ConceptioArchiveNCBI PubMed Central
NCBI PubMed Centralopen access

Harnessing multimodal deep representation with dimensionality reducing approach for enhanced intrusion detection system in internet of things networks.

Priyadharshini K et al. · ncbi_pmc
NCBI PubMed Central · Papers · License: Open Access
Open Source ↗Direct PDF ↓
cryptographysecurity
cryptography security

Skip to main content An official website of the United States government Here's how you know Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Log in Dashboard Publications Account settings Log out Search… Search NCBI Primary site navigation Search Logged in as: Dashboard Publications Account settings Log in Search PMC Full-Text Archive Search in PMC Journal List User Guide PERMALINK Copy As a library, NLM provides access to scientific literature. Inclusion in an NLM database does not imply endorsement of, or agreement with, the contents by NLM or the National Institutes of Health. Learn more: PMC Disclaimer | PMC Copyright Notice Sci Rep . 2026 Feb 28;16:11442. doi: 10.1038/s41598-026-36135-8 Search in PMC Search in PubMed View in NLM Catalog Add to search Harnessing multimodal deep representation with dimensionality reducing approach for enhanced intrusion detection system in internet of things networks K Priyadharshini K Priyadharshini 1 Department of Computing Technologies, School of Computing, College of Engineering and Technology, Faculty of Engineering and Technology, SRM Institute of Science and Technology, Kattankulathur, 603203 India Find articles by K Priyadharshini 1 , M Arulprakash M Arulprakash 2 Department of Computing Technologies, School of Computing, SRM Institute of Science and Technology, Kattankulathur, 603203 India Find articles by M Arulprakash 2 , R Jeya R Jeya 2 Department of Computing Technologies, School of Computing, SRM Institute of Science and Technology, Kattankulathur, 603203 India Find articles by R Jeya 2 , Anil Kumar Muthevi Anil Kumar Muthevi 3 Department of Computer Science and Engineering, Aditya University, Aditya Nagar, Surampalem, Andhra Pradesh 533437 India Find articles by Anil Kumar Muthevi 3 , Monalisa Sahu Monalisa Sahu 4 Department of Software and System Engineering, School of Computer Science & Engineering, VIT-AP University, Beside AP Secretariat, Amaravati, 522241, Andhra Pradesh India Find articles by Monalisa Sahu 4, ✉ , Sribidhya Mohanty Sribidhya Mohanty 5 Department of Electronics and Communication Engineering, Graphic ERA (Deemed to be University), Dehradun, Uttarakhand India Find articles by Sribidhya Mohanty 5 , Ravendra Singh Ravendra Singh 6 Department of Computer Science and Engineering, Pranveer Singh Institute of Technology, Kanpur, India Find articles by Ravendra Singh 6 Author information Article notes Copyright and License information 1 Department of Computing Technologies, School of Computing, College of Engineering and Technology, Faculty of Engineering and Technology, SRM Institute of Science and Technology, Kattankulathur, 603203 India 2 Department of Computing Technologies, School of Computing, SRM Institute of Science and Technology, Kattankulathur, 603203 India 3 Department of Computer Science and Engineering, Aditya University, Aditya Nagar, Surampalem, Andhra Pradesh 533437 India 4 Department of Software and System Engineering, School of Computer Science & Engineering, VIT-AP University, Beside AP Secretariat, Amaravati, 522241, Andhra Pradesh India 5 Department of Electronics and Communication Engineering, Graphic ERA (Deemed to be University), Dehradun, Uttarakhand India 6 Department of Computer Science and Engineering, Pranveer Singh Institute of Technology, Kanpur, India ✉ Corresponding author. Received 2025 Jul 26; Accepted 2026 Jan 9; Collection date 2026. © The Author(s) 2026 Open Access This article is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License, which permits any non-commercial use, sharing, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if you modified the licensed material. You do not have permission under this licence to share adapted material derived from this article or parts of it. The images or other third party material in this article are included in the article’s Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article’s Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this licence, visit http://creativecommons.org/licenses/by-nc-nd/4.0/ . PMC Copyright notice PMCID: PMC13057260  PMID: 41764232 Abstract The revitalization of traditional villages is shifting from single village to contiguous areas, with a cycling network connecting these villages serving as a key facilitator for the coordinated development of their culture and tourism. However, current rural cycling network planning primarily depends on static, materialized evaluations and fails to leverage the dynamic flow of people in the region, leading to generally low utilization rates. Consequently, this study proposes a method for generating a cycling network based on flow-based attractiveness evaluation. By utilizing Wi-Fi probes to monitor the intensity and stability of people’s movement, we established an attractiveness evaluation for the preliminary cycling route. Based on this evaluation, we incorporated the shortest routes to historical attractions and the concentration of public service facilities to construct an optimal cycling network. The research then conducted an empirical study in the traditional village contiguous area of Tonglu County, China, and found that: (1) the flow attraction of the initial route was highly polarized and unevenly distributed; (2) compared to the original plan, the cycling network generated by this research demonstrated superior overall performance, with improvements in accessibility, connectivity to historical attractions and integration with public service facilities. These findings suggest that the method can be used to create a cycling network that encourages people to remain in traditional village contiguous areas, thereby promoting the synergistic development of culture and tourism. Keywords: Cycling network, Traditional village, Attractiveness evaluation Subject terms: Engineering, Mathematics and computing Introduction Network attacks are malicious activities aimed at disrupting, denying, degrading, or destroying critical data and services on a host computer network 1 . Attacks on computer systems involve data streaming across networks to compromise the computer system’s reliability, privacy, or the computer network’s availability. Recently, Cybercrime has led to substantial losses, reaching billions of dollars 2 . If this trajectory persists without intervention, the global economy could experience significant instability. The arrival of wireless access has significantly altered cybercrime patterns, with offenders who can afford such services now exploiting wireless connectivity to conveniently carry out cybercrimes from the comfort of their