In the expanding Internet of Things(IoT)ecosystem,billions of interconnected devices exchange sensitive data,making secure and usable authentication critical.IoT devices in public or shared environments are vulnerable...In the expanding Internet of Things(IoT)ecosystem,billions of interconnected devices exchange sensitive data,making secure and usable authentication critical.IoT devices in public or shared environments are vulnerable to shoulder-surfing and video recorded observation attacks.Traditional passwords and static graphical schemes remain susceptible due to predictable patterns and direct credential entry.This study presents a novel recognition-based graphical authentication scheme that combines pass-image selection with compass direction substitution and rotation logic to resist observation-based attacks.A prototype was evaluated with 58 participants over three days.Usability metrics included registration time,login time,success rate,and error rate.Memorability and resistance to shoulder-surfing were also assessed.Results showed that login times decreased from 43.62 to 37.78 s,while success rates increased from 40%to 53%,indicating rapid adaptation.Memorability scores improved from 2.05 to 2.19 on a 3-point scale,with perfect recall for five-image passwords by Day 3.Shoulder-surfing tests recorded a 0%attacker success rate.The preliminary results suggest that the scheme offers a useful balance of usability,memorability,and resistance to single session observation attacks.Future work will explore adaptive complexity and accessibility features to further enhance secure authentication.展开更多
随着物联网(Internet of Things,IoT)设备的普及,使用入侵检测来保护IoT设备免受恶意攻击至关重要。但是,IoT的数据稀缺性限制了传统入侵检测方法的效果。同时,现有基于域自适应的入侵检测方法的对齐方式粗糙,忽略了内在语义属性的转移...随着物联网(Internet of Things,IoT)设备的普及,使用入侵检测来保护IoT设备免受恶意攻击至关重要。但是,IoT的数据稀缺性限制了传统入侵检测方法的效果。同时,现有基于域自适应的入侵检测方法的对齐方式粗糙,忽略了内在语义属性的转移,降低了特征的可区分性。为解决上述问题,提出了一种基于Transformer的域自适应物联网入侵检测(Transformer-Based Domain-Adaptive IoT Intrusion Detection,TDAIID)模型,从域间、类间和样本间3个层次对齐互联网入侵(Network Intrusion,NI)域和物联网入侵(Internet of Things Intrusion,Ⅱ)域。交叉注意力机制聚焦于NI源域和Ⅱ目标域中相同类别样本之间的相似特征,实现样本级别的域特征对齐;多重几何语义对齐从域级和类级两个角度进行语义对齐,有助于交叉注意力机制学习更丰富、更准确的源NI域知识。此外,为了充分挖掘未标记Ⅱ目标域的潜力,从几何角度提出了一种动态中心感知伪标签算法,用于提高伪标签标记的准确性,有效降低错误分配伪标签造成的负迁移。在多个常用入侵检测数据集上的综合实验表明,TDAIID模型的性能优于当前先进的基线模型。展开更多
The real-time systems perform key functionalities in various fields to automate the communication and response in critical events.The Internet of Things(IoT),integrated with numerous physical objects,gathers environme...The real-time systems perform key functionalities in various fields to automate the communication and response in critical events.The Internet of Things(IoT),integrated with numerous physical objects,gathers environmental data,processes it at the edge,and provides intelligent decisions while routing health records to processing units.However,the dynamic and resource-constrained nature of IoT-based healthcare environments introduces significant challenges related to latency,transmission costs,and the reliable interaction of devices amid uncertain activities.In this work,we propose a framework for a consistent and trustworthy system that uses a weighted trust aggregation model to consider multiple parameters and support timely routing decisions in a Fog-driven healthcare environment.Furthermore,authorized access to critical and sensitive health data is achieved through mutual authentication among devices,ensuring data integrity.The analysis of trust scores dynamically enhances resilience and the timely detection of malicious actions,thereby improving the healthcare system’s performance across unpredictable channels.The performance of the proposed framework is tested and validated against CLCSR and FSRF,and performance results revealed the significance for energy consumption,response time,network throughput,trust level,and accuracy across varying fog node capacity and interference scenarios.展开更多
