{"id":{"repo_id":"utc","oai_identifier":"oai:scholar.utc.edu:theses-1910"},"canonical_url":"https://search.dev.ndltd.org/etd/utc/oai:scholar.utc.edu:theses-1910","repository":{"repo_id":"utc","name":"University of Tennessee - Chattanooga","base_url":"https://scholar.utc.edu/do/oai/"},"display":{"title":"Deep learning-based anomaly detection for edge-layer devices","abstract":"This thesis work proposes a novel DL-based anomaly detection framework for IoT environments, employing higher-capacity embedded devices as a first line of defense for the IoT edge layer. In the proposed framework, embedded devices implement the DL anomaly detection engine at the network gateway and adapt to potential attacks by retraining on incoming network traffic. In order to test the feasibility of this framework, two neural network models, trained on variations of the CICIDS 2018 Intrusion Detection Data Set, are deployed and tested on the Raspberry Pi 4. Model performance metrics, including fit and evaluation time across various batch and data sizes, are compared alongside those of identical models running on higher-capacity devices. Device resource metrics of CPU and Memory usage are monitored for comparison across model variations, batch and data sizes.The potential benefit of retraining models at the edge is evaluated by comparing performance of models executing consistent retraining.","abstract_html":"This thesis work proposes a novel DL-based anomaly detection framework for IoT environments, employing higher-capacity embedded devices as a first line of defense for the IoT edge layer. In the proposed framework, embedded devices implement the DL anomaly detection engine at the network gateway and adapt to potential attacks by retraining on incoming network traffic. In order to test the feasibility of this framework, two neural network models, trained on variations of the CICIDS 2018 Intrusion Detection Data Set, are deployed and tested on the Raspberry Pi 4. Model performance metrics, including fit and evaluation time across various batch and data sizes, are compared alongside those of identical models running on higher-capacity devices. Device resource metrics of CPU and Memory usage are monitored for comparison across model variations, batch and data sizes.The potential benefit of retraining models at the edge is evaluated by comparing performance of models executing consistent retraining.","abstract_has_math":false,"creators":["Hunter, Jonathan"],"institution":"University of Tennessee at Chattanooga","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":["Kandah, Farah","Ward, Michael; Skjellum, Anthony; Reising, Donald R.","College of Engineering and Computer Science"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":null,"date_issued":"","date_published":null,"updated_at":"2026-07-24T05:47:06Z","subjects":["Internet of things","Intrusion detection systems (Computer science)","Machine learning","Neural networks (Computer science)"],"languages":["English","eng"],"rights":[],"rights_urls":["http://rightsstatements.org/vocab/InC/1.0/"],"identifier_entries":[]},"links":{"outbound_url":"https://scholar.utc.edu/theses/740","outbound_label":"Repository record","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Kandah, Farah","Ward, Michael; Skjellum, Anthony; Reising, Donald R.","College of Engineering and Computer Science"]},{"key":"dc:creator","label":"Author","values":["Hunter, Jonathan"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2022-05-01T07:00:00Z"]},{"key":"dc:publisher","label":"Institution","values":["University of Tennessee at Chattanooga","Chattanooga (Tenn.)"]},{"key":"dc:relation","label":"Dc Relation","values":["Masters Theses and Doctoral Dissertations"]},{"key":"dc:type","label":"Dc Type","values":["Masters theses","Text"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Internet of things","Intrusion detection systems (Computer science)","Machine learning","Neural networks (Computer science)"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["English","eng"]},{"key":"dc:rights","label":"Dc Rights","values":["http://rightsstatements.org/vocab/InC/1.0/"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://scholar.utc.edu/theses/740"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Dept. of Computer Science and Engineering","M. S.; A thesis submitted to the faculty of the University of Tennessee at Chattanooga in partial fulfillment of the requirements of the degree of Master of Science."]},{"key":"dc:description.abstract","label":"Abstract","values":["This thesis work proposes a novel DL-based anomaly detection framework for IoT environments, employing higher-capacity embedded devices as a first line of defense for the IoT edge layer. In the proposed framework, embedded devices implement the DL anomaly detection engine at the network gateway and adapt to potential attacks by retraining on incoming network traffic. In order to test the feasibility of this framework, two neural network models, trained on variations of the CICIDS 2018 Intrusion Detection Data Set, are deployed and tested on the Raspberry Pi 4. Model performance metrics, including fit and evaluation time across various batch and data sizes, are compared alongside those of identical models running on higher-capacity devices. Device resource metrics of CPU and Memory usage are monitored for comparison across model variations, batch and data sizes.The potential benefit of retraining models at the edge is evaluated by comparing performance of models executing consistent retraining."]},{"key":"dc:title","label":"Title","values":["Deep learning-based anomaly detection for edge-layer devices"]}]}],"canonical_facts":{"dc:contributor":["Kandah, Farah","Ward, Michael; Skjellum, Anthony; Reising, Donald R.","College of Engineering and Computer Science"],"dc:creator":["Hunter, Jonathan"],"dc:date":["2022-05-01T07:00:00Z"],"dc:description":["Dept. of Computer Science and Engineering","M. S.; A thesis submitted to the faculty of the University of Tennessee at Chattanooga in partial fulfillment of the requirements of the degree of Master of Science."],"dc:description.abstract":["This thesis work proposes a novel DL-based anomaly detection framework for IoT environments, employing higher-capacity embedded devices as a first line of defense for the IoT edge layer. In the proposed framework, embedded devices implement the DL anomaly detection engine at the network gateway and adapt to potential attacks by retraining on incoming network traffic. In order to test the feasibility of this framework, two neural network models, trained on variations of the CICIDS 2018 Intrusion Detection Data Set, are deployed and tested on the Raspberry Pi 4. Model performance metrics, including fit and evaluation time across various batch and data sizes, are compared alongside those of identical models running on higher-capacity devices. Device resource metrics of CPU and Memory usage are monitored for comparison across model variations, batch and data sizes.The potential benefit of retraining models at the edge is evaluated by comparing performance of models executing consistent retraining."],"dc:identifier":["https://scholar.utc.edu/theses/740"],"dc:language":["English","eng"],"dc:publisher":["University of Tennessee at Chattanooga","Chattanooga (Tenn.)"],"dc:relation":["Masters Theses and Doctoral Dissertations"],"dc:rights":["http://rightsstatements.org/vocab/InC/1.0/"],"dc:subject":["Internet of things","Intrusion detection systems (Computer science)","Machine learning","Neural networks (Computer science)"],"dc:title":["Deep learning-based anomaly detection for edge-layer devices"],"dc:type":["Masters theses","Text"]},"updated_at":"2026-07-24T05:47:06Z"}