PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
August 14, 2026Sensors0 citationsOpen Access

Hybrid Intrusion Detection System with Real-Time Concept Drift Detection for Enhanced IoT Security

View Full Paper
MOMuath ObaidatMAMeryem AboualiASAneeza Shakeel

Key Points

  • Develop and evaluate a hybrid intrusion detection framework combining supervised classification, anomaly detection, and concept drift monitoring for evolving IoT network environments.
  • Integrated supervised Random Forest, unsupervised Isolation Forest trained solely on benign traffic, and Kolmogorov–Smirnov-based concept drift monitoring.
  • Evaluated on a chronologically sampled subset of the CICIoT2023 dataset (N=3,890,621 records; 2.35% benign, 97.65% attack) using an 80/20 chronological file-level train/test split.
  • Conducted a leave-one-attack-family-out experiment withholding MITM-ArpSpoofing from training to assess generalization to unseen attack types.
  • On the 746,094-record test set, the hybrid IDS achieved 99.73% accuracy, 99.89% precision, 99.83% recall, 99.86% F1-score, 95.23% specificity, 97.53% balanced accuracy, and a 4.77% false positive rate (TN=16,683, FP=836, FN=1,205, TP=727,370).
  • In the leave-one-attack-family-out evaluation, the hybrid model identified 85.26% of unseen MITM-ArpSpoofing attack samples, compared to 85.18% for Random Forest alone and 7.05% for Isolation Forest alone.

Abstract

The rapid deployment of Internet of Things (IoT) devices across smart cities, healthcare systems, industrial automation, transportation networks, smart grids, and cyber-physical infrastructures has expanded the modern cyberattack surface. IoT devices are often constrained by limited processing capacity, memory, battery power, and communication bandwidth, making conventional security mechanisms difficult to deploy consistently at scale. Intrusion detection systems (IDSs) provide an important defensive layer; however, many machine-learning-based IDSs are developed under static assumptions and may experience performance degradation as traffic distributions evolve due to firmware changes, device onboarding, protocol updates, user behavior variation, or adaptive attacks. This paper presents a hybrid IDS framework that integrates supervised Random Forest classification, unsupervised Isolation Forest anomaly monitoring, and Kolmogorov–Smirnov (KS)-based concept drift monitoring. In the experimental pipeline, Isolation Forest is trained exclusively on benign traffic to ensure that the anomaly detector models normal behavior rather than an attack-dominated training distribution. The evaluation uses a large-scale chronologically sampled subset of the CICIoT2023 dataset containing 3,890,621 records while preserving the natural class distribution of 2.35% benign traffic and 97.65% attack traffic. The chronological 80/20 train/test split is established first at the file level, followed by systematic sampling within each split to reduce the risk of leakage across the evaluation boundary. On the 746,094-record test set, the proposed hybrid IDS achieved 99.73% accuracy, 99.89% precision, 99.83% recall, 99.86% F1-score, and a false positive rate of 4.77%. The corresponding confusion matrix contains TN = 16,683, FP = 836, FN = 1205, and TP = 727,370, yielding 95.23% specificity and 97.53% balanced accuracy. Standalone Random Forest marginally outperformed the hybrid model in raw accuracy and false positive rate; therefore, the contribution of the proposed framework is centered on deployment-oriented anomaly monitoring, drift awareness, and generalization rather than absolute superiority in static classification metrics. A leave-one-attack-family-out experiment withholding MITM-ArpSpoofing from training showed that the hybrid model detected 85.26% of the unseen attack-family samples, compared with 85.18% for Random Forest alone and 7.05% for Isolation Forest alone. These findings provide initial evidence of generalization to one held-out attack family but should not be interpreted as proof of broad zero-day detection capability. The framework is therefore positioned as a competitive IDS that combines supervised detection with anomaly monitoring and concept drift awareness for deployment-oriented IoT security.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Obaidat et al. (2026) studied this question.

synapsesocial.com/papers/6a7ec71db70b84ec8b913482https://doi.org/10.3390/s26165117
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Effect of Data Scaling Methods on Machine Learning Algorithms and Model Performance2021 · 746 citations
  2. 2Machine Learning DDoS Detection for Consumer Internet of Things Devices2018 · 674 citations
  3. 3Open for hire2021 · 39 citations
  4. 4Explainable AI for Intrusion Detection Systems: LIME and SHAP Applicability on Multi-Layer Perceptron2024 · 209 citations
  5. 5Internet of Things intrusion detection systems: a comprehensive review and future directions2022 · 332 citations