An Explainable and Tamper-Proof DDoS Detection Framework for IoT Networks Using Hybrid LSTM and Ethereum Blockchain

PDF (935KB), PP.219-235

Views: 0 Downloads: 0

Author(s)

Manjit Kumar Nayak 1 Debasis Gountia 1 Naresh Kumar 2,* Satyabrat Jena 1

1. School of Computer Sciences, Odisha University of Technology and Research, Bhubaneswar, India

2. Department of Mathematical and Physical Sciences, University of Nizwa (UoN), Sultanate, Oman

* Corresponding author.

DOI: https://doi.org/10.5815/ijwmt.2026.05.13

Received: 28 May 2026 / Revised: 18 Jun. 2026 / Accepted: 2 Jul. 2026 / Published: 8 Oct. 2026

Index Terms

DDoS, CUDA, Long-Short-Term Memory, CNN, Intrusion detection system, Shapley Additive Explanationable AI

Abstract

The rapid expansion of IoT networks is leaving them susceptible to threats like DDoS attacks, which have the potential to affect the operation of vital services. This work proposes a hybrid intrusion detection system combining GPUaccelerated CuDNNLSTM and CNNLSTM models to capture both spatial and temporal traffic features. Using the Kitsune dataset with nine attack scenarios, the models were trained and tested in a Kaggle GPU environment (NVIDIA Tesla T4/P100, CUDA 11.x, CUDNN 8.x). The hybrid approach achieved over 98% accuracy, 97% precision, and ROCAUC above 0.98, outperforming classical ML baselines such as SVM and Random Forest. SHAP explanations provided transparency by highlighting key features behind each detection, while blockchain logging ensured tamperproof records of attack events. This system grants its users a clear view of the process logic by breaking it down into SHAP-based Explainable AI, which demonstrates decisive features for each decision. The attacks identified are stored in a safe manner on the Ethereum blockchain via smart contracts, making the solution difficult to tamper with using any intrusion technique. Therefore, the proposed approach presents a very viable option for reliable intrusion detection in an efficient and faster version for designing a DDoS detection system with new network configurations. Challenges include blockchain latency and deploying resource-constrained IoT devices. Future work will explore lightweight variants and federated learning to improve scalability.

Cite This Paper

Manjit Kumar Nayak, Debasis Gountia, Naresh Kumar, Satyabrat Jena, "An Explainable and TamperProof DDoS Detection Framework for IoT Networks Using Hybrid LSTM and Ethereum Blockchain", International Journal of Wireless and Microwave Technologies(IJWMT), Vol.16, No.5, pp. 219-235, 2026. DOI:10.5815/ijwmt.2026.05.13

