IJWMT Vol. 16, No. 4, 8 Aug. 2026
Cover page and Table of Contents: PDF (size: 1064KB)
PDF (1064KB), PP.44-64
Views: 0 Downloads: 0
Intrusion Detection Systems, Class Imbalance, Stacking, Deep learning, Internet of Things
The recent development of the Internet of Things (IoT) has increased the severity of security threats. It is mainly caused by IoT devices' inherent weaknesses, making them vulnerable to attack. Therefore, strengthening the security of such network systems is crucial. This study proposes a novel stacking model to identify attacks in the IoT environment. As a first step, we preprocess the data to make it more reliable. To address the issue of class imbalance, synthetic minority samples are generated by using SMOTE-SVM. Then, a novel stacking model was built by integrating four neural networks: deep neural network (DNN), recurrent neural network (RNN), long short-term memory (LSTM) and gated recurrent unit (GRU) with hyper-parameter tuned Light gradient boosting machine (BTE-LGBM). The performance of the proposed stacking model was evaluated on two recent IoT datasets, namely the ToN_IoT and CIC-IoT23. The efficacy of the suggested stacking model is evaluated and compared with Deep learning, machine learning, and state-of-the-art approaches with respect to metrics such as detection rate, precision, accuracy, and F1 score. The findings of our experiments indicate that the suggested IDS achieves a high accuracy of 99.81% and 99.78% for ToN_IoT and CIC-IoT23 datasets, respectively. It might enhance IoT device security, eventually benefiting consumers who depend on these devices. These findings, however, are based on benchmark dataset and could be impacted by variables including class distribution, attack diversity, and dataset characteristics. More research is needed to determine how well the model performs in real-world IoT contexts with changing attack patterns and heterogeneous devices.
Seshu Bhavani Mallampati, Hari Seetha, "Intrusion Detection System using Stacking of Deep Learning Models with Bte-Lgbm for IoT Networks", International Journal of Wireless and Microwave Technologies(IJWMT), Vol.16, No.4, pp. 44-64, 2026. DOI:10.5815/ijwmt.2026.04.04
[1]R. A. Elsayed, R. A. Hamada, M. I. Abdalla, and S. A. Elsaid, “Securing IoT and SDN systems using deep-learning based automatic intrusion detection,” Ain Shams Eng. J., vol. 14, no. 10, p. 102211, 2023, doi: 10.1016/j.asej.2023.102211.
[2]Y. Cao, Z. Wang, H. Ding, J. Zhang, and B. Li, “An intrusion detection system based on stacked ensemble learning for IoT network,” Comput. Electr. Eng., vol. 110, no. July, p. 108836, 2023, doi: 10.1016/j.compeleceng.2023.108836.
[3]S. Bhavani Mallampati and S. Hari, “Fusion of Feature Ranking Methods for an Effective Intrusion Detection System,” Comput. Mater. Contin., vol. 76, no. 2, pp. 1721–1744, 2023, doi: 10.32604/cmc.2023.040567.
[4]S. B. Mallampati and H. Seetha, “A Review on Recent Approaches of Machine Learning , Deep Learning , and Explainable Artificial Intelligence in Intrusion Detection Systems,” vol. 17, no. 1, pp. 29–54, 2023, doi: 10.30486/mjee.2023.1976657.1046.
[5]B. Sharma, L. Sharma, C. Lal, and S. Roy, “Anomaly based network intrusion detection for IoT attacks using deep learning technique,” Comput. Electr. Eng., vol. 107, no. February, p. 108626, 2023, doi: 10.1016/j.compeleceng.2023.108626.
[6]R. Lazzarini, H. Tianfield, and V. Charissis, “A stacking ensemble of deep learning models for IoT intrusion detection,” Knowledge-Based Syst., vol. 279, p. 110941, 2023, doi: 10.1016/j.knosys.2023.110941.
[7]R. E. Schapire, “A brief introduction to boosting,” IJCAI Int. Jt. Conf. Artif. Intell., vol. 2, pp. 1401–1406, 1999.
[8]S. A. Khanday, H. Fatima, and N. Rakesh, “Implementation of intrusion detection model for DDoS attacks in Lightweight IoT Networks,” Expert Syst. Appl., vol. 215, no. November 2022, 2023, doi: 10.1016/j.eswa.2022.119330.
[9]A. Hossain and S. Islam, “Ensuring network security with a robust intrusion detection system using,” Array, vol. 19, no. June, p. 100306, 2023, doi: 10.1016/j.array.2023.100306.
[10]A. Thakkar and R. Lohiya, “Attack Classification of Imbalanced Intrusion Data for IoT network Using Ensemble Learning-based Deep Neural Network,” IEEE Internet Things J., pp. 1–8, 2023, doi: 10.1109/JIOT.2023.3244810.
[11]E. C. P. Neto, S. Dadkhah, R. Ferreira, A. Zohourian, R. Lu, and A. A. Ghorbani, “CICIoT2023: A Real-Time Dataset and Benchmark for Large-Scale Attacks in IoT Environment,” Sensors, vol. 23, no. 13, 2023, doi: 10.3390/s23135941.
[12]H. Zhou, L. Kang, H. Pan, G. Wei, and Y. Feng, “An intrusion detection approach based on incremental long short-term memory,” Int. J. Inf. Secur., vol. 22, no. 2, pp. 433–446, 2023, doi: 10.1007/s10207-022-00632-4.