The Internet of Things(IoT)enables seamless real-time monitoring and data exchange across distributed and heterogeneous environments with wireless sensor networks(WSNs).The open architecture and resource constraints o...The Internet of Things(IoT)enables seamless real-time monitoring and data exchange across distributed and heterogeneous environments with wireless sensor networks(WSNs).The open architecture and resource constraints of wireless sensor networks(WSNs)make them highly vulnerable to internal security threats caused by malicious or compromised nodes,particularly in Internet of Things(IoT)environments.To address this issue,we proposed Dynamic Trust Evaluation Model(DTEM),designed to provide a secure,scalable,and efficient framework for IoT-based WSNs.The proposed model identifies the role of trust management in routing,data aggregation,and intrusion detection,including trust-based protocols.DTEM incorporates a lightweight elliptic curve cryptography(ECC)mechanism to ensure secure communication,protect trust information from manipulation,and enhance overall system reliability.In addition,machine learning techniques are employed to improve malicious node classification accuracy.Component-wise analysis demonstrates that the dynamic trust evaluation forms the core detection mechanism,while ECC enhances communication security and machine learning improves malicious node classification accuracy.A large-scale network simulation is conducted to evaluate DTEM’s performance under various attack scenarios.Results demonstrate improved malicious node detection accuracy,higher packet delivery ratios,reduced energy consumption,and lower communication overheads.The proposed DTEM framework proves to be a robust and scalable solution for securing IoT-based wireless sensor networks,making it suitable for real-world applications.展开更多
The rapid growth of the Internet of Things(IoT)devices has increased the attack area of modern networks,which makes effective intrusion detection systems(IDSs)essential to detect attacks that target IoT infrastructure...The rapid growth of the Internet of Things(IoT)devices has increased the attack area of modern networks,which makes effective intrusion detection systems(IDSs)essential to detect attacks that target IoT infrastructures.Federated learning is a promising approach for collaborative model training in the absence of centralized raw data.Conventional federated approaches rely on fixed client participation and static training configurations,which ensure symmetric treatment of clients despite heterogeneous local data distributions.This can limit convergence and degrade detection performance in non-IID conditions.This paper proposes an Adaptive Action-Based Federated Learning(AAFL)framework for decentralized intrusion detection in heterogeneous IoT environments.The framework dynamically adjusts both participating clients and local training workload at each communication round using a Linear Upper Confidence Bound(LinUCB)contextual bandit controller.The proposed Adaptive-FL model is based on XGBoost boosters and uses quality-weighted server-side ensemble aggregation.At the same time,adaptation is guided by a multi-objective reward that balances classification performance,training latency,communication overhead,and computational cost.The framework is evaluated on CIC IoMT 2024 and RT-IoT2022 under realistic non-IID conditions using stratified 5-fold cross-validation and benchmarked against Static-FL,FedAvg-FL,and a centralized XGBoost upper bound.Experimental results demonstrate that Adaptive-FL outperforms all federated baselines across both datasets,achieving Macro-F1 scores of 98.27%on RT-IoT2022 and 94.21%on CIC IoMT 2024,with statistically significant improvements over Static-FL on both datasets.Adaptive-FL maintains superior classification stability while avoiding raw-data centralization.It remains within 0.67 and 0.35 percentage points of the centralized upper bounds on RT-IoT2022 and CIC IoMT 2024,respectively.展开更多
Anomaly detection is a vibrant research direction in controller area networks,which provides the fundamental real-time data transmission underpinning in-vehicle data interaction for the internet of vehicles.However,ex...Anomaly detection is a vibrant research direction in controller area networks,which provides the fundamental real-time data transmission underpinning in-vehicle data interaction for the internet of vehicles.However,existing unsupervised learning methods suffer from insufficient temporal and spatial constraints on shallow features,resulting in fragmented feature representations that compromise model stability and accuracy.To improve the extraction of valuable features,this paper investigates the influence of clustering constraints on shallow feature convergence paths at the model level and further proposes an end-to-end intrusion detection system based on efficient deep embedded subspace clustering(EDESC-IDS).Following the standard learning approach,continuous messages are encoded into two-dimensional data frames via a frame builder,which are then input into an extended convolutional autoencoder for extracting shallow features from high-dimensional data.On this basis,the dual constraints of these output features and the embedding clustering module facilitate end-to-end training of the EDESC-IDS in various attack scenarios.Extensive experimental results show that such a system exhibits significant detection performance on four types of attack datasets,including DoS,Gear,Fuzzy,and RPM,with precision,recall,and F1 scores consistently above 97.79%,while maintaining a false negative rate(FNR)and an error rate(ER)below 2.22%.展开更多
