An adaptive hybrid intrusion detection framework for industrial Iot: Architecture, datasets, and learning techniques

Loading...
Thumbnail Image

Journal Title

Journal ISSN

Volume Title

Publisher

University of New Brunswick

Abstract

The rapid proliferation of the Internet of Things (IoT) in industrial domains has led to the Industrial Internet of Things (IIoT), enabling unprecedented levels of automation, connectivity, and efficiency. However, the integration of heterogeneous sensors, embedded devices, and network infrastructures significantly expands the attack surface of cyber-physical systems and exposes them to diverse security threats. Securing these environments requires anomaly detection that is accurate, scalable, lightweight, and adaptive under real-time and resource-constrained conditions. This thesis proposes DeepSense, a hybrid multi-layer intrusion detection framework designed to provide scalable and adaptive IIoT anomaly detection. It integrates three components within a layered architecture. RuleSense performs lightweight rule-based detection at the network edge to rapidly filter suspicious activity with minimal overhead. NeuroSense applies machine learning and deep learning models for fine-grained attack classification and improved accuracy. DataSense provides an IIoT testbed and dataset with realistic benign traffic and 50 attack types across seven categories to support training and evaluation. Together, these components balance low-latency edge filtering with accurate large-scale analysis. To improve adaptability and operational efficiency, the framework further incorporates several supporting mechanisms. An adaptive scalable ensemble continuously monitors detection performance, identifies concept drift, and dynamically triggers model retraining or rule reprofiling as needed to maintain robustness under evolving attacks and constrained device coverage. A multi-objective feature selection method reduces dimensionality while preserving detection quality, improving computational efficiency and scalability. The thesis also introduces a performance evaluation framework that assesses IIoT anomaly detection across Detection Quality, Speed and Latency, Coverage, and Resource Usage. Using normalized metrics and multi-criteria decision-making, it supports fair comparison and ensemble selection. Experiments show that RuleSense exceeds 99% detection accuracy with minimal overhead, and NeuroSense achieves strong performance in both 8-class and 50-class settings. The adaptive ensemble further improves resilience under constrained deployment. Overall, DeepSense provides a principled and practical framework for IIoT anomaly detection by integrating lightweight edge-level filtering, intelligent learning-based classification, adaptive ensemble optimization, and systematic evaluation to address key limitations of existing IIoT security solutions and establishes a robust foundation for securing industrial systems against both known and emerging cyber threats.

Description

Keywords

Citation

Endorsement

Review

Supplemented By

Referenced By