Jul 2026· International Conference Computing Methodologies and Communication· pp. 565-570· 0 citations· 10 references
Abstract
A security tool can be used to monitor network related tasks and activities of a system to identify unwanted activities and unauthorized access that can be referred to as intrusion Detection System (IDS). Within the Internet of Things (IoT) systems, the IDS examines the large volume and non-uniform traffic of the distributed and resource-constrained devices with the aim of detecting the cyber-attacks in real time. However, the existing designs of the IoT-based IDS are not only expensive to compute but are also limited in their dynamism to the variations in the traffic, and degrade substantially in their performance under the condition of the distribution shifts. In an attempt to relieve these problems this paper will propose a new light and adaptive IDS architecture. Adaptive Feature-aware Traffic Encoding (AFTE) is the method which dynamically adjusts the network parameter, which is the feature of the network the network according to the statistic and time, which enhances resistance to the changing IoT traffic. It has been demonstrated that Hybrid Partial -Temporal Convolution Network (HPTCN) provides a good way to capture discriminative spatio-temporal features at a low cost of computation through partial convolution and gated temporal modelling. Continual Multi-source Knowledge Distillation (CMKD) is an online cross-domain adaptation algorithm that employs knowledge transfer between two or more teachers that adapt with time, and thus is more resistant to unseen and few-shot attacks. It is experimentally demonstrated that the proposed framework is very precise in finding and much less expensive in computation and enhanced generalization in dynamic IoT.
The rapid proliferation of the Internet of Things (IoT) has increased network complexity and exposed IoT infrastructures to diverse and evolving cyber threats. Traditional intrusion detection systems (IDSs), whether signature based or machine learning based, often struggle to adapt to emerging attack patterns and frequently operate as “black boxes” with limited interpretability. To address these challenges, this paper proposes a novel Large Language Model-based Explainable IDS for IoT networks. The system fine-tunes an open-source large language model, LLaMA 3.3, to jointly perform intrusion detection and natural-language explanation generation. The model is trained on multiple IoT security datasets, namely CIC-IoT-2023 [1], BoT-IoT [2], and ToN_IoT [3] to recognize various attack types, including distributed denial-of-service (DDoS), botnet activity, man-in-the-middle (MITM), and data exfiltration. Experimental results show that the fine-tuned LLM outperforms both zero-shot LLM baselines and traditional machine learning classifiers, achieving competitive accuracy while delivering concise, human-readable explanations for each prediction. By integrating detection and explainability within a single model, the proposed framework enhances transparency, interpretability, and usability.
In the era of contemporary data traffic routing, the concept of Intrusion Detection Systems (IDS) is substantially utilized. However, the efficacy of IDS is often decreased because of the reality that high-concentration traffic postfixes, sophisticated cyber criminals, and more and more stringent demands are tending to decrease in resource-limited environments. The paper presents the enhanced intrusion detection system based on deep learning architecture, which can be flexible, adaptive and as well maintain the high detection capability with confidence under changing or to-be changed network settings. The objectives of this and aforementioned also address the issue of avoiding strong overtting behavior by models during the transfer learning and even rich feature representation through the first-stage operation: moving to address and ideally preventing attacks rather than supporting other attacks. The work is tailored to the deployment of the light-weight and adaptive IDS design which is supposed to be large enough to work in real time on low-powered devices such as IoTs and edge devices that are nondominated in energy and computationally less demanding. Real-time adaptability of the model will be examined through operational deployment simulations. It is also expected that such simulations would take into account latency, throughput, and energy consumption of the IDS model. On the one hand, In a stage nested within the very last period of this research, the IDS model has been merged with Explainable AI technologies; now LIME and SHAP are also preserved to improve the interpretability of the model decisions and the level of decision-making. What kind of feature attributions are made with the intrusion data? How is Interpretability of the model evaluated in terms of fidelity, comprehensibility, and expert belief? Therefore, all the above-mentioned events will be a perfect example of how the technologically ingrained tasks, particularly in the technical discipline of security studies, can be wrapped into the very cognitive resource of human beings.