The large-scale deployment of Internet of Things(IoT)technology across various aspects of daily life has significantly propelled the intelligent development of society.Among them,the integration of IoT and named data ...The large-scale deployment of Internet of Things(IoT)technology across various aspects of daily life has significantly propelled the intelligent development of society.Among them,the integration of IoT and named data networks(NDNs)reduces network complexity and provides practical directions for content-oriented network design.However,ensuring data integrity in NDN-IoT applications remains a challenging issue.Very recently,Wang et al.(Entropy,27(5),471(2025))designed a certificateless aggregate signature(CLAS)scheme for NDN-IoT environments.Wang et al.stated that their construction was provably secure under various types of security attacks.Using theoretical analysis methods,in this work,we reveal that their CLAS design fails to meet unforgeability,a core security requirement for CLAS schemes.In particular,we demonstrate that their scheme is vulnerable to amalicious public-key replacement attack,enabling an adversary to produce authentic signatures for arbitrary fraudulent messages.Therefore,Wang et al.’s design cannot achieve its goal.To address the issue,we systematically examine the root causes behind the vulnerability and propose a security-enhanced CLAS construction for NDN-IoT environments.We prove the security ofour improveddesignunder the standard security assumptionandalsoanalyze its practicalperformanceby comparing the computational and communication costs with several related works.The comparison results show the practicality of our design.展开更多
The Internet of Vehicles(IoV)operates in highly dynamic and open network environments and faces serious challenges in secure and real-time authentication and consensus mechanisms.Existing methods often suffer from com...The Internet of Vehicles(IoV)operates in highly dynamic and open network environments and faces serious challenges in secure and real-time authentication and consensus mechanisms.Existing methods often suffer from complex certificate management,inefficient consensus protocols,and poor resilience in high-frequency communication,resulting in high latency,poor scalability,and unstable network performance.To address these issues,this paper proposes a secure and efficient distributed authentication scheme for IoV with reputation-driven consensus and SM9.First,this paper proposes a decentralized authentication architecture that utilizes the certificate-free feature of SM9,enabling lightweight authentication and key negotiation,thereby reducing the complexity of key management.To ensure the traceability and global consistency of authentication data,this scheme also integrates blockchain technology,applying its inherent invariance.Then,this paper introduces a reputation-driven dynamic node grouping mechanism that transparently evaluates and groups’node behavior using smart contracts to enhance network stability.Furthermore,a new RBSFT(Reputation-Based SM9 Friendly-Tolerant)consensus mechanism is proposed for the first time to enhance consensus efficiency by optimizing the PBFT algorithm.RBSFT aims to write authentication information into the blockchain ledger to achieve multi-level optimization of trust management and decision-making efficiency,thereby significantly improving the responsiveness and robustness in high-frequency IoV scenarios.Experimental results show that it excels in authentication,communication efficiency,and computational cost control,making it a feasible solution for achieving IoV security and real-time performance.展开更多
