Submitted:
06 September 2025
Posted:
09 September 2025
Read the latest preprint version here
Abstract
Keywords:
1. Introduction
- 1)
- Malware infects compromised IoT devices.
- 2)
- The malware spreads through device-to-device infection to create botnets.
- 3)
- Synchronized attacks occur using different methods (Layer 7 application-based, IP-based, TCP-based, UDP-based, and Service Discovery Protocol-based attacks).
- 4)
- Resources are exhausted through bandwidth and processing overload.
- 5)
- Legitimate service requests are blocked.
- 6)
- Finally, this leads to denial of service for all legitimate users, regardless of their authenticity.
- We created an efficient anomaly-based intrusion detection framework using Modified Gated Recurrent Units (MGRU). This framework is designed specifically for multi-vector intrusion detection in resource-limited IoMT environments [9]. The MGRU model outperforms traditional LSTM networks by reducing computational demands while maintaining effective sequence modeling for network traffic monitoring [13].
- We developed two detection classifiers to meet different user needs. The Binary Label Classifier (BLC) serves non-technical healthcare staff by providing basic notifications of attack presence, while the Multi-Label Classifier (MLC) offers technical users detailed information about attack vectors and categorization. This dual-classifier approach ensures that the correct information reaches various groups within healthcare facilities.
- We conducted thorough testing using current datasets, specifically the CICIoT2023 and CICIoMT2024 datasets, as well as genetic algorithm-based feature selection to optimize detection performance [14,15]. The testing assesses various performance metrics, including accuracy, precision, recall, F1-score, sensitivity, specificity, false alarm rate (FAR), false positive rate (FPR), Matthews Correlation Coefficient (MCC), model size, training time, and attack detection time [16,17].
- We evaluate MGRU's performance against previous intrusion detection models, highlighting the benefits of a genetic algorithm-based feature selection approach.
2. Literature Review
2.1. Deep Learning Approaches in Healthcare IDS
2.2. Lightweight IDS Solutions for Resource-Constrained Environments
2.3. Multi-Vector Attack Detection and Classification
2.4. Ensemble and Hybrid Learning Approaches
2.5. Specialized Detection for Healthcare Applications
2.6. Emerging Threats and Advanced Detection Techniques
3. Preliminaries
3.1. Gated Recurrent Unit (GRU): The Lightweight Solution
-
Update Gate (zt): This gate determines the amount of the past hidden state to retain for the current hidden state. It is calculated by:(1)
-
Reset Gate (rt): This gate controls how much of the past hidden state to forget when calculating the candidate hidden state. It is calculated by:(2)
-
Candidate Activation (): The reset gate will add this new information.:(3)
-
Hidden State Update (): The new hidden state is a weighted sum of the old hidden state and the candidate hidden state, governed by the update gate:(4)
3.2. Modified GRU Architecture
-
Update Gate (zt): Similar to the regular GRU, it regulates the proportion of keeping the past hidden state and integrating new information:(5)
-
Candidate Activation (): Without a reset gate, the candidate hidden state is calculated directly from the last hidden state:(6)
-
Hidden State Update (): Calculate the latest hidden state as:(7)
4. Dataset Selection and Preparation
4.1. Healthcare-Specific Dataset Analysis
4.2. General IoT Dataset Evaluation
4.3. Dataset Selection Methodology
4.4. Attack Label Selection and Categorization
4.5. Data Preprocessing and Preparation Pipeline
4.5.1. Feature Engineering and Selection
4.5.2. Dataset Balancing and Augmentation
| Algorithm 1 Genetic Algorithm for Feature Selection |
|
Ensure:Training data matrix, labels Require: Population size P, number of generations G, crossover probability pc, mutation probability pm, tournament size T Initialize Population For each individual i = 1 to P, generate a random bitmask where sj(i) = 1 indicates feature j is selected. Evaluate Initial Fitness For each individual s(i):Form reduced dataset Train a lightweight classifier on (X′,Y). Compute validation accuracy F(s(i)). Evolutionary Loop For generation g = 1 to G: 3.1. Selection (Tournament) For each of P offspring: Randomly pick T individuals from the current population. Parent p := individual with the highest fitness among those T. 3.2.Crossover Pair up selected parents at random. For each pair (pa,pb): With probability pc, choose two crossover points c1 < c2. Swap bits between c1 and c2 to form two children. Otherwise, children = exact copies of parents. 3.3. Mutation For each bit in each child, flip the bit with probability pm. 3.4. Fitness Evaluation For each new child s: Compute F(s) as in step 2. 3.5. Elitism & Replacement Combine the current population and offspring. Sort all 2P individuals by fitness F. Keep the top P individuals for the next generation.Return Best Mask Let Output the feature index set |
5. Proposed Framework

- Cardiac Pacemakers: High-end cardiac rhythm management devices that track heart function and offer electrical stimulation to ensure optimal cardiac performance.
