IJWMT Vol. 16, No. 5, 8 Oct. 2026
Cover page and Table of Contents: PDF (size: 1347KB)
PDF (1347KB), PP.66-88
Views: 0 Downloads: 0
IoT Security, Intrusion Detection System, CNN-GRU, Mutual Information Feature Selection, SMOTE
The rapid expansion of memory and resource-constrained IoT devices has enormously increased vulnerability to cyber intrusions. Although deep learning-based intrusion detection systems (IDS) aim to improve intrusion precision, this improvement comes at the cost of increased inference latency and resource utilization. In this paper, we propose a lightweight CNN-GRU-based IDS model that utilizes mutual information-based feature selection to reduce input dimensionality, retaining the most informative features. The model is validated using four popular IoT security datasets: BoT-IoT, ToN-IoT, Edge-IIoTSeT and NSL-KDD. We employ SMOTE to reduce class imbalance in the training dataset for classifying both major and minor attacks. We achieve accuracies of 99.31%, 98.80%, 96.73%, and 94.20% on BoT-IoT, NSL-KDD, ToN-IoT and Edge-IIoTSeT respectively. Since inference latency is a critical requirement for resource-constrained IoT devices, the proposed model achieves inference times of 0.064 ms, 0.086 ms, 0.078 ms, and 0.073 ms on the respective datasets. These results demonstrate that the proposed IDS provides an effective balance between detection performance and computational efficiency for real-time IoT applications. In future we will focus on validating the proposed framework in real-world IoT deployment scenarios.
Safwan Ishrak, Puja Dhar, Md. Abdul Wahab, Ratnadip Kuri, ARM Mahamudul Hasan Rana, Humayun Kabir, "A Lightweight CNN-GRU Based Intrusion Detection Model with Mutual Information Feature Selection for IoT Edge Devices", International Journal of Wireless and Microwave Technologies(IJWMT), Vol.16, No.5, pp. 66-88, 2026. DOI:10.5815/ijwmt.2026.05.05
[1]L. Thomas, B. Anoop, An Efficient IoT Based Intrusion Detection System Using Optimization Kernel Extreme Learning Machine. International Journal of Computer Network and Information Security 17, 2025. https://doi.org/10.5815/ijcnis.2025.02.05
[2]M. Fatima, O. Rehman, I.M. Rahman, A. Ajmal, S.J. Park, Towards ensemble feature selection for lightweight intrusion detection in resource-constrained IoT devices. Future Internet. 2024 Oct 12;16(10):368. https://doi.org/10.3390/fi16100368
[3]L. Atzori, A. Iera, G. Morabito, The internet of things: A survey, Computer Networks 54.15 (2010) 2787–2805. https://doi.org/10.1016/j.comnet.2010.05.010
[4]G.A. Mukhaini, M. Anbar, S. Manickam, T.A. Al-Amiedy, A.A. Momani, A systematic literature review of recent lightweight detection approaches leveraging machine and deep learning mechanisms in Internet of Things networks, Journal of King Saud University Computer and Information Sciences 36.1(2024) 101866. https://doi.org/10.1016/j.jksuci.2023.101866
[5]D. Gaikwad, Intrusion detection system using ensemble of rule learners and first search algorithm as feature selectors, International Journal of Computer Network and Information Security (IJCNIS) 13.4 (2021) 26–34. https://doi.org/10.5815/ijcnis.2021.04.03
[6]C. Yin, Y. Zhu, J. Fei, X. He, A deep learning approach for intrusion detection using recurrent neural networks, Ieee Access 5 (2017) 21954–21961. https://doi.org/10.1109/ACCESS.2017.2762418
[7]S. Zavrak, M. Iskefiyeli, Anomaly-based intrusion detection from network flow features using variational autoencoder, IEEe Access 8 (2020) 108346–108358. https://doi.org/10.1109/ACCESS.2020.3001350
[8]V. Hnamte, H. Nhung-Nguyen, J. Hussain, Y. Hwa-Kim, A novel two-stage deep learning model for network intrusion detection: LSTM-AE, Ieee Access. 11 (2023) .https://doi.org/10.1109/ACCESS.2023.3266979