Intrusion Detection Systems(IDS)play a critical role in protecting networked environments from cyberattacks.They have become increasingly important in smart environments such as the Internet of Things(IoT)systems.Howe...Intrusion Detection Systems(IDS)play a critical role in protecting networked environments from cyberattacks.They have become increasingly important in smart environments such as the Internet of Things(IoT)systems.However,IDS for IoT networks face critical challenges due to hardware constraints,including limited computational resources and storage capacity,which lead to high feature dimensionality,prediction uncertainty,and increased processing cost.These factors make many conventional detection approaches unsuitable for real-time IoT deployment.To address these challenges,this paper proposes an adaptive intrusion detection framework that intelligently balances detection accuracy and computational efficiency.The proposed framework integrates mutual information(MI)feature selection model,deep contextual embeddings,and an adaptive decision mechanism.The MI model identifies and retains the most informative features,which reduces dimensionality while maintaining high detection accuracy.The adaptive decision dynamically selects between multiple inference paths to ensure that additional computation is needed only when the uncertainty level is high.Experimental evaluations on benchmark IoT datasets namely RT-IoT-2022,CIC-IoT-2023 and CIC-IoMT-2024 show that the proposed framework achieves F1-score of 99.92%,96.66%,and 99.84%,respectively,with an average inference time of approximately 0.105 ms per sample.These results demonstrate that the framework effectively adapts inference complexity to data uncertainty,which provides an intelligent,interpretable and efficient solution for real-world IoT intrusion detection.展开更多
With the large-scale deployment of the Internet of Things(IoT)devices,their weak securitymechanisms make them prime targets for malware attacks.Attackers often use Domain Generation Algorithm(DGA)to generate random do...With the large-scale deployment of the Internet of Things(IoT)devices,their weak securitymechanisms make them prime targets for malware attacks.Attackers often use Domain Generation Algorithm(DGA)to generate random domain names,hiding the real IP of Command and Control(C&C)servers to build botnets.Due to the randomness and dynamics of DGA,traditional methods struggle to detect them accurately,increasing the difficulty of network defense.This paper proposes a lightweight DGA detection model based on knowledge distillation for resource-constrained IoT environments.Specifically,a teacher model combining CharacterBERT,a bidirectional long short-term memory(BiLSTM)network,and attention mechanism(ATT)is constructed:it extracts character-level semantic features viaCharacterBERT,captures sequence dependencieswith the BiLSTM,and integrates theATT for key feature weighting,formingmulti-granularity feature fusion.An improved knowledge distillation approach transfers the teacher model’s learned knowledge to the simplified DistilBERT student model.Experimental results show the teacher model achieves 98.68%detection accuracy.The student modelmaintains slightly improved accuracy while significantly compressing parameters to approximately 38.4%of the teacher model’s scale,greatly reducing computational overhead for IoT deployment.展开更多
基金supported by the Ministry of Higher Education(MoHE),Malaysia through the Fundamental Research Grant Scheme(FRGS/1/2023/ICT03/UTAR/02/1)。
摘要In the expanding Internet of Things(IoT)ecosystem,billions of interconnected devices exchange sensitive data,making secure and usable authentication critical.IoT devices in public or shared environments are vulnerable to shoulder-surfing and video recorded observation attacks.Traditional passwords and static graphical schemes remain susceptible due to predictable patterns and direct credential entry.This study presents a novel recognition-based graphical authentication scheme that combines pass-image selection with compass direction substitution and rotation logic to resist observation-based attacks.A prototype was evaluated with 58 participants over three days.Usability metrics included registration time,login time,success rate,and error rate.Memorability and resistance to shoulder-surfing were also assessed.Results showed that login times decreased from 43.62 to 37.78 s,while success rates increased from 40%to 53%,indicating rapid adaptation.Memorability scores improved from 2.05 to 2.19 on a 3-point scale,with perfect recall for five-image passwords by Day 3.Shoulder-surfing tests recorded a 0%attacker success rate.The preliminary results suggest that the scheme offers a useful balance of usability,memorability,and resistance to single session observation attacks.Future work will explore adaptive complexity and accessibility features to further enhance secure authentication.
