<p>The Internet of Things (IoT) networks have introduced significant cybersecurity vulnerabilities, and traditional Intrusion Detection Systems (IDSs) have proven inadequate for addressing IoT-specific threat landscapes. Existing machine learning-based IDS approaches suffer from three critical limitations: (i) poor generalization across heterogeneous IoT architectures and protocols, leading to degraded detection performance in diverse ecosystems; (ii) high false positive rates (often exceeding 15–20%), undermining operational feasibility; and (iii) static learning models that cannot adapt to polymorphic and zero-day attacks. To overcome these challenges, we propose the Meta-Classification Ensemble Stacking with Convolutional Neural Networks (MCES-CNN), a novel, adaptive, and interpretable IDS framework specifically engineered for IoT environments. MCES-CNN introduces three key innovations: (1) a meta-classification mechanism that utilizes ensemble stacking of traditional classifiers to generate high-level predictive features, which an optimized CNN further processes to enable robust cross-domain generalization; (2) integration of the Local Interpretable Model-Agnostic Explanation (LIME) framework for quantitative feature attribution, enabling explainable decisions and interpretability-guided reduction of false positives; and (3) a compression-aware design incorporating structured pruning and quantization, evaluated in terms of memory footprint and inference latency on representative IoT hardware, which maintains detection efficacy while ensuring computational efficiency for deployment on resource-constrained edge devices. Experimental validation on benchmark datasets CIC-IDS2017, EIIoT, and RT-IoT2022- demonstrated the effectiveness of MCES-CNN, achieving 99.95% binary and 98.29% multiclass accuracy, with consistent performance (98.28%) on RT-IoT2022. Notably, it reduces false positives by 98.4%, 79%, and 99.2%, respectively, while outperforming state-of-the-art methods by 13% in terms of precision. These results affirm MCES-CNN as a scalable, interpretable, and deployable IDS solution for real-world IoT security.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

MCES-CNN: A Hybrid Meta-classification Framework with Explainable AI for Enhanced IoT Intrusion Detection

  • Usman Ahmed,
  • Sadiq Muhammad,
  • Heba G. Muhammad,
  • Jaeyoung Choi,
  • Salman Mazhar Aleem

摘要

The Internet of Things (IoT) networks have introduced significant cybersecurity vulnerabilities, and traditional Intrusion Detection Systems (IDSs) have proven inadequate for addressing IoT-specific threat landscapes. Existing machine learning-based IDS approaches suffer from three critical limitations: (i) poor generalization across heterogeneous IoT architectures and protocols, leading to degraded detection performance in diverse ecosystems; (ii) high false positive rates (often exceeding 15–20%), undermining operational feasibility; and (iii) static learning models that cannot adapt to polymorphic and zero-day attacks. To overcome these challenges, we propose the Meta-Classification Ensemble Stacking with Convolutional Neural Networks (MCES-CNN), a novel, adaptive, and interpretable IDS framework specifically engineered for IoT environments. MCES-CNN introduces three key innovations: (1) a meta-classification mechanism that utilizes ensemble stacking of traditional classifiers to generate high-level predictive features, which an optimized CNN further processes to enable robust cross-domain generalization; (2) integration of the Local Interpretable Model-Agnostic Explanation (LIME) framework for quantitative feature attribution, enabling explainable decisions and interpretability-guided reduction of false positives; and (3) a compression-aware design incorporating structured pruning and quantization, evaluated in terms of memory footprint and inference latency on representative IoT hardware, which maintains detection efficacy while ensuring computational efficiency for deployment on resource-constrained edge devices. Experimental validation on benchmark datasets CIC-IDS2017, EIIoT, and RT-IoT2022- demonstrated the effectiveness of MCES-CNN, achieving 99.95% binary and 98.29% multiclass accuracy, with consistent performance (98.28%) on RT-IoT2022. Notably, it reduces false positives by 98.4%, 79%, and 99.2%, respectively, while outperforming state-of-the-art methods by 13% in terms of precision. These results affirm MCES-CNN as a scalable, interpretable, and deployable IDS solution for real-world IoT security.