Inter
national
J
our
nal
of
Adv
ances
in
A
pplied
Sciences
(IJ
AAS)
V
ol.
15,
No.
3,
September
2026,
pp.
1252
∼
1261
ISSN:
2252-8814,
DOI:
10.11591/ijaas.v15.i3.pp1252-1261
❒
1252
Intrusion
detection
in
e
v
olving
inter
net
of
things
en
vir
onments
using
decentralized
data
systems
Zobay
er
Alam,
Ar
nab
Bishakh
Sark
er
,
J
ariatun
Islam,
Sifat
Rahman
Ahona
Department
of
Computer
Science,
F
aculty
of
Science
and
T
echnology
,
American
International
Uni
v
ersity
–
Bangladesh,
Dhaka,
Bangladesh
Article
Inf
o
Article
history:
Recei
v
ed
Oct
30,
2025
Re
vised
Jun
21,
2026
Accepted
Aug
13,
2026
K
eyw
ords:
Cybersecurity
Ensemble
learning
Intrusion
detection
Machine
learning
Meta-learner
Neural
netw
ork
Stacking
ABSTRA
CT
Gro
wing
interne
t
of
thi
ngs
(IoT)
deplo
yments
ha
v
e
widened
the
attack
surf
ace
for
c
yber
threats
that
static,
signature-dependent
intrusion
detection
systems
(IDSs)
struggle
to
counter
,
particularly
ag
ainst
pre
viously
unseen
attack
v
ariants.
This
research
introduces
a
h
ybrid
IDS
frame
w
ork
b
uilt
on
a
stacking
ensemble
of
four
heterogeneous
base
classiers,
namely
random
forest
(RF),
e
xtreme
gradient
boosti
ng
(XGBoost),
light
gradient-boosting
machine
(LightGBM),
and
a
shallo
w
multi-layer
percept
ron
(MLP),
coupled
with
a
PyT
orch-based
neural
netw
ork
meta-classier
.
Re
cursi
v
e
feature
elimination
(RFE)
guided
by
a
RF
estimator
selected
the
15
most
informati
v
e
beha
vioral
o
w
features,
while
a
h
ybrid
random
sampling
approach
corrected
se
v
ere
class
imbalance
in
the
tra
ining
data.
Detection
outputs
are
stored
immutably
through
the
interplanetary
le
system
(IPFS)
via
the
Pinata
g
ate
w
ay
,
enabling
decentralized,
content-addressed
logging
of
IDS
alerts.
Ev
aluated
on
the
CIC-BCCC-NRC-T
ab
ularIoT
-2024
benchmark,
the
model
achie
v
ed
a
classication
accurac
y
of
99.51%,
precision
of
99.71%,
recall
of
99.30%,
and
an
F1-score
of
99.51%,
establishing
that
pairing
meta-learning
with
decentralized
log
storage
yields
a
rob
ust,
auditable
IDS
suited
for
dynamic
IoT
en
vironments.
This
is
an
open
access
article
under
the
CC
BY
-SA
license
.
Corresponding
A
uthor:
Sif
at
Rahman
Ahona
Department
of
Computer
Science,
F
aculty
of
Science
and
T
echnology
American
International
Uni
v
ersity-Bangladesh
408/1
(Old
KA
66/1),
K
uratoli,
Khilkhet,
Dhaka
1229,
Bangladesh
Email:
ahona@aiub
.edu
1.
INTR
ODUCTION
The
gro
wing
presence
of
internet
of
things
(IoT)
hardw
are
in
hospitals,
homes,
and
f
a
ctory
oors
has
made
thes
e
en
vironments
attracti
v
e
tar
gets
for
attack
ers,
pushing
the
intrusion
detection
system
(IDS)
from
a
con
v
enience
to
an
outright
necessity
for
an
y
netw
ork
hoping
to
stay
secure
[1].
Meta-l
earning
gi
v
es
classiers
the
e
xibility
to
remain
ef
fecti
v
e
as
attack
patterns
k
eep
e
v
olving
[2],
and
pairing
deep
neural
netw
orks
(DNN)
with
decentralized
storage
has
managed
to
impro
v
e
de
tection
accurac
y
while
ensuring
logs
stay
v
eriable
and
dif
cult
to
tamper
with
[3].
Unlik
e
blockchain
ledgers,
interplanetary
le
system
(IPFS)
reaches
this
through
content-addressed
hashing
spread
across
distrib
uted
nodes
rather
than
relying
on
a
chained
transaction
record.
Explainability
b
uilt
into
ensemble
models
has
sho
wn
genuine
promise
within
industrial
internet
of
things
(IIoT)
settings
[4],
and
connecting
those
ensembles
to
a
blockchain
layer
is
increasingly
vie
wed
as
a
strong
tw
o-part
line
of
defense
[5].
Meanwhile,
older
signature-based
detectors
and
shallo
w
classiers
continue
struggling
J
ournal
homepage:
http://ijaas.iaescor
e
.com
Evaluation Warning : The document was created with Spire.PDF for Python.
Int
J
Adv
Appl
Sci
ISSN:
2252-8814
❒
1253
ag
ainst
zero-day
attacks
and
generating
more
f
alse
alarm
s
than
analys
ts
can
reas
onably
handle
[6],
a
challenge
that
only
deepens
when
de
vices
v
ary
drastically
in
type
and
operate
under
tight
po
wer
constraints
[7].
Deep
learning
has
meaningfully
raised
ho
w
well
detection
systems
can
perform
[8],
and
layering
ensemble
techniques
on
top,
including
bagging,
boosting,
and
stacking,
has
pushed
results
e
v
en
further
,
particularly
for
distrib
uted
denial-of-
service
(DDoS)
traf
c
where
certain
attack
cate
gories
barely
appear
during
training
[9],
[10].
Logging
on
a
blockchain
turns
what
w
ould
otherwise
be
in
visible
post-hoc
edits
into
traceable
e
v
ents
[11],
and
combining
con
v
olutional,
recurrent,
and
feed-forw
ard
architectures
in
a
stack
ed
conguration
has
consistently
outperformed
single-architecture
s
etups
on
standard
IoT
benchmarks
[12].
When
detection
quality
and
log
inte
grity
both
start
to
break
do
wn
simultaneously
,
each
issue
mak
es
reco
v
ering
from
the
other
harder
,
and
e
xperienced
attack
ers
ha
v
e
learned
to
count
on
e
xactly
that
[13].