摘要随着物联网(Internet of Things,IoT)设备的普及,使用入侵检测来保护IoT设备免受恶意攻击至关重要。但是,IoT的数据稀缺性限制了传统入侵检测方法的效果。同时,现有基于域自适应的入侵检测方法的对齐方式粗糙,忽略了内在语义属性的转移,降低了特征的可区分性。为解决上述问题,提出了一种基于Transformer的域自适应物联网入侵检测(Transformer-Based Domain-Adaptive IoT Intrusion Detection,TDAIID)模型,从域间、类间和样本间3个层次对齐互联网入侵(Network Intrusion,NI)域和物联网入侵(Internet of Things Intrusion,Ⅱ)域。交叉注意力机制聚焦于NI源域和Ⅱ目标域中相同类别样本之间的相似特征,实现样本级别的域特征对齐;多重几何语义对齐从域级和类级两个角度进行语义对齐,有助于交叉注意力机制学习更丰富、更准确的源NI域知识。此外,为了充分挖掘未标记Ⅱ目标域的潜力,从几何角度提出了一种动态中心感知伪标签算法,用于提高伪标签标记的准确性,有效降低错误分配伪标签造成的负迁移。在多个常用入侵检测数据集上的综合实验表明,TDAIID模型的性能优于当前先进的基线模型。
基金funded by the Deanship of Graduate Studies and Scientific Research at Jouf University under grant No.(DGSSR-2025-02-01291).
摘要The real-time systems perform key functionalities in various fields to automate the communication and response in critical events.The Internet of Things(IoT),integrated with numerous physical objects,gathers environmental data,processes it at the edge,and provides intelligent decisions while routing health records to processing units.However,the dynamic and resource-constrained nature of IoT-based healthcare environments introduces significant challenges related to latency,transmission costs,and the reliable interaction of devices amid uncertain activities.In this work,we propose a framework for a consistent and trustworthy system that uses a weighted trust aggregation model to consider multiple parameters and support timely routing decisions in a Fog-driven healthcare environment.Furthermore,authorized access to critical and sensitive health data is achieved through mutual authentication among devices,ensuring data integrity.The analysis of trust scores dynamically enhances resilience and the timely detection of malicious actions,thereby improving the healthcare system’s performance across unpredictable channels.The performance of the proposed framework is tested and validated against CLCSR and FSRF,and performance results revealed the significance for energy consumption,response time,network throughput,trust level,and accuracy across varying fog node capacity and interference scenarios.
摘要The Internet of Things(IoT)enables seamless real-time monitoring and data exchange across distributed and heterogeneous environments with wireless sensor networks(WSNs).The open architecture and resource constraints of wireless sensor networks(WSNs)make them highly vulnerable to internal security threats caused by malicious or compromised nodes,particularly in Internet of Things(IoT)environments.To address this issue,we proposed Dynamic Trust Evaluation Model(DTEM),designed to provide a secure,scalable,and efficient framework for IoT-based WSNs.The proposed model identifies the role of trust management in routing,data aggregation,and intrusion detection,including trust-based protocols.DTEM incorporates a lightweight elliptic curve cryptography(ECC)mechanism to ensure secure communication,protect trust information from manipulation,and enhance overall system reliability.In addition,machine learning techniques are employed to improve malicious node classification accuracy.Component-wise analysis demonstrates that the dynamic trust evaluation forms the core detection mechanism,while ECC enhances communication security and machine learning improves malicious node classification accuracy.A large-scale network simulation is conducted to evaluate DTEM’s performance under various attack scenarios.Results demonstrate improved malicious node detection accuracy,higher packet delivery ratios,reduced energy consumption,and lower communication overheads.The proposed DTEM framework proves to be a robust and scalable solution for securing IoT-based wireless sensor networks,making it suitable for real-world applications.
基金funded by the Deanship of Scientific Research(DSR)at King Abdulaziz University,Jeddah,Saudi Arabia,under grant No.(IPP:1315-611-2025).
