PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 16, 20260 citationsOpen Access

A Comparative Analysis of Self-Aware Reinforcement Learning Models for Real-Time Intrusion Detection in Fog Networks

View Full Paper
NTNyashadzashe TamukaTMTopside E. MathonsiTOThomas Otieno Olwal

Key Points

  • This study aims to compare self-aware reinforcement learning models for intrusion detection in fog networks against traditional methods.
  • Proposed self-aware RL models, HATS-RL and F-HATS-RL, for real-time intrusion detection.
  • Simulated a fog network environment with heterogeneous nodes and streaming traffic.
  • Assessed models on metrics such as latency, energy consumption, detection accuracy, AUPR, and AUROC.
  • F-HATS-RL achieved the best AUROC of 0.933 and AUPR of 0.857.
  • Latency was measured at 0.27 ms with an energy consumption of 0.0137 mJ.
  • Self-aware RL models adapt effectively to traffic-dynamic attack methods, enhancing long-term performance.

Abstract

Fog computing extends cloud services to the network edge, enabling low-latency processing for Internet of Things (IoT) applications. However, this distributed approach is vulnerable to a wide range of attacks, necessitating advanced intrusion detection systems (IDSs) that operate under resource constraints. This study proposes integrating self-awareness (online learning and concept drift adaptation) into a lightweight RL (reinforcement learning)-based IDS for fog networks and quantitatively comparing it with non-RL static thresholds and bandit-based approaches in real time. Novel self-aware reinforcement learning (RL) models, the Hierarchical Adaptive Thompson Sampling–Reinforcement Learning (HATS-RL) model, and the Federated Hierarchical Adaptive Thompson Sampling–Reinforcement Learning (F-HATS-RL), were proposed for real-time intrusion detection in a fog network. These self-aware RL policies integrated online uncertainty estimation and concept-drift detection to adapt to evolving attacks. The RL models were benchmarked against the static threshold (ST) model and a widely adopted linear bandit (Linear Upper Confidence Bound/LinUCB). A realistic fog network simulator with heterogeneous nodes and streaming traffic, including multi-type attack bursts and gradual concept drift, was established. The models’ detection performance was compared using metrics including latency, energy consumption, detection accuracy, and the area under the precision–recall curve (AUPR) and the area under the receiver operating characteristic curve (AUROC). Notably, the federated self-aware agent (F-HATS-RL) achieved the best AUROC (0.933) and AUPR (0.857), with a latency of 0.27 ms and the lowest energy consumption of 0.0137 mJ, indicating its ability to detect intrusions in fog networks with minimal energy. The findings suggest that self-aware RL agents can detect traffic–dynamic attack methods and adapt accordingly, resulting in more stable long-term performance. By contrast, a static model’s accuracy degrades under drift.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Tamuka et al. (2026) studied this question.

synapsesocial.com/papers/69926552eb1f82dc367a1327https://doi.org/10.3390/fi18020100
Ask AI
Helpful
Bookmark
Share
View Full Paper