International Journal of Innovative Research in Computer and Communication Engineering

ISSN Approved Journal | Impact factor: 8.771 | ESTD: 2013 | Follows UGC CARE Journal Norms and Guidelines

| Monthly, Peer-Reviewed, Refereed, Scholarly, Multidisciplinary and Open Access Journal | High Impact Factor 8.771 (Calculated by Google Scholar and Semantic Scholar | AI-Powered Research Tool | Indexing in all Major Database & Metadata, Citation Generator | Digital Object Identifier (DOI) |


TITLE An Empirical Evaluation of Lightweight Ensemble Learning for IoT Network Intrusion Detection
ABSTRACT The rapid proliferation of Internet of Things (IoT) devices has expanded the attack surface for network intrusions, necessitating efficient and reliable intrusion detection systems (IDS). While machine-learning (ML) classifiers have demonstrated strong aggregate performance on benchmark datasets, their comparative robustness across heterogeneous attack categories—and the incremental reliability gains from simple ensemble decision fusion—remain insufficiently characterized in contemporary IoT contexts. This paper presents an empirical evaluation of conventional ML classifiers and a lightweight soft-voting ensemble for multiclass intrusion detection using the CICIoT2023 dataset. We assess five baseline models (Logistic Regression, Decision Tree, Random Forest, Gradient Boosting, and XGBoost) and a proposed three-model soft-voting ensemble under identical preprocessing and evaluation protocols. Our methodology emphasizes leakage-free train/test separation, class-imbalance mitigation via class weighting, and comprehensive per-class performance analysis. In the illustrative results presented here, the ensemble achieves a 0.928 macro F1-score, outperforming the best individual classifier by 0.32 percentage points, with particular improvements in minority-class recall. However, certain low-prevalence attack categories (e.g., Web-based, Brute Force) remain challenging, with recall below 0.85. These findings underscore that traffic-only features, even when fused via ensemble learning, exhibit inherent limitations for detecting structurally complex attacks—motivating future integration of attack-path context. This work is intended as a reproducible foundation study supporting a broader research trajectory toward attack-aware IDS.
AUTHOR SHAILESH PRASAD, DR. JOE ARUN RAJA Research Scholar, School of Information Science, Presidency University, Bengaluru, India Presidency School of Information Science, Presidency University, Bengaluru, India
VOLUME 187
DOI DOI: 10.15680/IJIRCCE.2026.1408025
PDF pdf/25_An Empirical Evaluation of Lightweight Ensemble Learning for IoT Network Intrusion Detection.pdf
KEYWORDS
References [1] E. C. P. Neto, S. Dadkhah, R. Ferreira, A. Zohourian, R. Lu, and A. A. Ghorbani, “CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment,” Sensors, vol. 23, no. 13, p. 5941, 2023.
[2] M. Houichi et al., “Enhancing Smart City Security: An Intrusion Detection System Using the UNB CIC IoT 2023 Dataset,” IET Smart Cities, 2025.
[3] S. A. Almahaqeri et al., “An optimized gradient boosting framework for IoT intrusion detection: a comprehensive evaluation on the CICIoT2023 dataset,” Scientific Reports, 2026.
[4] K. S. Adewole, A. Jacobsson, and P. Davidsson, “Intrusion Detection Framework for Internet of Things with Rule Induction for Model Explanation,” Sensors, vol. 25, no. 6, p. 1845, 2025.
[5] Y. Alotaibi and M. Ilyas, “Ensemble-Learning Framework for Intrusion Detection to Enhance Internet of Things' Devices Security,” Sensors, vol. 23, no. 12, p. 5568, 2023.
[6] B. Susilo et al., “Intelligent Intrusion Detection System Against Various Attacks Using CIC IoT-2023 Dataset,” PMC, 2025.
[7] S. M. Tseng et al., “Multi-class intrusion detection based on transformer for IoT networks using CIC-IoT-2023 dataset,” Future Internet, 2024.
[8] A. Hozouri et al., “A comprehensive survey on intrusion detection systems with ensemble learning,” Discover Internet of Things, 2025.
[9] A. Zohourian et al., “Overview of the CICIoT2023 Dataset for Internet of Things Security Research,” MJBD, 2025.
[10] K. Jakotiya, V. Shirsath, and R. G. Mishra, “Feature engineering using machine learning techniques on CIC-IoT-2023 dataset,” Machine Vision and Augmented Intelligence, 2024.
[11] A. H. Ali et al., “Unveiling machine learning strategies and considerations for intrusion detection in IoT,” Frontiers in Computer Science, 2024.
[12] C. Christy et al., “Machine learning based multi-stage intrusion detection for VANETs,” Scientific Reports, 2025.
[13] O. E. Akinbowale et al., “Machine learning based approach to intrusion detection in IoT: A review,” PMC, 2026.
[14] M. M. Abou Elasaad et al., “AegisGuard: A Multi-Stage Hybrid Intrusion Detection System for IIoT,” PMC, 2025.
[15] M. A. O. Ahmed et al., “Enhancing Internet of Things security using performance gradient boosting for network intrusion detection systems,” Egyptian Informatics Journal, 2025.
[16] F. Alhayan et al., “Voting-based ensemble classifiers model on ransomware detection for IIoT,” Egyptian Informatics Journal, 2025.
[17] A. Odeh et al., “Ensemble-Based Deep Learning Models for Enhancing IoT Security,” Applied Sciences, vol. 13, no. 21, p. 11985, 2023.
[18] L. Diana et al., “Overview on Intrusion Detection Systems for Computers and Networks: A Survey,” Computers, vol. 14, no. 3, p. 87, 2025.
[19] K. S. Mubasshir, I. Karim, and E. Bertino, “Gotta Detect 'Em All: Fake Base Station and Multi-Step Attack Detection in Cellular Networks,” USENIX Security, 2025.
[20] I. H. Witten, E. Frank, M. A. Hall, and C. J. Pal, Data Mining: Practical Machine Learning Tools and Techniques, 4th ed. Morgan Kaufmann, 2016.
[21] L. Breiman, “Random Forests,” Machine Learning, vol. 45, no. 1, pp. 5–32, 2001.
[22] T. Chen and C. Guestrin, “XGBoost: A Scalable Tree Boosting System,” in Proc. 22nd ACM SIGKDD Int. Conf. Knowledge Discovery and Data Mining, 2016, pp. 785–794.
[23] M. Sokolova and G. Lapalme, “A systematic analysis of performance measures for classification tasks,” Information Processing & Management, vol. 45, no. 4, pp. 427–437, 2009.
[24] F. Pedregosa et al., “Scikit-learn: Machine Learning in Python,” Journal of Machine Learning Research, vol. 12, pp. 2825–2830, 2011.
[25] H. He and E. A. Garcia, “Learning from imbalanced data,” IEEE Transactions on Knowledge and Data Engineering, vol. 21, no. 9, pp. 1263–1284, 2009.
[26] N. V. Chawla, K. W. Bowyer, L. O. Hall, and W. P. Kegelmeyer, “SMOTE: Synthetic Minority Over-sampling Technique,” Journal of Artificial Intelligence Research, vol. 16, pp. 321–357, 2002.
[27] J. Han, M. Kamber, and J. Pei, Data Mining: Concepts and Techniques, 3rd ed. Elsevier, 2012.
[28] A. Géron, Hands-On Machine Learning with Scikit-Learn, Keras, and TensorFlow, 3rd ed. O'Reilly, 2022.


Copyright © IJIRCCE 2020.All right reserved