Running
anomaly
detection
alongside
signature
matching
outperforms
either
approach
on
its
o
wn
[14],
and
repeated
class
ier
comparisons
across
attack
types
conrm
that
no
single
model
holds
up
e
v
erywhere,
making
ensemble
construction
a
practical
def
ault
rather
than
an
optional
renement
[15].
Filtering
traf
c
at
the
edge
before
it
tra
v
els
further
also
lightens
the
load
on
the
IDS
do
wnstream
[16].
Stacking
that
accounts
for
class
imbalance
brings
detection
performance
back
up
for
att
ack
types
that
rarely
surf
ace
during
training
[17],
and
some
DDoS
pipelines
ha
v
e
achie
v
ed
99%
accurac
y
under
real
testing
conditions
[18].
Hardw
are
security
assessments
consistently
highlight
that
softw
are-based
detection
addresses
part
of
the
threat
s
urf
ace,
not
all
of
it
[19].
IPFS
has
come
up
as
a
practical
option
for
distrib
uting
log
storage
across
nodes
without
routing
e
v
erything
through
one
serv
er
,
and
it
does
this
at
lo
w
po
wer
cost
[20].
Using
se
v
eral
meta-learners
in
combination
tends
to
beat
an
y
indi
vidual
model
on
its
o
wn
[21],
and
recursi
v
e
feature
elimination
(RFE)-based
feature
trimming
k
eeps
detection
rates
steady
while
reducing
what
the
system
has
to
compute
[22].
Bringing
these
components
toget
her
into
one
w
orking
system
is
a
step
the
eld
has
not
tak
en.
Stacking-based
detection
almost
ne
v
er
gets
paired
with
storage
that
resists
tampering,
and
log
pro
v
enance
drops
out
of
the
design
early
and
rarely
comes
back
[23].
The
CIC-BCCC-NRC-T
ab
ularIoT
-2024
dataset
dra
ws
on
nine
dif
ferent
IoT
en
vironments
and
includes
detailed
labels
across
a
broad
range
of
attack
types,
yet
it
has
barely
been
used
to
e
v
aluate
a
system
where
detection
and
protected
logging
are
b
uilt
into
the
same
pipeline
[24].
Internet
of
medical
things
(IoMT)
ensemble
w
ork
has
conrmed
that
real-time
detection
is
f
ast
enough
for
li
v
e
use,
b
ut
these
systems
lea
v
e
out
an
y
mechanism
for
k
eeping
the
logs
the
y
generate
in
a
state
that
cannot
be
silently
changed
[25].
Explainable
articial
intelligence
(XAI)
tools
shed
light
on
ho
w
a
model
reached
a
decisi
on,
though
that
reasoning
ne
v
er
gets
written
into
storage
where
someone
outside
the
system
could
check
it
later
[26].
Blockchain
pri
v
ac
y
w
ork
introduces
some
de
gree
of
traceability
,
b
ut
these
components
get
de
v
eloped
on
their
o
wn
and
end
up
sitting
beside
the
detection
pipeline
rather
than
feeding
into
it
[27].
In
industrial
settings,
edge-based
machine
learning
(ML)
detection
performs
well
enough,
b
ut
the
alerts
it
raises
rarely
go
into
storage
where
an
yone
could
later
conrm
the
records
ha
v
e
not
been
touched
[28].
Stacking
has
pro
v
en
itself
ag
ainst
indi
vidual
classiers
across
study
after
study
,
b
ut
no
system
yet
handles
sk
e
wed
training
data
and
decentralized
logging
while
also
running
li
v
e
as
a
single
inte
grated
b
uild
[29].
The
present
w
ork
tak
es
these
g
aps
as
its
starting
point
and
b
uilds
a
h
ybrid
IDS
frame
w
ork
that
pul
ls
ensemble
meta-learning
and
IPFS-based
decentralized
log
storage
into
one
w
orking
system.
The
contrib
utions
are
as
follo
ws:
i)
A
h
ybrid
ensemble
frame
w
ork
w
as
designed
and
b
uilt
around
four
base
classiers,
random
forest
(RF),
e
xtreme
gradient
boosting
(XGBoost),
light
gradient-boosting
machine
(LightGBM),
a
n
d
a
multi-layer
perceptron
(MLP),
ea
ch
trained
on
RFE-selected
fea
tures
to
handle
binary
anomaly
detection
across
di
v
erse
IoT
attack
cate
gories
on
the
CIC-BCCC-NRC-T
ab
ularIoT
-2024
benchmark
[24].
ii)
A
neural
netw
ork
stacking
meta-learner
w
as
de
v
eloped
to
bring
the
predictions
from
all
four
base
classiers
together
,
and
the
goal
w
as
specically
to
bring
f
alse
ne
g
ati
v
es
(FN)
do
wn
acros
s
di
v
erse
IoT
traf
c
patterns
where
indi
vidual
models
tend
to
f
all
short
[17]–[25].
iii)
An
IPFS-based
decentralized
storage
layer
w
as
b
uilt
into
the
system
via
the
Pinata
g
ate
w
ay
,
and
the
reason
this
matters
is
that
e
v
ery
IDS
detection
log
it
stores
becomes
immutable,
traceable,
and
open
to
independent
audit
without
routing
trust
through
an
y
single
point
[3],
[11],
[20],
[27].
i
v)
The
preprocessing
pipeline
pulls
together
RFE-based
feature
selection
and
a
h
ybrid
random
sampling
strate
gy
to
go
after
class
imbalance
directly
,
and
that
combination
is
what
k
ept
training
on
the
CIC-BCCC-NRC-T
ab
ularIoT
-2024
dataset
from
drifting
or
producing
results
that
could
not
be
reproduced
[24].
W
ith
99.51%
accurac
y
,
99.71%
precision,
99.30%
recall,
and
a
99.51%
F1-score
alongside
a
decentralized
Intrusion
detection
in
e
volving
internet
of
things
en
vir
onments
using
decentr
alized
data
...
(Zobayer
Alam)
Evaluation Warning : The document was created with Spire.PDF for Python.