- Cochlear Implants: Advanced auditory prosthetic devices that translate sound signals into electrical impulses for individuals with profound hearing loss.
- Gastric Stimulators: Medical devices that modulate digestive system function by controlled electrical stimulation.
- Implantable Biosensors: Real-time monitoring devices that monitor multiple physiological parameters such as glucose, blood pressure, and tissue oxygenation.
- Smart ECG Monitors: Handheld electrocardiogram units that continuously record cardiac electrical activity and identify arrhythmias or other cardiac abnormalities.
- Depression Level Monitors: An advanced way to track psychological health-related behavioral patterns, along with physiological markers involved.
- Smart Insulin Monitors: Continuous glucose monitoring systems combined with the provision of automatic implantable mechanisms for insulin delivery in patients who have diabetes.
- Smart Blood Pressure Monitors: Blood pressure measurement units with automatic capabilities and remote monitoring via wireless connectivity.

5.1. Stakeholder Classification and Alert Mechanisms
- Hospital Management: Management staff are in charge of operational management and resource allocation decisions.
- Medical Physicians: Clinicians who need continued access to patient data and medical systems.
- Nursing Staff: Frontline medical caregivers who rely on stable IoMT systems for patient monitoring and care provision.
- Patient Caregivers: Support staff involved in patient care activities and health status monitoring.
- Emergency Services: Emergency response teams need immediate access to patient information during emergency responses.
5.2. Proposed Intrusion Detection Framework Architecture
5.2.1. Binary Label Classifier (BLC) Design
5.2.2. Multi-Label Classifier (MLC) Design
5.3. MGRU-Based Deep Learning Implementation
5.3.1. Modified GRU Architecture Optimization
5.3.2. Training and Optimization Methodology
6. Experimental Results and Performance Analysis
| Algorithm 2 Training and Evaluation of BLC | |
|
1: 2: 3: 4: 5: 6: 7: 8: 9: 10: 11: 12: 13: 14: 15: 16: 17: 18: 19: 20: 21: 22: 23: 24: 25: 26: 27: 28: 29: |
Inputs: Datasets, Batch size B, Number of epochs E, Learning rate Lr Split Dataset into training set X_train, validation set X_val, and test set X_test Preprocess features: for each X in X_train, X_val, X_test do X_norm ← normalize(X) end for Define model: Input → mGRU(128, return_sequences=True) → mGRU(64, return_sequences=True) → mGRU(32, return_sequences=False) → Dense(1, activation='sigmoid') Compile model with: optimizer = Adam(learning_rate=Lr) loss = BinaryCrossentropy() metrics = [Accuracy()] Train model: history ← model.fit( x = X_train.features, y = X_train.labels, batch_size = B, epochs = E, validation_data = (X_val.features, X_val.labels) ) Evaluate model on X_test: results ← model.evaluate(X_test.features, X_test.labels) Print test loss and metrics from results |
| Algorithm 3 Training and Evaluation of MLC | |
|
1: 2: 3: 4: 5: 6: 7: 8: 9: 10: 11: 12: 13: 14: 15: 16: 17: 18: 19: 20: 21: 22: 23: 24: 25: 26: 27: 28: 29: |
Inputs: Datasets, Batch size B, Number of epochs E, Learning rate Lr Split Dataset into training set X_train, validation set X_val, and test set X_test Preprocess features: for each X in X_train, X_val, X_test do X_norm ← normalize(X) end for Define model: Input → mGRU(128, return_sequences=True) → mGRU(64, return_sequences=True) → mGRU(32, return_sequences=False) → Dense(C, activation='softmax') Compile model with: optimizer = Adam(learning_rate=Lr) loss = SparseCategoricalCrossentropy() metrics = [Accuracy()] Train model: history ← model.fit( x = X_train.features, y = X_train.labels, batch_size = B, epochs = E, validation_data = (X_val.features, X_val.labels) ) Evaluate model on X_test: results ← model.evaluate(X_test.features, X_test.labels) Print test loss and metrics from results |
6.1. Results of BLC
6.2. Results of MLC
7. Discussion
Complexity Analysis
- Real-Time Data: In the future, we will construct a testbed to monitor real-time IoT healthcare traffic through multiple medical sensors and wearable devices.
- Authentication: This study assumes that all IoMT devices in an IoT environment are authenticated. Hence, it does not cover authentication and identification schemes. We aim to develop a lightweight authentication protocol for IoT-based healthcare devices based on Authenticated Encryption with Associated Data (AEAD).