homes, eliminating the need to visit Internet cafes 3 . Although breaching current wireless systems requires computational resources on the part of the hacker, it is certainly not beyond the realm of possibility. It is widely recognised that the growing issue of wireless network breaches continues to pose a serious threat to the current state of cyberspace. The current escalation in the volume of data produced and transferred over the internet, the need to protect that information, and the persistent rise in intrusions are prompting both industrial and academic groups to devote greater attention to cybersecurity systems 4 . To protect computer systems from threats, IDS is utilised to assist user authentication, guarantee secure access, and avert data loss 5 . Malicious attacks are becoming more advanced, and the primary concern is detecting new and complex malware, as cyber attackers use various evasion techniques to conceal malicious activity and make it harder to identify. Moreover, there has been an increase in security attacks, namely zero-day attacks targeting internet users. IDS serves as a crucial protective measure, safeguarding network infrastructure from cyberattacks by detecting unauthorised access and malicious behaviour 6 . Since their advent in the mid-80s, they have undergone significant advancements to keep pace with the evolving complexities of computer-related cybercrime. IDS are classified into network IDS (NIDS) and prevention networks that examine network traffic for indications of malicious behaviour through statistical and signature anomaly detection, and heuristic behavioural analysis 7 . These methods can detect and prevent attacks and malicious activities more effectively than traditional security measures. Figure 1 depicts the general representation of intrusion detection in IoT devices. Fig. 1. Open in a new tab Structure of intrusion detection in IoT devices. As a result, it is essential to develop IDSs capable of detecting new attacks 8 . To address cyberattack issues, scholars began developing IDSs using machine learning (ML) approaches. ML is a branch of artificial intelligence (AI) that learns from large datasets. ML-driven IDSs can achieve acceptable detection rates when sufficient training data is available and ML paradigms are sufficiently relevant to identify attack types and unknown attacks 9 . Furthermore, ML-driven IDSs don’t depend heavily on domain expertise; thus, they are easy to develop. DL is a subfield of ML that can attain excellent performance. Furthermore, DL can automatically learn feature representations from fresh data and then produce outcomes; they work in an end-to-end manner and are useful 10 . In this paper, an Optimised Feature Selection with Multimodal Deep Representation for Robust Intrusion Detection System (OFSMDR-RIDS) model is proposed in an IoT network. The OFSMDR-RIDS model aims to develop an effective intelligent IDS that enhances cybersecurity by accurately detecting and mitigating malicious activities in digital environments. The data pre-processing stage initially uses quantile normalisation to convert the input data into a more helpful format. Followed by, the minimum redundancy maximum relevance (mRMR) technique is employed for the feature selection (FS) process. Finally, the OFSMDR-RIDS technique implements a hybrid system that combines bidirectional long short-term memory with an autoencoder (BiL-AE) to classify and detect cybersecurity attacks effectively. The validation of the OFSMDR-RIDS technique emphasised superior accuracy outcomes under the ToN-IoT and BoT-IoT datasets. The major contribution of the OFSMDR-RIDS technique is listed below. The quantile normalization is applied for robust preprocessing to convert raw IoT network data into a consistent and informative format, thus improving the data quality and model readiness while also enhancing the overall performance of the IDS. The mRMR is employed for detecting the most crucial features while also mitigating redundancy, thus enhancing the efficiency of the model and enhancing the accuracy of intrusion detection in IoT networks. A hybrid BiL-AE model incorporating BiL-AE methodology is developed to accurately classify and detect cybersecurity attacks, improving the detection capabilities and overall reliability of IoT network intrusion systems. Thus, the OFSMDR-RIDS method presents a novel multimodal deep representation approach with dimensionality reduction, uniquely integrating quantile normalization, mRMR-based feature selection, and a BiL-AE hybrid model, presenting a comprehensive framework that improves feature representation, intrusion detection, and mitigating computational complexity in IoT networks compared to conventional methods. Review of existing IDS approaches in IoT environments Grandhi and Singh 11 introduced an Interrelated Dynamic Biased FS approach employing Enhanced Gorilla Troops Optimiser (IDBFS-EGTO) to generate a feature vector set for ID. Even though it’s a noticeable achievement in managing a broad spectrum of real-time issues, it risks getting entangled in local optima and early convergence, and it faces more optimisation challenges, which EGTO solves. The EGTO method employs a set of operators to achieve a more stable balance between exploration and exploitation. In 12 , an innovative technique was created to improve the input data quality. This method leverages the Random Missing Value (RMV) model to simulate missing data, enabling detailed testing and evaluation of several imputation methodologies. Ranpara et al. 13 proposed GreenMU, a groundbreaking architecture designed to address two key problems: energy efficiency, a central focus of the study, and detection performance in IDSs. In the study, by incorporating sophisticated ML methods, namely Support Vector Machine (SVM) and Random Forest (RF) classifiers, with knowledge distillation and an adaptive energy-aware optimiser. Pillai et al. 14 proposed an improved NIDs. A detailed pre-processing stage with normalisation functions enhances data consistency and precision. The Single Candidate Optimiser (SCO) FS paradigm maximises NIDS effectiveness. A hybrid approach utilising Artificial Neural Networks (ANN), Wavelet Transform (WT), and LSTM is employed for classification, as it can recognise sequential relations in network traffic data. Then, the SCO iteration for hyperparameter tuning enhances model performance. Aljehane et al. 15 introduced a novel Golden Jackal Optimiser Algorithm alongside DL-based IDS for Network Security (GJOADL-IDSNS) model. This model focuses on detecting and classifying intrusions to achieve network security. Firstly, data normalisation is performed to scale the input data into a more useful form. In this model, the GJOA-enabled FS (GJOA-FS) methodology is used to select the best feature subset. Subsequently, the presented model implements the attention-based bidirectional LSTM (A-BiLSTM) paradigm. Saikam