data throughout the network, ensuring data confidentiality. The trade-off between security and computational cost associated with PHE is acknowledged. The effectiveness of the proposed system FedShield-PHE will be evaluated through simulations, comparing its performance to existing methods across various metrics including detection accuracy, network overhead, and energy consumption. This research offers a promising path forward for securing WSNs by enabling distributed, privacy-preserving anomaly detection with real-time adaptation capabilities.
N. Karthick, K. Ranjith Singh· International journal of com...· 0 citations