Enhancing IoT intrusion detection performance using autoencoder-based feature optimization and K-Means clustering
Identifikátory výsledku
Kód výsledku v IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F00216275%3A25410%2F25%3A39923441" target="_blank" >RIV/00216275:25410/25:39923441 - isvavai.cz</a>
Výsledek na webu
<a href="https://www.sciencedirect.com/science/article/pii/S1877050925031205" target="_blank" >https://www.sciencedirect.com/science/article/pii/S1877050925031205</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1016/j.procs.2025.09.447" target="_blank" >10.1016/j.procs.2025.09.447</a>
Alternativní jazyky
Jazyk výsledku
angličtina
Název v původním jazyce
Enhancing IoT intrusion detection performance using autoencoder-based feature optimization and K-Means clustering
Popis výsledku v původním jazyce
Deep learning plays a critical role in designing intrusion detection systems (IDS) to protect Internet of Things (IoT) environments against cyberattacks. However, the performance of DL-based IDS models heavily depends on the quality and balance of the training data. Real-world intrusion detection datasets often suffer from severe class imbalance, causing models to become biased toward majority attack types and underperform in detecting rare threats. While various techniques have been proposed to address class imbalance, the high dimensionality and complexity of IoT datasets remain significant challenges in building effective classifiers. Due to the dynamic nature of cyberattacks, no single method can fully address the diverse security threats in IoT networks. As a result, hybrid approaches have gained traction in enhancing cybersecurity solutions. This paper presents a novel hybrid method that combines an autoencoder and K-means clustering to generate a synthetic dataset that balances minority classes in the training set. The autoencoder reduces feature dimensionality, while K-means clustering supports oversampling of underrepresented classes. DL models are then employed for multi-class attack classification. The proposed approach is evaluated on the recent CICIoT2023 dataset. Experimental results demonstrate substantial improvements in recall, precision, and F1-score, especially in detecting minority class attacks. These findings indicate that the proposed method improves detection accuracy for rare intrusions, reduces false alarms, and supports administrators in deploying more effective IoT security measures.
Název v anglickém jazyce
Enhancing IoT intrusion detection performance using autoencoder-based feature optimization and K-Means clustering
Popis výsledku anglicky
Deep learning plays a critical role in designing intrusion detection systems (IDS) to protect Internet of Things (IoT) environments against cyberattacks. However, the performance of DL-based IDS models heavily depends on the quality and balance of the training data. Real-world intrusion detection datasets often suffer from severe class imbalance, causing models to become biased toward majority attack types and underperform in detecting rare threats. While various techniques have been proposed to address class imbalance, the high dimensionality and complexity of IoT datasets remain significant challenges in building effective classifiers. Due to the dynamic nature of cyberattacks, no single method can fully address the diverse security threats in IoT networks. As a result, hybrid approaches have gained traction in enhancing cybersecurity solutions. This paper presents a novel hybrid method that combines an autoencoder and K-means clustering to generate a synthetic dataset that balances minority classes in the training set. The autoencoder reduces feature dimensionality, while K-means clustering supports oversampling of underrepresented classes. DL models are then employed for multi-class attack classification. The proposed approach is evaluated on the recent CICIoT2023 dataset. Experimental results demonstrate substantial improvements in recall, precision, and F1-score, especially in detecting minority class attacks. These findings indicate that the proposed method improves detection accuracy for rare intrusions, reduces false alarms, and supports administrators in deploying more effective IoT security measures.
Klasifikace
Druh
D - Stať ve sborníku
CEP obor
—
OECD FORD obor
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Návaznosti výsledku
Projekt
—
Návaznosti
S - Specificky vyzkum na vysokych skolach<br>I - Institucionalni podpora na dlouhodoby koncepcni rozvoj vyzkumne organizace
Ostatní
Rok uplatnění
2025
Kód důvěrnosti údajů
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Údaje specifické pro druh výsledku
Název statě ve sborníku
Procedia Computer Science, vol. 270
ISBN
—
ISSN
1877-0509
e-ISSN
1877-0509
Počet stran výsledku
10
Strana od-do
3221-3230
Název nakladatele
Elsevier B.V.
Místo vydání
Amsterdam
Místo konání akce
Osaka
Datum konání akce
10. 9. 2025
Typ akce podle státní příslušnosti
WRD - Celosvětová akce
Kód UT WoS článku
—