and Ch 16 presented an NIDS method that combines hybrid sampling with a deep neural network. The Difficult Set Sampling Technique (DSSTE) approach initially decreases the noise samples in the majority class before employing Deep Convolutional Generative Adversarial Networks (DCGANs) to increase the minority sample size. The authors 17 suggested an optimised nature-inspired metaheuristic model for the effective identification and classification of multistage threats. Every sub-model uses an improved Harris Hawk optimiser (HHO) alongside an extreme learning machine (ELM) at the base classifier. This hierarchy yields an optimal feature subset for each attack, with enhanced ELM weights that significantly improve recognition rates. AlGhamdi 18 recommended the NIDS through a Lion Optimiser FS alongside a DL (NIDS-LOFSDL) technique. Additionally, the A-BiLSTM network was implemented for ID. To improve the ID efficiency of the ABiLSTM, the GTO is utilised to execute parameter tuning. Ahanger et al. 19 improved IoT security by utilising ML, DL, and Federated Learning (FL) techniques for effective intrusion detection. Nandanwar and Katarya 20 detected and classified botnet attacks in IoT using a hybrid Convolutional Neural Network-Bidirectional Long Short-Term Memory (CNN-BiLSTM) model. Also, the transfer learning (TL) technique is utilised for enhancing feature extraction and classification across diverse IoT device types. Nandanwar and Katarya 21 proposed a model by employing a Genetic Algorithm (GA)-Optimised eXtreme Gradient Boosting (GAO-XGBoost) method for effective FS and an Elliptic Curve Cryptography (ECC)-enabled blockchain for secure, decentralised data storage. Duraibi and Alashjaee 22 introduced a methodology by using a hybrid DL technique. The Improved Mayfly Optimisation Algorithm (IMFO) is employed for FS, while the LSTM-based Deep Stacked Sequence-to-Sequence Autoencoder (LSTM-DSSAE) is utilised for classification. Additionally, the Dipper-Throated Optimisation Algorithm (DTOA) method is employed to improve detection accuracy and robustness. Nandanwar and Katarya 23 developed a secure network by implementing a Hybrid Blockchain-Based Framework with Elliptic Curve Cryptography (ECC), the Digital Signature Algorithm (DSA), SHA-512 hashing, and a Self-Adaptive Differential Evolution (SADE) approach for optimised key generation. The model also employs a GA and an XGBoost-based model. Ullah et al. 24 presented a technique that utilises multimodal significant data representation, TL, and an attention-based Residual Network (ResNet) model to extract and integrate semantic and texture features. Nandanwar and Katarya 25 introduced a robust and interpretable IDS by utilising a DL-based technique integrated with Shapley Additive Explanations (SHAP). Kamal and Mashaly 26 employed a hybrid Transformer-CNN model for contextual feature extraction and classification, integrated with data resampling techniques—Adaptive Synthetic (ADASYN), Synthetic Minority Oversampling Technique (SMOTE), Edited Nearest Neighbours (ENN)—and class weights to handle imbalanced datasets. Hu et al. 27 proposed an Improved Gannet Optimisation Algorithm (IGOA) that integrates an Adaptive Deep Capsule Network (ADCapsNet) for accurate anomaly detection. This integration of IGOA and ADCapsNet ensures improved hyperparameter tuning. Nandanwar and Katarya 28 presented a hybrid blockchain framework incorporating Elliptic Curve Cryptography (ECC), Zero-Knowledge Proofs (ZKP), and Istanbul Byzantine Fault Tolerance (IBFT). They integrated with a CNN-BiLSTM hybrid model under FL. Comparison analysis of existing intrusion detection attacks in IoT networks is presented in Table 1 . Table 1. A comparative study of diverse advanced techniques on intrusion detection attacks in IoT networks. Authors Objectives Methods Datasets Results Grandhi and Singh 11 To improve system security and classify the task of allocating classes to the collection of features. IDBFS-EGTO KDD Cup’99 Dataset Accuracy of 98.4% and 98.6%. Tahir et al. 12 To increase the input data quality by successfully controlling missing values. RMV NSL-KDD and UNSW-NB15 Datasets - Ranpara et al. 13 Tackling the dual significant energy challenges of efficiency and recognition performance in IDS is a key area of investigation. SVM and RF KDD 1999 Dataset Accuracy of 99%. Pillai et al. 14 To enhance the proficiency of NIDS against modifying cyberattacks. SCO, ANN, WT, and LSTM BoT-IoT Dataset Accuracy of 99.6%. Aljehane et al. 15 As the types of threats and the size of the network continue to grow, the need for effective IDS becomes increasingly essential. GJOADL-IDSNS, GJOA-FS, A-BiLSTM CICIDS-2017 Dataset Accuracy of 99.70%. Saikam and Ch 16 To present a NIDS model that integrates hybrid sampling and deep networks. DSSTE, DCGAN BOT-IOT, ToN-IoT, and CICIDS2019 Datasets Accuracy of 99.89%. Alzaqebah et al. 17 To reduce the crossover error rate and increase the IDS’s ability to detect various threats. HHO and ELM UNSWNB-15 Dataset - AlGhamdi 18 To present an innovative model for the recognition of intrusions to achieve network safety. NIDS-LOFSDL, A-BiLSTM, GTO UNSW-NB15 and AWID Datasets Accuracy of 96.88% and 96.92%. Ahanger et al. 19 To improve IoT security using AI-driven IDS. ML, DL, FL IoT Device Logs (2014–2023) Detection Accuracy, Resource Efficiency, Adaptability Nandanwar and Katarya 20 To detect and classify botnet attacks in IoT networks. Hybrid CNN-BiLSTM, TL N_BaIoT (Real-Time IoT Device Packets) Testing Accuracy of 99.52%, Training Accuracy of 99.55%, Loss of 0.015 Nandanwar and Katarya 21 To develop a secure, scalable, and intelligent IDS for IoT networks. GAO-XGBoost, ECC Benchmark IoT Dataset Accuracy of 98%, TPR of 97%, Recall of 97.4% Duraibi and Alashjaee 22 To classify intrusions and enhance cybersecurity in IoT environments. IMFO, LSTM-DSSAE, DTOA BoT-IoT Dataset Accuracy of 98.3%, Precision of 97.9%, Recall of 97.5% Nandanwar and Katarya 23 To develop a secure, efficient, and resilient IDS for IoT networks. ECC, DSA, SHA-512 Hashing, SADE, PBFT, IPFS, GA, XGBoost Heterogeneous IoT Dataset Accuracy of 98.12%, F1 Score of 97.98%, False Positive Rate (FPR) of 2.24%, False Negative Rate (FNR) of 2.19%, Latency of 0.342 s, Throughput of 67 TPS, Network Overhead of 1.69 MB Ullah et al. 24 To enhance IoT security by detecting and classifying flood and DDoS attacks. PCAP Crawling, Spark Optimisation, Word2Vec, Attention-Based ResNet, Multimodal Feature Fusion CIC-IoT 2022, CIC-IoT 2023, Edge-IIoT Accuracy of 98.2% Nandanwar andKatarya 25 To introduce a DL-based IDS for CPS in Industry 5.0 environments. DL, SHAP Edge-IIoT-2022 Accuracy of 97.46%, Precision of 97.7%, Recall of 97.2%, Loss of 0.182 Kamal and Mashaly 26 To improve cloud intrusion detection by precisely detecting known and zero-day attacks. Transformer-CNN, ADASYN, SMOTE, ENN NF-UNSW-NB15-v2, CICIDS2017 Accuracy of 99.71–99.93%, Precision