Back to results

University of Wales Trinity Saint David

Optimizing Deep Learning and Machine Learning Models for Real-Time Intrusion Detection in IoT Networks

Abstract

dc:description.abstract

The rapid growth of Internet of Things (IoT) deployments has expanded the network attack surface and increased the operational need for intrusion detection systems (IDS) that remain accurate under multi-class class imbalance while also being computationally feasible for near-real-time use. Using the CICIoT2023 benchmark dataset, this dissertation develops a reproducible end-to-end experimental pipeline and evaluates representative families of intrusion detection models, including the traditional machine learning, deep learning, ensemble learning, and proposed hybrid approaches. Five CICIoT2023 CSV partitions were ingested with a robust Drive-to-local caching strategy, then controlled via per-class capping (cap=3,225) to manage scale. After rare-class filtering (minimum 200 samples/class), the final experimental dataset comprised 73,211 samples, 50 features, and 27 classes, split stratified into 51,539 train, 7,029 validation, and 14,643 test instances. Across 27 evaluated models, the Proposed Voting Ensemble achieved the strongest overall detection quality (Accuracy=0.9528, Macro-F1=0.9441, MCC=0.9508) with a training time of 224.0 s, marginally exceeding strong ensemble baselines such as Bagging (DT) (MacroF1=0.9417, 95.8 s) and XGBoost (Macro-F1=0.9416, 52.9 s). Notably, runtime–performance trade-offs were material: Gradient Boosting delivered competitive Macro-F1 (0.9391) but incurred substantially higher training time (2835.6 s), while LightGBM offered a favorable efficiency profile (Macro-F1=0.9360, 40.6 s). Deep learning baselines underperformed leading ensembles (best DL: Wide MLP Macro-F1=0.7666) and one attention-based model collapsed (MacroF1=0.0031), indicating sensitivity of generic neural architectures to tabular IoT traffic representations under imbalance. Knowledge distillation did not improve detection quality versus ensembles in this setting (KD student Macro-F1=0.7247), but remains relevant for future edge focused compression studies. The dissertation’s contributions are (i) a transparent, imbalance aware benchmark emphasizing Macro-F1 and MCC, (ii) validated ensemble and tuning strategies (Optuna-guided HistGB, soft voting), and (iii) a reproducible experimental workflow with saved artefacts and figures.

Degree

thesis:*
Name dc:type.qualificationname
msc
Level dc:type.qualificationlevel
masters
Grantor dc:publisher.institution
University of Wales Trinity Saint David
Year dc:date.issued
2026

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Islam, Rezuan

Subjects

dc:subject × 1

Identifiers

dc:identifier.*
Dc Identifier Grantnumber
UWTSD
OAI identifier oai:identifier
oai:repository.uwtsd.ac.uk:4224

Chain of custody

source
Harvested from
University of Wales Trinity Saint David
Base URL
repository.uwtsd.ac.uk/cgi/oai2
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Islam, Rezuan. Optimizing Deep Learning and Machine Learning Models for Real-Time Intrusion Detection in IoT Networks. masters thesis, University of Wales Trinity Saint David, 2026. https://doi.org/10.82227/repository.uwtsd.ac.uk.00004224