arXiv:2605.02987v1 [cs.CR] 4 May 2026
LiteShield: Hybrid Feature Selection-Driven Lightweight Intrusion Detection for Resource-Constrained IoT Networks 1st Dileepa Mabulage
2nd Banuka Athuraliya
Department of Computing Informatics Institute of Technology Colombo, Sri Lanka [email protected]
Department of Computing Informatics Institute of Technology Colombo, Sri Lanka [email protected]
Abstract—The rapid expansion of Internet of Things (IoT) deployments has enlarged the attack surface of modern digital infrastructure while exposing a key security mismatch: many intrusion detection systems (IDSs) remain too computationally expensive for constrained IoT environments. This paper presents LiteShield, a lightweight machine learning-based IDS that combines hybrid feature selection with efficient classifiers to support accurate attack detection under limited computational budgets. The proposed framework uses the UNSW-NB15 dataset, applies data preprocessing and imbalance-aware preparation, and employs a two-stage feature selection pipeline based on Mutual Information (MI) and Recursive Feature Elimination with Cross-Validation (RFECV). Six lightweight classifiers are evaluated for both binary and multiclass intrusion detection: Decision Tree, Random Forest, K-Nearest Neighbors (KNN), Logistic Regression, Naı̈ve Bayes, and Support Vector Machine. Experimental results show that KNN achieved the highest raw predictive performance, reaching 98.26% accuracy for binary classification and 85.22% accuracy for multiclass classification. However, Random Forest delivered the most practical trade-off between detection quality and deployment efficiency, obtaining 98.01% binary accuracy and 80.39% multiclass accuracy with substantially lower model size and inference cost than KNN. Additional ablation analysis on minority attack classes indicates that class imbalance materially affects multiclass performance. Overall, LiteShield demonstrates that hybrid feature selection and lightweight machine learning can provide a viable path toward accurate and computationally feasible intrusion detection for IoT-focused environments. Index Terms—Internet of Things, intrusion detection system, lightweight machine learning, feature selection
I. I NTRODUCTION The Internet of Things has transformed domains such as healthcare, smart cities, transportation, and industrial automation, but the resulting ecosystems have also become highly exposed to cyberattacks [1], [2]. IoT devices are typically constrained by limited memory, compute, bandwidth, and power, which makes deployment of conventional security controls difficult [1], [3]. At the same time, modern intrusion detection increasingly relies on machine learning (ML) and deep learning (DL), yet many high-performing models remain too computationally intensive for realistic edge deployment [4], [5].
This creates a design tension: an IoT IDS must preserve detection quality while remaining lightweight enough for constrained devices. Existing lightweight IDS studies report encouraging results, but several gaps remain. First, many approaches rely on single-stage filter methods or standard dimensionality reduction rather than hybrid feature selection [3], [4]. Second, several systems emphasize binary classification or a narrow subset of attack types, limiting practical utility in multiclass scenarios [5], [8]. Third, dataset imbalance continues to impair minority-class detection [9], [10]. To address these issues, this paper proposes LiteShield, a lightweight IDS built around three ideas: (i) a hybrid MI+RFECV feature selection pipeline, (ii) comparative evaluation of six lightweight ML classifiers, and (iii) explicit analysis of the trade-off between predictive performance and resource efficiency. The main contributions are as follows: 1) A hybrid feature selection pipeline for reducing highdimensional network traffic data while preserving discriminative information. 2) A comparative binary and multiclass evaluation of lightweight ML models for IoT intrusion detection. 3) A practical analysis showing that the best raw classifier is not always the best deployment candidate under resource constraints. II. R ELATED W ORK AND R ESEARCH G AP Recent studies show growing interest in designing intrusion detection systems that are both accurate and lightweight enough for IoT environments. A major direction in the literature is the use of classical machine learning models with dimensionality reduction or feature selection to reduce computational cost. For example, [1] proposed an IDS that combines Incremental Principal Component Analysis (IPCA) with SAM-KNN, showing that careful reduction of the feature space can support deployment on constrained platforms while preserving strong detection capability. Similarly, [3] introduced a lightweight supervised IDS that integrates PCA, multicollinearity removal, and data sampling to improve efficiency and reduce false alarms. These studies demonstrate
