IDS-Twin: Digital Twin-Based Intrusion Detection Systems for Wireless Networks
Hassan El Alami, Danda B. Rawat · IEEE Networking Letters · 2025
The rapid expansion of IoT devices has greatly enhanced wireless connectivity but also increased exposure to sophisticated and evolving cyber threats. Recent intrusion detection systems (IDS) based on Artificial Intelligence (AI) often rely on offline training and static models, limiting their ability to adapt in dynamic environments where device behavior and attack patterns continuously change. To address these challenges, we propose IDS-Twin, a Digital Twin (DT)-based intrusion detection framework designed for wireless IoT. IDS-Twin incorporates a self-adaptive anomaly detection model powered by contrastive learning, enabling real-time learning from streaming traffic with minimal labeled data. The DT component is implemented as a lightweight software replay engine that emulates real-time arrival by sequentially streaming flows in timestamp order, enabling the system to continuously detect and adapt to new or evolving attacks. Experimental validation on the UNSW-NB15 and CIC-IoT-2023 datasets demonstrates the superior performance and adaptability of IDS-Twin, outperforming state-of-the-art IDS solutions in detecting both known and unknown attacks in wireless networks.