“They Will Adapt”: Improving Anomaly Detection on IoT Networks Through Continuous Learning

Giacomo Quadrio, Roberto Pompa, Enrico Bassetti, C. D'Elia, Gianluca Scacco, Mauro Conti · 2024

The ubiquitous presence of Internet-of-Things devices represents a menace to cybersecurity since their low computational power does not allow classic countermeasures techniques. In recent years, anomaly detection using Machine Learning has acquired popularity among researchers; however, current datasets in literature are sub-optimal, making exhaustive benchmarks challenging to create. Moreover, the current proposed ML solutions do not consider the necessity of adapting to IoT networks that mutate fast. We propose a Continuous Learning approach to anomaly detection on IoT networks: frequent model retraining and the exploitation of previous knowledge allow a classifier to quickly adapt to new network configurations. We deployed this approach firstly by defining a benchmark methodology for ML algorithms that helps train and test models for anomaly detection in IoT networks. This phase allowed us to identify the best-performing algorithm for the task. Then, we employed Semi-supervised Learning techniques to deploy the continuous part concretely. Our results show that applying Continuous Learning can progressively improve anomaly detection performance in key metrics such as Recall (up to 75%) and Roc AUC (up to 33%).

Read the paper · More papers on PaperTik