NAS-Optimized tinyML intrusion detection for ultralow-power IoT edge devices
Iván Ortiz-Garcés, Milton Román Cañizares, Pablo Palacios, William Eduardo Villegas-Ch · Internet of Things · 2026
Intrusion detection in Internet of Things (IoT) environments faces a persistent gap between the high predictive performance of deep learning models and their feasibility on ultra-low-power embedded devices, as many existing approaches exceed the memory, latency, and energy constraints of edge microcontrollers and rely on domain-specific datasets that limit cross-domain generalization. This work proposes a Tiny Machine Learning (TinyML) intrusion detection framework optimized through Neural Architecture Search (NAS) and trained on a multidomain, feature-aligned dataset integrating heterogeneous sources, including TON_IoT, IoT-23, Edge-IIoTset, and a controlled experimental dataset, using statistical alignment and dimensionality reduction to obtain compact representations of 32–64 features while preserving over 99% of the informative variance. Experimental results achieve F1-macro scores above 0.95 on IoT-23 and 0.98 in controlled scenarios. At the same time, hardware-level validation confirms deployment feasibility with an inference latency of 2.48 ms, RAM usage below 20 KB, and energy consumption of 0.39 mJ per inference, demonstrating the viability of efficient and autonomous intrusion detection directly on IoT edge devices.