of 99%+, Recall of 99%+, F1-score of 99%+ Hu et al. 27 To detect and prevent network intrusions in IoT systems using optimised DL techniques. IGOA, ADCapsNet Anomaly Detection Dataset FPR, Negative Predictive Value (NPV), F1-Score, Precision, Specificity, Sensitivity, False Discovery Rate (FDR) Nandanwar and Katarya 28 To develop a scalable, secure, and privacy-preserving IDS for IoT networks. ECC, FL, CNN-BiLSTM Hybrid, ZKP, IBFT IoT Network Dataset Encryption/Decryption Faster, Block Generation Quicker, Key Production Efficient, Throughput Higher, Response Time Lower Open in a new tab The limitations include reliance on specific ML/DL models, which may lead to overfitting. The model also exhibits mitigated generalisation in real-world IoT networks. Various techniques rely on centralised training, restricting scalability and adaptability in diverse IoT environments. Also, multiple techniques concentrate on accuracy and classification performance, often overlooking latency, energy efficiency, and resource constraints. Furthermore, several techniques illustrate the difficulty in handling encrypted traffic and zero-day attacks. Most studies use static FS or optimisation methods that may not adapt to evolving attack patterns. The research gap is the lack of a lightweight, adaptive, and scalable IDS framework capable of real-time detection across heterogeneous IoT systems. Model design and techniques In this manuscript, a new OFSMDR-RIDS methodology is introduced for IoT networks. The OFSMDR-RIDS paper aims to progress an effective intelligent IDS that enhances cybersecurity by accurately detecting and mitigating malicious activities in digital environments. To perform that, the OFSMDR-RIDS approach has a data normalisation method, a redundancy-minimised feature ranking approach, and a hybrid learning-based threat detection. Figure 2 represents the overall block diagram of the OFSMDR-RIDS approach. Fig. 2. Open in a new tab Block diagram of OFSMDR-RIDS approach. Data normalisation using quantile technique Initially, the data pre-processing employs quantile normalisation to convert the input data into a more useful pattern. The collected data are pre-processed employing quantile normalisation 29 . This normalisation is chosen for its efficiency in ensuring uniform dispersion across all samples, thereby mitigating bias and variability caused by outliers or different scales. It also preserves the relative ranking of values while making patterns more comparable across datasets, compared to min-max or z-score normalisation. This also improves the performance of downstream FS and DL techniques by providing a consistent and stable input representation. It is used to ensure that the data is comparable and reliable. Normalising the data eliminates discrepancies caused by environmental reasons and guarantees data uniformity. The new data are ranked utilising the following Eq. ( 1 ): 1 The ranked data are sorted in increasing sequence utilising the succeeding Eq. ( 2 ): 2 Whereas the superscript number specifies the ranking order, the first position before the ranking is presented by the subscript number. Then, apply a sorted reference vector instead of this sorted vector provided in the succeeding Eq. ( 3 ): 3 Moreover, it is in ascending order. For example, replaces . This successively reversed the order and mapped to revert to position . The input vector’s full distribution is mapped to the reference vector’s distribution via quantile normalisation. The training data reference vector was pre-calculated by averaging every sorted recording. It ensures that these different datasets are equivalent by mapping them to a standard reference distribution and reducing batch effects, thereby improving the model’s performance. mRMR-Based dimensionality reduction Next, the mRMR technique is employed in the FS process to extract the most informative features 30 . This technique demonstrates excellence in selecting features highly relevant to the target variable while mitigating redundancy, resulting in a compact yet informative feature set. This method preserves interpretability and focuses on features that contribute most to classification accuracy, unlike procedures such as principal component analysis (PCA) or simple correlation-based selection. This also enhances efficiency and performance while mitigating overfitting in DL-based intrusion detection. Because datasets contain enormous amounts of data, there may be several redundant and lower-level features. These features can improve computational efficiency but further reduce classification efficacy. In predictive modelling, higher-dimensional features can exacerbate overfitting and lead to poor generalisation at test time, even if the method performs well in training. Therefore, the MRMR model is presented to improve the efficacy of the presented method through FS. The MRMR technique is applied to maximise the correlation among characteristics and variables. Simultaneously, it aims to reduce feature correlation, thereby selecting a subset of the complete set of features that differentiate related data and remove unrelated or redundant ones. The MRMR model uses mutual information (MI) (characterised by ) to determine the comparison among variables. Assume are variables; is applied to calculate MI based on Eq. ( 4 ). 4 Now, and denote feature vectors, and p denotes probability. Assume the sub-set of the complete features (epitomised by the features ). The MI between features is given by , and the MI among the targeted classes allows identifying the maximal relevance by understanding the recognition ability of the classes. Meanwhile, the maximal dependable criteria are used in higher-dimensional areas and are problematic to execute. Utilising maximal relevance is the appropriate choice, as it seeks features that satisfy Eq. ( 5 ) by estimating maximal dependency. 5 Whereas denotes feature counts of the set . The outcome of maximal relevance is feature redundancy, which leads to feature dependence; removing these features does not affect the approximation’s precision. To eliminate redundant features, the minimal redundancy is gained over Eq. ( 6 ). 6 The MRMR concurrently incorporates the two principles of max-relevance and min‐redundancy, and the simpler description of their incorporation is given by the Φ function in Eq. ( 7 ). 