Enhancing IoT intrusion detection performance using autoencoder-based feature optimization and K-Means clustering
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216275%3A25410%2F25%3A39923441" target="_blank" >RIV/00216275:25410/25:39923441 - isvavai.cz</a>
Result on the web
<a href="https://www.sciencedirect.com/science/article/pii/S1877050925031205" target="_blank" >https://www.sciencedirect.com/science/article/pii/S1877050925031205</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1016/j.procs.2025.09.447" target="_blank" >10.1016/j.procs.2025.09.447</a>
Alternative languages
Result language
angličtina
Original language name
Enhancing IoT intrusion detection performance using autoencoder-based feature optimization and K-Means clustering
Original language description
Deep learning plays a critical role in designing intrusion detection systems (IDS) to protect Internet of Things (IoT) environments against cyberattacks. However, the performance of DL-based IDS models heavily depends on the quality and balance of the training data. Real-world intrusion detection datasets often suffer from severe class imbalance, causing models to become biased toward majority attack types and underperform in detecting rare threats. While various techniques have been proposed to address class imbalance, the high dimensionality and complexity of IoT datasets remain significant challenges in building effective classifiers. Due to the dynamic nature of cyberattacks, no single method can fully address the diverse security threats in IoT networks. As a result, hybrid approaches have gained traction in enhancing cybersecurity solutions. This paper presents a novel hybrid method that combines an autoencoder and K-means clustering to generate a synthetic dataset that balances minority classes in the training set. The autoencoder reduces feature dimensionality, while K-means clustering supports oversampling of underrepresented classes. DL models are then employed for multi-class attack classification. The proposed approach is evaluated on the recent CICIoT2023 dataset. Experimental results demonstrate substantial improvements in recall, precision, and F1-score, especially in detecting minority class attacks. These findings indicate that the proposed method improves detection accuracy for rare intrusions, reduces false alarms, and supports administrators in deploying more effective IoT security measures.
Czech name
—
Czech description
—
Classification
Type
D - Article in proceedings
CEP classification
—
OECD FORD branch
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Result continuities
Project
—
Continuities
S - Specificky vyzkum na vysokych skolach<br>I - Institucionalni podpora na dlouhodoby koncepcni rozvoj vyzkumne organizace
Others
Publication year
2025
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Article name in the collection
Procedia Computer Science, vol. 270
ISBN
—
ISSN
1877-0509
e-ISSN
1877-0509
Number of pages
10
Pages from-to
3221-3230
Publisher name
Elsevier B.V.
Place of publication
Amsterdam
Event location
Osaka
Event date
Sep 10, 2025
Type of event by nationality
WRD - Celosvětová akce
UT code for WoS article
—