Synthetic Minority Over-sampling Technique for detecting Malicious Traffic targeting Internet of Things' devices
Jaqueline Damacena Duarte, Guilherme Dantas Bispo, Gabriel Arquelau Pimenta Rodrigues, André Luiz Marques Serrano, Gabriela Mayumi Saiki, Vinícius P. Gonçalves · Journal of Internet Services and Applications · 2025
This study proposes a multiclass machine learning approach for detecting 34 distinct types of cyberattacks in Internet of Things (IoT) traffic using the CICIoT2023 dataset. We evaluate the performance of lightweight classifiers—Bernoulli Naive Bayes, Decision Tree, Random Forest, and XGBoost—under highly imbalanced conditions. To address class imbalance and improve minority-class detection, we apply the Synthetic Minority Over-sampling Technique (SMOTE). In addition, we conduct hyperparameter tuning using RandomizedSearchCV and assess model performance using macro-average metrics, including recall, precision, and F1-score. Experimental results demonstrate that XGBoost and Random Forest, when optimized and combined with SMOTE, consistently achieves high and balanced detection rates across all classes. These findings suggest its applicability to real-world IoT intrusion detection scenarios, particularly in resource-constrained environments.