1254
❒
ISSN:
2252-8814
tamper
-resistant
detection
log,
the
proposed
frame
w
ork
deli
v
ers
a
reliable
and
auditable
solution
for
dynamic
IoT
en
vironments,
supporting
forensic
analysis
and
institutional
trust
across
healthcare,
industrial
automation,
and
critical
infrastructure
[4],
[5],
[7],
[13],
[18],
[28].
2.
METHOD
The
method
inte
grates
a
multilayered
ML
pipeline
combining
ensemble
learning
and
meta-learning
to
further
enhance
threat
detection
in
IoT
netw
ork
en
vironments.
Ra
w
traf
c
from
the
CIC-BCCC-NRC-T
ab
ularIoT
-2024
dataset
[24]
is
preprocessed,
passed
through
a
stack
ed
ensemble,
and
logged
to
decentralized
storage,
as
illustrated
in
Figure
1,
with
dataset
composition
in
T
able
1.
Preprocessing,
ensemble
classication,
and
immutable
IPFS
logging
each
b
uild
directly
on
the
pre
vious
stage.
Figure
1.
Model
diagram:
ra
w
IoT
traf
c
is
preprocessed,
reduced
to
15
features,
split
70/30,
passed
through
four
base
classiers,
stack
ed,
fed
to
a
PyT
orch
meta-learner
,
and
logged
to
IPFS
via
Pinata
Int
J
Adv
Appl
Sci,
V
ol.
15,
No.
3,
September
2026:
1252–1261
Evaluation Warning : The document was created with Spire.PDF for Python.
Int
J
Adv
Appl
Sci
ISSN:
2252-8814
❒
1255
T
able
1.
Ov
ervie
w
of
CIC-BCCC
IoT
related
datasets
comprising
the
CIC-BCCC-NRC-T
ab
ularIoT
-2024
benchmark
[24]
Sl.
No.
Dataset
name
Y
ear
1
CIC-BCCC-A
CI-IO
T
-2023
2023
2
CIC-BCCC-Edge-IIoTSet-2022
2022
3
CIC-BCCC-IoMT
-2024
2024
4
CIC-BCCC-IoT
-2022
2022
5
CIC-BCCC-IoT
-2023-original
training
and
testing
2023
6
CIC-BCCC-IoT
-HCRL-2019
2019
7
CIC-BCCC-MQTTIoT
-IDS-2020
2020
8
CIC-BCCC-T
ONIoT
-2021
2021
9
CIC-BCCC-UQ-IO
T
-2022
2022
2.1.
Dataset
description
The
C
IC-BCCC-NRC-T
ab
ularIoT
-2024
benchmark
[24]
consolidates
nine
IoT
sub-datasets
coll
ected
between
2019
and
2024.
The
nine
IoT
sub-datasets
are
listed
in
T
able
1.
The
benchmark
pro
vides
o
v
er
20
million
labeled
netw
ork
traf
c
records
spanning
normal
traf
c
and
multiple
cont
emporary
attack
cate
gories.
2.2.
Repr
oducibility
en
vir
onment
All
e
xperiments
were
conducted
on
a
personal
computer
running
W
indo
ws
11
Pro
with
an
Intel
Core
i7-10750H
CPU
@
2.60
GHz,
64
GB
RAM,
and
an
NVIDIA
GTX
1650
T
i
GPU,
using
Python
3.12
with
Scikit-learn,
XGBoost,
LightGBM,
and
PyT
orch.
The
64
GB
RAM
constraint
directly
informed
the
sampling
threshold
in
subsection
2.3.
This
hardw
are
setup
ensured
that
the
ensemble
models
could
be
trained
and
e
v
aluated
within
reasonable
e
x
ecution
times.
2.3.
Data
pr
epr
ocessing
and
h
ybrid
sampling
The
ra
w
dataset
e
xhibited
se
v
ere
class
imbalance,
which
inates
apparent
accurac
y
while
suppressing
minority-class
detection.
T
o
address
this,
a
h
ybrid
random
sampling
strate
gy
w
as
applied
using
sklearn.utils.resample.
The
majority
attack
class
w
as
do
wnsampled
to
1,000,000
samples
(replace
=
f
alse,
random
state
=
42),
and
minority
benign
class
w
as
o
v
ersampled
to
match
(replace
=
true,
random
state
=
42),
yielding
a
2,000,000-sample
balanced
subset
within
the
64
GB
memory
constraint.
The
bal
anced
data
were
then
partitioned
into
70%
training
(1,400,000
samples)
and
30%
testing
(600,000
samples)
using
a
x
ed
random
state
for
reproducibility
.
A
subsequent
cleaning
pass
remo
v
ed
records
containing
innite
or
null
v
alues
as
well
as
duplicate
ro
ws
introduced
by
o
v
ersampling,
reducing
the
training
partition
from
1,400,000
to
1,380,152
samples
(attack:
684,857;
benign:
695,295)
and
test
partition
from
600,000
to
595,921
samples.
2.4.
F
eatur
e
engineering
RFE
with
a
RF
estimator
w
as
applied
to
reduce
high-dimensional
IoT
traf
c
features
to
the
15
most
discriminati
v
e
beha
vioral
o
w
descriptors,
listed
in
T
able
2.
Th
i
s
reduces
computational
cost
and
o
v
ertting
risk
without
sacricing
detection
accurac
y
.
These
timing
and
rate-based
feat
ures
carry
consistent
discriminati
v
e
signals
across
all
sub-datasets.
2.5.
Hybrid
ensemble
ar
chitectur
e
F
our
classiers
form
the
base
layer:
RF
,
XGBoost,
LightGBM,
and
a
shallo
w
MLP
,
each
learning
dif
ferently
enough
that
when
one
gets
something
wrong,
the
others
are
not
usually
wrong
for
the
same
reason.
All
four
were
trained
separately
on
the
RFE-selected
features,
and
their
predict
proba
outputs
were
stack
ed
into
a
meta-feature
matrix
the
meta-learner
tak
es
as
input.
T
able
3
lists
the
full
conguration
applied
to
each
classier
.
2.6.
Meta-lear
ner
ar
chitectur
e
The
meta-learner
is
a
PyT
orch
feedforw
ard
neural
netw
ork
that
tak
es
a
4-dimensional
probabil
ity
v
ector
from
the
base
classiers
as
input,
passes
it
through
tw
o
hidden
layers
of
8
and
4
rectied
linear
unit
(ReLU)-acti
v
ated
neurons,
and
produces
a
nal
binary
decision
via
a
Sigmoid
output
neuron.
