PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
July 2, 2026PeerJ Computer Science0 citationsOpen Access

A blockchain-enabled hybrid intrusion detection framework for resource-constrained devices

View Full Paper
CSCharles StolzJZJielun Zhang

Key Points

  • This work aims to enhance intrusion detection in IoT networks facing complex threats using a blockchain-enabled framework.
  • Developed a lightweight, blockchain-secured distributed IDS combining anomaly detection, signature detection, and log analysis.
  • Implemented on Raspberry Pi and ESP32 devices using federated learning and transformer models.
  • Evaluated using CICIDS2017 and HDFS datasets, focusing on robustness against adversarial attacks.
  • Achieved 98.8% detection accuracy for federated network traffic analysis and 99.6% F1-score for host-based log anomalies.
  • Reputation scoring with L2-norm filtering effectively mitigated the impact of malicious model updates.
  • Blockchain logging demonstrated 21.47 TPS with 736 ms latency on Raspberry Pi 4.

Abstract

Threats to Internet of Things (IoT) networks are becoming increasingly complex and distributed, challenging the effectiveness of traditional Intrusion Detection Systems (IDS). IDS based on federated learning (FL) offer the ability to train machine learning models among distributed nodes without sharing data, but they are vulnerable to adversarial attacks such as model poisoning. Trust among distributed nodes is also a major challenge. To address these issues, this work presents a lightweight, blockchain-secured distributed IDS for IoT networks. The proposed system combines anomaly-based detection using federated learning, Snort-based signature detection, and host-based log analysis with transformer models. The blockchain is used for immutable logging of model updates and reputation-based trust scores. These updates are linked to unique blockchain identities, and the ledger enforces Sybil-resistant enrollment, allowing only authenticated nodes to contribute valid updates. Evaluation on the CICIDS2017 and HDFS datasets shows that the proposed approach achieves detection accuracy near 98.8% for federated network traffic analysis and an F1-score of 99.6% for host-based log anomaly detection with BERT-mini-class models. In poisoning experiments using random-weight injection, reputation scoring with L2-norm update filtering mitigates the impact of malicious updates. Experiments are conducted on a hardware testbed using Raspberry Pi and ESP32 devices. Blockchain logging achieved 21.47 TPS with 736 ms average latency on a Raspberry Pi 4. BERT-mini inference achieved ~59 ms average latency (real-time).

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Stolz et al. (2026) studied this question.

synapsesocial.com/papers/6a45ff6f9ed134303130fddchttps://doi.org/10.7717/peerj-cs.3899
Ask AI
Helpful
Bookmark
Share
View Full Paper