Autonomous Reinforcement Learning-Based Intrusion Detection for IoT Cyber Defense
Ammar Odeh · Digital · 2026
The rapid proliferation of Internet of Things (IoT) devices has dramatically expanded the attack surface for cyber threats, exposing critical infrastructure to sophisticated intrusion attempts that traditional static intrusion detection systems (IDS) fail to counter effectively. This paper proposes an autonomous reinforcement learning (RL)-based IDS framework for dynamic IoT networks, capable of adaptive, real-time threat detection without human intervention. The proposed system integrates a Deep Q-Network (DQN) agent with a hybrid convolutional neural network–long short-term memory (CNN-LSTM) feature extractor to identify and classify malicious network traffic across 33 attack categories. We evaluate the framework on two recent, publicly available benchmark datasets: CICIoT2023, comprising 8.94 GB of traffic from 105 real IoT devices, and CIC IoT-DIAD 2024, a flow-based dataset with diverse attack and benign scenarios. Experimental results demonstrate superior detection performance compared to baseline classifiers, including SVM, Random Forest, and standalone deep learning models, with improved F1-score, reduced false alarm rate (FAR), and lower detection latency. The reward-shaping strategy explicitly penalizes false positives, addressing a key limitation of prior RL-based IDS approaches. This work contributes a scalable, dataset-agnostic autonomous defense architecture suitable for real-world IoT deployment.