摘要The rapid growth of the Internet of Things(IoT)devices has increased the attack area of modern networks,which makes effective intrusion detection systems(IDSs)essential to detect attacks that target IoT infrastructures.Federated learning is a promising approach for collaborative model training in the absence of centralized raw data.Conventional federated approaches rely on fixed client participation and static training configurations,which ensure symmetric treatment of clients despite heterogeneous local data distributions.This can limit convergence and degrade detection performance in non-IID conditions.This paper proposes an Adaptive Action-Based Federated Learning(AAFL)framework for decentralized intrusion detection in heterogeneous IoT environments.The framework dynamically adjusts both participating clients and local training workload at each communication round using a Linear Upper Confidence Bound(LinUCB)contextual bandit controller.The proposed Adaptive-FL model is based on XGBoost boosters and uses quality-weighted server-side ensemble aggregation.At the same time,adaptation is guided by a multi-objective reward that balances classification performance,training latency,communication overhead,and computational cost.The framework is evaluated on CIC IoMT 2024 and RT-IoT2022 under realistic non-IID conditions using stratified 5-fold cross-validation and benchmarked against Static-FL,FedAvg-FL,and a centralized XGBoost upper bound.Experimental results demonstrate that Adaptive-FL outperforms all federated baselines across both datasets,achieving Macro-F1 scores of 98.27%on RT-IoT2022 and 94.21%on CIC IoMT 2024,with statistically significant improvements over Static-FL on both datasets.Adaptive-FL maintains superior classification stability while avoiding raw-data centralization.It remains within 0.67 and 0.35 percentage points of the centralized upper bounds on RT-IoT2022 and CIC IoMT 2024,respectively.
基金supported by the National Natural Science Foundation of China(Grant No.62172292).
摘要Anomaly detection is a vibrant research direction in controller area networks,which provides the fundamental real-time data transmission underpinning in-vehicle data interaction for the internet of vehicles.However,existing unsupervised learning methods suffer from insufficient temporal and spatial constraints on shallow features,resulting in fragmented feature representations that compromise model stability and accuracy.To improve the extraction of valuable features,this paper investigates the influence of clustering constraints on shallow feature convergence paths at the model level and further proposes an end-to-end intrusion detection system based on efficient deep embedded subspace clustering(EDESC-IDS).Following the standard learning approach,continuous messages are encoded into two-dimensional data frames via a frame builder,which are then input into an extended convolutional autoencoder for extracting shallow features from high-dimensional data.On this basis,the dual constraints of these output features and the embedding clustering module facilitate end-to-end training of the EDESC-IDS in various attack scenarios.Extensive experimental results show that such a system exhibits significant detection performance on four types of attack datasets,including DoS,Gear,Fuzzy,and RPM,with precision,recall,and F1 scores consistently above 97.79%,while maintaining a false negative rate(FNR)and an error rate(ER)below 2.22%.
基金supported in part by theHubei Engineering Research Center for BDS-CloudHigh-Precision Deformation Monitoring Open Funding(No.HBBDGJ202507Y)the National Natural Science Foundation of China(No.62377037).
摘要The large-scale deployment of Internet of Things(IoT)technology across various aspects of daily life has significantly propelled the intelligent development of society.Among them,the integration of IoT and named data networks(NDNs)reduces network complexity and provides practical directions for content-oriented network design.However,ensuring data integrity in NDN-IoT applications remains a challenging issue.Very recently,Wang et al.(Entropy,27(5),471(2025))designed a certificateless aggregate signature(CLAS)scheme for NDN-IoT environments.Wang et al.stated that their construction was provably secure under various types of security attacks.Using theoretical analysis methods,in this work,we reveal that their CLAS design fails to meet unforgeability,a core security requirement for CLAS schemes.In particular,we demonstrate that their scheme is vulnerable to amalicious public-key replacement attack,enabling an adversary to produce authentic signatures for arbitrary fraudulent messages.Therefore,Wang et al.’s design cannot achieve its goal.To address the issue,we systematically examine the root causes behind the vulnerability and propose a security-enhanced CLAS construction for NDN-IoT environments.We prove the security ofour improveddesignunder the standard security assumptionandalsoanalyze its practicalperformanceby comparing the computational and communication costs with several related works.The comparison results show the practicality of our design.
基金supported by the National Natural Science Foundation of China(Grant No.61762071,Grant No.61163025).