Reference

[1]Mirsky, Y., Doitshman, T., Elovici, Y., & Shabtai, A. (2018). Kitsune: An ensemble of autoencoders for online network Intrusion detection. arXiv preprint arXiv:1802.09089. https://doi.org/10.48550/arXiv.1802.09089 
[2]Abu Khalil, D., & Abuzir, Y. (2025). Detecting and Analyzing Network Attacks: A Time-Series Analysis Using the Kitsune Dataset. Journal of Emerging Computer Technologies, 5(1), 9-23. https://doi.org/10.57020/ject.1563146 
[3]Liu, H., & Wang, H. (2023). Real-time anomaly detection of network traffic based on CNN. Symmetry, 15(6), 1205. https://doi.org/10.3390/sym15061205
[4]Kona, S. S. (2020). Detection of DDoS attacks using RNN-LSTM and hybrid model ensemble (Masters thesis, National College of Ireland).
[5]Aljohani, A. M., & Elgendi, I. (2024, March). A Hybrid SHAP-RNN Model for Predicting and Explaining DDoS Attacks on IoT Networks. In CS & IT Conference Proceedings (Vol. 14, No. 6). CS & IT Conference Proceedings.
[6]Lu, K. (2024). Network anomaly traffic analysis. Academic Journal of Science and Technology, 10(3), 65–68.
[7]Z. Wu, H. Li, Y. Qian, Y. Hua, H. Gan, "Poison-Resilient Anomaly Detection: Mitigating Poisoning Attacks in Semi-Supervised Encrypted Traffic Anomaly Detection," IEEE Transactions on Network Science and Engineering, vol. 11, no. 5, pp. 4744-4757, Sep. 2024, doi: 10.1109/TNSE.2024.3397719.
[8]Gajin, S. (2022). Network traffic anomaly detection and analysis from research to the implementation. In N. Zdravković, D. Domazet, S. López-Pernas, M. Conde, & P. Vijayakumar (Eds.), BISEC (pp. 9–19). Belgrade Metropolitan University. https://ceur-ws.org/Vol-3529/short_2.pdf
[9]Thwaini, M. H. (2022). Anomaly detection in network traffic using machine learning for early threat detection. Data and Metadata, 1, 72. https://doi.org/10.56294/dm202272
[10]Sharma, A., & Babbar, H. (2024). Guarding against IoT threats: An analysis of intrusion detection with the Kitsune attack dataset. In 4th International Conference on Technological Advancements in Computational Sciences(ICTACS). IEEE. https://ieeexplore.ieee.org/document/10840935
[11]Marwa, K., Nickolaos, K., Nam, P., Nour, M., Benjamin, T., & Albert, Y. (2023). An explainable deep learning-enabled intrusion detection framework in IoT networks. Information Sciences, 639, Art. no. 119000. https://doi.org/10.1016/j.ins.2023.119000
[12]Zelichenok, I., & Kotenko, I. (2024). Kitsune dataset analysis via big data and deep learning techniques. In IEEE USBEREIT Conference. IEEE. https://ieeexplore.ieee.org/document/10584030
[13]Raghavendra, M., & Chen, Z. (2022). Detecting IoT botnets on IoT edge devices. In WS22 IEEE ICC: The 4th International Workshop on Data Driven Intelligence for Networks and Systems. IEEE. https://ieeexplore.ieee.org/abstract/document/9814555
[14]Aswathy, M. C., & Rajkumar, T. (2024). Real-time anomaly detection in network traffic: A comparative analysis of machine learning algorithms. International Research Journal on Advanced Engineering Hub (IRJAEH), 2(07), 1968–1977. https://doi.org/10.47392/IRJAEH.2024.0269
[15]Zhang, W., & Lazaro, J. P. (2024). A survey on network security traffic analysis and anomaly detection techniques. International Journal of EmergingTechnologies and Advanced Applications, 1(4). https://doi.org/10.62677/IJETAA.2404117
[16]Gumma, Y. R., & Peram, S. (2024). Review of cybercrime detection approaches using machine learning and deep learning techniques. In 2024 3rd International Conference on Applied Artificial Intelligence and Computing (ICAAIC).IEEE. https://ieeexplore.ieee.org/document/10575058
[17]Khalaf, L. I., Alhamadani, B., Ismael, O. A., Radhi, A. A., Ahmed, S. R., & Algburi, S. (2024). Deep learning-based anomaly detection in network traffic for cyber threat identification. In Proceedings of the Cognitive Models and Artificial Intelligence Conference (pp. 303–309). https://doi.org/10.1145/3660853.3660932
[18]Redhu, A., Choudhary, P., Srinivasan, K., & Das, T. K. (2024). Deep learning-powered malware detection in cyberspace: A contemporary review. Frontiers in Physics, 12, 1349463. https://doi.org/10.3389/fphy.2024.1349463
[19]Ibrahim, J., & Gajin, S. (2022). Entropy-based network traffic anomaly classification method resilient to deception. Computer Science and Information Systems, 19(1), 87–116. https://doi.org/10.2298/CSIS201229045I
[20]Cvitić, I., Peraković, D., Gupta, B. B., & Choo, K. K. R. (2022). Boosting-based DDoS detection in Internet of Things systems. IEEE Internet of Things Journal, 9(3), 2109–2123. https://doi.org/10.1109/JIOT.2021.3090909
[21]Bhayo, J., Jafaq, R., Ahmed, A., Hameed, S., & Shah, S. A. (2022). A time-efficient approach toward DDoS attack detection in IoT network using SDN. IEEE Internet of Things Journal, 9(5), 3612–3630. https://doi.org/10.1109/JIOT.2021.3098029
[22]Cvitić, I., Peraković, D., Periša, M., & Botica, M. (2021). Novel approach for detection of IoT generated DDoS traffic. Wireless Networks, 27(3), 1573–1586. https://doi.org/10.1007/s11276-019-02043-1
