<p>The exponential growth of Internet of Things (IoT) ecosystems has introduced unprecedented cybersecurity challenges, making traditional Intrusion Detection Systems (IDS) increasingly ineffective in addressing sophisticated and evolving threats. Existing IDS frameworks often encounter issues such as high false positive rates, limited adaptability to new types of attacks, and poor efficiency in dynamic network environments. This paper presents an Intelligent Adaptive Intrusion Detection System (IA-IDS) that integrates advanced deep learning (DL) models with a dynamic feature selection strategy known as Dynamic Correlation-based Recursive Feature Selection (DCRFS). Unlike traditional anomaly-based IDS approaches that often rely on shallow models or handcrafted features, the proposed IA-IDS enhances anomaly detection capabilities by integrating Convolutional Neural Networks (CNNs), Bidirectional Long Short-Term Memory (BiLSTM) networks, and an attention mechanism to synergize their strengths for improved detection accuracy and adaptability. CNNs are used to extract spatial traffic patterns from raw network data, enabling the detection of complex behaviors and anomalies. BiLSTM networks capture long-term temporal dependencies within traffic sequences. An attention mechanism further enhances detection by focusing on the most critical segments of the temporal data, improving both performance and interpretability. The core contribution of this study is the development of the DCRFS algorithm, which enables real-time adaptation to changing threat landscapes by identifying and utilizing only the most pertinent features. This dynamic strategy overcomes the inefficiencies of static feature selection techniques by minimizing computational overhead while preserving high detection accuracy. Comprehensive evaluations on the BoT-IoT and TON-IoT datasets validate the system’s performance, with the IA-IDS achieving accuracies of 98.12% and 98.67%, and F1-scores of 98.08% and 98.51%, respectively. In addition to high accuracy and F1-scores, the IA-IDS achieves low False Positive Rates of 0.65% on the BoT-IoT dataset and 0.79% on the TON-IoT dataset, demonstrating its robustness in reducing false alarms and enhancing detection reliability in real-world IoT scenarios. These outcomes highlight substantial improvements compared to traditional intrusion detection models. The proposed approach offers a scalable, intelligent, and adaptive IDS framework, well-suited to counter both known and emerging threats within complex IoT ecosystems.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

IA-IDS: an intelligent adaptive intrusion detection system for IoT security using CNN, BiLSTM, and attention mechanism

  • Logeswari G,
  • Rudraksh Purbia,
  • Tamilarasi K,
  • Bose S

摘要

The exponential growth of Internet of Things (IoT) ecosystems has introduced unprecedented cybersecurity challenges, making traditional Intrusion Detection Systems (IDS) increasingly ineffective in addressing sophisticated and evolving threats. Existing IDS frameworks often encounter issues such as high false positive rates, limited adaptability to new types of attacks, and poor efficiency in dynamic network environments. This paper presents an Intelligent Adaptive Intrusion Detection System (IA-IDS) that integrates advanced deep learning (DL) models with a dynamic feature selection strategy known as Dynamic Correlation-based Recursive Feature Selection (DCRFS). Unlike traditional anomaly-based IDS approaches that often rely on shallow models or handcrafted features, the proposed IA-IDS enhances anomaly detection capabilities by integrating Convolutional Neural Networks (CNNs), Bidirectional Long Short-Term Memory (BiLSTM) networks, and an attention mechanism to synergize their strengths for improved detection accuracy and adaptability. CNNs are used to extract spatial traffic patterns from raw network data, enabling the detection of complex behaviors and anomalies. BiLSTM networks capture long-term temporal dependencies within traffic sequences. An attention mechanism further enhances detection by focusing on the most critical segments of the temporal data, improving both performance and interpretability. The core contribution of this study is the development of the DCRFS algorithm, which enables real-time adaptation to changing threat landscapes by identifying and utilizing only the most pertinent features. This dynamic strategy overcomes the inefficiencies of static feature selection techniques by minimizing computational overhead while preserving high detection accuracy. Comprehensive evaluations on the BoT-IoT and TON-IoT datasets validate the system’s performance, with the IA-IDS achieving accuracies of 98.12% and 98.67%, and F1-scores of 98.08% and 98.51%, respectively. In addition to high accuracy and F1-scores, the IA-IDS achieves low False Positive Rates of 0.65% on the BoT-IoT dataset and 0.79% on the TON-IoT dataset, demonstrating its robustness in reducing false alarms and enhancing detection reliability in real-world IoT scenarios. These outcomes highlight substantial improvements compared to traditional intrusion detection models. The proposed approach offers a scalable, intelligent, and adaptive IDS framework, well-suited to counter both known and emerging threats within complex IoT ecosystems.