8. Conclusions and Future Work
Author Contributions
Funding
Conflicts of Interest
References
- Ul, I.; Bin, M.; Asif, M.; Ullah, R. DoS/DDoS Detection for E-Healthcare in Internet of Things. Int. J. Adv. Comput. Sci. Appl. 2018, 9. [Google Scholar] [CrossRef]
- Sharma, S.; Kumari, B.; Ali, A.; Yadav, R.K.; Sharma, A.K.; Sharma, K.K.; Hajela, K.; Singh, G.K. Mobile technology. J. Fam. Med. Prim. Care 2022, 11, 37–43. [Google Scholar] [CrossRef]
- Dzamesi, L.; Elsayed, N. A Review on the Security Vulnerabilities of the IoMT Against Malware Attacks and DDoS. 2025 IEEE 4th International Conference on Computing and Machine Intelligence (ICMI). LOCATION OF CONFERENCE, United StatesDATE OF CONFERENCE; pp. 01–08.
- Elsayed, N.; Dzamesi, L.; ElSayed, Z.; Ozer, M. Extreme Learning Machine-Based System for DDoS Attacks Detections on IoMT Devices. arXiv.org. [Online]. Available: https://arxiv.org/abs/2507.05132.
- Pakmehr, A.; Aßmuth, A.; Taheri, N.; Ghaffari, A. DDoS attack detection techniques in IoT networks: a survey. Clust. Comput. 2024, 27, 14637–14668. [Google Scholar] [CrossRef]
- Aguru, A.; Erukala, S. OTI-IoT: A Blockchain-based Operational Threat Intelligence Framework for Multi-vector DDoS Attacks. ACM Trans. Internet Technol. 2024, 24, 1–31. [Google Scholar] [CrossRef]
- Abiramasundari, S.; Ramaswamy, V. Distributed denial-of-service (DDOS) attack detection using supervised machine learning algorithms. Sci. Rep. 2025, 15, 1–14. [Google Scholar] [CrossRef]
- Hassan, A.I.; El Reheem, E.A.; Guirguis, S.K. An entropy and machine learning based approach for DDoS attacks detection in software defined networks. Sci. Rep. 2024, 14, 1–18. [Google Scholar] [CrossRef]
- P. N. K. Intrusion Detection System Using Gated Recurrent Neural Network. 618, vol. 10, no. 01, pp. 1–8, May 2024.
- Kumar, D.; Pateriya, R.; Gupta, R.K.; Dehalwar, V.; Sharma, A. DDoS Detection using Deep Learning. Procedia Comput. Sci. 2023, 218, 2420–2429. [Google Scholar] [CrossRef]
- Kasongo, S.M.; Sun, Y. A Deep Gated Recurrent Unit based model for wireless intrusion detection system. ICT Express 2021, 7, 81–87. [Google Scholar] [CrossRef]
- Neal, D. Choosing an electronic health records system: professional liability considerations. 2011, 8, 43–45. [Google Scholar]
- Agarap, A.F.M. A Neural Network Architecture Combining Gated Recurrent Unit (GRU) and Support Vector Machine (SVM) for Intrusion Detection in Network Traffic Data. In Proceedings of the 2018 10th International Conference on Machine Learning and Computing, Macau, China, 26–28 February 2018. [Google Scholar]
- Neto, E.C.P.; Dadkhah, S.; Ferreira, R.; Zohourian, A.; Lu, R.; Ghorbani, A.A. CICIoT2023: A Real-Time Dataset and Benchmark for Large-Scale Attacks in IoT Environment. Sensors 2023, 23, 5941. [Google Scholar] [CrossRef]
- Dadkhah, S.; Neto, E.C.P.; Ferreira, R.; Molokwu, R.C.; Sadeghi, S.; Ghorbani, A. CiCIoMT2024: Attack Vectors in Healthcare Devices-A Multi-Protocol Dataset for Assessing IoMT Device Security. Elsevier BV, 2024. Accessed: Aug. 04, 2025. [Online]. [CrossRef]
- Maseno, E.M.; Wang, Z. Hybrid wrapper feature selection method based on genetic algorithm and extreme learning machine for intrusion detection. J. Big Data 2024, 11, 1–25. [Google Scholar] [CrossRef]
- Alghoson, E.S.; Abbass, O. Detecting Distributed Denial of Service Attacks using Machine Learning Models. Int. J. Adv. Comput. Sci. Appl. 2021, 12. [Google Scholar] [CrossRef]
- Kumaar, M.A.; Samiayya, D.; Vincent, P.M.D.R.; Srinivasan, K.; Chang, C.-Y.; Ganesh, H. A Hybrid Framework for Intrusion Detection in Healthcare Systems Using Deep Learning. Front. Public Heal. 2022, 9, 824898. [Google Scholar] [CrossRef]
- Saif, S.; Das, P.; Biswas, S.; Khari, M.; Shanmuganathan, V. HIIDS: Hybrid intelligent intrusion detection system empowered with machine learning and metaheuristic algorithms for application in IoT based healthcare. Microprocess. Microsystems 2022. [Google Scholar] [CrossRef]
- Patel, S.K. Improving intrusion detection in cloud-based healthcare using neural network. Biomed. Signal Process. Control. 2023, 83. [Google Scholar] [CrossRef]
- Hady, A.A.; Ghubaish, A.; Salman, T.; Unal, D.; Jain, R. Intrusion Detection System for Healthcare Systems Using Medical and Network Data: A Comparison Study. IEEE Access 2020, 8, 106576–106584. [Google Scholar] [CrossRef]
- Iwendi, C.; Anajemba, J.H.; Biamba, C.; Ngabo, D. Security of Things Intrusion Detection System for Smart Healthcare. Electronics 2021, 10, 1375. [Google Scholar] [CrossRef]
- Basharat, A.; Bin Mohamad, M.M.; Khan, A. Machine Learning Techniques for Intrusion Detection in Smart Healthcare Systems: A Comparative Analysis. 2022 4th International Conference on Smart Sensors and Application (ICSSA). LOCATION OF CONFERENCE, MalaysiaDATE OF CONFERENCE; pp. 29–33.