7 The stated number of features is achieved by repeating this stage, which is organised by significance. In such a case, it aims to maximise the correlation among variables and minimise the correlation among all features. This work utilises the MRMR FS model to select between the spatial and temporal features. The MRMR using the FS model can reduce feature dimensionality while increasing the training speed of the learning model. Intrusion detection using hybrid deep models Finally, a hybrid system combining the BiL-AE model to classify and detect cybersecurity threats effectively. The following design, comprised of a decoder and an encoder, both consist of Bi-LSTM layers 31 . This model effectively learns compressed representations of input data, while the Bi-LSTM layers capture both past and future dependencies in sequential IoT data. This hybrid approach enhances anomaly detection accuracy while also efficiently handling temporal correlations and mitigating false positives, compared to a standalone LSTM. It is particularly effective for intrinsic, high-dimensional IoT traffic patterns, making it appropriate for robust intrusion detection. Figure 3 depicts the structure of BiL-AE. Fig. 3. Open in a new tab Architecture of BiL-AE. LSTMs are a form of Recurrent Neural Network (RNN) that can capture both short- and long-term dependencies. It includes a memory cell and three linear gates: a forget , an input , and an output gate. The forward computation procedure of the LSTM model at time is described as shown below: 8 9 10 11 12 13 14 Whereas, , and represent the network’s weights; , and specify the state of the cell, input, LSTM output vector, and hidden state, respectively. and epitomise the activation functions of the hyperbolic tangent and the sigmoid. By incorporating data from upcoming time steps, the RNN’s input can significantly improve the method’s performance. One potential model involves delaying the output using a specific time-frame calculation. On the one hand, intensifying these delays allows the technique to collect additional data; by contrast, it increases the method’s efficiency in recalling the input data. Then, selecting the suitable delay that maximises the method’s performance is essential and necessarily requires a “trial and error” approach, which restricts this model. A dissimilar approach that uses Bidirectional RNNs (Bi-RNNs). Here, the RNN’s neurons are divided into two portions: one processes data in the forward direction, whereas the other processes it in the reverse direction. This allows the method to be trained using input data from either previous or upcoming time steps relative to the present one. The bidirectional LSTM layers is used within the AE. Relying on the consideration of general bi-directional LSTMs and networks, it is promising to lengthen the expression epitomised in Eqs. ( 8 )-( 14 ) regarding a backward and a forward network. The AE is a type of NN that learns to convert input data into a latent representation. The AE structure comprises two major components: the decoder and the encoder. The role of the encoder is to learn a dissimilar-dimensional representation of the input data by capturing temporal dependencies and key attributes. When the encoder converts the data, the decoder tries to reconstruct the new input. It begins by reiterating the encoding sequence, utilising a repeated vector layer to match the original sequence length. Next, the Bi-LSTM layers are applied to mirror the encoding architecture. At last, the output is passed through a time-distributed dense layer with the ReLU activation function, which proces 15 ses each time step separately to produce the reconstructed input. The loss is described as the Mean Absolute Error (MAE) between the reconstructed and the new input sequences, measured as shown: Whereas embodies the new input, and means rebuilt sequences. Algorithm 1 illustrates the BiL-AE technique. Algorithm 1. Open in a new tab BiL-AE model. Model assessment and results The simulation validation of the OFSMDR-RIDS technique is examined under ToN-IoT 32 and BoT-IoT 33 datasets. The method is simulated using Python 3.6.5 on a PC with an i5-8600k, 250GB SSD, GeForce 1050Ti 4GB, 16GB RAM, and 1 TB HDD. Parameters include a learning rate of 0.01, ReLU activation, 50 epochs, 0.5 dropout, and a batch size of 5. The ToN-IoT contains 119,957 cardinalities with nine attack types. It holds 63, but only 25 features are selected. At the same time, the BoT-IoT dataset covers 2056 counts under five classes. This dataset has 34 features in total, but only 22 are chosen. The complete details of these datasets are shown in Table 2 below. Table 2. Details of ToN-IoT and BoT-IoT datasets. Datasets Attack Type Cardinality ToN-IoT Dataset 32 Normal 78,369 MiTM 336 DoS 5440 DDoS 5987 Password 6016 Injection 5867 XSS 5951 Ransomware 5976 Backdoor 6015 Total Count 119,957 BoT-IoT Dataset 33 DDoS 500 DoS 500 Recon 500 Theft 79 Normal 477 Total Count 2056 Open in a new tab Table 3 ; Fig. 4 depict the attack detection of the OFSMDR-RIDS technique on the ToN-IoT dataset. On 70% TRPHE, the OFSMDR-RIDS technique attains an average of 99.46%, of 93.06%, of 87.27%, of 88.52%, and of 88.83%. Moreover, on 30% TSPHE, the OFSMDR-RIDS methodology reaches an average of 99.43%, of 92.73%, of 87.04%, of 88.31%, and of 88.58%. Table 3. Attack detection of OFSMDR-RIDS model on ToN-IoT dataset. Class Labels TRPHE (70%) Normal 98.56 98.74 99.07 98.90 96.82 MiTM 99.76 71.43 19.65 30.82 37.39 DoS 99.51 95.61 93.47 94.52 94.27 DDoS 99.52 95.31 95.08 95.19 94.94 Password 99.60 95.69 96.32 96.00 95.79 Injection 99.64 95.65 96.95 96.29 96.11 XSS 99.56 95.77 95.35 95.56 95.33 Ransomware 99.46 93.61 95.61 94.60 94.32 Backdoor 99.48 95.72 93.88 94.79 94.53 Average 99.46 93.06 87.27 88.52 88.83 TSPHE (30%) Normal 98.56 98.68 99.10 98.89 96.83 MiTM 99.74 70.00 19.63 30.66 36.98 DoS 99.48 95.17 93.43 94.29 94.03 DDoS 99.57 95.21 96.08 95.64 95.42 Password 99.55 94.82 96.33 95.57 95.34 Injection 99.59 95.62 96.35 95.98 95.76 XSS 99.52 95.67 94.71 95.19 94.94 Ransomware 99.39 93.82 94.02 93.92 93.60 Backdoor 99.46 95.62 93.67 94.64 94.36 Average 99.43 92.73 87.04 88.31 88.58 Open in a new tab Fig. 4. Open in a new tab Average values of OFSMDR-RIDS model on ToN-IoT dataset. Figure 5 exemplifies the training (TRAIN) and validation (VALID) of an OFSMDR-RIDS approach on the ToN-IoT dataset over 25 epochs. At the primary stage, either TRAIN or VALID rises quickly, indicating the effective learning of designs from the data. Around the epoch, the VALID somewhat exceeds the training , proposing improved generality without overfitting. As training progresses, imitating the larger and smaller performance gaps between TRAIN and VALID. The neighbouring alignment of both curves in training suggests that the method is generalised and well-regularised. This establishes the model’s stronger capability to learn and retain valuable features from both unnoticed and noticed data. Fig. 5. Open in a new tab curve of OFSMDR-RIDS technique on ToN-IoT dataset. Figure 6 shows the TRAIN and VALID losses of the OFSMDR-RIDS methodology on the ToN-IoT dataset over 25 epochs. Initially, either TRAIN or VALID losses are at their maximum, indicating that the method begins with a partial understanding of the data. As training progresses, both losses steadily decrease, indicating that the technique is effectively learning and improving its parameters. The alignment between the TRAIN and VALID loss curves during training suggests