[9]B. Cao, C. Li, Y. Song, Y. Qin, C. Chen, Network intrusion detection model based on CNN and GRU, Applied Sciences 12.9 (2022) 4184. https://doi.org/10.3390/app12094184
[10]M. Jouhari, M. Guizani, Lightweight CNN-BiLSTM based intrusion detection systems for resource-constrained IoT devices, in: 2024 International Wireless Communications and Mobile Computing (IWCMC), IEEE, 2024: pp. 1558–1563. https://doi.org/10.1109/IWCMC61514.2024.10592352
[11]S. Ullah, J. Wu, M.M. Kamal, A.K.J. Saudagar, KronNet a lightweight Kronecker enhanced feed forward neural network for efficient IoT intrusion detection, Scientific Reports 15 .1 (2025) 20850. https://doi.org/10.1038/s41598-025-08921-3
[12]L.K.G. Danquah, S.Y. Appiah, V.A. Mantey, I. Danlard, E.K. Akowuah, Computationally efficient deep federated learning with optimized feature selection for iot botnet attack detection, Intelligent Systems with Applications 25 (2025) 200462. https://doi.org/10.1016/j.iswa.2024.200462
[13]N. Koroniotis, N. Moustafa, E. Sitnikova, B. Turnbull, Towards the development of realistic botnet dataset in the internet of things for network forensic analytics: Bot-iot dataset, Future Generation Computer Systems 100 (2019) 779–796. https://doi.org/10.1016/j.future.2019.05.041
[14]N. Moustafa, A new distributed architecture for evaluating AI-based security systems at the edge: Network TON_IoT datasets, Sustainable Cities and Society 72 (2021) 102994. https://doi.org/10.1016/j.scs.2021.102994
[15]M.A. Ferrag, O. Friha, D. Hamouda, L. Maglaras, H. Janicke, Edge-IIoTset: A new comprehensive realistic cyber security dataset of IoT and IIoT applications for centralized and federated learning, IEEe Access 10 (2022) 40281–40306. https://doi.org/10.1109/ACCESS.2022.3165809
[16]M. Tavallaee, E. Bagheri, W. Lu, A.A. Ghorbani, A detailed analysis of the KDD CUP 99 data set, in: 2009 IEEE Symposium on Computational Intelligence for Security and Defense Applications, Ieee, 2009: pp. 1–6. https://doi.org/10.1109/CISDA.2009.5356528
[17]K. Mounika, P.V. Rao, A. Anbalagan, Modified CNN Model for Network Intrusion Detection and Classification System Using Local Outlier Factor-based Recursive Feature Elimination, International Journal of Computer Network and Information Security 17.1 (2025) 82–91. https://doi.org/10.5815/ijcnis.2025.01.07
[18]J. Sinha, M. Manollas, Efficient deep CNN-BiLSTM model for network intrusion detection, in: Proceedings of the 2020 3rd International Conference on Artificial Intelligence and Pattern Recognition, 2020: pp. 223–231. https://doi.org/10.1145/3430199.3430224
[19]V. Hnamte, J. Hussain, DCNNBiLSTM: An efficient hybrid deep learning-based intrusion detection system, Telematics and Informatics Reports 10 (2023) 100053. https://doi.org/10.1016/j.teler.2023.100053
[20]M. Catillo, A. Pecchia, U. Villano, A deep learning method for lightweight and cross-device IoT botnet detection, Applied Sciences 13.2 (2023) 837. https://doi.org/10.3390/app13020837
[21]S.I. Popoola, B. Adebisi, M. Hammoudeh, G. Gui, H. Gacanin, Hybrid deep learning for botnet attack detection in the internet-of-things networks, IEEE Internet of Things Journal 8.6 (2021) 4944–4956. https://doi.org/10.1109/JIOT.2020.3034156
[22]F. Zawaideh, G. Al-Asad, G. Swaneh, S. Batainah, H. Bakkar, Intrusion detection system for (IoT) networks using Convolutional Neural Network (CNN) and XGBoost algorithm 102(2024). https://www.researchgate.net/publication/385591170_Intrusion_Detection_System_for_IoT_Networks_Using_Convolutional_Neural_Network_CNN_and_XGboost_Algorithm.