Krishna Kumar Tiwari· 2026 International Conferenc...· 0 citations
The Internet of Things (IoT) has become increasingly integrated into our daily lives, offering a wide range of services through the proliferation of connected devices. While this connectivity enhances convenience and functionality, it also introduces significant security challenges, exposing IoT systems to various forms of cyberattacks. In this paper, we propose a lightweight edge-based intrusion detection approach for massive IoT networks, leveraging a Long Short-Term Memory (LSTM) model to achieve high accuracy with minimal resource consumption. Unlike centralized solutions, the proposed system is fully implemented and deployed at the edge level, enabling local traffic analysis directly on edge devices. This design reduces latency, minimizes bandwidth consumption, enhances data privacy, and ensures real-time detection capabilities in large-scale IoT environments. The approach incorporates an efficient data pre-processing methodology applied to the wellknown Avast IoT-23 dataset, resulting in a detection accuracy of 99.9% with a compact model size of only 1767 KB. To further optimize performance, the system decomposes the data into clusters before applying a tailored LSTM model for each subset. Experimental evaluation using real malicious traffic demonstrates that the proposed model achieves up to 90% specificity and 88% precision under real-world conditions. These results confirm the effectiveness of our edge-level LSTM framework in providing secure, scalable, and resource-efficient intrusion detection for large-scale IoT environments.
In the fast-growing world of Internet of Things (IoT), devices have exploded that are not only efficient but also expose serious security vulnerabilities that can be used as vectors for more advanced cyber-attacks. Traditional IDS has the challenge of false positive rate, which could cause critical operations to be disrupted in various domains from smart medical devices (SMDs) to municipal infrastructure. Machine Learning (ML) and Deep Learning (DL) models are state-of-the art solutions to detect complex, high-dimensional and temporal network anomalies in terms of accuracy but their deployment is still hampered severely due to the fact that they lack interpretability. This paper introduces a new explainable hybrid IDS architecture for IoT environments named XABiL-IDS (Explainable Attention-based Bi LSTM-Intrusion Detection System) in response to this challenge. This study uses a robust hybrid architecture to detect attacks effectively. Global analysis using the SHAP method for determining the most relevant traffic attributes affecting the classification process in the dataset on the other hand local analysis done by LIME for providing explanation at the instance level on the prediction made regarding network flows. The key differentiating feature of this approach compared to earlier methods is the incorporation of both global and local explainability in single pipeline.
Ravi Patni, Gurvinder Singh· International journal of com...· 0 citations
A behavior-sensitive access control solution is presented, which integrates lightweight supervised Machine Learning on the IoT gateway to provide dynamic authorization and uses a Supervised Random Forest model to process real-time statistical feature summaries in terms of mean, standard deviation, and sparsity of the IoT telemetry data.
Yaseen Alduwayl, Abdullah T. Al-Essa, Mounir Frikha· International Journal of Adv...· 0 citations
Internet of Things (IoT) devices are vulnerable to zero-day attacks because most of them have weak or no inherent security due to the resource constraints of the devices. This weakness underscores the growing need for anomaly-based intrusion detection systems tailored to IoT networks. Nevertheless, general anomaly detection traditionally has a high number of false positives that drain analysts' time. Also, a semantic difference exists between the system's results and the operators' interpretations. We introduce a machine learning-based framework to tackle these issues in traditional systems in this paper by combining large language models (LLMs). Our model is effective in identifying possible threats as well as filling the semantic gap. The framework uses isolation forests to detect anomalies and random forests to measure device integrity. To further improve the assessment of anomalies and increase interpretability, system insights are further refined using GPT-4o mini, an LLM. The model gives statistical summaries of the IoT traffic, a risk score, and an explanation in easy language, which is easy to understand and therefore makes the process of decision-making easier. Such a novel system reduces the reliance on dedicated network operators and allows non-technical users to better understand and act on the results of the system.
M. Saeed, Rashid A. Saeed, Salah Hagahmoodi et al.· Baghdad Science Journal· 0 citations