that the method has not overfitted and maintains improved generalisation to unseen data. Fig. 6. Open in a new tab Loss curve of OFSMDR-RIDS technique on ToN-IoT dataset. Table 4 ; Fig. 7 determined the attack detection of the OFSMDR-RIDS technique on the BoT-IoT dataset. On 70% TRPHE, the OFSMDR-RIDS technique achieves average , , , , and of 99.19%, 98.00%, 97.17%, 97.57%, and 97.06%, respectively. Additionally, on 30% TSPHE, the OFSMDR-RIDS approach achieves average , , , , and of 99.42%, 97.14%, 97.15%, 97.14%, and 96.78%, respectively. Table 4. Attack detection of the OFSMDR-RIDS technique on the BoT-IoT dataset. Class Labels TRPHE (70%) DDoS 98.96 98.48 97.01 97.74 97.07 DoS 99.44 99.17 98.62 98.90 98.52 Recon 98.96 97.78 98.06 97.92 97.22 Theft 99.65 98.18 93.10 95.58 95.43 Normal 98.96 96.40 99.07 97.72 97.06 Average 99.19 98.00 97.17 97.57 97.06 TSPHE (30%) DDoS 99.51 99.39 98.80 99.09 98.76 DoS 99.51 97.86 100.00 98.92 98.61 Recon 99.19 99.27 97.14 98.19 97.68 Theft 99.35 90.48 90.48 90.48 90.14 Normal 99.51 98.70 99.35 99.02 98.70 Average 99.42 97.14 97.15 97.14 96.78 Open in a new tab Fig. 7. Open in a new tab Average values of the OFSMDR-RIDS technique on the BoT-IoT dataset. Figure 8 portrays the TRAIN and VALID of an OFSMDR-RIDS technique on the BoT-IoT dataset over 25 epochs. At first, either TRAIN or VALID upsurge quickly, illustrating the effective learning of forms from the data. Around the epoch, the VALID marginally outperforms the training , suggesting excellent generalisation without overfitting. As training progresses, replicate the maximum and minimum performance gaps between TRAIN and VALID. The adjacent alignment of both curves in training implies that the method is generalised and well-regularised. This establishes the model’s robust capability to learn and retain valuable features from both unseen and seen data. Fig. 8. Open in a new tab curve of OFSMDR-RIDS model on BoT-IoT dataset. Figure 9 exhibits the TRAIN and VALID losses of the OFSMDR-RIDS approach on the BoT-IoT dataset over 25 epochs. Initially, either TRAIN or VALID losses are superior, since the method starts with a limited understanding of the data. As training progresses, both losses steadily decline, indicating that the approach is successfully learning and enhancing its parameters. The nearby alignment between the TRAIN and VALID loss curves during training suggests that the approach has not overfitted and preserves improved generalisation to unseen data. Fig. 9. Open in a new tab Loss curve of OFSMDR-RIDS model on BoT-IoT dataset. Table 5 presents a comparison and computational time (CT) analysis of the OFSMDR-RIDS method with recent techniques on ToN-IoT and BoT-IoT datasets across various metrics 20 , 21 , 25 , 26 , 34 – 37 . Table 5. Comparative study of OFSMDR-RIDS method on ToN-IoT and BoT-IoT datasets. Approaches CT ToN-IoT Dataset CNN-BiLSTM 92.29 90.60 82.91 82.85 7.31 GAO-XGBoost 98.98 90.03 86.02 84.02 6.57 RNN + Attention 99.19 85.32 79.39 86.83 11.59 BiGRU 91.63 89.86 82.24 82.22 7.24 CatBoost 98.35 89.29 85.43 83.33 4.48 Extra Trees 93.61 89.57 83.67 82.09 11.14 CNN-GRU 96.95 91.56 85.68 79.42 7.45 Xception 97.87 91.91 80.17 84.81 10.63 MobileNetV2 95.02 90.83 86.93 84.86 11.78 OFSMDR-RIDS 99.46 93.06 87.27 88.52 4.00 BoT-IoT Dataset SHAP 97.92 93.52 87.61 89.16 6.05 Hybrid Transformer-CNN 93.97 97.65 92.73 87.41 5.71 LSTM + DNN 96.84 92.72 89.44 91.40 10.98 XGBoost 97.16 92.87 87.09 88.58 7.17 LightGBM 93.38 96.93 92.10 86.86 6.07 RNN-LSTM 97.23 94.08 88.18 89.97 4.55 XGBoost + AFSO 93.28 91.62 94.86 95.56 11.09 InceptionV3 93.82 91.62 91.53 87.30 10.70 EfficientNetB0 96.16 85.69 92.07 88.70 8.23 OFSMDR-RIDS 99.42 97.14 97.15 97.14 3.98 Open in a new tab Figures 10 and 11 illustrates the comparison and CT outcomes of the OFSMDR-RIDS methodology on the ToN-IoT dataset with recent methods. The findings underscored that the OFSMDR-RIDS methodology has gained maximum performance. The CNN-BiLSTM, GAO-XGBoost, RNN + Attention, BiGRU, CatBoost, Extra Trees, CNN-GRU, Xception, and MobileNetV2 models have performed poorly. However, the OFSMDR-RIDS technique has achieved superior , , , and CT of 99.46%, 93.06%, 87.27%, 88.52%, and 4.00 s, respectively. Fig. 10. Open in a new tab Comparative analysis of OFSMDR-RIDS method on ToN-IoT dataset. Fig. 11. Open in a new tab CT assessment of OFSMDR-RIDS method on ToN-IoT dataset. The BoT-IoT dataset comparison and CT study of the OFSMDR-RIDS approach with recent models, as presented in Figs. 12 and 13 . The SHAP, Hybrid Transformer-CNN, LightGBM, XGBoost + AFSO, and InceptionV3 approaches have performed poorly. Meanwhile, the recent techniques, LSTM + DNN and EfficientNetB0, have acquired somewhat closer performance. Next, the XGBoost and RNN-LSTM methods have slightly better performance. At the same time, the OFSMDR-RIDS method has achieved of of 99.42%, of 97.14%, of 97.15%, of 97.14%, and CT of 3.98 s, correspondingly. Therefore, the OFSMDR-RIDS model is applied for enhanced cybersecurity in the IoT environment. Fig. 12. Open in a new tab Comparative study of OFSMDR-RIDS approach on BoT-IoT dataset. Fig. 13. Open in a new tab CT evaluation of OFSMDR-RIDS approach on BoT-IoT dataset. Table 6 presents the ablation study analysis of the OFSMDR-RIDS methodology. The BiLSTM without AE and FS attains an of 97.43%, of 91.29%, of 85.33%, and of 86.59%. Furthermore, by using only the AE without BiLSTM and FS improved the metrics to an of 98.12%, of 91.85%, of 85.96%, and of 87.11%. The combined BiLSTM and AE without FS achieved an of 98.69%, of 92.48%, of 86.48%, and of 87.78%. Finally, the OFSMDR-RIDS model incorporating BiLSTM with FS reached the highest performance with an of 99.46%, of 93.06%, of 87.27%, and of 88.52%. Likewise, on the BoT-IoT dataset, BiLSTM without AE and FS reached an of 97.70%, of 95.37%, of 95.14%, and of 95.33%, while the AE alone attained an of 98.21%, of 96.00%, of 95.76%, and of 95.93%. The combination of BiLSTM and AE without FS illustrated an of 98.71%, of 96.64%, of 96.36%, and of 96.45%. The OFSMDR-RIDS model with BiLSTM and FS outperformed all other methods with an of 99.42%, of 97.14%, of 97.15%, and of 97.14%. Thus, the outcomes emphasize the consistent improvement of the OFSMDR-RIDS model across both datasets, highlighting its efficiency in capturing relevant patterns and improving predictive accuracy. Table 6. Ablation study analysis of the OFSMDR-RIDS methodology. Methodology ToN-IoT Dataset BiLSTM (Without AE and FS) 97.43 91.29 85.33 86.59 AE (Without BiLSTM and FS) 98.12 91.85 85.96 87.11 BiLSTM-AE (Without FS) 98.69 92.48 86.48 87.78 OFSMDR-RIDS (BiLSTM with FS) 99.46 93.06 87.27 88.52 BoT-IoT Dataset BiLSTM (Without AE and FS) 97.70 95.37 95.14 95.33 AE (Without BiLSTM and FS) 98.21 96.00 95.76 95.93 BiLSTM-AE (Without FS) 98.71 96.64 96.36 96.45 OFSMDR-RIDS (BiLSTM with FS) 99.42 97.14 97.15 97.14 Open in a new tab Table 7 indicates the computational efficiency