Return
Empowering IoT security: deploying TinyML ensemble techniques for cyberattack detection
DOI:10.1016/j.sciaf.2025.e02809.png)
Abstract
En 中文
As the Internet of Things (IoT) grows and devices connect, protecting IoT networks from vulnerabilities is crucial. Intrusion detection systems (IDS) that use machine learning (ML) techniques are vital for increasing security and preventing unauthorized access. Traditionally, ML models have been trained and deployed on forceful computers, such as cloud services. However, sending data to the cloud can slow the detection of attacks in real time. This research constructs and assesses the TinyML ensemble and singular techniques, focusing on bagging (Random Forest) and boosting (XGBoost) using decision trees as the base learner, employing three feature selection (FS) methods (analysis of variance (ANOVA), maximum relevance minimum redundancy (mRMR), and chi-square), and different feature thresholds over the NF-ToN-IoT-v2 and NF-BoT-IoT-v2 datasets for cyberattack detection. The evaluations were performed on the Arduino UNO, considering two prediction performance criteria (Matthew's correlation coefficient and Cohen's kappa), three performance aspects linked to the embedded device: inference time (i.e. latency), static RAM, and flash memory, and using the Borda Count voting system to rank the models. A total of 140 TinyML ensembles and 14 singular classifier variants were tested on the Arduino UNO. The results show that XGBoost with 5 estimators, ANOVA with mRMR as FS, and selecting 40 % of the best features is the best configuration for a TinyML-based IDS. This underscores its usefulness in detecting cyberattacks in IoT settings.
Keywords:
Bagging
Boosting
TinyML
Internet of things
Intrusion detection systems
Arduino UNO
Journal
IF:
3.3
Papers:
1.0K
Citations:
6.7K

