XGBoost-Based Anomaly Detection in IoT Networks Using the RT-IoT2022 Dataset
Gaurav Tuteja, Anmol Rattan Singh, Gotte Ranjith Kumar, Mohhamied Husaein Fallaah · 2025
The research presents a robust methodology for anomaly detection in IoT networks using the XGBoost Classifier, evaluated on the RT-IoT2022 dataset. The methodology begins with comprehensive data preprocessing and addresses class imbalance through the Synthetic Minority Oversampling Technique (SMOTE), ensuring balanced representation of both normal and anomalous traffic. The RT-IoT2022 dataset, 12 traffic classes, including 9 attack types and 3 normal behaviors, provides a diverse and realistic benchmark. The proposed approach achieves an overall accuracy of 99%, with a weighted F1-score of 0.99, indicating strong performance across all classes. High precision, recall, and F1-scores are observed for major attack classes such as DOS SYN_Hping and NMAP XMAS TREE SCAN. Error analysis highlights challenges in low-performing classes like Wipro bulb, where false negatives impacted recall. The ROC curve confirms excellent discriminative ability, with most classes achieving an Area Under the Curve (AUC) of 1.00. Feature importance rankings demonstrate the significance of temporal and flow-based features, such as Flow Duration and Flow IAT Mean, in identifying anomalies. The proposed methodology showcases effective classification of diverse IoT traffic patterns, providing a reliable solution for anomaly detection in resource-constrained IoT environments. The findings emphasize the potential of XGBoost-based models in enhancing IoT security and reliability across critical applications.