Hybrid CNN‐LSTM Anomaly Detection in IoT Traffic Using the Hurst Self‐Similarity Parameter Under Gaussian Noise

Roya Morshedi, S. Mojtaba Matinkhah, Mohammad Taghi Sadeghi · IET Information Security · 2025

The rapid growth of Internet of Things (IoT) devices has posed significant security challenges, particularly in detecting anomalies and malicious behaviors in network traffic. This study presents an innovative intrusion detection system (IDS) framework that combines Gaussian noise injection and Hurst parameter calculation with a hybrid convolutional neural network‐long short‐term memory (CNN‐LSTM) model for anomaly detection in IoT traffic. The proposed approach is evaluated using the CIC‐IDS2017 dataset, a comprehensive source representing network attacks. During the preprocessing stage, noise is added to simulate real‐world network fluctuations, and Hurst parameter values are calculated to measure the long‐term memory of traffic patterns. Principal component analysis (PCA) is also employed to reduce data dimensionality while preserving critical features, including the Hurst parameter. The CNN‐LSTM model, optimized with the Adam optimizer, effectively learns the spatiotemporal features of network traffic and demonstrates high accuracy in classifying benign and attack samples. Experimental results reveal that the model achieves an accuracy and detection rate of 99.69%, even in the presence of noise. Incorporating the Hurst parameter as a distinguishing feature enhances the detection of subtle anomalies that traditional IDS methods may overlook. The anomaly detection mechanism analyzes traffic patterns using an error threshold and flags deviations as potential security threats. The proposed IDS framework effectively distinguishes between normal and malicious traffic, balancing the detection of both rare and common attacks. The findings underscore the importance of integrating statistical metrics, such as the Hurst parameter, with deep learning models to enhance the robustness and reliability of IoT security systems. This hybrid approach addresses the dynamic and evolving nature of IoT networks, offering a scalable and efficient solution for real‐time anomaly detection. The proposed method marks a promising advancement in securing IoT ecosystems against evolving cyberthreats.

Read the paper · More papers on PaperTik