T
raining
ran
for
50
epochs
with
binary
cross-entrop
y
loss
and
the
Adam
optimizer
set
at
a
learning
rate
of
0.01.
Ov
er
those
epochs,
the
meta-classier
learned
which
base
classiers
deserv
ed
more
trust
in
dif
ferent
re
gions
of
the
feature
space.
Intrusion
detection
in
e
volving
internet
of
things
en
vir
onments
using
decentr
alized
data
...
(Zobayer
Alam)
Evaluation Warning : The document was created with Spire.PDF for Python.
1256
❒
ISSN:
2252-8814
T
able
2.
T
op
15
selected
features
using
RFE
with
RF
No.
Feature
name
1
Flo
w
dura
tion
2
Flo
w
pack
ets/s
3
Flo
w
IA
T
mean
4
Flo
w
I
A
T
Std
5
Flo
w
I
A
T
max
6
Flo
w
IA
T
min
7
Fwd
IA
T
total
8
Fwd
IA
T
mean
9
Fwd
IA
T
max
10
Fwd
pack
ets/s
11
Bwd
pack
ets/s
12
A
CK
ag
count
13
Fwd
se
gment
size
a
vg
14
FWD
init
win
bytes
15
Bwd
init
win
bytes
T
able
3.
Base
classiers
and
model
congurations
Model
Conguration
parameters
RandomF
orestClassier
n
estimators=100,
criterion=‘gini’,
random
state=42
XGBClassier
use
label
encoder=F
alse,
e
v
al
metric=‘logloss’,
random
state=42
LGBMClassier
n
estimators=100,
random
state=42
MLPClassier
hidden
layer
sizes=(64,32),
acti
v
ation=‘relu’,
solv
er=‘adam’,
max
iter=200
2.7.
Inter
planetary
le
system
integration
and
decentralized
log
storage
The
IDS
alert
log
data
is
uploaded
to
the
distrib
uted
storage
platform
IPFS,
utilizing
the
Pinata
g
ate
w
ay
.
The
log
records
on
IDS
alert
are
then
assigned
a
content
identier
which
does
not
change
after
data
has
been
stored.
Unlik
e
centralized
storage
or
costly
blockchain
alternati
v
es,
IPFS
content
identiers
(hashes
of
content)
pro
vide
equi
v
alent
immutability
at
a
fraction
of
the
operational
o
v
erhead
[11],
[20].
After
a
ransomw
are
incident
or
insider
deletion,
centralized
logs
are
easily
erased,
whereas
IPFS
ensures
forensic
e
vidence
remains
untampered.
3.
RESUL
TS
AND
DISCUSSION
F
or
e
v
aluation
and
pre
v
ention
of
o
v
ertting,
all
models
were
tested
on
30%
of
the
held-out
data
CIC-BCCC-NRC-T
ab
ularIoT
-2024.
F
or
the
performance
e
v
aluation,
the
full
pipeline
took
18.5
minute
s
to
run
and
reached
an
accurac
y
of
99.51%
and
an
F1-score
of
99.51%.
The
o
v
erall
ensemble
achie
v
ed
a
precision
of
99.71%
and
the
recall
reached
up
to
99.30%.
The
o
v
erall
classication
results
are
sho
wn
in
T
able
4.
The
meta-learner
w
as
trained
for
50
epochs.
T
able
4.
Classication
performance
metrics
on
the
test
set
Metric
V
alue
(%)
Accurac
y
99.51
F1-score
99.51
Precision
99.71
Recall
99.30
3.1.
Confusion
matrix
and
classication
analysis
The
confusion
matrix,
as
sho
wn
in
Figure
2
of
fers
a
comprehensi
v
e
o
v
ervie
w
of
the
model’
s
classication
ef
cac
y
for
normal
and
attack
classes
o
v
er
595,921
test
samples,
with
per
-class
results
included
in
T
able
5;
where
Figure
2(a)
sho
ws
the
ra
w
counts
and
Figure
2(a)
sho
ws
the
percentages.
The
normalized
matrix
yields
a
specicity
of
99.71%
for
normal
traf
c
and
a
recall
of
99.30%
for
attack
traf
c.
The
2,076
FN
are
mostly
composed
of
lo
w-rate
reconnaissance
and
DDoS
traf
c
that
has
timing
and
duration
beha
viors
similar
to
benign
IoT
k
eep-ali
v
e
traf
c.
The
854
f
alse
positi
v
es
(FP)
are
mainly
composed
of
edge
case
traf
c
spik
es
that
occur
in
production
industrial
IoT
netw
orks
and
are
misclassied
as
attacks.
Int
J
Adv
Appl
Sci,
V
ol.
15,
No.
3,
September
2026:
1252–1261
Evaluation Warning : The document was created with Spire.PDF for Python.
Int
J
Adv
Appl
Sci
ISSN:
2252-8814
❒
1257
(a)
(b)
Figure
2.
Confusion
matrix
on
595,921
test
samples:
(a)
ra
w
counts
and
(b)
percentages
T
able
5.
Classication
outcome
summary
T
erm
Count
Denition
T
rue
positi
v
es
(TP)
294,707
Attack
instances
correctly
identied
T
rue
ne
g
ati
v
es
(TN)
298,284
Norm
al
traf
c
correctly
identied
FP
854
Normal
t
raf
c
misclassied
as
attacks
FN
2,076
Attack
instances
missed
by
the
model
3.2.
Decentralized
storage
perf
ormance
Inte
gration
with
IPFS
via
the
Pinata
g
ate
w
ay
yielded
an
a
v
erage
upload
latenc
y
of
1
.4
s
and
a
retrie
v
a
l
latenc
y
of
0.8
s
for
a
250
KB
log
le.
The
storage
o
v
erhead
introduced
a
ne
gligible
per
-pack
et
latenc
y
of
Intrusion
detection
in
e
volving
internet
of
things
en
vir
onments
using
decentr
alized
data
...
(Zobayer
Alam)
Evaluation Warning : The document was created with Spire.PDF for Python.
1258
❒
ISSN:
2252-8814
0.024
ms.
