Deep and Ensemble Learning for IoT Network Intrusion Detection: Comparative Performance and Deployment Considerations for AI-Enabled Connected Environments

Authors

Keywords:

Internet of Things, intrusion detection system, deep learning, ensemble learning, DNN, CNN, LSTM, GRU, TON-IoT, trustworthy artificial intelligence

Abstract

 

Internet of Things (IoT) networks connect devices used in smart homes, education, healthcare, transportation, and critical infrastructure, but their heterogeneity and limited device resources create a broad and rapidly changing attack surface. This study compared four standalone deep-learning architectures—deep neural network (DNN), one-dimensional convolutional neural network (CNN), long short-term memory (LSTM), and gated recurrent unit (GRU)—with all six pairwise probability ensembles formed from these models for binary intrusion detection. The analysis used 461,043 observations and 45 features from the TON-IoT network-traffic data. Data were divided into 322,730 training observations and 138,313 test observations using a 70/30 class-preserving record-level split. Preprocessing included missing-value treatment, categorical encoding, removal of non-informative features, and standardization estimated from the training data and applied to the test data. Models were trained under common optimization settings and evaluated using accuracy, F1 score, area under the receiver operating characteristic curve (AUC-ROC), and confusion-matrix errors. Every pairwise ensemble ranked above the four standalone models by F1 score in this single-split analysis. The DNN + GRU ensemble achieved the highest point estimates, with accuracy of 0.9774, F1 score of 0.9680, and AUC-ROC of 0.9963. It produced 87,926 true negatives, 47,260 true positives, 2,074 false positives, and 1,053 false negatives. The DNN + LSTM ensemble ranked second, with accuracy of 0.9769, F1 score of 0.9673, and AUC-ROC of 0.9957. Because the evaluation used one split and single point estimates, the small differences between leading models should be interpreted descriptively rather than as evidence of statistically significant superiority. For deployment, external validation, calibrated thresholds, explainable alerts, drift monitoring, and analyst oversight remain necessary.

Downloads

Download data is not yet available.

References

Afraji, D. M. A. A., Lloret, J., & Peñalver, L. (2025). An integrated hybrid deep learning framework for intrusion detection in IoT and IIoT networks using CNN-LSTM-GRU architecture. Computation, 13(9), Article 222. https://doi.org/10.3390/computation13090222

Ahmad, J., Latif, S., Khan, I. U., Alshehri, M. S., Khan, M. S., Alasbali, N., & Jiang, W. (2025). An interpretable deep learning framework for intrusion detection in industrial Internet of Things. Internet of Things, 33, Article 101681. https://doi.org/10.1016/j.iot.2025.101681

Alsaedi, A., Moustafa, N., Tari, Z., Mahmood, A., & Anwar, A. (2020). TON-IoT telemetry dataset: A new generation dataset of IoT and IIoT for data-driven intrusion detection systems. IEEE Access, 8, 165130–165150. https://doi.org/10.1109/ACCESS.2020.3022862

Breiman, L. (1996). Bagging predictors. Machine Learning, 24, 123–140. https://doi.org/10.1007/BF00058655

Cho, K., van Merriënboer, B., Gulcehre, C., Bahdanau, D., Bougares, F., Schwenk, H., & Bengio, Y. (2014). Learning phrase representations using RNN encoder-decoder for statistical machine translation. In Proceedings of the 2014 Conference on Empirical Methods in Natural Language Processing (pp. 1724–1734). https://doi.org/10.3115/v1/D14-1179

Diro, A. A., & Chilamkurti, N. (2018). Distributed attack detection scheme using deep learning approach for Internet of Things. Future Generation Computer Systems, 82, 761–768. https://doi.org/10.1016/j.future.2017.08.043

Ferrag, M. A., Maglaras, L., Moschoyiannis, S., & Janicke, H. (2020). Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. Journal of Information Security and Applications, 50, Article 102419. https://doi.org/10.1016/j.jisa.2019.102419

Goodfellow, I., Bengio, Y., & Courville, A. (2016). Deep learning. MIT Press.