[13]H. S. & R. K. B. Seshu Bhavani Mallampati, “PCB-LGBM: A Hybrid Feature Selection by Pearson Correlation and Boruta-LGBM for Intrusion Detection Systems,” in International Conference on Computational Intelligence and Data Engineering, 2022, pp. 523–533, [Online]. Available: https://doi.org/10.1007/978-981-99-0609-3_37.
[14]S. M. Kasongo, “A deep learning technique for intrusion detection system using a Recurrent Neural Networks based framework,” Comput. Commun., vol. 199, pp. 113–125, Feb. 2023, doi: 10.1016/j.comcom.2022.12.010.
[15]S. Latif et al., “Intrusion Detection Framework for the Internet of Things Using a Dense Random Neural Network,” IEEE Trans. Ind. Informatics, vol. 18, no. 9, pp. 6435–6444, 2022, doi: 10.1109/TII.2021.3130248.
[16]C. A. de Souza, C. B. Westphall, and R. B. Machado, “Two-step ensemble approach for intrusion detection and identification in IoT and fog computing environments,” Comput. Electr. Eng., vol. 98, no. December 2021, p. 107694, 2022, doi: 10.1016/j.compeleceng.2022.107694.
[17]N. Thockchom and M. Marjit, “A novel ensemble learning-based model for network intrusion detection,” Complex Intell. Syst., 2023, doi: 10.1007/s40747-023-01013-7.
[18]A. Abbas, M. A. Khan, S. Latif, M. Ajaz, A. A. Shah, and J. Ahmad, “A New Ensemble-Based Intrusion Detection System for Internet of Things,” Arab. J. Sci. Eng., 2021, doi: 10.1007/s13369-021-06086-5.
[19]P. Kumar, G. P. Gupta, and R. Tripathi, “An ensemble learning and fog-cloud architecture-driven cyber-attack detection framework for IoMT networks,” Comput. Commun., vol. 166, no. April 2020, pp. 110–124, 2021, doi: 10.1016/j.comcom.2020.12.003.
[20]A. Awajan, “A Novel Deep Learning-Based Intrusion Detection System for IoT Networks,” Computers, vol. 12, no. 2, 2023, doi: 10.3390/computers12020034.
[21]H. Xu, L. Sun, G. Fan, W. Li, and G. Kuang, “A Hierarchical Intrusion Detection Model Combining Multiple Deep Learning Models With Attention Mechanism,” IEEE Access, vol. 11, no. July, pp. 1–1, 2023, doi: 10.1109/access.2023.3290613.
[22]S. Aktar and A. Yasin Nur, “Towards DDoS attack detection using deep learning approach,” Comput. Secur., vol. 129, p. 103251, 2023, doi: 10.1016/j.cose.2023.103251.
[23]W. Ding, M. Abdel-Basset, and R. Mohamed, “DeepAK-IoT: An effective deep learning model for cyberattack detection in IoT networks,” Inf. Sci. (Ny)., vol. 634, no. January, pp. 157–171, 2023, doi: 10.1016/j.ins.2023.03.052.
[24]S. I. Popoola, B. Adebisi, M. Hammoudeh, H. Gacanin, and G. Gui, “Stacked recurrent neural network for botnet detection in smart homes,” Comput. Electr. Eng., vol. 92, no. June, 2021, doi: 10.1016/j.compeleceng.2021.107039.
[25]I. Syarif, E. Zaluska, A. Prugel-Bennett, and G. Wills, “Application of bagging, boosting and stacking to intrusion detection,” Lect. Notes Comput. Sci. (including Subser. Lect. Notes Artif. Intell. Lect. Notes Bioinformatics), vol. 7376 LNAI, pp. 593–602, 2012, doi: 10.1007/978-3-642-31537-4_46.
[26]M. Ibrahim and R. Elhafiz, “Modeling an intrusion detection using recurrent neural networks,” J. Eng. Res., vol. 11, no. 1, p. 100013, 2023, doi: 10.1016/j.jer.2023.100013.
[27]P. Sun et al., “DL-IDS: Extracting features using CNN-LSTM hybrid network for intrusion detection system,” Secur. Commun. Networks, vol. 2020, 2020, doi: 10.1155/2020/8890306.
[28]T. A. Tang, D. McLernon, L. Mhamdi, S. A. R. Zaidi, and M. Ghogho, “Intrusion detection in sdn-based networks: Deep recurrent neural network approach,” Adv. Sci. Technol. Secur. Appl., no. NetSoft, pp. 175–195, 2019, doi: 10.1007/978-3-030-13057-2_8.
[29]G. Ke et al., “LightGBM: A highly efficient gradient boosting decision tree,” Adv. Neural Inf. Process. Syst., vol. 2017-Decem, no. Nips, pp. 3147–3155, 2017.
[30]S. Watanabe, “Tree-Structured Parzen Estimator: Understanding Its Algorithm Components and Their Roles for Better Empirical Performance,” pp. 1–74, 2023, [Online]. Available: http://arxiv.org/abs/2304.11127.
[31]R. K. Batchu and H. Seetha, “A Hybrid Detection System for DDoS Attacks Based on Deep Sparse Autoencoder and Light Gradient Boost Machine,” J. Inf. Knowl. Manag., vol. 22, no. 1, 2022, doi: 10.1142/S021964922250071X.