Hybrid Deep Learning Behavioral Detection of MITM, Spoofing, and Flooding Attacks in IoT Networks.

Authors

  • atheer Hammad Computer Science Shivaji University
  • Kavita S. Oza Department of Computer Science, Shivaji University, Kolhapur, India.

DOI:

https://doi.org/10.31642/JoKMC/2018/130207

Keywords:

IoT Security,, Intrusion Detection System, , Deep Learning,

Abstract

Current IoT intrusion detection research has shown very high performance on crafted datasets, but its practical usefulness is constrained by three unresolved data issues: highly skewed class distribution, overlapping profiles of similar attack patterns, and lack of convincing evidence that synthetic sample augmentation is able to capture realistic traffic patterns. This paper proposes a multi-class behavioral IoT attack detection framework for 18 categories of attacks to overcome these problems. Our framework adopts a consistent preprocessing procedure on real flow-based traffic and experiments with four deep models and a hybrid model under the same circumstances. The highest performance is achieved when CNN layers are used to learn local traffic patterns and temporal information is encoded using LSTM-based representations; the learned deep representations are then fed to a Random Forest classifier for multi-class classification. To ensure fair evaluation, we first divide the real traffic into training and test subsets, and apply CTGAN to the training set only. This protocol allows for two well-controlled experiments: original imbalanced dataset, and after adding proportionally generated synthetic samples. In this work, we use a dataset of 220,000 real IoT traffic samples, and generate 220,000 synthetic samples used exclusively for expanding the training set. The hybrid CNN-RF/LSTM architecture exhibits the best overall performance (98.71% accuracy, 98.62% Macro-F1 over 18 attack classes), compared to CNN-LSTM, Transformer-BiLSTM, CNN-Transformer and Tab Transformer using the same protocol. Based on comparative ROC curves, precision-recall curves, confusion matrices and latent space visualization, the hybrid design enhances class reparability and alleviates confusion between behaviorally similar attacks. These findings demonstrate the benefit of controlled synthetic augmentation, when confined to the training partition, and combined with deep feature extraction and ensemble classification, in boosting robustness but not in changing the distribution of the original traffic.

Downloads

Download data is not yet available.

References

[1] Le, T. T., Kim, H., Kang, H., & Kim, H. (2022). Classification and Explanation for Intrusion Detection System Based on Ensemble Trees and SHAP Method. Sensors (Basel, Switzerland), 22(3), 1154. https://doi.org/10.3390/s22031154

[2] Yaras, S., & Dener, M. (2024). IoT-Based Intrusion Detection System Using New Hybrid Deep Learning Algorithm. Electronics, 13(6), 1053. https://doi.org/10.3390/electronics13061053

[3] Kadhum Ayoob, H., Hasan Hadi Rubaye, H., & Hayder Hashim, S. (2025). Marine Predator Optimized BiLSTM Framework for Real-Time Intrusion Detection in IoT Environments. Wasit Journal for Pure Sciences, 4(4), 37-52. https://doi.org/10.31185/wjps.898

[4] S. A. Bajpai and A. B. Patankar, “Marine Goal Optimizer Tuned Deep BiLSTM-Based Self-Configuring Intrusion Detection in Cloud,” Journal of Grid Computing, vol. 22, art. no. 24, Feb. 2024.

[5] M. Jouhari and M. Guizani, “Lightweight CNN–BiLSTM based Intrusion Detection Systems for Resource-Constrained IoT Devices,” arXiv preprint, arXiv:2406.04897, Jun. 2024.

[6] M. Jouhari, H. Benaddi, and K. Ibrahimi, “Efficient Intrusion Detection: Combining χ² Feature Selection with CNN–BiLSTM on the UNSW–NB15 Dataset,” arXiv preprint, arXiv:2407.14945, Jul. 2024.

[7] A. Naeem, M. A. Khan, N. Alasbali, J. Ahmad, A. A. Khattak, and M. S. Khan, “Efficient IoT Intrusion Detection with an Improved Attention-Based CNN–BiLSTM Architecture,” arXiv preprint, arXiv:2503.19339, Mar. 2025.

[8] S. W. A. Alsudani and G. K. Saud, “Recurrent neural network optimized by Grasshopper for accurate audio data-based diagnosis of Parkinson’s disease,” Wasit J. Pure Sci., vol. 4, no. 2, pp. 56–75, 2025.