- Tuteja, A.; Matta, P.; Sharma, S.; Nandan, K.; Gautam, P. Intrusion Detection in Health Care System: A logistic Regression Approach. 2022 5th International Conference on Contemporary Computing and Informatics (IC3I). LOCATION OF CONFERENCE, IndiaDATE OF CONFERENCE; pp. 1794–1799.
- Ahmed, M.; Byreddy, S.; Nutakki, A.; Sikos, L.F.; Haskell-Dowland, P. ECU-IoHT: A dataset for analyzing cyberattacks in Internet of Health Things. Ad Hoc Networks 2021, 122. [Google Scholar] [CrossRef]
- Dina, A.S.; Siddique, A.; Manivannan, D. A deep learning approach for intrusion detection in Internet of Things using focal loss function. Internet Things 2023, 22. [Google Scholar] [CrossRef]
- Almutairi, A.F.; Alshargabi, A.A. Using Deep Learning Technique to Protect Internet Network from Intrusion in IoT Environment. 2022 2nd International Conference on Emerging Smart Technologies and Applications (eSmarTA). LOCATION OF CONFERENCE, YemenDATE OF CONFERENCE; pp. 1–6.
- Ariffin, S.H.S.; Mustaffa, N.H.; Dewanta, F.; Hamzah, I.W.; Baharudin, M.A.; Wahab, N.H.A. Hybrid Feature Selection Based Lightweight Network Intrusion Detection System for MQTT Protocol. 2023 15th International Conference on Software, Knowledge, Information Management and Applications (SKIMA). LOCATION OF CONFERENCE, MalaysiaDATE OF CONFERENCE; pp. 226–230.
- Alani, M.M. IoTProtect: A Machine-Learning Based IoT Intrusion Detection System. 2022 6th International Conference on Cryptography, Security and Privacy (CSP). LOCATION OF CONFERENCE, ChinaDATE OF CONFERENCE; pp. 61–65.
- Ramaiah, M.; Rahamathulla, M.Y. Securing the Industrial IoT: A Novel Network Intrusion Detection Models. 2024 3rd International Conference on Artificial Intelligence For Internet of Things (AIIoT). LOCATION OF CONFERENCE, IndiaDATE OF CONFERENCE; pp. 1–6.
- Adebayo, P.O.; Abdulahi, M.J.; Lawrence, O.M.; Ibrahim, Y.A.; Faki, S.A.; Hassan, B.A. An Artificial Intelligence-based Ensemble Technique for Intrusion Detection and Prevention in IoT Systems. 2024 International Conference on Science, Engineering and Business for Driving Sustainable Development Goals (SEB4SDG). LOCATION OF CONFERENCE, NigeriaDATE OF CONFERENCE; pp. 1–6.
- Guo, G.; Pan, X.; Liu, H.; Li, F.; Pei, L.; Hu, K. An IoT Intrusion Detection System Based on TON IoT Network Dataset. 2023 IEEE 13th Annual Computing and Communication Workshop and Conference (CCWC). LOCATION OF CONFERENCE, United StatesDATE OF CONFERENCE; pp. 0333–0338.
