RPL (Routing Protocol for Low-Power and Lossy Networks) is a widely adopted routing protocol for 6LoWPAN-based IoT networks. Yet, it is vulnerable to several attacks compromising network security and reliability. This paper presents a machine learning-based approach for detecting four major RPL-specific attacks: Blackhole Attack, Flooding Attack, Decreased Rank Attack, and DODAG Version Number Attack. Using an existing IoT-RPL dataset generated from the Cooja simulator on the Mendeley platform, we implement ensemble learning techniques, including Random Forest, Gradient Boosting, AdaBoost, and Stacking Ensemble, to enhance attack detection accuracy. Feature selection techniques, such as Recursive Feature Elimination (RFE) and filter-based methods, are employed to identify key RPL-specific metrics, including packet delivery ratio, rank, and DODAG version number, which are critical for detecting attack patterns. The Stacking Ensemble model demonstrates the highest accuracy at 99.1%, outperforming other models in detecting the four types of attacks while maintaining a low false positive rate. To ensure the interpretability of the models, we apply SHAP (Shapley Additive explanations) and LIME (Local Interpretable Model-agnostic Explanations). SHAP values reveal the most influential features contributing to attack detection, such as packet delivery ratio and rank, while LIME provides local interpretability for individual predictions. These explainability methods confirm the reliability of the models, making them suitable for real-world IoT deployments. Future work will enhance model efficiency in real-time and under dynamic network conditions.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Ensemble Learning Based Intrusion Detection System for RPL-Based IoT Networks

  • Archana Chougule,
  • Rohit Mane,
  • Krishnanjan Bhattacharjee,
  • Swati Mehta

摘要

RPL (Routing Protocol for Low-Power and Lossy Networks) is a widely adopted routing protocol for 6LoWPAN-based IoT networks. Yet, it is vulnerable to several attacks compromising network security and reliability. This paper presents a machine learning-based approach for detecting four major RPL-specific attacks: Blackhole Attack, Flooding Attack, Decreased Rank Attack, and DODAG Version Number Attack. Using an existing IoT-RPL dataset generated from the Cooja simulator on the Mendeley platform, we implement ensemble learning techniques, including Random Forest, Gradient Boosting, AdaBoost, and Stacking Ensemble, to enhance attack detection accuracy. Feature selection techniques, such as Recursive Feature Elimination (RFE) and filter-based methods, are employed to identify key RPL-specific metrics, including packet delivery ratio, rank, and DODAG version number, which are critical for detecting attack patterns. The Stacking Ensemble model demonstrates the highest accuracy at 99.1%, outperforming other models in detecting the four types of attacks while maintaining a low false positive rate. To ensure the interpretability of the models, we apply SHAP (Shapley Additive explanations) and LIME (Local Interpretable Model-agnostic Explanations). SHAP values reveal the most influential features contributing to attack detection, such as packet delivery ratio and rank, while LIME provides local interpretability for individual predictions. These explainability methods confirm the reliability of the models, making them suitable for real-world IoT deployments. Future work will enhance model efficiency in real-time and under dynamic network conditions.