that feature reduction is central to lightweight IDS design, particularly when memory footprint and inference latency are critical. Another prominent direction is the use of optimized ensemble or hybrid learning pipelines. In this area, [17] developed a two-stage feature selection framework that combines Spearman Correlation Coefficient with Salp Swarm Optimization and then applies LightGBM for classification. This work highlights the benefit of combining a fast filter stage with a more selective optimization stage to improve predictive performance. Likewise, [6] showed that combining multiple feature ranking strategies can improve the quality of selected features compared to relying on a single statistical criterion. These studies suggest that hybrid feature selection is promising because it can better balance computational efficiency and predictive power than purely filter-based methods. Deep learning has also been explored for IoT intrusion detection, especially to improve representation learning for complex traffic patterns. For instance, [4] presented a lightweight CNN-BiLSTM framework with Chi-Square-based feature selection on the UNSW-NB15 dataset, while [5] evaluated deep models such as CNN, CNN-LSTM, and DenseNet for intrusion detection. These approaches demonstrate strong pattern learning capability, especially for nonlinear attack behaviors. However, despite their detection potential, deep architectures typically require higher memory, longer training time, and greater inference cost. Such characteristics may reduce their practicality for resource-constrained IoT nodes, gateways, or edge devices where lightweight deployment is a core requirement. A further issue identified in the literature is that many studies emphasize binary classification or only a narrow subset of attacks. For example, [8] focused primarily on DDoSoriented detection, which is valuable for specific threat scenarios but does not fully address the broader requirement of distinguishing among multiple heterogeneous attack categories. In real IoT networks, intrusion detection systems must often identify not only whether traffic is malicious, but also what type of malicious behavior is present. This makes multiclass classification more challenging and more practically relevant than binary-only detection. However, the literature consistently reports that multiclass intrusion detection suffers when attack classes are highly imbalanced or when minority classes have only limited training examples [9]. These observations reveal several research gaps. First, although feature selection is widely used, many studies rely on single filter-based methods such as PCA, Chi-Square, or correlation analysis. While these methods are computationally efficient, they may overlook feature dependencies and interactions that wrapper-based methods can capture [6], [7]. Second, although deep models may improve classification performance, they often introduce computational overhead that conflicts with the lightweight requirements of IoT deployment [4], [5]. Third, multiclass intrusion detection remains insufficiently addressed, especially for rare attack categories, where class imbalance can significantly reduce recall and increase
misclassification [8], [9]. Finally, many prior studies prioritize predictive accuracy but provide limited discussion of model size, inference efficiency, and deployment suitability, which are essential in practical IoT security systems. Motivated by these gaps, LiteShield focuses on three design objectives: (1) integrating hybrid feature selection to combine the speed of filter methods with the subset refinement capability of wrapper methods, (2) supporting both binary and multiclass intrusion detection, and (3) benchmarking detection performance alongside efficiency-related factors relevant to resource-constrained IoT settings. In this way, the proposed system aims to offer a more balanced solution between detection effectiveness and deployment feasibility. III. M ETHODOLOGY A. Dataset and Preprocessing LiteShield uses the UNSW-NB15 dataset, a widely adopted benchmark containing modern normal and attack traffic with nine attack classes [11]. Following the dataset configuration used in prior work, the study uses the official train–test split and operates on 45 predictive features after removal of irrelevant identifiers and timestamps [11], [12]. Data preprocessing includes cleaning, duplicate handling, categorical encoding, and feature scaling. For multiclass detection, a balanced training set is used to reduce the effect of severe class imbalance. B. Hybrid Feature Selection The proposed framework combines a filter stage and a wrapper stage. Mutual Information (MI) is first applied to rank features by dependency with the target labels. Recursive Feature Elimination with Cross-Validation (RFECV) then refines the subset by iteratively removing less useful features according to classifier performance. This two-stage design aims to preserve the speed advantages of filter methods while improving subset quality through wrapper-based optimization [6], [13]. The final model uses 20 selected features for binary classification and 20 selected features for multiclass classification. C. Classification and Evaluation Six lightweight classifiers are trained and evaluated: Decision Tree (DT), Random Forest (RF), KNN, Logistic Regression (LR), Naı̈ve Bayes (NB), and Support Vector Machine (SVM). Binary classification distinguishes benign from malicious traffic. Multiclass classification predicts one of the attack categories or normal traffic. Performance is measured using accuracy, precision, recall, F1-score, and false positive rate (FPR), while deployment practicality is assessed using model size, inference latency, and memory usage [15], [16]. IV. R ESULTS AND D ISCUSSION Table I summarizes the main quantitative findings. KNN achieved the highest predictive performance in both binary and multiclass settings. In binary detection, it obtained 98.26% accuracy and an F1-score of 98.42%. In multiclass detection, it reached 85.22% accuracy and an F1-score of 87.44%.
TABLE I L ITE S HIELD CLASSIFICATION PERFORMANCE AND DEPLOYMENT COST Binary
Model DT RF KNN SVM LR NB
Multiclass
Acc.
F1
Size (MB)
Acc.