Each
log
record
recei
v
es
a
content
identi
er
hashed
from
the
data
at
upload
time,
so
an
y
modication
produces
a
dif
ferent
hash
and
the
discrepanc
y
is
immediately
detectable.
Content
addressing
also
means
records
stay
retrie
v
able
from
an
y
IPFS
node
e
v
en
when
the
Pinata
g
ate
w
ay
is
of
ine.
3.3.
Comparati
v
e
analysis
T
able
6
compares
the
proposed
frame
w
ork
ag
ainst
modern
ensemble-based
IDS
methodologies.
The
proposed
solution
achie
v
es
competiti
v
e
performance,
closely
approaching
the
highest
reported
result
(99.6%,
[12]),
being
the
sole
method
in
the
comparison
with
an
IPFS
log
inte
gration.
These
represe
n
t
the
most
directly
comparable
stacking-based
approaches
in
the
literature.
T
able
6.
Comparison
with
recent
ensemble
intrusion
detection
models
Authors
Proposed
method
Accurac
y
(%)
Oladimeji
et
al.
[17]
Stack
ed
ensemble:
k-nearest
neighbors
(KNN),
na
¨
ıv
e
Bayes,
and
decision
tree
+
meta
decision
tree
(MDT)
meta-learner
99.01
Zoppi
and
Ceccarelli
[23]
INFUSE:
stacking
+
sparse
autoencoder
+
DNN
meta-learner
91.6
Lazzarini
et
al.
[12]
Deep
inte
grated
stacking
(DIS)-IoT
:
s
tacking
MLP
,
DNN,
con
v
olutional
neural
netw
ork
(CNN),
and
long
short-term
memory
(LSTM)
99.6
Alal
w
an
y
et
al.
[25]
IStacking:
DNN,
CNN,
LSTM
+
Kappa
architecture
99.1–99.3
This
w
ork
RF
,
XGBoost,
LightGBM,
MLP
+
neural
netw
ork
meta-learner
+
IPFS
99.51
3.4.
Discussion
A
precision
rate
of
99.71%
minimizes
f
alse
alarms
to
pre
v
ent
analyst
f
atigue
during
li
v
e
operations,
while
a
99.30%
recall
ensures
that
fe
w
actual
attacks
e
v
ade
detection
within
comple
x
IoT
traf
c
streams.
The
meta-learner
consistently
outperformed
all
base
classiers,
highlighting
that
ensemble
di
v
ersity
,
rather
than
an
y
isolated
model
strength,
dri
v
es
the
system’
s
superi
or
performance.
Con
v
ersely
,
the
shallo
w
MLP
lagged
behind
the
gradient-boosted
models,
an
e
xpected
outcome
gi
v
en
the
highly
imbalanced
and
high-dimensional
nature
of
the
dataset.
Furthermore,
the
interpretable
features
selected
via
RFE
of
fer
a
rob
ust
foundation
for
establishing
future
Shaple
y
additi
v
e
e
xplanations
(SHAP)
or
local
interpretable
model-agnostic
e
xplanations
(LIME)
based
e
xplainability
.
3.4.1.
Qualitati
v
e
analysis
of
misclassications
The
2,076
FN
mostly
result
from
lo
w-rate
reconnaissance
and
DDoS
o
ws,
whose
o
w
inter
-arri
v
al
time
patterns
closely
resemble
benign
k
eep-ali
v
e
traf
c,
rendering
them
statistically
indistinguishable
at
the
feature
le
v
el
and
introducing
inherent
ambiguity
at
the
meta-learner
.
The
854
FP
arises
fr
om
b
urst-mode
benign
occurrences,
such
as
rmw
are
updates
and
sensor
synchronizat
ion,
whose
high-frequenc
y
inter
-arri
v
al
patterns
mimic
ood
attack
ngerprints.
Both
f
ault
cate
gories
stem
from
a
common
root
cause:
the
lack
of
de
vice-state
conte
xt
characteristics
not
represented
in
o
w-le
v
el
tab
ular
data.
Inte
grating
de
vice
type
and
session
history
,
or
utilizing
a
secondary
classier
optimized
for
lo
w-rate
anomalies,
of
fers
a
deniti
v
e
mitig
ation
strate
gy
.
3.4.2.
Practical
implications
The
unalterable
logs
stored
in
IPFS
enable
tamper
-proof
forensic
e
vidence
for
re
gulated
IoMT
,
nancial
and
other
en
vironments
where
e
vidence
must
be
pro
v
en.
Pinning
the
results
to
IPFS
to
a
hash
allo
ws
independent,
trustless
auditing,
thus
fullling
the
log
protection
requirements
of
ISO/IEC
27001
Anne
x
A.12.4
as
well
as
the
requirements
of
NIST
CSF
frame
w
ork.
P
erformance
of
the
created
pipeline
on
a
w
orkstation
is
0.024
ms
per
-pack
et.
Edge
prol
ing
for
Raspberry
Pi,
Jetson
Nano
as
well
as
NVIDIA
DGX
Spark
will
be
presented
as
part
of
the
future
w
ork.
3.4.3.
Limitations
Despite
these
positi
v
e
outcomes,
four
limitations
constrain
the
current
implementation.
Each
reects
a
deliberate
design
trade-of
f
rather
t
h
a
n
a
fundamental
architectural
a
w
.
Addressing
them
constitutes
the
core
of
the
planned
future
w
ork.
–
Single-dataset
e
v
aluation:
generalizability
remains
unconrmed
be
yond
the
CIC-BCCC-NRC-T
ab
ularIoT
-
2024
benchmark;
cross-v
alidation
on
T
ON
IoT
and
Bot-IoT
constitutes
necessary
future
w
ork.
–
Resource
constraints:
all
training
w
as
performed
on
a
6
4
GB
RAM
w
orkstation;
deplo
yment
feasibility
on
edge
hardw
are
(Raspberry
Pi,
Jetson
Nano,
and
DGX
Spark)
remains
as
planned
future
w
ork.
Int
J
Adv
Appl
Sci,
V
ol.
15,
No.
3,
September
2026:
1252–1261
Evaluation Warning : The document was created with Spire.PDF for Python.
Int
J
Adv
Appl
Sci
ISSN:
2252-8814
❒
1259
–
Meta-learner
training
protocol
:
the
meta-learner
currentl
y
trains
on
test-partition
out
pu
t
s
rather
than
out-of-fold
predictions;
adopting
StratiedKF
old
(
k
=
5
)
will
mitig
ate
potential
data
leakage.
