University of Wales Trinity Saint David
Optimizing Deep Learning and Machine Learning Models for Real-Time Intrusion Detection in IoT Networks
Abstract
dc:description.abstractThe rapid growth of Internet of Things (IoT) deployments has expanded the network attack surface and increased the operational need for intrusion detection systems (IDS) that remain accurate under multi-class class imbalance while also being computationally feasible for near-real-time use. Using the CICIoT2023 benchmark dataset, this dissertation develops a reproducible end-to-end experimental pipeline and evaluates representative families of intrusion detection models, including the traditional machine learning, deep learning, ensemble learning, and proposed hybrid approaches. Five CICIoT2023 CSV partitions were ingested with a robust Drive-to-local caching strategy, then controlled via per-class capping (cap=3,225) to manage scale. After rare-class filtering (minimum 200 samples/class), the final experimental dataset comprised 73,211 samples, 50 features, and 27 classes, split stratified into 51,539 train, 7,029 validation, and 14,643 test instances. Across 27 evaluated models, the Proposed Voting Ensemble achieved the strongest overall detection quality (Accuracy=0.9528, Macro-F1=0.9441, MCC=0.9508) with a training time of 224.0 s, marginally exceeding strong ensemble baselines such as Bagging (DT) (MacroF1=0.9417, 95.8 s) and XGBoost (Macro-F1=0.9416, 52.9 s). Notably, runtime–performance trade-offs were material: Gradient Boosting delivered competitive Macro-F1 (0.9391) but incurred substantially higher training time (2835.6 s), while LightGBM offered a favorable efficiency profile (Macro-F1=0.9360, 40.6 s). Deep learning baselines underperformed leading ensembles (best DL: Wide MLP Macro-F1=0.7666) and one attention-based model collapsed (MacroF1=0.0031), indicating sensitivity of generic neural architectures to tabular IoT traffic representations under imbalance. Knowledge distillation did not improve detection quality versus ensembles in this setting (KD student Macro-F1=0.7247), but remains relevant for future edge focused compression studies. The dissertation’s contributions are (i) a transparent, imbalance aware benchmark emphasizing Macro-F1 and MCC, (ii) validated ensemble and tuning strategies (Optuna-guided HistGB, soft voting), and (iii) a reproducible experimental workflow with saved artefacts and figures.
Degree
thesis:*- Name dc:type.qualificationname
- msc
- Level dc:type.qualificationlevel
- masters
- Grantor dc:publisher.institution
- University of Wales Trinity Saint David
- Year dc:date.issued
- 2026
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Islam, Rezuan
Subjects
dc:subject × 1Identifiers
dc:identifier.*- Dc Identifier Grantnumber
- UWTSD
- OAI identifier oai:identifier
- oai:repository.uwtsd.ac.uk:4224