F1
Size (MB)
96.91 98.01 98.26 80.44 81.22 69.50
97.23 98.21 98.42 83.72 84.18 65.19
0.64 1.91 62.92 0.0013 0.0014 0.0018
78.47 80.39 85.22 59.53 59.48 43.26
81.65 83.55 87.44 66.18 66.16 50.50
2.29 4.32 124.97 0.0027 0.0029 0.0043
TABLE II M ULTICLASS ACCURACY UNDER ATTACK - CLASS ABLATION Model
Full
-Worms
-Shellcode
-Both
DT RF KNN LR NB SVM
78.47 80.39 85.22 59.48 43.26 59.53
77.30 80.48 85.23 60.80 43.59 59.43
79.53 80.85 85.34 62.66 43.42 59.50
78.46 80.62 85.34 63.95 45.55 60.23
However, this performance came with substantial cost: 62.92 MB model size for binary, 124.97 MB for multiclass, and the highest latency among all compared methods. By contrast, Random Forest produced a stronger balance between effectiveness and efficiency. It delivered 98.01% binary accuracy with a 1.90 MB model and 80.39% multiclass accuracy with a 4.32 MB model. This makes RF far more attractive for practical IoT deployment despite KNN’s superior raw accuracy. Decision Tree also remained lightweight and fast, but its multiclass performance was lower than RF and KNN. The results also reinforce the value of the hybrid feature selection strategy. By narrowing the feature space before classification, LiteShield maintains strong predictive performance without requiring heavyweight DL architectures. This is particularly important because computational feasibility matters as much as raw accuracy in edge settings [2], [18]. The results additionally align with broader literature showing that ensemble and tree-based methods often provide robust performance for network intrusion detection [17], [19]. A. Ablation and Validation Ablation analysis on minority classes (Worms and Shellcode) further clarified the effect of class imbalance. When these classes were removed, accuracy increased across all models, indicating that underrepresented attacks degrade multiclass learning stability. For example, RF improved from 80.39% multiclass accuracy in the full setting to 80.62% when both Worms and Shellcode were removed, while KNN improved from 85.22% to 85.34%. Although the gains are modest, their consistency supports the claim that imbalance handling remains essential for realistic multiclass IDS design. B. Positioning Against Prior Work LiteShield’s results compare favorably with several published baselines on UNSW-NB15 and related intrusion bench-
marks. The binary RF result of 98.01% accuracy is higher than values reported by Pansari et al. (95.03%) and Pal et al. (87.53%) [12], [14]. Likewise, binary KNN reaches 98.26%, exceeding several earlier KNN-based results. In multiclass evaluation, LiteShield’s KNN result of 85.22% surpasses Pansari et al.’s 81.77% but remains below the 93.06% reported by Jouhari et al. for a different hybrid setting. These comparisons suggest that LiteShield is competitive, especially when practical efficiency is considered together with predictive performance. V. L IMITATIONS This study has several limitations. First, evaluation relies primarily on UNSW-NB15, which may not fully capture the heterogeneity of real IoT deployments or evolving attack behavior. Second, the system was not validated on physical IoT hardware, so real-world deployment feasibility remains partly inferred from model size and runtime characteristics rather than directly observed. Third, while oversampling and balanced training help, rare and zero-day attacks remain difficult to model reliably. Finally, only lightweight ML models were evaluated; future work could examine quantized or compressed DL alternatives that preserve a low deployment footprint. VI. C ONCLUSION AND F UTURE W ORK This paper presented LiteShield, a lightweight IoT intrusion detection framework that combines hybrid feature selection with efficient machine learning classifiers. The results show that high detection performance is achievable without resorting to computationally expensive DL models. KNN delivered the best predictive scores overall, but Random Forest provided the most practical trade-off for constrained deployment because it preserved strong accuracy while remaining far smaller and faster. The study confirms three main findings: hybrid feature selection is effective for reducing dimensionality without undermining detection quality; multiclass IoT intrusion detection remains strongly affected by class imbalance; and efficiencyaware benchmarking is necessary because the highest-accuracy model may be unsuitable for real deployment. Future work should extend evaluation to additional datasets such as BoTIoT, CICIDS2017, and ToN-IoT, test the framework on real IoT hardware, support streaming data, and explore adaptive, explainable, and compressed learning methods for evolving attack environments. R EFERENCES [1] P. R. Agbedanu, N. H. Mvungi, and T. O. Olwal, “IPCA-SAMKNN: A Novel Network IDS for Resource Constrained Devices,” in Proc. 2nd Int. Seminar on Machine Learning, Optimization, and Data Science (ISMODE), 2022, pp. 540–545. [2] X.-H. Nguyen, Q.-V. Tran, H.-V. Huynh, and T.-T. Nguyen, “Realguard: A Lightweight Network Intrusion Detection System for IoT Gateways,” Sensors, vol. 22, no. 2, p. 432, 2022. [3] S. Roy, M. Chattopadhyay, S. Das, and S. Maitra, “A Lightweight Supervised Intrusion Detection Mechanism for IoT Networks,” Future Generation Computer Systems, vol. 127, pp. 276–285, 2022. [4] H. Benaddi, M. Jouhari, and O. Elharrouss, “A Lightweight Hybrid Approach for Intrusion Detection Systems Using a Chi-Square Feature Selection Approach in IoT,” Internet of Things, vol. 32, p. 101624, 2025.