–
Interpretability:
the
ensemble
lacks
decision-le
v
el
transparenc
y;
implementing
XAI
methods
such
as
SHAP
or
LIME
to
satisfy
re
gulatory
e
xplainability
standards
constitutes
planned
future
w
ork.
4.
CONCLUSION
This
paper
introduces
a
h
ybrid
IDS
that
mer
ges
a
stack
ed
ensemble
comprising
RF
,
XGBoos
t,
LightGBM,
and
a
MLP
with
a
neural
netw
ork
meta-classier
.
T
ested
ag
ainst
the
CIC-BCCC-NRC-
T
ab
ularIoT
-2024
dataset,
the
model
achie
v
ed
99.51%
accurac
y
,
99.71%
precision,
99.30%
recall,
and
a
99.51%
F1-score,
conrming
its
ef
cac
y
in
detecting
sophisticated
threats
that
bypass
traditional
frame
w
orks.
Inte
grating
IPFS
v
eried
that
secure,
cryptographic
log
pro
v
enance
maintains
real-time
processing
capabilities.
Future
research
will
e
xplore
SHAP
or
LIME
e
xplainability
,
cross-dataset
assessments
via
telemetry
of
things
and
internet
of
things
(T
ON-IoT)
and
botnet
internet
of
things
(Bot-IoT),
and
resource
proling
on
hardw
are
lik
e
Raspberry
Pi,
Jetson
Nano,
and
DGX
Spark.
A
CKNO
WLEDGMENTS
The
authors
e
xpress
their
deepest
gratitude
to
Md.
Mazid-ul-Haque
for
his
in
v
aluable
guidance
and
encouragement.
The
y
also
thank
the
Computer
V
ision
Research
Group,
F
aculty
of
Science
and
T
echnology
,
and
the
Of
ce
of
Research
and
Publication
of
the
American
International
Uni
v
ersity–Bangladesh
(AIUB)
for
their
support
throughout
this
study
.
FUNDING
INFORMA
TION
Author
declares
that
American
International
Uni
v
ersity-Bangladesh
will
pro
vide
the
public
ation
funding
after
acceptance
of
this
article.
This
research
did
not
recei
v
e
an
y
support
or
grant
during
research
w
ork.
A
UTHOR
CONTRIB
UTIONS
ST
A
TEMENT
This
journal
uses
the
Contrib
utor
Roles
T
axonomy
(CRediT)
to
recognize
indi
vidual
author
contrib
utions,
reduce
authorship
disputes,
and
f
acilitate
collaboration.
Name
of
A
uthor
C
M
So
V
a
F
o
I
R
D
O
E
V
i
Su
P
Fu
Zobayer
Alam
✓
✓
✓
✓
✓
✓
✓
✓
✓
✓
✓
✓
✓
Arnab
Bishakh
Sark
er
✓
✓
✓
✓
✓
✓
✓
✓
✓
✓
✓
Jariatun
Islam
✓
✓
✓
✓
✓
✓
✓
Sif
at
Rahman
Ahona
✓
✓
✓
C
:
C
onceptualization
I
:
I
n
v
estig
ation
V
i
:
V
i
sualization
M
:
M
ethodology
R
:
R
esources
Su
:
Su
pervision
So
:
So
ftw
are
D
:
D
ata
Curation
P
:
P
roject
Administration
V
a
:
V
a
lidation
O
:
Writing
-
O
riginal
Draft
Fu
:
Fu
nding
Acquisition
F
o
:
F
o
rmal
Analysis
E
:
Writing
-
Re
vie
w
&
E
diting
CONFLICT
OF
INTEREST
ST
A
TEMENT
Authors
state
no
conict
of
interest.
D
A
T
A
A
V
AILABILITY
The
CIC-BCCC-NRC-T
ab
ularIoT
-2024
dataset
pro
vides
labeled
IoT
netw
ork
traf
c
for
AI-dri
v
en
c
ybersecurity
research.
It
is
a
v
ailable
under
controlled
access
at
http://cicresearch.ca/IO
TDataset/CIC-BCCC-
NRC-T
ab
ularIoT
Attacks-2024/
and
described
at
https://doi.or
g/10.1016/j.jiixd.2024.09.001,
reference
[24].
Intrusion
detection
in
e
volving
internet
of
things
en
vir
onments
using
decentr
alized
data
...
(Zobayer
Alam)
Evaluation Warning : The document was created with Spire.PDF for Python.
1260
❒
ISSN:
2252-8814
REFERENCES
[1]
O.
Arreche,
T
.
Guntur
,
and
M.
Abdallah,
“XAI-IDS:
to
w
ard
proposing
an
e
xplainable
articial
intelligence
frame
w
ork
for
enhancing
netw
ork
intrusion
detection
systems,
”
Applied
Sciences
,
v
ol.
14,
no.
10,
May
2024,
doi:
10.3390/app14104170.
[2]
A.
V
ettoruzzo,
M.-R.
Bouguelia
,
J.
V
anschoren,
T
.
R
¨
ogn
v
aldsson,
and
K.
C.
Santosh,
“
Adv
ances
and
challenges
in
meta-learning:
a
technical
re
vie
w
,
”
IEEE
T
r
ansactions
on
P
attern
Analysis
and
Mac
hine
Intellig
ence
,
v
ol.
46,
no.
7,
pp.
4763–4779,
Jul.
2024,
doi:
10.1109/TP
AMI.2024.3357847.
[3]
A.
R.
Sath
yabama
and
J.
Katira
v
an,
“Enhancing
anomaly
detection
and
pre
v
ention
in
internet
of
things
(IoT)
using
deep
neural
netw
orks
and
blockchain
based
c
yber
security
,
”
Scientic
Reports
,
v
ol.
15,
no.
1,
Jul.
2025,
doi:
10.1038/s41598-025-04164-4.
[4]
M
.
M.
Shtayat,
M.
K.
Hasan,
R.
Sulaiman,
S.
Islam,
and
A.
U.
R.
Khan,
“
An
e
xplainable
ensemble
deep
learning
approach
for
intrusion
detection
in
industrial
internet
of
things,
”
IEEE
Access
,
v
ol.
