IOT INTRUSION DETECTION USING MIXED DUNG BEETLE OPTIMISATION-BASED FEATURE SELECTION AND ATTENTION-BASED BIRNN WITH HYPERPARAMETER TUNING
DOI:
https://doi.org/10.22452/Keywords:
Internet of Things (IoT), Intrusion Detection System (IDS), Mixed Dung Beetle Optimisation (MDBO), Attention-Based BiRNN, Artificial Rabbits Optimisation (ARO), WSNDS Dataset, Imbalanced Classification, Feature Selection, Attention Mechanism, Deep LearningAbstract
The exponential growth of the Internet of Things (IoT) has led to new cybersecurity threats from the rise in the number of various and resource-limited connected devices. Conventional intrusion detection systems (IDSs) may not be efficient in dealing with real-time, high-dimensional, class-imbalanced nonstationary IoT traffic data. To overcome these limitations, in this paper, an IoT intrusion detection framework is proposed based on Mixed Dung Beetle Optimisation with Deep Learning Cyber Security (MDBODR-DLCS). To this end, Z-score normalisation is first performed to normalise the features of network traffic, which enhances the stability of subsequent models. Then, Mixed Dung Beetle Optimisation (MDBO) is used for optimal feature selection and dimensionality reduction to remove redundant and irrelevant attributes. To employ the established temporal dependency information and contextual traffic patterns as features for intrusion classification, our proposed method utilises an Attention-Based Bidirectional Recurrent Neural Network (ABiRNN). Besides, Artificial Rabbits Optimisation (ARO) is employed to fine-tune hyperparameters to improve classification accuracy and convergence speed. We conduct an experimental evaluation on the WSNDS dataset that shows that our framework is able to outperform state-of-the-art intrusion detection solutions, with over 99% accuracy and very high sensitivity, specificity, F-score, and AUC for multiple attack classes. The comparative analyses showed that the proposed method outperforms other existing methods using machine learning and deep learning-based IDS structures while maintaining low computational complexity with an average execution time of 0.60 seconds per instance. The results were found to demonstrate that the developed method MDBODR-DLCS efficiently achieves high accuracy performance in real time and scalability, while being resilient due to its ability to detect even the variations an attacker might introduce, whilst maintaining very low overhead, making it appropriate for resource-constrained environments such as IoT.

