Author
Listed:
- Amir Muhammad Hafiz Othman
(Faculty of Computing, Universiti Malaysia Pahang Al-Sultan Abdullah, Pekan 26600, Malaysia)
- Mohd Faizal Ab Razak
(Faculty of Computing, Universiti Malaysia Pahang Al-Sultan Abdullah, Pekan 26600, Malaysia)
- Ahmad Firdaus
(Faculty of Computing, Universiti Malaysia Pahang Al-Sultan Abdullah, Pekan 26600, Malaysia)
- Hamid Tahaei
(Institute of Artificial Intelligence, Shaoxing University, Shaoxing 312010, China)
- Mehdi Gheisari
(Institute of Artificial Intelligence, Shaoxing University, Shaoxing 312010, China
Department of Computer Science and Engineering, Saveetha School of Engineering, Saveetha Institute of Medical and Technical Science, Chennai 602105, India
Department of Computer Engineering, Shiraz Branch, Islamic Azad University, Shiraz 71987-74731, Iran
Department of R&D, Shenzhen BKD Co., Ltd., Shenzhen 518000, China)
Abstract
The rapid growth of Internet of Things (IoT) devices has led to security concerns due to increasing IoT attacks. Traditional intrusion detection systems (IDS) struggle to effectively detect attacks due to the evolving nature of threats and heterogeneous traffic patterns. Therefore, this study presents a structured and reproducible intrusion detection approach that integrates preprocessing and deep learning-based classification for binary detection in IoT networks. The datasets used are ToN_IoT and UNSW-NB15 datasets, which contain IoT network traffic data. This study deploys a meta-heuristic algorithm called Gray Wolf Optimizer (GWO) for feature selection. SMOTE is used for balancing the class sample, and MinMax and standard normalization for data scaling during preprocessing. A comparative analysis is performed across multiple deep learning models, including Convolutional Neural Network–Long Short-Term Memory (CNN–LSTM), Multi-Layer Perceptron (MLP), Deep Neural Network (DNN), Convolutional Neural Network (CNN), and Recurrent Neural Network (RNN). Results show that the CNN–LSTM model demonstrates strong performance consistency across datasets, achieving 99.68% and 92.05% accuracy on ToN_IoT and UNSW-NB15, respectively. Threshold sensitivity analysis reveals key detection and false-positive trade-offs for edge IDS. Through extensive performance evaluation and sensitivity analysis, this study highlights the importance of combining preprocessing, model evaluation, and threshold analysis for reliable IoT intrusion detection.
Suggested Citation
Amir Muhammad Hafiz Othman & Mohd Faizal Ab Razak & Ahmad Firdaus & Hamid Tahaei & Mehdi Gheisari, 2026.
"A Hybrid CNN–LSTM Model for IoT Intrusion Detection: A Robustness Analysis Across Datasets,"
Future Internet, MDPI, vol. 18(7), pages 1-21, June.
Handle:
RePEc:gam:jftint:v:18:y:2026:i:7:p:345-:d:1979017
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jftint:v:18:y:2026:i:7:p:345-:d:1979017. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager The email address of this maintainer does not seem to be valid anymore. Please ask MDPI Indexing Manager to update the entry or send us the correct address
(email available below). General contact details of provider: https://www.mdpi.com .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.