Evaluating Transfer-Learning Ensembles and Autoencoders against CNN Baselines in IoT Intrusion Detection
DOI:
https://doi.org/10.64751/Abstract
Intrusion detection in Internet-of-Things (IoT) networks must operate under shifting traffic distributions, scarce labels, and edge-level resource limits. This paper presents a comparative study of three systems we developed to span these constraints: (S1) a compact supervised convolutional neural network (CNN) with feature selection and early stopping; (S2) a transfer-learning ensemble of deep backbones tuned via particle swarm optimisation; and (S3) an unsupervised autoencoder with adaptive, percentile-based thresholding for open-set threat detection. Using a unified preprocessing and evaluation pipeline on UNSW-NB15, we report accuracy, macro-precision/recall/F1, ROC-AUC, and error rates; for S3, we also quantify detection of previously unseen attacks. Results show S1 offers dependable, low-latency baselines (≈95% accuracy), S2 achieves the strongest closed-set performance (≈98.8% accuracy, macro-F1 ≈0.986), and S3 provides the best threshold-free separability at low falsepositive budgets (ROC-AUC ≈0.992) while maintaining an unknown-attack false-negative rate below 8.2%. We analyse computational and operational trade-offs across edge, fog, and cloud deployments and propose policy-level fusion strategies that combine strengths under practical alerting constraints. The study yields actionable guidance on when to favour simplicity, accuracy ceilings, or novelty robustness, and outlines future work in federated/continual learning, robustness, and energy-aware inference.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.