of the OFSMDR-RIDS technique in terms of Floating Point Operations (FLOPs), Graphics Processing Unit (GPU) memory usage, and inference time 38 . Faster R-CNN needed the highest computational resources with 149,200 million FLOPs, 3,875 MB GPU memory, and an inference time of 114.40 s. Additionally, YOLOv2 significantly mitigated computational cost with 10,551 million FLOPs, 3,065 MB GPU memory, and 15.20 s inference time, while SSD300 required 31,339 million FLOPs, 3,249 MB GPU memory, and 21.00 s for inference. The FIDHRC-LEGPUs method further optimized GPU utilization with 11,850 million FLOPs, 4,996 MB GPU memory, and an inference time of 14.50 s. The OFSMDR-RIDS methodology illustrated superior efficiency with only 784 million FLOPs, 932 MB GPU memory usage, and an inference time of 10.98 s, emphasizing its ability for faster and more resource-efficient processing without compromising performance. Table 7. Ablation study analysis of the OFSMDR-RIDS methodology. Approach FLOPs (M) GPU (M) Inference Time (sec) Faster R-CNN 149,200 3875 114.40 YOLOv2 10,551 3065 15.20 SSD300 31,339 3249 21.00 FIDHRC-LEGPUs 11,850 4996 14.50 OFSMDR-RIDS 784 932 10.98 Open in a new tab Conclusion In this study, a novel OFSMDR-RIDS technique is developed. The OFSMDR-RIDS technique aims to propose an effective intelligent IDS that enhances cybersecurity by accurately detecting and mitigating malicious activities in digital environments. To perform this, the OFSMDR-RIDS model includes a data normalisation method, a redundancy-minimised feature ranking approach, and a hybrid learning-based threat detection approach. Initially, the data pre-processing employs the quantile normalisation method to convert the input data. Next, the mRMR technique is applied to the FS process to extract the most informative features. Finally, the OFSMDR-RIDS approach applies a hybrid system that combines the BiL-AE model to classify and detect cybersecurity threats effectively. The comparison analysis of the OFSMDR-RIDS technique demonstrated superior accuracy of 99.46% and 99.42% on the ToN-IoT and BoT-IoT datasets, respectively. The limitations include reliance on pre-collected datasets that may not fully capture the diversity and unpredictability of real-world network traffic. Also, performance assessment under dynamic conditions is restricted by controlled evaluation, and the model primarily focuses on detection accuracy, with less emphasis on resource utilisation, energy efficiency, or deployment constraints in heterogeneous IoT devices. The technique may also face challenges in handling encrypted traffic and in defending against zero-day attacks, and the interpretability of the detection results remains limited. Future work may include a section on how the technique could be deployed in real IoT environments, addressing latency, scalability, and adaptability to evolving attack types. The examination of lightweight implementations suitable for resource-constrained devices and the exploration of hybrid approaches integrating anomaly detection with threat intelligence could further improve practical applicability. Moreover, longitudinal studies involving live IoT networks would help validate robustness and reliability over time. Author contributions K.Priyadharshini: Conceptualization, methodology development, experiment, formal analysis, investigation, writing. M.Arulprakash: Formal analysis, investigation, validation, visualization, writing. R. Jeya: Formal analysis, review and editing. Anil Kumar Muthevi: Methodology, investigation. Sribidhya Mohanty: Review and editing.Ravendra Singh: Discussion, review and editing. Monalisa Sahu: Conceptualization, methodology development, investigation, supervision, review and editing.All authors have read and agreed to the published version of the manuscript. Funding Open access funding provided by Vellore Institute of Technology- AP University. Data availability The data that support the findings of this study are openly available in Kaggle repository at [https://www.kaggle.com/datasets/mohamedamineferrag/edgeiiotset-cyber-security-dataset-of-iot-iiot](https:/www.kaggle.com/datasets/mohamedamineferrag/edgeiiotset-cyber-security-dataset-of-iot-iiot) and [https://www.kaggle.com/datasets/vigneshvenkateswaran/bot-iot](https:/www.kaggle.com/datasets/vigneshvenkateswaran/bot-iot) , reference number 22 , 23 . Declarations Competing interests The authors declare no competing interests. Footnotes Publisher’s note Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations. References 1. Dini, P. et al. Overview on intrusion detection systems design exploiting machine learning for networking cybersecurity. Appl. Sci. , 13 (13), .7507. (2023). 2. Gümüşbaş, D., Yıldırım, T., Genovese, A. & Scotti, F. A comprehensive survey of datasets and deep learning methods for cybersecurity and intrusion detection systems. IEEE Syst. J. 15 (2), 1717–1731 (2020). [ Google Scholar ] 3. Markevych, M. & Dawson, M. June. A review of enhancing intrusion detection systems for cybersecurity using artificial intelligence (ai). In: International conference knowledge-based organisation 29 , 3, 30–37. (2023). 4. Abushark, Y. B. et al. Cyber security analysis and evaluation for intrusion detection systems. Comput. Mater. Contin . 72 (1), 1765–1783 (2022). [ Google Scholar ] 5. Sarker, I. H., Abushark, Y. B., Alsolami, F. & Khan, A. I. Intrudtree: a machine learning based cyber security intrusion detection model. Symmetry , 12 (5), 754. (2020). 6. Alharbi, A. et al. Analysing the impact of cyber security related attributes for intrusion detection systems. Sustainability , 13 (22), 12337. (2021). 7. Pascale, F., Adinolfi, E. A., Coppola, S. & Santonicola, E. Cybersecurity in automotive: An intrusion detection system in connected vehicles. Electronics , 10 (15), 1765. (2021). 8. Sadaram, G. et al. Internet of things (IoT) cybersecurity enhancement through artificial intelligence: A study on intrusion detection systems. Universal Libr. Eng. Technology , (2022). (Issue). 9. Sun, C. C., Cardenas, D. J. S., Hahn, A. & Liu, C. C. Intrusion detection for cybersecurity of smart meters. IEEE Trans. Smart Grid . 12 (1), 612–622 (2020). [ Google Scholar ] 10. Hijazi, A., Alhafez, N. & Al-khayat, I. An adaptive distributed intrusion detection system in local network: hybrid classification methods. J. Intell. Syst. & Internet Things , 12 (1). (2024). 11. Grandhi, A. & Singh, S. K. Interrelated dynamic biased feature selection and classification model using enhanced Gorilla troops optimiser for intrusion detection. Alexandria Eng. J. 114 , 312–330 (2025). [ Google Scholar ] 12. Tahir, M., Abdullah, A., Udzir, N. I. & Kasmiran, K. A. A novel approach for handling missing data to enhance network intrusion detection system. Cyber Security and Applications , 3 , 100063. (2025). 