- Ma, R.; Wang, Q.; Bu, X.; Chen, X. Real-Time Detection of DDoS Attacks Based on Random Forest in SDN. Appl. Sci. 2023, 13, 7872. [Google Scholar] [CrossRef]
- Ahmed, S.; Khan, Z.A.; Mohsin, S.M.; Latif, S.; Aslam, S.; Mujlid, H.; Adil, M.; Najam, Z. Effective and Efficient DDoS Attack Detection Using Deep Learning Algorithm, Multi-Layer Perceptron. Futur. Internet 2023, 15, 76. [Google Scholar] [CrossRef]
- Li, J.; Lyu, L.; Liu, X.; Zhang, X.; Lyu, X. FLEAM: A Federated Learning Empowered Architecture to Mitigate DDoS in Industrial IoT. IEEE Trans. Ind. Informatics 2021, 18, 4059–4068. [Google Scholar] [CrossRef]
- Vishwakarma, R.; Jain, A.K. A Honeypot with Machine Learning based Detection Framework for defending IoT based Botnet DDoS Attacks. 2019 3rd International Conference on Trends in Electronics and Informatics (ICOEI). LOCATION OF CONFERENCE, IndiaDATE OF CONFERENCE; pp. 1019–1024.
- Zeeshan, M.; Riaz, Q.; Bilal, M.A.; Shahzad, M.K.; Jabeen, H.; Haider, S.A.; Rahim, A. Protocol-Based Deep Intrusion Detection for DoS and DDoS Attacks Using UNSW-NB15 and Bot-IoT Data-Sets. IEEE Access 2021, 10, 2269–2283. [Google Scholar] [CrossRef]
- Roopak, M.; Tian, G.Y.; Chambers, J. An Intrusion Detection System Against DDoS Attacks in IoT Networks. 2020 10th Annual Computing and Communication Workshop and Conference (CCWC). LOCATION OF CONFERENCE, United StatesDATE OF CONFERENCE; pp. 0562–0567.
- Jia, Y.; Zhong, F.; Alrawais, A.; Gong, B.; Cheng, X. FlowGuard: An Intelligent Edge Defense Mechanism Against IoT DDoS Attacks. IEEE Internet Things J. 2020, 7, 9552–9562. [Google Scholar] [CrossRef]
- Sangodoyin, A.O.; Akinsolu, M.O.; Pillai, P.; Grout, V. Detection and Classification of DDoS Flooding Attacks on Software-Defined Networks: A Case Study for the Application of Machine Learning. IEEE Access 2021, 9, 122495–122508. [Google Scholar] [CrossRef]
- McDermott, C.D.; Majdani, F.; Petrovski, A.V. Botnet Detection in the Internet of Things using Deep Learning Approaches. 2018 International Joint Conference on Neural Networks (IJCNN). LOCATION OF CONFERENCE, BrazilDATE OF CONFERENCE; pp. 1–8.
- Ali, M.; Saleem, Y.; Hina, S.; Shah, G.A. DDoSViT: IoT DDoS attack detection for fortifying firmware Over-The-Air (OTA) updates using vision transformer. Internet Things 2025, 30. [Google Scholar] [CrossRef]
- M. Faltys et al., "HiRID, a high time-resolution ICU dataset." [Online]. Available: https://physionet.org/content/hirid/1.1/.
- Goldberger, A.L.; Amaral, L.A.N.; Glass, L.; Hausdorff, J.M.; Ivanov, P.C.; Mark, R.G.; Mietus, J.E.; Moody, G.B.; Peng, C.-K.; Stanley, H.E. PhysioBank, PhysioToolkit, and PhysioNet: Components of a New Research Resource for Complex Physiologic Signals. Circulation 2000, 101, E215–20. [Google Scholar] [CrossRef]
- WUSTL-IIOT-2021 Dataset for IIoT Cybersecurity Research." [Online]. Available: http://www.cse.wustl.edu/~jain/iiot2/index.
- Thomas, C.; Sharma, V.; Balakrishnan, N.; Dasarathy, B.V. Usefulness of DARPA dataset for intrusion detection system evaluation. SPIE Defense and Security Symposium. LOCATION OF CONFERENCE, United StatesDATE OF CONFERENCE;
- Koroniotis, N.; Moustafa, N.; Sitnikova, E.; Turnbull, B. Towards the development of realistic botnet dataset in the Internet of Things for network forensic analytics: Bot-IoT dataset. Futur. Gener. Comput. Syst. 2019, 100, 779–796. [Google Scholar] [CrossRef]
- Moustafa, N. and J. Slay. UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). in 2015 military communications and information systems conference (MilCIS). 2015. IEEE.
