Enhancing IoT Attack Classification through Domain Generalization

Iram Bibi, Tanır Özçelebi, Nirvana Meratnia · 2025

The widespread adoption of the Internet of Things (IoT) has revolutionized numerous industries such as healthcare, transportation, and smart homes. However, the rapid deployment of IoT systems and their limited resources, heterogeneity, and security measures make them highly vulnerable to a wide range of cyber-attacks. These attacks can lead to unauthorized access, data breaches, or even complete failure of the operation. IoT devices often generate a mix of high-frequency, low-volume, and event-driven data flows. This mix of traffic patterns contributes to variability, which can make it difficult to identify consistent attack patterns. In this paper, we benchmark three domain generalization algorithms named Group Distributionally Robust Optimization (GroupDRO), ANDMASK, and Mixup to show their generalization capability across different IoT attack datasets. We first transform IoT network traffic data, traditionally presented in tabular format, into images using the Image Generator for Tabular Data (IGTD) and DeepInsight techniques. This conversion process is designed to reveal the latent structures within the data. We perform extensive experimentation using various publicly available datasets, namely Kitsune, MUDScope, ToN_IoT, and IoT_23 focusing on the classification of DoS and scanning attacks. Overall performance is measured using metrics such as accuracy, precision, recall, f1 score, and execution time. The results demonstrate that the GroupDRO algorithm combined with the tabular-to-image conversion technique achieves moderate classification performance even in scenarios where the target domain differs significantly from the source domains, while also highlighting opportunities for further improvement.

Read the paper · More papers on PaperTik