Hochreiter, S., & Schmidhuber, J. (1997). Long short-term memory. Neural Computation, 9(8), 1735–1780. https://doi.org/10.1162/neco.1997.9.8.1735

Ishtiaq, W., Zannat, A., Parvez, A. H. M. S., Hossain, M. A., Kanchan, M. H., & Tarek, M. M. (2025). CST-AFNet: A dual attention-based deep learning framework for intrusion detection in IoT networks. Array, 27, Article 100501. https://doi.org/10.1016/j.array.2025.100501

Karimi Dastgerdi, A., & Zamani Boroujeni, F. (2020). A review of deep learning methods for financial market prediction. Transactions on Data Analysis in Social Science, 2(3), 164–172. https://doi.org/10.47176/TDASS.2020.164

LeCun, Y., Bottou, L., Bengio, Y., & Haffner, P. (1998). Gradient-based learning applied to document recognition. Proceedings of the IEEE, 86(11), 2278–2324. https://doi.org/10.1109/5.726791

Lundberg, S. M., & Lee, S.-I. (2017). A unified approach to interpreting model predictions. In Advances in Neural Information Processing Systems 30 (pp. 4765–4774).

Maoudj, S. E., & Belghiat, A. (2025). A deep learning-based approach with two-step minority classes prediction for intrusion detection in Internet of Things networks. Knowledge-Based Systems, 312, Article 113143. https://doi.org/10.1016/j.knosys.2025.113143

Mirsky, Y., Doitshman, T., Elovici, Y., & Shabtai, A. (2018). Kitsune: An ensemble of autoencoders for online network intrusion detection. In Proceedings of the Network and Distributed System Security Symposium. https://doi.org/10.14722/ndss.2018.23204

Mohammadi, S., & Anisheh, S. M. (2024). Human activity recognition based on deep learning using sensor data. Transactions on Data Analysis in Social Science, 6(4), 222–230. https://doi.org/10.47176/TDASS.2024.222

Moradi, M. (2023). A Bayesian model and Bayesian classification on the data obtained from children's educational activity in the IoT environment. Transactions on Machine Intelligence, 6(3), 126–136. https://doi.org/10.47176/TMI.2023.126

Moustafa, N., Ahmed, M., & Ahmed, S. (2020). Data analytics-enabled intrusion detection: Evaluations of ToN-IoT Linux datasets. In 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (pp. 727–735). IEEE. https://doi.org/10.1109/TrustCom50675.2020.00100

Rahmani Seryasat, O., Kor, I., Ghayoumi Zadeh, H., & Shams Taleghani, A. (2021). Predicting the number of comments on Facebook posts using an ensemble regression model. International Journal of Nonlinear Analysis and Applications, 12(Special Issue), 49–62. https://doi.org/10.22075/IJNAA.2021.4796

Ravaei, B., Ravaei, S., Moshrefzadeh, S., & Rahmani Seryasat, O. (2022). An efficient and load-balanced task offloading in vehicular Internet of Things. Transactions on Machine Intelligence, 5(1), 46–56. https://doi.org/10.47176/TMI.2022.46

Sagi, O., & Rokach, L. (2018). Ensemble learning: A survey. Wiley Interdisciplinary Reviews: Data Mining and Knowledge Discovery, 8(4), e1249. https://doi.org/10.1002/widm.1249

Shone, N., Ngoc, T. N., Phai, V. D., & Shi, Q. (2018). A deep learning approach to network intrusion detection. IEEE Transactions on Emerging Topics in Computational Intelligence, 2(1), 41–50. https://doi.org/10.1109/TETCI.2017.2772792

Vinayakumar, R., Alazab, M., Soman, K. P., Poornachandran, P., Al-Nemrat, A., & Venkatraman, S. (2019). Deep learning approach for intelligent intrusion detection system. IEEE Access, 7, 41525–41550. https://doi.org/10.1109/ACCESS.2019.2895334

Wolpert, D. H. (1992). Stacked generalization. Neural Networks, 5(2), 241–259. https://doi.org/10.1016/S0893-6080(05)80023-1

Published

2026-07-24

Issue

Section

Articles

How to Cite

Sahep Majeed, S., Deypir, M. ., Farazkish, R. ., & Broumandnia, A. . (2026). Deep and Ensemble Learning for IoT Network Intrusion Detection: Comparative Performance and Deployment Considerations for AI-Enabled Connected Environments. AI and Tech in Behavioral and Social Sciences. https://www.journals.kmanpub.com/index.php/aitechbesosci/article/view/5855