- Bala, R.; Nagpal, R. A REVIEW ON KDD CUP99 AND NSL-KDD DATASET. Int. J. Adv. Res. Comput. Sci. 2019, 10, 64–67. [Google Scholar] [CrossRef]
- Meidan, Y.; Bohadana, M.; Mathov, Y.; Mirsky, Y.; Shabtai, A.; Breitenbacher, D.; Elovici, Y. N-BaIoT—Network-Based Detection of IoT Botnet Attacks Using Deep Autoencoders. IEEE Pervasive Comput. 2018, 17, 12–22. [Google Scholar] [CrossRef]
- Kurniabudi; Stiawan, D. ; Darmawijoyo; Bin Idris, M.Y.; Bamhdi, A.M.; Budiarto, R. CICIDS-2017 Dataset Feature Analysis With Information Gain for Anomaly Detection. IEEE Access 2020, 8, 132911–132921. [Google Scholar] [CrossRef]
- Leevy, J.L.; Hancock, J.; Zuech, R.; Khoshgoftaar, T.M. Detecting cybersecurity attacks across different network features and learners. J. Big Data 2021, 8, 1–29. [Google Scholar] [CrossRef]
- Sharafaldin, AI. H.; Lashkari, SA.H. ; Hakak, and AS. A.; Ghorbani, “A.A. Developing Realistic Distributed Denial of Service (DDoS) Attack Dataset and Taxonomy,” in 2019 International Carnahan Conference on Security Technology (ICCST), Oct. 2019, pp. 1––8. [CrossRef]
- Hussain, F.; Abbas, S.G.; Husnain, M.; Fayyaz, U.U.; Shahzad, F.; Shah, G.A. IoT DoS and DDoS Attack Detection using ResNet. 2020 IEEE 23rd International Multitopic Conference (INMIC). LOCATION OF CONFERENCE, PakistanDATE OF CONFERENCE; pp. 1–6.
- Ravi, N.; Shalinie, S.M. Learning-Driven Detection and Mitigation of DDoS Attack in IoT via SDN-Cloud Architecture. IEEE Internet Things J. 2020, 7, 3559–3570. [Google Scholar] [CrossRef]
- Yao, Y.; Su, L.; Lu, Z. DeepGFL: Deep Feature Learning via Graph for Attack Detection on Flow-Based Network Traffic. MILCOM 2018 - IEEE Military Communications Conference. LOCATION OF CONFERENCE, COUNTRYDATE OF CONFERENCE; pp. 579–584.
- Roopak, M.; Tian, G.Y.; Chambers, J. Deep Learning Models for Cyber Security in IoT Networks. In Proceedings of the 2019 IEEE 9th Annual Computing and Communication Workshop and Conference (CCWC), Las Vegas, NV, USA, 7–9 January 2019; pp. 0452–0457. [Google Scholar]














| Reference | Mechanism | Dataset/Database | Detection Strategy | Attack Classification | Lightweight IDS | User Specific Results |
|---|---|---|---|---|---|---|
| Kumaar et al. [18] | Deep learning-based hybrid IDS framework (ImmuneNet) | Network traffic using CICFlowMeter/Wireshark | Binary classification (attack presence detection) | Binary (benign/malicious) | Not specified | NAÏVE attack detection |
|
Saif et al. [19] |
Hybrid IDS with an AI-powered cloud medical server | KSL-KDD dataset | Multi-label classification | Multi-label attack vectors | Not specified | Decision Tree algorithms have proven effective |
| Patel et al. [20] | Neural network-based intrusion detection | Cloud-based ECG healthcare data | Hybrid tempest algorithm with Tempest-NN | Arrhythmia classification | Not specified | Cloud-based ECG data protection |
| Hady et al. [21] | Enhanced Healthcare Monitoring System (EHMS) testbed | WUSTL-EHMS-2020 (MITM dataset) | Network and biometric patient data analysis | Binary classification | Not specified | Realistic dataset creation and validation |
| Iwendi et al. [22] | Genetic algorithm-based feature optimization | KSL-KDD dataset | Multi-label classification with GA optimization | Multi-label attack vectors | Feature optimization addressed | Improved feature selection performance |
|
Basharat et al. [23] |
Ensemble Machine Learning-based IDS | Smart healthcare systems dataset | AdaBoost classifier ensemble | Multi-class classification | Not specified | Higher attack detection rate with AdaBoost |
|
Tuteja et al. [24] |
Logistic regression and LSTM-based approach | Healthcare systems dataset | Binary classification with pattern detection | Binary (attack/normal) | Not specified | LSTM tested for attack patterns |
|
Ahmed et al. [25] |