[23]A. Qaddos, M.U. Yaseen, A.S. Al-Shamayleh, M. Imran, A. Akhunzada, S.Z. Alharthi, A novel intrusion detection framework for optimizing IoT security, Scientific Reports 14.1(2024) 21789. https://doi.org/10.1038/s41598-024-72049-z
[24]M. Jouhari, H. Benaddi, K. Ibrahimi, Efficient intrusion detection: Combining x 2 feature selection with CNN-BiLSTM on the UNSW-NB15 dataset, in: 2024 11th International Conference on Wireless Networks and Mobile Communications (WINCOM), IEEE, 2024: pp. 1–6. https://doi.org/10.1109/WINCOM62286.2024.10658099
[25]T. Altaf, X. Wang, W. Ni, G. Yu, R.P. Liu, R. Braun, GNN-based network traffic analysis for the detection of sequential attacks in IoT, Electronics 13.12 (2024) 2274. https://doi.org/10.3390/electronics13122274
[26]J.P. Singh, R. Kazmi, Fusion Sec-IoT: A Federated Learning-Based Intrusion Detection System for Enhancing Security in IoT Networks., International Journal of Advanced Computer Science & Applications 15.11 (2024). https://doi.org/10.14569/IJACSA.2024.0151116
[27]N.V. Chawla, K.W. Bowyer, L.O. Hall, W.P. Kegelmeyer, SMOTE: synthetic minority over-sampling technique, Journal of Artificial Intelligence Research 16 (2002) 321–357. https://doi.org/10.1613/jair.953
[28]H. Peng, F. Long, C. Ding, Feature selection based on mutual information criteria of max-dependency, max-relevance, and min-redundancy, IEEE Transactions on Pattern Analysis and Machine Intelligence 27.8 (2005) 1226–1238. https://doi.org/10.1109/TPAMI.2005.159
[29]A. Kraskov, H. Stögbauer, P. Grassberger, Estimating mutual information, Physical Review E—Statistical, Nonlinear, and Soft Matter Physics 69.6 (2004) 066138. https://doi.org/10.1103/PhysRevE.69.066138
[30]Y. Imrana, Y. Xiang, L. Ali, A. Noor, K. Sarpong, M.A. Abdullah, CNN-GRU-FF: a double-layer feature fusion-based network intrusion detection system using convolutional neural network and gated recurrent units, Complex & Intelligent Systems 10.3(2024) 3353–3370. https://doi.org/10.1007/s40747-023-01313-y
[31]J. Chung, C. Gulcehre, K. Cho, Y. Bengio, Empirical evaluation of gated recurrent neural networks on sequence modeling, arXiv Preprint arXiv:1412.3555 (2014). https://doi.org/10.48550/arXiv.1412.3555
[32]H. Zhou, H. Zou, P. Zhou, Y. Shen, D. Li, W. Li, CBCTL-IDS: A transfer learning-based intrusion detection system optimized with the black kite algorithm for IoT-enabled smart agriculture, IEEE Access 13 (2025) 46601–46615. https://doi.org/10.1109/ACCESS.2025.3550800
[33]R. Alshamy, M. AKCAYOL, Intrusion detection model using machine learning algorithms on NSL-KDD dataset, International Journal of Computer Networks and Communications 16.6(2024) https://doi.org/10.5121/ijcnc.2024.16605.