[23]Shukla, P., Krishna, C. R., & Patil, N. V. (2024). IoT traffic-based DDoS attacks detection mechanisms: A comprehensive review. Journal of Supercomputing, 80(7), pp. 9986–10043. https://doi.org/10.1007/s11227-023-05843-7
[24]Khanday, S. A., Fatima, H., & Rakesh, N. (2023). Implementation of intrusion detection model for DDoS attacks in lightweight IoT networks. Expert Systems with Applications, 215, 119330. https://doi.org/10.1016/j.eswa.2022.119330
[25]Pakmehr, A., Aßmuth, A., Taheri, N., & Ghaffari, A. (2024). DDoS attack detection techniques in IoT networks: A survey. Cluster Computing, 27(10), 14637–14668. https://doi.org/10.1007/s10586-024-04662-6
[26]Roopak, M., Tian, G. Y., & Chambers, J. (2020). Multi-objective-based feature selection for DDoS attack detection in IoT networks. IET Networks, 9(3), 120–127. https://doi.org/10.1049/iet-net.2018.5206
[27]Yin, D., Zhang, L., & Yang, K. (2018). A DDoS attack detection and mitigation with software-defined Internet of Things framework. IEEE Access, 6, 24694–24705. https://doi.org/10.1109/ACCESS.2018.2831284
[28]Dash, S. K., Dash, S., Mahapatra, S., Mohanty, S. N., Khan, M. I., Medani, M., Gupta, M. (2024). Enhancing DDoS attack detection in IoT using PCA. Egyptian Informatics Journal, 25, 100450. https://doi.org/10.1016/j.eij.2024.100450
[29]Yousuf, O., & Mir, R. N. (2022). DDoS attack detection in Internet of Things using recurrent neural network. Computers and Electrical Engineering, 101, 108034. https://doi.org/10.1016/j.compeleceng.2022.108034
[30]Pandey, N., & Mishra, P. K. (2024). Devising a hybrid approach for near real-time DDoS detection in IoT. Computers and Electrical Engineering, 118, 109448. https://doi.org/10.1016/j.compeleceng.2024.109448
[31]Doshi, K., Yilmaz, Y., & Uludag, S. (2021). Timely detection and mitigation of stealthy DDoS attacks via IoT networks. IEEE Transactions on Dependable and Secure Computing, 18(5), 2164–2175. https://doi.org/10.1109/TDSC.2021.3049942
[32]Saiyed, M. F., & Al-Anbagi, I. (2024). A genetic algorithm-and t-test-based system for DDoS attack detection in IoT networks. IEEE Access, 12, 25623–25641. https://doi.org/10.1109/ACCESS.2024.3367357
[33]Kumar, R., Kumar, P., Tripathi, R., Gupta, G. P., Garg, S., & Hassan, M. M. (2022). A distributed intrusion detection system to detect DDoS attacks in blockchain-enabled IoT network. Journal of Parallel and Distributed Computing, 164, 55–68. https://doi.org/10.1016/j.jpdc.2022.01.030
[34]Vishwakarma, R., & Jain, A. K. (2020). A survey of DDoS attacking techniques and defence mechanisms in the IoT network. Telecommunication Systems, 73(1), 3–25. https://doi.org/10.1007/s11235-019-00599-z
[35]Ravi, N., & Shalinie, S. M. (2020). Learning-driven detection and mitigation of DDoS attack in IoT via SDN-cloud architecture. IEEE Internet of Things Journal, 7(4), 3559–3570. https://doi.org/10.1109/JIOT.2020.2973176
[36]Saiyed, M. F., & Al-Anbagi, I. (2024). Deep ensemble learning with pruning for DDoS attack detection in IoT networks. IEEE Transactions on Machine Learning in Communications and Networking, 2, 596–616 https://ieeexplore.ieee.org/abstract/document/10513369
[37]Al-Hadhrami, Y., & Hussain, F. K. (2021). DDoS attacks in IoT networks: A comprehensive systematic literature review. World Wide Web, 24(3), 971–1001. https://doi.org/10.1007/s11280-020-00855-2
[38]Gaur, V., & Kumar, R. (2022). Analysis of machine learning classifiers for early detection of DDoS attacks on IoT devices. Arabian Journal for Science and Engineering, 47(2), 1353–1374. https://doi.org/10.1007/s13369-021-05947-3
[39]Bhayo, J., Shah, S. A., Hameed, S., Ahmed, A., Nasir, J., & Draheim, D. (2023). Towards a machine learning-based framework for DDoS attack detection in software-defined IoT (SD-IoT) networks. Engineering Applications of Artificial Intelligence, 123, 106432. https://doi.org/10.1016/j.engappai.2023.106432
[40]Nawaz, M., Tahira, S., Shah, D., Ali, S., & Tahir, M. (2025). Lightweight machine learning framework for efficient DDoS attack detection in IoT networks. Scientific Reports, 15(1), 24961. https://doi.org/10.1038/s41598-025-10092-0
[41]Hizal, S., Cavusoglu, U., & Akgun, D. (2024). A novel deep learning-based intrusion detection system for IoT DDoS security. Internet of Things, 28, 101336. https://doi.org/10.1016/j.iot.2024.101336
[42]Anjum, M., Dutta, A. K., Elrashidi, A., Shahab, S., Aldrees, A., Shaikh, Z. A., & Aljohani, A. (2025). GraphFedAI framework for DDoS attack detection in IoT systems using federated learning and graph-based artificial intelligence. Scientific Reports, 15(1), 28050. https://doi.org/10.1038/s41598-025-10826-0
[43]Haq, M. Y. M., Affinito, A., Botta, A., Sperotto, A., Nieuwenhuis, L. J., Jonker, M., & Abhishta, A. (2025). Victimization in DDoS attacks: The role of popularity and industry sector. Journal of Information Security and Applications, 94, 104242. https://doi.org/10.1016/j.jisa.2025.104242