Multiple ML algorithms evaluation | ECU-IoHT (Internet of Health Things) | k-nearest neighbor algorithms | Multi-class classification | Not specified | k-NN has proven most efficient |
|
Dina et al. [26] |
Deep learning with FNN and CNN | IoT healthcare dataset | Feed-forward Neural Network and CNN comparison | Multi-class classification, | Not specified | FNN outperformed CNN |
| Almutairi and Alshargabi [27] | Recurrent Neural Network (RNN) | NSL-KDD dataset | RNN-based pattern recognition | Multi-class classification | Not specified | 87% accuracy achieved |
| Ariffin et al. [28] | Hybrid feature selection with XGBoost and MaxPoolingID | MQTT attacks dataset | Lightweight IDS for MQTT-enabled IoT | Binary classification | Yes – specifically designed | 90% accuracy for both uni/bidirectional flows |
| Alani [29] | Machine learning-based IDS (IoTProtect) | TON_IoT dataset | ML-based attack detection | Binary classification | Yes – optimized for IoT devices | 99.999% accuracy, 0.001% FPR, 0% FNR |
|
Ramaiah and Rahamathulla [30] |
LSTM and ML models for Industrial IoT | EdgeIIoT-2021 dataset | Network traffic rregularity detection | Multi-class classification | Designed for IIoT networks | ERT: 99.93%, LSTM: 99.85% accuracy |
| Adebayo et al. [31] | AI-based IPS/IDS with Light Gradient Boosting Machine | N-BaIoT dataset | Ensemble features complexity reduction | Real-time attack prediction | Yes – gateway-based processing | 99.9% accuracy with LightGBM |
| Guo et al. [32] | ML-based IDS with stacking-ensemble | TON_IoT attack dataset | Ten learning methods evaluation | Binary and multi-class classification | Not specified | Stacking-ensemble: 0.9971 MCC (binary), 0.9909 (multi-class) |
| Ma et al. [33] | Random Forest with feature selection on edge computing | CIC-DdoS2019 dataset | Edge computing deployment with RF | DDoS attack classification | Yes – edge computing focused | 99.99% accuracy, 0.4s prediction time |
| Ahmed et al. [34] | Multilayer Perceptron (MLP) deep learning | Application-layer DDoS dataset | Packet characteristics inspection | Application-layer DDoS detection | Not specified | 98.99% efficiency, 2.11% FPR |
| Li et al. [35] | Federated Learning with fog/edge computing | Industrial IoT distributed datasets | FL-based global model training | Industrial IoT attack detection | Yes – distributed edge approach | 98% accuracy, 72% response time reduction |
| Vishwakarma and Jain [36] | Honeypot-based ML for malware detection | IoT honeypots data | Dynamic ML model training from honeypots | Zero-day DDoS attacks | Honeypot-based approach | Zero-day attack detection capability |
|
Zeeshan et al. [37] |
Protocol-Based Deep Intrusion Detection (PB-DID) | UNSWNB15 and Bot-IoT merged datasets | Deep learning with class imbalance handling | Normal, DoS, and DDoS classification | Protocol-based optimization | 96.3% attack recognition accuracy |
| Roopak et al. [38] | CNN-LSTM with multi-objective optimization | CISIDS2017 dataset | DL with Jumping Gene-adapted NSGA-II | DDoS attack classification | Dimensionality reduction applied | 99.03% accuracy, reduced training time |
| Jia et al. [39] | FlowGuard with LSTM and CNN models | CICDDoS2019 and DDoS simulators data | Traffic variation-based detection | DDoS attack identification and classification | Edge server deployment | LSTM: 98.9% identification, CNN: 99.9% classification |
| Sangodoyin et al. [40] | CART, k-NN, QDA, and GNB algorithms | SDN experimental data (throughput, jitter, response time) | ML techniques for SDN DDoS detection, | DDoS flooding attacks classification | SDN-specific optimization | CART: 98% accuracy, 5.3x10^6 obs/sec, 12.4ms training |
| McDermott et al. [41] | Bidirectional LSTM-RNN (BLSTM-RNN) | Home automation botnet data | Word embedding with bidirectional LSTM | Mirai botnet multi-vector attacks | Botnet-specific detection | Superior long-term performance vs standard LSTM |
