Multi Cyber Attacks Detection System in Interet of Things Based on Machine Learning

Rand Nabeel Dawood, Neamet Akeel Fawzi, Hind Ali abdul Hassan · Journal Européen des Systèmes Automatisés · 2025

In this work, we propose a machine learning-based approach to improvement in cybersecurity in sensor networks (SNs).Indeed, SNs are vital to a wide range from environmental monitoring and military surveillance to underwater exploration.Due to their open and distributed nature, they inherently remain much more vulnerable to cyberattacks.Because of unique constraints about the bandwidth, latency, and energy, traditional security approaches remain inappropriate for them.In our proposed approach, we have used a Random Forest Classifier (RFC) and Supported Vector Machine Classifier (SVM) for detecting and mitigating various kinds of network attacks.The dataset used in this work is wireless sensor network dataset (WSN-DS), which contains SN-relevant features such as attack types like normal, flooding, time division multiple access (TDMA), Grayhole, and Blackhole.Preprocessing will be done by dropping the irrelevant columns, scaling the features, and encoding the target variable.Our model worked well using the RFC approach compared to SVM, yielding an accuracy of 99.66%, with precision at 99.69%, recall at 99.66%, and an F1-score of 99.67%.Besides, we also tested our Random Forest-based IDS on the Network Security Lab-Knowledge Discovery and Data Mining (NSL-KDD) dataset that includes a number of features relevant to network traffic and intrusion detection.The obtained results for the "NSL-KDD" test set are as follows: accuracy-1.00,precision-0.87,recall-0.87,F1-score-0.87.We can understand from the confusion matrix that this model correctly identified various attack types and normal behavior.Also, a classification report shows more about the performance of the model for each class.The high performances of our Random Forest models on both datasets confirm the potentiality of machine learnin-based solutions against intrusion detection in UWSNs.Indeed, robustness against imbalanced data and the ability tо capture complex interactions between features explain their success.In the future, other machine learning models can be explored, including deep learning approaches, as well as real-time deployment of IDS í ñ UWSNs.Besides, extending the datasets to more types of attacks and scenarios would improve the generalization capability of these models.

Read the paper · More papers on PaperTik