13. Ranpara, R., Alsalman, O., Kumar, O. P. & Patel, S. K. A simulation-driven computational framework for adaptive energy-efficient optimisation in machine learning-based intrusion detection systems. Sci. Rep. , 15 (1), 13376. (2025). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 14. Pillai, S. E. V. S., Vallabhaneni, R., Pareek, P. K. & Dontu, S. March. Strengthening Cybersecurity using a Hybrid Classification Model with SCO Optimization for Enhanced Network Intrusion Detection System. In 2024 International Conference on Distributed Computing and Optimisation Techniques (ICDCOT) (1–9). (IEEE, 2024). 15. Aljehane, N. O. et al. Golden Jackal optimisation algorithm with deep learning assisted intrusion detection system for network security. Alexandria Eng. J. 86 , 415–424 (2024). [ Google Scholar ] 16. Saikam, J. & Ch, K. EESNN: hybrid deep learning empowered Spatial–Temporal features for network intrusion detection system. IEEE Access. 12 , 15930–15945 (2024). [ Google Scholar ] 17. Alzaqebah, A., Aljarah, I. & Al-Kadi, O. A hierarchical intrusion detection system based on extreme learning machine and nature-inspired optimisation. Comput. Security , 124 , 102957. (2023). 18. AlGhamdi, R. Design of network intrusion detection system using lion optimisation-based feature selection with deep learning model. Mathematics , 11 (22), 4607. (2023). 19. Ahanger, T. A., Ullah, I., Algamdi, S. A. & Tariq, U. Machine learning-inspired intrusion detection system for IoT: Security issues and future challenges. Comput. Electrical Eng. , 123 , 110265. (2025). 20. Nandanwar, H. & Katarya, R. TL-BILSTM iot: transfer learning model for prediction of intrusion detection system in IoT environment. Int. J. Inf. Secur. 23 (2), 1251–1277 (2024). [ Google Scholar ] 21. Nandanwar, H. & Katarya, R. Optimised intrusion detection and secure data management in IoT networks using GAO-Xgboost and ECC-integrated blockchain framework. Knowledge Inform. Syst. ,1–56. (2025). 22. Duraibi, S. & Alashjaee, A. M. Enhancing cyberattack detection using dimensionality reduction with hybrid deep learning on internet of things environment. IEEE Access. 12 , 84752–84762 (2024). [ Google Scholar ] 23. Nandanwar, H. & Katarya, R. A hybrid Blockchain-Based framework for securing intrusion detection systems in internet of things. Cluster Comput. , 28 (7), 471. (2025). [ Google Scholar ] 24. Ullah, F., Turab, A., Ullah, S., Cacciagrano, D. & Zhao, Y. Enhanced network intrusion detection system for internet of things security using multimodal big data representation with transfer learning and game theory. Sensors , 24 (13), 4152. (2024). [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 25. Nandanwar, H. & Katarya, R. Securing Industry 5.0: An explainable deep learning model for intrusion detection in cyber-physical systems. Comput. Electrical Eng. , 123 , 110161. (2025). 26. Kamal, H. & Mashaly, M. Advanced hybrid transformer-CNN deep learning model for effective intrusion detection systems with class imbalance mitigation using resampling techniques. Fut. Internet , 16 (12), 481. (2024). 27. Hu, W. et al. Enhancing IoT Network Security by Anomaly Detection and Intrusion Prevention Using Gannet Optimization-Based Adaptive Deep Capsule Network. Int. J. Comput. Intell. Syst , 18 (1), 237. (2025). 28. Nandanwar, H. & Katarya, R. December. A secure and privacy-preserving ids for iot networks using hybrid blockchain and federated learning. In International Conference on Next-Generation Communication and Computing (207–219). Singapore: Springer Nature Singapore. (2024). 29. Wu, B. Research on the strategy of promoting rural tourism development through IoT technology in rural revitalization. Int. J. High. Speed Electron. Syst. , p.2540592. (2025). 30. Hassan, A. N., Feghhi, M. M. & Tazehkand, B. M. DOA Estimation by Feature Extraction Based on Parallel Deep Neural Networks and MRMR Feature Selection Algorithm. IEEE Access . (2025). 31. Barnabei, V. F., Ancora, T. C., Delibra, G., Corsini, A. & Rispoli, F. Semi-Supervised Deep Learning Framework for Predictive Maintenance in Offshore Wind Turbines. International Journal of Turbomachinery, Propulsion and Power , 10 (3), 14. (2025). 32. https:// www.kaggle.com/datasets/mohamedamineferrag/edgeiiotset-cyber-security-dataset-of-iot-iiot 33. https://www.kaggle.com/datasets/vigneshvenkateswaran/bot-iot 34. Tayebi, M. & Kafhali, S. E. ‘Performance analysis of recurrent neural networks for intrusion detection systems in Industrial-Internet of Things,’ Franklin Open , 100310. (2025). 10.1016/j.fraope.2025.100310 35. Ahmed, M. A. O., AbdelSatar, Y., Alotaibi, R. & Reyad, O. Enhancing internet of things security using performance gradient boosting for network intrusion detection systems. Alexandria Eng. J. 116 , 472–482 (2025). [ Google Scholar ] 36. Song, W., Zhu, X., Ren, S., Tan, W. & Peng, Y. A hybrid blockchain and machine learning approach for intrusion detection system in industrial internet of things. Alexandria Eng. J. 127 , 619–627 (2025). [ Google Scholar ] 37. Li, J. et al. NFIoT-GATE-DTL IDS: Genetic algorithm-tuned ensemble of deep transfer learning for NetFlow-based intrusion detection system for internet of things. Engineering Applications of Artificial Intelligence , 143 , 110046. (2025). 38. Wang, Y. & Yu, P. A fast intrusion detection method for high-speed railway clearance based on low-cost embedded GPUs. Sensors , 21 (21), p.7279. (2021). [ DOI ] [ PMC free article ] [ PubMed ] Associated Data This section collects any data citations, data availability statements, or supplementary materials included in this article. Data Availability Statement The data that support the findings of this study are openly available in Kaggle repository at [https://www.kaggle.com/datasets/mohamedamineferrag/edgeiiotset-cyber-security-dataset-of-iot-iiot](https:/www.kaggle.com/datasets/mohamedamineferrag/edgeiiotset-cyber-security-dataset-of-iot-iiot) and [https://www.kaggle.com/datasets/vigneshvenkateswaran/bot-iot](https:/www.kaggle.com/datasets/vigneshvenkateswaran/bot-iot) , reference number 22 , 23 . Articles from Scientific Reports are provided here courtesy of Nature Publishing Group ACTIONS View on publisher site PDF (4.3 MB) Cite Collections Permalink PERMALINK Copy RESOURCES Similar articles Cited by other articles Links to NCBI Databases Cite Copy Download .nbib .nbib Format: AMA APA MLA NLM Add to Collections Create a new collection Add to an existing collection Name your collection * Choose a collection Unable to load your collection due to an error Please try again Add Cancel Follow NCBI NCBI on X (formerly known as Twitter) NCBI on Facebook NCBI on LinkedIn NCBI on GitHub NCBI RSS feed Connect with NLM NLM on X (formerly known as Twitter) NLM on Facebook NLM on YouTube National Library of Medicine 8600 Rockville Pike Bethesda, MD 20894 Web Policies FOIA HHS Vulnerability Disclosure Help Accessibility Careers NLM NIH HHS USA.gov Back to Top

Record · ID 1144 · SHA-256 898e4c662f319699
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.