| Dataset | Data Source | Number of Features | Labels | Suitability for Multi-vector Intrusion Detection |
|---|---|---|---|---|
| HiRID [43] | Healthcare data | 18 | Contains demographic information of 34,000 patents, but no attack data is included | Not Suitable |
| ECU-IoHT [25] | Healthcare data | 6 | ARP Spoofing, No Attack, Nmap Port Scan, Smurf Attack, DoS Attack | Not Suitable |
| WUSTL EHMS 2020 [21] | Healthcare data | 44 | Normal, Attack | Not Suitable |
| MIT-BIH Arrhythmia database [44] | Healthcare data | 47 | Benign, Malicious | Not Suitable |
| CICIoMT2024 [15] | Healthcare data | 46 | ARP_Spoofing, ICMP, UDP, SYN TCP, MQTT, Recon, Benign | Fully Suitable |
| WUSTL-IIOT-2021 [45] | IoT data | 41 | Command Injection, DoS, Reconnaissance, Backdoor, Normal | Not Suitable |
| DARPA 1999 [46] | IoT data | 41 | Probe, DoS, R2L, U2R | Not Suitable |
| BoT-IoT [47] | IoT data | 29 | DoS-HTTP, DoS-TCP, DoS-UDP, Benign | Partially Suitable |
| UNSW-NB15 [48] | IoT data | 49 | Normal, Attack | Not Suitable |
| NSL-KDD [49] | IoT data | 41 | TCP, UDP, ICMP | Partially Suitable |
| N-BaIoT [50] | IoT data | 115 | Scan, Ack, Syn, UDP, UDPplain | |
| CICIDS2017 [51] | IoT data | 80 | Brute Force FTP, Brute Force SSH, DoS, Heartbleed, Web Attack, Infiltration, Botnet, and DDoS |
Not Suitable |
| CSE-CIC-IDS2018 [52] | IoT data | 78 | Benign, DDoS, DoS, Brute Force, Botnet, Infiltration, Web attack | Not Suitable |
| CICDDoS2019 [53] | IoT data | 88 | BENIGN, UDP-Lag, TFTP, Portmap, DNS, MSSQL, LDAP, NetBIOS, NTP, SSDP, SNMP, Syn and UDP |
Fully Suitable |
| CICIoT2023 [14] | IoT data | 47 | PSHACKFlood, ICMP, UDP, Benign, ICMPFragmentation, SYN, SlowLoris, HTTP, SynonymousIPFlood, RSTFINFlood, TCP, ACKFragmentation, UDPFragmentation |
Fully Suitable |
| Model Parameters | Selected Choices |
| Loss Function | Binary Crossentropy (Binary Classification) & Categorical Crossentropy (Multi-label Classification) |
| Optimizer | Adam |
| Activation Function | Relu, Sigmoid, Softmax |
| No. of Epochs, Batch Size, Learning Rate | 40, 1000, 0.001 |
| No. of Hidden Layers | 3 |
| Metric | CICIoT2023 | CICIoMT2024 |
|---|---|---|
| Accuracy | 0.9974 | 0.9996 |
| Precision | 0.9993 | 0.9999 |
| Recall | 0.9981 | 0.9996 |
| F1-score | 0.9987 | 0.9998 |
| FAR | 0.0278 | 0.0004 |
| FPR | 0.0278 | 0.0004 |
| Sensitivity | 0.9981 | 0.9996 |
| Specificity | 0.9722 | 0.9996 |
| MCC | 0.9478 | 0.9983 |
| Metric | CICIoT2023 | CICIoMT2024 |
| Accuracy | 0.9718 | 0.9992 |
| Precision | 0.9746 | 0.9992 |
| Recall | 0.9718 | 0.9992 |
| F1-score | 0.9706 | 0.9992 |
| FAR | 0.0029 | 0.0001 |
| FPR | 0.0029 | 0.0001 |
| Sensitivity | 0.9396 | 0.9991 |
| Specificity | 0.9969 | 0.9998 |
| MCC | 0.9679 | 0.9991 |
| Method | Accuracy | Precision | Recall | F1-score |
| MVIID | 0.9992 | 0.9992 | 0.9992 | 0.9992 |
| DDoSViT [42] | 0.9950 | 0.9953 | 0.9950 | 0.9950 |
| RestNet18 [54] | 08706 | 0.8700 | 0.8600 | 0.8600 |
| LEDEM [55] | 0.9628 | 0.9700 | 0.9800 | 0.9700 |
| DeepGFL [56] | 0.9300 | 0.7567 | 0.3024 | 0.4321 |
| MLP [57] | 0.8634 | 0.8847 | 0.8625 | 08735 |
| ID-CNN [57] | 0.9514 | 0.9017 | 0.9017 | 0.9399 |
| LSTM [57] | 0.9624 | 0.9814 | 0.8989 | 0.8959 |
| ID-CNN-LSTM [57] | 0.9716 | 0.9741 | 0.9910 | 0.9825 |
| Dataset | BLC | MLC | ||||||||
| Model Size (KB) |
Training Time (Sec.) | Accuracy | Loss | Detection Time per Sample (Sec.) | Model Size (KB) |
Training Time (Sec.) | Accuracy | Loss | Detection Time per Sample (Sec.) | |
| CICIoT2023 | 379.61 | 715.06 | 0.9974 | 0.0068 | 0.000099 | 383.05 | 707.86 | 0.9718 | 0.0571 | 0.000099 |
| CICIoMT2024 | 364.26 | 625.46 | 0.9996 | 0.0012 | 0.000131 | 366.51 | 363.55 | 0.9992 | 0.0024 | 0.000131 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).