ALEIDF: An Adaptive Lightweight and Explainable Hybrid Deep Learning Framework for Intrusion Detection in Resource-Constrained IoT Networks
DOI:
https://doi.org/10.59992/IJCI.2026.v5n8p1الكلمات المفتاحية:
IoT، IDS، Lightweight Deep Learning، Adaptive Learning، Federated Learning، Network Securityالملخص
The proliferation of Internet of Things (IoT) networks in smart homes, healthcare, industrial systems, and critical infrastructure has greatly extended the attack surface, and the deep learning models that are best suited to detecting these attacks are challenging to deploy on resource-limited edge devices, difficult to trust because they are black-box, and difficult to maintain effectively because traffic and attack distributions are evolving over time. Lightweight, explainable, and adaptive intrusion detection have been researched as largely distinct lines of work so far. This paper proposes a unified framework (ALEIDF) which consolidates eight tightly coupled modules, namely: Adaptive Feature Evolution Module (AFE), Hybrid Deep Learning Engine (HDLE), Adaptive Threat Memory (ATM), Explainability Module (XM), Decision Engine (DE), Resource Optimization Module (ROM), and Online Learning Module (OLM). The ALEIDF is equipped with feature level-drift detection, as well as retraining triggers; externalizes threat knowledge into an episodic memory query; calibrates detection confidence against this memory; and scopes the generation of explanations towards the drift adapted feature subset, which address the accuracy-efficiency gap, efficiency-explainability gap, and adaptability-knowledge-retention gap pointed out in the recent IoT-IDS literature. In a cross-dataset test with UNSW-NB15 and X-IIoTID, ALEIDF achieves a macro F1 score of about 97.7%, fast inference latency of < 10ms on microcontroller-class hardware and about 40% faster recovery from simulated concept drift than federated-incremental baselines, while costing just 10% as much relative to explanation generation as full-feature SHAP. Having identified joint integration of efficiency, explainability and adaptability as an open field in recent surveys regarding IoT network security research, ALEIDF is well positioned to further this integration.
المراجع
] E. C. P. Neto, S. Dadkhah, R. Ferreira, A. Zohourian, R. Lu, and A. A. Ghorbani, "CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment," Sensors, vol. 23, no. 13, Art. no. 5941, 2023, doi: 10.3390/s23135941.
[2] Z. Wang, H. Chen, S. Yang, X. Luo, D. Li, and J. Wang, "A lightweight intrusion detection method for IoT based on deep learning and dynamic quantization," PeerJ Computer Science, vol. 9, Art. no. e1569, 2023, doi: 10.7717/peerj-cs.1569.
[3] P. Fusco, G. P. Rimoli, and M. Ficco, "TinyIDS — An IoT intrusion detection system by tiny machine learning," in Computational Science and Its Applications — ICCSA 2024 Workshops, Springer, 2024, pp. 71–82, doi: 10.1007/978-3-031-65223-3_5.
[4] H. Peng, C. Wu, and Y. Xiao, "FD-IDS: Federated learning with knowledge distillation for intrusion detection in non-IID IoT environments," Sensors, vol. 25, no. 14, Art. no. 4309, 2025, doi: 10.3390/s25144309.
[5] S. Neupane, J. Ables, W. Anderson, S. Mittal, S. Rahimi, I. Banicescu, and M. Seale, "Explainable Intrusion Detection Systems (X-IDS): A survey of current methods, challenges, and opportunities," IEEE Access, vol. 10, pp. 112392–112415, 2022, doi: 10.1109/ACCESS.2022.3216617.
[6] M. Keshk, N. Koroniotis, N. Pham, N. Moustafa, B. Turnbull, and A. Y. Zomaya, "An explainable deep learning-enabled intrusion detection framework in IoT networks," Information Sciences, vol. 639, Art. no. 119000, 2023, doi: 10.1016/j.ins.2023.119000.
[7] Z. Abou El Houda, B. Brik, and L. Khoukhi, "‘Why should I trust your IDS?’: An explainable deep learning framework for intrusion detection systems in Internet of Things networks," IEEE Open Journal of the Communications Society, vol. 3, pp. 1164–1176, 2022, doi: 10.1109/OJCOMS.2022.3188750.
[8] Z. Jin, J. Zhou, B. Li, X. Wu, and C. Duan, "FL-IIDS: A novel federated learning-based incremental intrusion detection system," Future Generation Computer Systems, vol. 151, pp. 57–70, 2024, doi: 10.1016/j.future.2023.09.019.
[9] R. Kalakoti, S. Nõmm, and H. Bahsi, "Federated learning of explainable AI (FedXAI) for deep learning-based intrusion detection in IoT networks," Computer Networks, Art. no. 111479, 2025, doi: 10.1016/j.comnet.2025.111479.
[10] S. Arisdakessian, O. A. Wahab, A. Mourad, H. Otrok, and M. Guizani, "A survey on IoT intrusion detection: Federated learning, game theory, social psychology, and explainable AI as future directions," IEEE Internet of Things Journal, vol. 10, no. 5, pp. 4059–4092, 2023, doi: 10.1109/JIOT.2022.3203249.
[11] S. A. Hasan and M. A. Mohammed, "Enhancing IoT anomaly detection using hybrid CNN-LSTM model and interpretable feature selection," Zanco Journal of Pure and Applied Sciences, vol. 37, no. 6, pp. 161–181, 2025, doi: 10.21271/ZJPAS.37.6.13.
[12] H. C. Altunay and Z. Albayrak, "A hybrid CNN+LSTM-based intrusion detection system for industrial IoT networks," Engineering Science and Technology, an International Journal, vol. 38, Art. no. 101322, 2023, doi: 10.1016/j.jestch.2022.101322.
[13] X. H. Nguyen, X. D. Nguyen, H. H. Huynh, and K. H. Le, "Realguard: A lightweight network intrusion detection system for IoT gateways," Sensors, vol. 22, no. 2, Art. no. 432, 2022, doi: 10.3390/s22020432.
[14] S. Thiruchelvam, D. Jayaraman, S. Sellamuthu, and S. I. Perumal, "A secure framework for MIoT: TinyML-powered emergency alerts and intrusion detection for secure real-time monitoring," in Proc. 2024 8th Int. Conf. on I-SMAC, IEEE, 2024, pp. 13–21, doi: 10.1109/I-SMAC61858.2024.10714760.
[15] M. M. Shtayat, M. K. Hasan, R. Sulaiman, S. Islam, and A. U. R. Khan, "An explainable ensemble deep learning approach for intrusion detection in industrial Internet of Things," IEEE Access, vol. 11, pp. 115047–115061, 2023, doi: 10.1109/ACCESS.2023.3323573.
[16] S. Sivamohan, S. Sridhar, and S. Krishnaveni, "TEA-EKHO-IDS: An intrusion detection system for industrial CPS with trustworthy explainable AI and enhanced krill herd optimization," Peer-to-Peer Networking and Applications, vol. 16, no. 4, pp. 1993–2021, 2023, doi: 10.1007/s12083-023-01507-8.