PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 2, 2026Applied Sciences7 citationsOpen Access

AI-Based Embedded Framework for Cyber-Attack Detection Through Signal Processing and Anomaly Analysis

View Full Paper
SDSebastian-Alexandru DrăgușinRBRobert-Nicolae BoştinaruNBNicu Bizon

Key Points

  • The aim is to develop a framework for detecting cyberattacks in resource-constrained embedded/IoT environments using AI models.
  • Combination of signal-processing feature construction with supervised and unsupervised AI models
  • Dataset preparation, normalization, and correlation-driven feature analysis
  • Utilization of PCA for compact representation
  • Assessment of detection performance using various classical and ensemble learning models
  • Inclusion of Fourier-domain, wavelet-domain descriptors, and Kalman-based features
  • Ensemble-based models showed the strongest overall detection performance
  • Signal-processing augmentation and PCA support efficient deployment in embedded contexts
  • Integration of lightweight signal processing with AI enables adaptable identification of malicious traffic

Abstract

This paper proposes an applied framework for cyberattack and anomaly detection in resource-constrained embedded/IoT environments by combining signal-processing feature construction with supervised and unsupervised AI (Artificial Intelligence) models. The workflow covers dataset preparation and normalization, correlation-driven feature analysis, and compact representations via PCA (Principal Component Analysis), followed by classification and anomaly scoring. In addition to the original UNSW-NB15 (University of New South Wales—Network-Based Dataset 2015) traffic features, Fourier-domain descriptors, wavelet-domain descriptors, and Kalman-based smoothing/innovation features are considered to improve robustness under variability and measurement noise. Detection performance is assessed using classical and ensemble learning methods (SVM (Support Vector Machines), RF (Random Forest), XGBoost (Extreme Gradient Boosting), LightGBM (Light Gradient Boosting Machine)), unsupervised baselines (K-Means and DBSCAN (Density-Based Spatial Clustering of Applications with Noise)), and DL (Deep-Learning) anomaly detectors based on Autoencoder reconstruction and GAN (Generative Adversarial Network)-based scoring. Experimental results on UNSW-NB15 indicate that ensemble-based models provide the strongest overall detection performance, while the signal-processing augmentation and PCA-based compactness support efficient deployment in embedded contexts. The findings confirm that integrating lightweight signal processing with AI-driven models enables effective and adaptable identification of malicious network traffic supporting deployment-oriented embedded cybersecurity and motivating future real-time validation on edge hardware.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Drăgușin et al. (2026) studied this question.

synapsesocial.com/papers/6980fe35c1c9540dea81014dhttps://doi.org/10.3390/app16031416
Ask AI
Helpful
Bookmark
Share
View Full Paper