[9] F. S. Alrayes et al., “Privacy-Preserving Approach for IoT Networks Using Statistical Learning with Optimization Algorithm on High-Dimensional Big Data Environment,” Scientific Reports, vol. 15, art. no. 3338, Jan. 2025.

[10] P. Sinha et al., “A High Performance Hybrid LSTM–CNN Secure Architecture for IoT Environments Using Deep Learning,” Scientific Reports, vol. 15, art. no. 9684, Jul. 2025.

[11] S. E. Sorour, M. Aljaafari, A. M. Shaker, and A. E. Amin, “LSTM–JSO Framework for Privacy-Preserving Adaptive Intrusion Detection in Federated IoT Networks,” Scientific Reports, vol. 15, art. no. 11321, Apr. 2025.

[12] P. Turaka and S. K. Panigrahy, "Dynamic Attack Detection in IoT Networks: An Ensemble Learning Approach With Q-Learning and Explainable AI," in IEEE Access, vol. 12, pp. 161925-161940, 2024, doi: 10.1109/ACCESS.2024.3485989.

[13] Y. Alotaibi and M. Ilyas, “Ensemble-learning framework for intrusion detection to enhance ------Internet of Things’ devices security,” Sensors, vol. 23, no. 12, p. 5568, 2023, doi: 10.3390/s23125568.

[14] M. Al-Hawawreh, E. Sitnikova and N. Aboutorab, "Asynchronous Peer-to-Peer Federated Capability-Based Targeted Ransomware Detection Model for Industrial IoT," in IEEE Access, vol. 9, pp. 148738-148755, 2021, doi: 10.1109/ACCESS.2021.3124634.

[15] A. Nazir, J. He, N. Zhu, S. S. Qureshi, S. U. Qureshi, F. Ullah, A. Wajahat, and M. S. Pathan, “A deep learning-based novel hybrid CNN-LSTM architecture for efficient detection of threats in the IoT ecosystem,” Ain Shams Engineering Journal, vol. 15, no. 7, p. 102777, 2024, doi: 10.1016/j.asej.2024.102777.

[16] G. Engelen, V. Rimmer and W. Joosen, "Troubleshooting an Intrusion Detection Dataset: the CICIDS2017 Case Study," 2021 IEEE Security and Privacy Workshops (SPW), San Francisco, CA, USA, 2021, pp. 7-12, doi: 10.1109/SPW53761.2021.00009.

[17] G. Sripriyanka and A. Mahendran, "Securing IoMT: A Hybrid Model for DDoS Attack Detection and COVID-19 Classification," in IEEE Access, vol. 12, pp. 17328-17348, 2024, doi:

[18] H. Hakami, M. Faheem and M. Bashir Ahmad, "Machine Learning Techniques for Enhanced Intrusion Detection in IoT Security," in IEEE Access, vol. 13, pp. 31140-31158, 2025, doi: 10.1109/ACCESS.2025.3542227.

[19] S. Elouardi, A. Motii, M. Jouhari, A. Nasser Hassane Amadou and M. Hedabou, "A Survey on Hybrid-CNN and LLMs for Intrusion Detection Systems: Recent IoT Datasets," in IEEE Access, vol. 12, pp. 180009-180033, 2024, doi: 10.1109/ACCESS.2024.3506604.

[20] M. Alotaibi et al., "Integrating Two-Tier Optimization Algorithm With Convolutional Bi-LSTM Model for Robust Anomaly Detection in Autonomous Vehicles," in IEEE Access, vol. 13, pp. 6820-6833, 2025, doi: 10.1109/ACCESS.2024.3523539.

[21] S. Racherla, P. Sripathi, N. Faruqui, M. Alamgir Kabir, M. Whaiduzzaman and S. Aziz Shah, "Deep-IDS: A Real-Time Intrusion Detector for IoT Nodes Using Deep Learning," in IEEE Access, vol. 12, pp. 63584-63597, 2024, doi: 10.1109/ACCESS.2024.3396461.

[22] C. Zhang, J. Li, N. Wang, and D. Zhang, “Research on intrusion detection method based on transformer and CNN-BiLSTM in Internet of Things,” Sensors, vol. 25, no. 9, p. 2725, 2025, doi: 10.3390/s25092725.

Downloads

Published

2026-09-08

How to Cite

Hammad, atheer, & Oza, K. S. (2026). Hybrid Deep Learning Behavioral Detection of MITM, Spoofing, and Flooding Attacks in IoT Networks. Journal of Kufa for Mathematics and Computer, 13(2), 60-68. https://doi.org/10.31642/JoKMC/2018/130207

Share