Anomaly Detection in IoT Networks Using Random Forest and the RT-IoT2022 Dataset

Gaurav Tuteja, Anmol Rattan Singh, Gotte Ranjith Kumar · 2025

This research work aims to design an effective anomaly detection system for IoT networks using the RT-IoT2022 dataset and a Random Forest Classifier. Designed for research purposes, the given dataset includes 100,000 records and 80 features of normal and malicious traffic flows as well as DDoS, ARP Poisoning, and Nmap scan attacks. The research method was therefore descriptive and involved data preparation and SMOTE, used to handle class imbalance. This approach exposed hidden underrepresented attack categories to the classifier, making it easy for the classifier to attain a high degree of accuracy in detecting real attacks. The Random Forest classifier’s performance for different categories showed high results: precision, recall, and F1-score were 1.00 for attack types DOS_SYN_Hping and NMAP XMAS_TREE_SCAN. MQTT Publish traffic and Thing Speak traffic, classified as normal traffic, achieved values above 0.90 for all metrics. The final overall accuracy reached 98%, affirming the applicability of the offered methodology. Feature importance analysis and confusion matrix assessment demonstrated features such as Flow Duration and Protocol Type as significant for anomaly detection. The observed outcomes con- firm that further improvements in IoT network security can be achieved using ensemble learning models together with advanced preprocessing techniques. This approach lays the groundwork for constructing scalable and efficient anomaly detection systems needed to meet the increasing demands of IoT and emerging cyberspace threats.

Read the paper · More papers on PaperTik