<p>The quick implementation of Software-Defined Internet of Things (SD-IoT) infrastructures has exacerbated the challenge of security, as classical intrusion detection systems are not always well adapted to address the dynamic, large-scale, and heterogeneous traffic patterns. In order to address these weaknesses, this paper will introduce a hybrid intrusion detection and predictive mitigation architecture, including Graph Neural Networks (GNN), Transformer encoders, and a Proximal Policy Optimization (PPO)-based reinforcement learning agent. To optimize the features, a joint SHapley Additive exPlanations (SHAP) and Recursive Feature Elimination (RFE) model is applied; to optimize the system, we apply Golden Jackal Optimization (GJO) and Adaptive Differential Privacy (ADP) to the federated learning setup. Considerable tests on three benchmark datasets, namely, CIC-IoT-2023, ToN-IoT, and Edge-IIoTset, reveal the enhanced performance of the suggested framework. It achieves a maximum accuracy of 98.7% and false alarms of 98.6% on CIC-IoT-2023, 95.8% on ToN-IoT, and 93.4% on Edge-IIoTset at an average cross-dataset accuracy of 96.0 and a minimum false alarm rate of 3.5. Ablation experiments demonstrate the importance of the PPO, GNN, Transformer, GJO, and ADP, and demonstrate that the full model outperforms all reduced versions of the model. The results are statistically validated with 95% confidence intervals to ensure the results are reliable, and experimentation on federated learning has shown that it can provide good privacy with minimal accuracy loss and communication overhead. Having a significant potential for real-world implementation in edge-enabled smart environments, the conclusions of the study reveal the proposed architecture to be a reliable, scalable, and non-invasive intrusion detection and mitigation system for a wide range of IoT networks.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

AI-driven intrusion detection and mitigation framework for software-defined IoT networks

  • Jamal Alotaibi

摘要

The quick implementation of Software-Defined Internet of Things (SD-IoT) infrastructures has exacerbated the challenge of security, as classical intrusion detection systems are not always well adapted to address the dynamic, large-scale, and heterogeneous traffic patterns. In order to address these weaknesses, this paper will introduce a hybrid intrusion detection and predictive mitigation architecture, including Graph Neural Networks (GNN), Transformer encoders, and a Proximal Policy Optimization (PPO)-based reinforcement learning agent. To optimize the features, a joint SHapley Additive exPlanations (SHAP) and Recursive Feature Elimination (RFE) model is applied; to optimize the system, we apply Golden Jackal Optimization (GJO) and Adaptive Differential Privacy (ADP) to the federated learning setup. Considerable tests on three benchmark datasets, namely, CIC-IoT-2023, ToN-IoT, and Edge-IIoTset, reveal the enhanced performance of the suggested framework. It achieves a maximum accuracy of 98.7% and false alarms of 98.6% on CIC-IoT-2023, 95.8% on ToN-IoT, and 93.4% on Edge-IIoTset at an average cross-dataset accuracy of 96.0 and a minimum false alarm rate of 3.5. Ablation experiments demonstrate the importance of the PPO, GNN, Transformer, GJO, and ADP, and demonstrate that the full model outperforms all reduced versions of the model. The results are statistically validated with 95% confidence intervals to ensure the results are reliable, and experimentation on federated learning has shown that it can provide good privacy with minimal accuracy loss and communication overhead. Having a significant potential for real-world implementation in edge-enabled smart environments, the conclusions of the study reveal the proposed architecture to be a reliable, scalable, and non-invasive intrusion detection and mitigation system for a wide range of IoT networks.