[5] M. Ahsan et al., “Intrusion Detection for IoT Network Security with Deep Neural Network,” in Proc. IEEE Int. Conf. Electro Information Technology (eIT), 2022, pp. 467–472. [6] K. Albulayhi, M. Abuhamad, A. Alawairdhi, and A. Al-Dhelaan, “IoT Intrusion Detection Using Machine Learning with a Novel High Performing Feature Selection Method,” Applied Sciences, vol. 12, no. 10, p. 5015, 2022. [7] S. Kaushik, A. Gupta, A. K. Yadav, and P. K. Shukla, “Efficient, Lightweight Cyber Intrusion Detection System for IoT Ecosystems Using MI2G Algorithm,” Computers, vol. 11, no. 10, p. 142, 2022. [8] S. A. Khanday, H. Fatima, and N. Rakesh, “Implementation of Intrusion Detection Model for DDoS Attacks in Lightweight IoT Networks,” Expert Systems with Applications, vol. 215, p. 119330, 2023. [9] G. A. Mukhaini et al., “A Systematic Literature Review of Recent Lightweight Detection Approaches Leveraging Machine and Deep Learning Mechanisms in Internet of Things Networks,” J. King Saud Univ. – Computer and Information Sciences, vol. 36, no. 1, p. 101866, 2024. [10] A. Basati and M. M. Faghih, “DFE: Efficient IoT Network Intrusion Detection Using Deep Feature Extraction,” Neural Computing and Applications, vol. 34, no. 18, pp. 15175–15195, 2022. [11] N. Moustafa and J. Slay, “UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection Systems,” in Proc. Military Communications and Information Systems Conf. (MilCIS), 2015, pp. 1–6. [12] N. Pansari, D. Bhattacharyya, and A. Bhowmick, “Attack Classification Using Machine Learning on UNSW-NB15 Dataset Using XGBoost Feature Selection and Ablation Analysis,” in Proc. IEEE Int. Conf. for Convergence in Technology (I2CT), 2024, pp. 1–9. [13] A. Z. Mustaqim, E. M. Yuniarno, and M. H. Purnomo, “The Effect of Recursive Feature Elimination with Cross-Validation (RFECV) Feature Selection Algorithm toward Classifier Performance on Credit Card Fraud Detection,” in Proc. Int. Conf. Artificial Intelligence and Computer Science Technology (ICAICST), 2021, pp. 270–275. [14] K. K. Pal, A. V. Eriksen, and N. Dinh, “XGBoost Feature Selection for Multi-Class and Binary Classification on UNSW-NB15 Dataset,” in Proc. IEEE Int. Conf. Consumer Electronics (ICCE), 2025, pp. 1–6. [15] B. A. Tama and S.-H. Lim, “Ensemble Learning for Intrusion Detection Systems: A Systematic Mapping Study and Cross-Benchmark Evaluation,” Computer Science Review, vol. 39, p. 100357, 2021. [16] S. K. R. Mallidi and R. R. Ramisetty, “Optimizing Intrusion Detection for IoT: A Systematic Review of Machine Learning and Deep Learning Approaches With Feature Selection and Data Balancing,” WIREs Data Mining and Knowledge Discovery, vol. 15, no. 2, p. e70008, 2025. [17] D. Zhang, J. Liu, X. Zhao, and Y. Wang, “A Lightweight IoT Intrusion Detection Method Based on Two-Stage Feature Selection and Bayesian Optimization,” AIMS Electronics and Electrical Engineering, vol. 9, no. 3, pp. 359–389, 2025. [18] S. F. Misrak and H. M. Melaku, “Lightweight Intrusion Detection System for IoT with Improved Feature Engineering and Advanced Dynamic Quantization,” Discover Internet of Things, vol. 5, no. 1, p. 97, 2025. [19] M. Z. Mahmud, M. A. Hossain, and M. A. Rahman, “Optimized IoT Intrusion Detection using Machine Learning Technique,” in Proc. IEEE Int. Conf. Robotics, Automation, Artificial-Intelligence and Internet-ofThings (RAAICON), 2024, pp. 167–172.