摘要The Internet of Vehicles(IoV)operates in highly dynamic and open network environments and faces serious challenges in secure and real-time authentication and consensus mechanisms.Existing methods often suffer from complex certificate management,inefficient consensus protocols,and poor resilience in high-frequency communication,resulting in high latency,poor scalability,and unstable network performance.To address these issues,this paper proposes a secure and efficient distributed authentication scheme for IoV with reputation-driven consensus and SM9.First,this paper proposes a decentralized authentication architecture that utilizes the certificate-free feature of SM9,enabling lightweight authentication and key negotiation,thereby reducing the complexity of key management.To ensure the traceability and global consistency of authentication data,this scheme also integrates blockchain technology,applying its inherent invariance.Then,this paper introduces a reputation-driven dynamic node grouping mechanism that transparently evaluates and groups’node behavior using smart contracts to enhance network stability.Furthermore,a new RBSFT(Reputation-Based SM9 Friendly-Tolerant)consensus mechanism is proposed for the first time to enhance consensus efficiency by optimizing the PBFT algorithm.RBSFT aims to write authentication information into the blockchain ledger to achieve multi-level optimization of trust management and decision-making efficiency,thereby significantly improving the responsiveness and robustness in high-frequency IoV scenarios.Experimental results show that it excels in authentication,communication efficiency,and computational cost control,making it a feasible solution for achieving IoV security and real-time performance.
基金funded by the Deanship of Scientific Research(DSR)at King Abdulaziz University,Jeddah,Saudi Arabia under grant no.(IPP:753-611-2025)。
摘要Intrusion Detection Systems(IDS)play a critical role in protecting networked environments from cyberattacks.They have become increasingly important in smart environments such as the Internet of Things(IoT)systems.However,IDS for IoT networks face critical challenges due to hardware constraints,including limited computational resources and storage capacity,which lead to high feature dimensionality,prediction uncertainty,and increased processing cost.These factors make many conventional detection approaches unsuitable for real-time IoT deployment.To address these challenges,this paper proposes an adaptive intrusion detection framework that intelligently balances detection accuracy and computational efficiency.The proposed framework integrates mutual information(MI)feature selection model,deep contextual embeddings,and an adaptive decision mechanism.The MI model identifies and retains the most informative features,which reduces dimensionality while maintaining high detection accuracy.The adaptive decision dynamically selects between multiple inference paths to ensure that additional computation is needed only when the uncertainty level is high.Experimental evaluations on benchmark IoT datasets namely RT-IoT-2022,CIC-IoT-2023 and CIC-IoMT-2024 show that the proposed framework achieves F1-score of 99.92%,96.66%,and 99.84%,respectively,with an average inference time of approximately 0.105 ms per sample.These results demonstrate that the framework effectively adapts inference complexity to data uncertainty,which provides an intelligent,interpretable and efficient solution for real-world IoT intrusion detection.
基金supported by the following projects:National Natural Science Foundation of China(62461041)Natural Science Foundation of Jiangxi Province China(20242BAB25068).
摘要With the large-scale deployment of the Internet of Things(IoT)devices,their weak securitymechanisms make them prime targets for malware attacks.Attackers often use Domain Generation Algorithm(DGA)to generate random domain names,hiding the real IP of Command and Control(C&C)servers to build botnets.Due to the randomness and dynamics of DGA,traditional methods struggle to detect them accurately,increasing the difficulty of network defense.This paper proposes a lightweight DGA detection model based on knowledge distillation for resource-constrained IoT environments.Specifically,a teacher model combining CharacterBERT,a bidirectional long short-term memory(BiLSTM)network,and attention mechanism(ATT)is constructed:it extracts character-level semantic features viaCharacterBERT,captures sequence dependencieswith the BiLSTM,and integrates theATT for key feature weighting,formingmulti-granularity feature fusion.An improved knowledge distillation approach transfers the teacher model’s learned knowledge to the simplified DistilBERT student model.Experimental results show the teacher model achieves 98.68%detection accuracy.The student modelmaintains slightly improved accuracy while significantly compressing parameters to approximately 38.4%of the teacher model’s scale,greatly reducing computational overhead for IoT deployment.