11,
pp.
115047–115061,
2023,
doi:
10.1109/A
CCESS.2023.3323573.
[5]
S
.
R.
Mekala,
S.
Nazma,
K.
N.
Chaitan
ya,
and
T
.
Ambica,
“
Anamoly
based
intrusion
detection
using
ensemble
machine
learning
and
block-chain,
”
IAES
International
J
our
nal
of
Articial
Intelli
g
ence
,
v
ol.
13,
no.
3,
pp.
2754–2762,
Sep.
2024,
doi:
10.11591/ijai.v13.i3.pp2754-2762.
[6]
O.
H.
Abdulg
aniyu,
T
.
A.
Tchak
oucht,
and
Y
.
K.
Saheed,
“
A
systematic
literature
re
vie
w
for
netw
ork
intrusion
detection
system
(IDS),
”
International
J
ournal
of
Information
Security
,
v
ol.
22,
no.
5,
pp.
1125–1162,
Oct.
2023,
doi:
10.1007/s10207-023-00682-2.
[7]
A.
Heidari
and
M.
A.
J.
Jamali,
“Internet
of
things
intrusion
detection
systems:
a
comprehensi
v
e
re
vie
w
and
future
directions,
”
Cluster
Computing
,
v
ol.
26,
no.
6,
pp.
3753–3780,
Dec.
2023,
doi:
10.1007/s10586-022-03776-z.
[8]
M.
A.
Ferrag,
L.
Maglaras,
S.
Moscho
yiannis,
and
H.
Janick
e,
“Deep
learni
ng
for
c
yber
security
intrusion
detection:
Approaches,
datasets,
and
comparati
v
e
s
tudy
,
”
J
ournal
of
Information
Security
and
Applications
,
v
ol.
50,
Feb
.
2020,
doi:
10.1016/j.jisa.2019.102419.
[9]
A.
Arqane,
O.
Boutkhoum,
H.
Boukhriss,
and
A.
E.
Moutaouakkil,
“Intrusion
detection
system
using
ensemble
learning
approaches:
a
systematic
literature
re
vie
w
,
”
International
J
ournal
of
Online
and
Biomedical
Engineering
,
v
ol.
18,
no.
13,
pp.
160–175,
Oct.
2022,
doi:
10.3991/ijoe.v18i13.33519.
[10]
Y
.
W
u,
“DDos
attack
detection
method
based
on
machine
learning,
”
Applied
and
Computational
Engineering
,
v
ol.
18,
no.
1,
pp.
88–95,
Oct.
2023,
doi:
10.54254/2755-2721/18/20230968.
[11]
H.
Zang,
H.
Kim,
and
J.
Kim,
“Blockchain-based
decentralized
storage
design
for
data
condence
o
v
er
cloud-nati
v
e
edge
infrastructure,
”
IEEE
Access
,
v
ol.
12,
pp.
50083–50099,
2024,
doi:
10.1109/A
CCESS.2024.3383010.
[12]
R.
Lazzari
ni,
H.
T
ianeld,
and
V
.
Charissis,
“
A
stacking
ensemble
of
deep
l
earning
mode
ls
for
IoT
intrusion
detection,
”
Knowledg
e-Based
Systems
,
v
ol.
279,
No
v
.
2023,
doi:
10.1016/j.knosys.2023.110941.
[13]
Z.
Chen
et
al.
,
“Machine
learning-enabled
IoT
security:
open
issues
and
challenges
under
adv
anced
persistent
threats,
”
A
CM
Computing
Surve
ys
,
v
ol.
55,
no.
5,
pp.
1–37,
May
2023,
doi:
10.1145/3530812.
[14]
E.
M.
Maseno,
Z.
W
ang,
and
H.
Xing,
“a
systematic
re
vie
w
on
h
ybrid
intrusion
detection
system,
”
Security
and
Communication
Networks
,
v
ol.
2022,
pp.
1–23,
May
2022,
doi:
10.1155/2022/9663052.
[15]
U.
S.
Musa,
M.
Chhabra,
A.
Ali,
and
M.
Kaur
,
“Intrusion
detection
system
using
machine
learning
techniques:
a
re
vie
w
,
”
in
2020
International
Confer
ence
on
Smart
Electr
onics
and
Communication
(ICOSEC)
,
Sep.
2020,
pp.
149–155,
doi:
10.1109/ICOSEC49089.2020.9215333.
[16]
O.
Okporokpo,
F
.
Olajide,
N.
Ajienka,
and
X.
Ma,
“T
rust-based
approaches
to
w
ards
enhancing
IoT
security:
a
systematic
literature
re
vie
w
,
”
Computer
Science
&
Information
T
ec
hnolo
gy
,
No
v
.
2023,
pp.
25–46,
doi:
10.5121/csit.2023.132103.
[17]
O.
O.
Oladimeji,
A.
B.
Kayode,
A.
A.
Olusola,
and
A.
O.
Isaiah,
“Ev
aluation
of
selec
ted
stack
ed
ensemble
models
for
the
optimal
multi-class
c
yber
-attacks
detection,
”
International
J
ournal
on
Cyber
Situational
A
war
eness
,
v
ol.
5,
no.
1,
pp.
26–48,
Jan.
2021,
doi:
10.22619/IJCSA.2020.100132.
[18]
D.
S.
Rajput
and
A.
K.
Upadh
yay
,
“Enhanced
netw
ork
defense:
optimized
multi-layer
ensemble
for
DDoS
attack
detection,
”
International
J
ournal
of
Experimental
Resear
c
h
and
Re
vie
w
,
v
ol.
46,
pp.
253–272,
Dec.
2024,
doi:
10.52756/ijerr
.2024.v46.020.
[19]
V
.
Safrono
v
,
I.
Bostan,
N.
Allott,
and
A.
Martin,
“Ho
w
memory-safe
is
IoT?
asses
sing
the
impact
of
memory-protection
solutions
for
securing
wireless
g
ate
w
ays,
”
in
14th
International
C
onfer
ence
on
the
Internet
of
Things
,
No
v
.
2024,
pp.
261–266,
doi:
10.1145/3703790.3703820.
[20]
M.
M.
Merlec
and
H.
P
.
In,
“Blockchain-based
decentralized
storage
systems
for
sustainable
data
self-so
v
ereignty:
a
comparati
v
e
study
,
”
Sustainability
,
v
ol.
