Evaluating AI-Powered Honeypots for Edge Security: Threat Detection Performance on Resource-Constrained Iot Devices

Samuel Barry, Kehinde O. Babaagba, Zhiyuan Tan · 2026

This paper addresses the critical challenge of deploying effective intrusion detection on resource-constrained edge devices within IoT ecosystems. We propose and evaluate a lightweight security framework that integrates AI-driven be-havioural analysis with interactive honeypot technology to enable real-time threat detection at the network edge. To overcome the scarcity of representative attack data, our methodology combines the emulation of adversary interactions via Cowrie honeypots deployed on Raspberry Pi hardware with the curated MedBIoT dataset, using LightGBM for efficient anomaly classification. Experimental results demonstrate very high detection performance (F1-score ≈ 1.00, ROC-AUC ≈ 1.0) on the evaluated dataset of 64,193 samples, reflecting strong separability under controlled conditions. It also maintains minimal resource consumption (<2% RAM, <1% CPU during peak operations). The system achieves sub-second inference (0.128 seconds) and demonstrates sustained operational stability under edge constraints. These findings validate the practical viability of decentralised, AI-enhanced honeypots for scalable edge security, providing a blueprint for implementing adaptive, behaviour-based defence mechanisms in constrained environments.

Read the paper · More papers on PaperTik