Generalizable Intrusion Detection for IoT: A Cost-Sensitive Multimodal Approach
Tasnimul Hasan, Samia Tasnim · 2025
The rapid increase in Internet of Things (IoT) devices has transformed network connectivity. However, it has also exposed critical security vulnerabilities, heightening IoT networks' susceptibility to cyber threats. Traditional Intrusion Detection Systems (IDS) struggle with IoT-specific challenges, including data heterogeneity, multimodal inputs (e.g., numeric and image data), and severe class imbalance, where normal traffic vastly outweighs malicious activity. To address these issues, we propose a lightweight, distributed edge-deployable multimodal intrusion detection system that integrates a CostSensitive Autoencoder (CS-AE) for tabular data and a CostSensitive Convolutional Neural Network (CS-CNN) for image data. This technique unifies diverse input modalities into a shared feature space, enabling efficient anomaly detection while prioritizing rare but critical attacks through cost-sensitive learning. We evaluate our system on six contemporary IoT security datasets-CICIoT2023, DS2OS, Edge-IIoTset, ToN IoT Network, 913 Malicious Network Traffic, and CICIoMT2024-achieving a high detection accuracy of 99.95 % across various attack scenarios. Comparative analysis with state-of-the-art IDS approaches demonstrates superior performance in detecting both common and rare attacks, underscoring the system's scalability and adaptability. Furthermore, we deploy our model on a Jetson Nano, a resource-constrained edge device, where it achieves efficient real-time intrusion detection with an average prediction time of 0.32 seconds per instance. This demonstrates the feasibility of our approach for practical edge deployments, reducing latency and dependence on centralized cloud processing. By integrating multimodal learning and cost-sensitive optimization, our approach offers a robust and practical solution for securing evolving IoT networks against emerging cyber threats.