Simple Yet Powerful: Machine Learning-Based IoT Intrusion System With Smart Preprocessing and Feature Generation Rivals Deep Learning

dc.contributor.authorKivanc Eren, Kazim
dc.contributor.authorKucuk, Kerem
dc.contributor.authorOzyurt, Fatih
dc.contributor.authorAlhazmi, Omar H.
dc.date.accessioned2026-08-12T17:26:35Z
dc.date.issued2025
dc.departmentFırat Üniversitesi
dc.description.abstractWith the rapid advancements in deep learning, IoT intrusion detection systems have increasingly adopted deep learning models as the state-of-the-art solution due to their ability to handle complex data patterns. However, these solutions introduce the risk of overengineering, in which the complexity of the model outweighs its practical benefits. In contrast, classical machine learning techniques offer a more efficient alternative but are often overlooked due to a lack of focus on data pre-processing, which is critical for achieving optimal performance. Here we propose a classical machine learning system, built around a Random Forest classifier paired with a novel feature extraction algorithm adapted from Explainable Boosted Linear Regression (EBLR). Our workflow emphasizes the importance of well-structured preprocessing pipelines missing data handling, categorical feature encoding, and multicollinearity reduction, paired with classical machine learning models. We evaluated our method on the ToN-IoT dataset, which contains various network traffic data sets and various types of attacks. Experimental results show that our model achieves an area under the curve (AUC) score of 0.99 on both training and test sets with high performance in a variety of attack categories. Finally, we show that our method outperforms existing deep learning models, thus providing a novel and effective solution for intrusion detection in IoT environments. Experimental results show that our model achieves an area under the curve (AUC) score of 0.99 in both the training and test sets. Furthermore, the classifier achieves precision, recall and F1 score values of 0.999, 0.988, and 0.994, respectively, for normal traffic detection, while maintaining strong performance for other attack categories, such as denial of service (precision: 0.985, recall: 0.977, F1 score: 0.981) and scanning (precision: 0.984, recall: 0.992, F1 score: 0.988). Injection and ransomware attack types also demonstrate precision and recall scores above 0.90. These results highlight that, when paired with appropriate preprocessing and feature engineering, classical machine learning models still can provide an effective solution for intrusion detection in IoT environments.
dc.description.sponsorshipScientific and Technological Research Council of Turkiye (TUEBITAK) [124E307]; Kocali University Scientific Research Projects Coordination Unit [FBA-2024-3752]
dc.description.sponsorshipThis work was supported in part by the Scientific and Technological Research Council of Turkiye (TUEBITAK) under Grant 124E307,and in part by Kocali University Scientific Research Projects Coordination Unit under Grant FBA-2024-3752.
dc.identifier.doi10.1109/ACCESS.2025.3547642
dc.identifier.endpage41455
dc.identifier.issn2169-3536
dc.identifier.orcid0000-0002-6158-1801
dc.identifier.orcid0000-0002-8154-6691
dc.identifier.orcid0000-0002-2621-634X
dc.identifier.orcid0000-0002-5071-2722
dc.identifier.scopus2-s2.0-105001059830
dc.identifier.scopusqualityQ1
dc.identifier.startpage41435
dc.identifier.urihttps://doi.org/10.1109/ACCESS.2025.3547642
dc.identifier.urihttps://hdl.handle.net/11508/54861
dc.identifier.volume13
dc.identifier.wosWOS:001442889800021
dc.identifier.wosqualityQ2
dc.indekslendigikaynakWeb of Science
dc.indekslendigikaynakScopus
dc.language.isoen
dc.publisherIeee-Inst Electrical Electronics Engineers Inc
dc.relation.ispartofIeee Access
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/openAccess
dc.snmzKA_WoS_20260511
dc.subjectFeature extraction
dc.subjectData models
dc.subjectIntrusion detection
dc.subjectComputational modeling
dc.subjectTraining
dc.subjectEncoding
dc.subjectSupport vector machines
dc.subjectRadio frequency
dc.subjectDeep learning
dc.subjectConvolutional neural networks
dc.subjectAutomated feature generation
dc.subjectdata-driven applications
dc.subjectdata preprocessing
dc.subjectdeep learning
dc.subjectfeature extraction
dc.subjectthe Internet of Things
dc.subjectimbalanced learning
dc.subjectmachine learning
dc.subjectstratification
dc.titleSimple Yet Powerful: Machine Learning-Based IoT Intrusion System With Smart Preprocessing and Feature Generation Rivals Deep Learning
dc.typeArticle

Dosyalar