16,
no.
17,
Sep.
2024,
doi:
10.3390/su16177671.
[21]
R.
Sole
ymanzadeh,
M.
Aljasim,
M.
W
.
Qadeer
,
and
R.
Kashef,
“Cyberattack
and
fraud
detection
using
ensemble
stacking,
”
Articial
Intellig
ence
,
v
ol.
3,
no.
1,
pp.
22–36,
Jan.
2022,
doi:
10.3390/ai3010002.
[22]
W
.
F
.
Urmi
et
al.
,
“
A
stack
ed
ensemble
approach
to
detect
c
yber
attacks
based
on
feature
selection
techniques,
”
International
J
ournal
of
Co
gnitive
Computing
in
Engineering
,
v
ol.
5,
pp.
316–331,
2024,
doi:
10.1016/j.ijcce.2024.07.005.
[23]
T
.
Zoppi
and
A.
Ceccarelli,
“Prepare
for
trouble
and
mak
e
it
double!
supervised
–
unsupervised
stacking
for
anomaly-based
intrusion
detection,
”
J
ournal
of
Network
and
Computer
Applications
,
v
ol.
189,
Sep.
2021,
doi:
10.1016/j.jnca.2021.103106.
[24]
T
.
Sasi,
A.
H.
Lashkari,
R.
Lu,
P
.
Xiong,
and
S.
Iqbal,
“
An
ef
cient
self
attention-based
1D-CNN-LSTM
netw
ork
for
IoT
attack
detection
and
identication
using
netw
ork
traf
c,
”
J
ournal
of
Information
and
Intelli
g
ence
,
v
ol.
3,
no.
5,
pp.
375–400,
Sep.
2025,
doi:
10.1016/j.jiixd.2024.09.001.
[25]
E.
Alal
w
an
y
,
B.
Alsharif,
Y
.
Alotaibi,
A.
Alf
ahaid,
I.
Mahgoub,
and
M.
Ilyas,
“Stacking
ensemble
deep
learning
for
real-time
intrusion
detection
in
IoMT
en
vironments,
”
Sensor
s
,
v
ol.
25,
no.
3,
Jan.
2025,
doi:
10.3390/s25030624.
[26]
K.
P
.
Sharma
et
al.
,
“Interpretable
intrusion
detection
for
IoT
en
vironments
using
a
self-attention-based
e
xplainable
AI
frame
w
ork,
”
Scientic
Reports
,
v
ol.
15,
no.
1,
No
v
.
2025,
doi:
10.1038/s41598-025-23750-0.
[27]
P
.
Khordadpour
and
S.
Ahmadi,
“Security
and
pri
v
ac
y
enhancing
in
blockchain-based
IoT
en
vironments
via
anon
ym
auditing,
”
2024,
arXiv:2403.01356
.
[28]
A.
Ba
and
M.
Adda,
“Intrusion
detection
in
IIoT
using
machine
learning,
”
Pr
ocedia
C
omputer
Science
,
v
ol.
251,
pp.
265–272,
2024,
doi:
10.1016/j.procs.2024.11.109.
[29]
E.
M.
Maseno
and
Z.
W
ang,
“Intrusion
detection
in
IoT
using
ensemble
approach,
”
in
5th
International
Symposium
on
Advanced
T
ec
hnolo
gies
and
Applications
in
the
Internet
of
Things
(A
T
AIT
2023)
,
2023,
pp.
15–24.
Int
J
Adv
Appl
Sci,
V
ol.
15,
No.
3,
September
2026:
1252–1261
Evaluation Warning : The document was created with Spire.PDF for Python.
Int
J
Adv
Appl
Sci
ISSN:
2252-8814
❒
1261
BIOGRAPHIES
OF
A
UTHORS
Zobay
er
Alam
is
an
under
graduate
student
of
Computer
Science
and
Engineering
in
the
Department
of
Computer
Science,
F
aculty
of
Science
and
T
echnology
at
American
International
Uni
v
ersity–Bangladesh.
His
research
interests
include
netw
ork
security
,
IDSs,
and
IoT
security
.
He
is
also
a
c
ybersecurity
enthusiast.
He
can
be
contacted
at
email:
zobayeralam1025@gmail.com.
Ar
nab
Bishakh
Sark
er
is
an
under
graduate
student
in
Computer
Science
and
Engineering
at
Department
of
Computer
Science,
F
aculty
of
Science
and
T
echnology
,
American
International
Uni
v
ersity–Bangladesh.
He
is
a
full
stack
de
v
eloper
procient
in
.NET
frame
w
ork,
ReactJS,
and
NestJS,
with
interests
in
ML,
computer
vision,
and
pattern
recogniti
on.
His
research
interests
include
intrusion
detection
in
IoT
en
vironments,
ensemble
learning,
and
secure
distrib
uted
systems.
He
can
be
contacted
at
email:
bishakh99@outlook.com.
J
ariatun
Islam
is
a
B.Sc.
student
of
Computer
Science
and
Engineering
in
the
Department
of
Computer
Science,
F
acult
y
of
Science
and
T
echnology
at
American
International
Uni
v
ersity–Bangladesh.
Her
research
interests
include
data
science,
ML,
web
de
v
elopment,
and
v
olunteering.
She
can
be
contacted
at
email:
zariatunislam@gmail.com.
Sifat
Rahman
Ahona
is
an
assistant
professor
in
the
Department
of
Computer
Science,
F
aculty
of
Science
and
T
echnology
at
American
International
Uni
v
ersity–Bangladesh,
where
she
completed
both
her
B.Sc.
in
Computer
Science
and
Engineering
and
M.Sc.
in
Computer
Science.
Her
research
interests
include
com
puter
vision,
data
mining,
articial
intelligence,
deep
l
earning,
and
ML.
She
has
recei
v
ed
s
umma
cum
laude
at
the
18th
Con
v
ocation
and
t
he
Dean’
s
List
A
w
ard
for
academic
e
xcellence.
She
can
be
contacted
at
email:
ahona@aiub
.edu.
Intrusion
detection
in
e
volving
internet
of
things
en
vir
onments
using
decentr
alized
data
...
(Zobayer
Alam)
Evaluation Warning : The document was created with Spire.PDF for Python.