Enhancing safety with IoT and machine learning: a novel smart safety net design

(1) * Shokhan M Al-Barzinji Mail (College of Computer Science and Information Technology, University of Anbar, Ramad, Iraq)
(2) Zahraa H Ameen Mail (Department of Computer Science, Al-Nukhba University College, Baghdad, Iraq)
(3) Noor Abdul Khaleq Zghair Mail (University of Technology, Baghdad, Iraq)
(4) Abubakr S Issa Mail (University of Technology, Baghdad, Iraq)
(5) Samer Raad Azzawie Mail (Department of Computer Sciences, University of Technology, Iraq)
(6) Ali Abdulateef Abdulbari Mail (University of Technology, Baghdad, Iraq)
*corresponding author

Abstract


The Internet of Things (IoT) represents a complex network of embedded devices that exchange data through heterogeneous communication technologies, making them increasingly vulnerable to sophisticated cyber attacks. This paper presents a hybrid Intrusion Detection System (HIDS) that integrates Extra Trees (ExtraTreesClassifier) for feature selection with four ensemble classifiers: XGBoost, CatBoost, AdaBoost, and Gradient Boosting. Our approach performs supervised feature selection exclusively on training data to prevent information leakage, applies class balancing for imbalanced datasets, and evaluates each hybrid model using comprehensive metrics including ROC-AUC, PR-AUC, false positive/negative rates, and Matthews Correlation Coefficient. We validate our methodology on three benchmark datasets with contrasting characteristics: UNSW-NB15 (real-world network traffic, 175K samples), IoTNet24 (laboratory-controlled traffic, 23K samples), and BoTNeTIoT-L01 (large-scale laboratory traffic, 2.4M samples). On UNSW-NB15, our best model (EXT-GB) achieves 87.73% accuracy, 0.90 F1-score, 0.98 ROC-AUC, and 98.58% recall with 1.42% false negative rate, representing realistic performance for production IDS. On laboratory datasets after addressing class imbalance, models achieve near-perfect performance (IoTNet24: 99.96%, BoTNeTIoT: 99.99%). The 12-percentage-point performance gap between real-world and laboratory data highlights a critical finding: controlled laboratory datasets significantly overestimate real-world IDS capability, underscoring the importance of evaluation on realistic traffic captures for assessing production deployment readiness.

Keywords


Iot, ids, hybrid ids, classification

   

DOI

https://doi.org/10.26555/ijain.v12i2.1856
      

Article metrics

Abstract views : 186 | PDF views : 11

   

Cite

   

Full Text

Download

References


[1] S. Li, L. Da Xu, and S. Zhao, “The internet of things: a survey,” Inf. Syst. Front., vol. 17, no. 2, pp. 243–259, Apr. 2015, doi: 10.1007/s10796-014-9492-7.

[2] N. Nazar Kamal, Q. F. Al-Doori, and O. Alani, “A Review of Modern and Recent Studies on the Low-Density Parity-Check Technology Approach,” Iraqi J. Comput. Commun. Control Syst. Eng., vol. 23, no. 1, pp. 165–178, Mar. 2023, doi: 10.33103/uot.ijccce.23.1.13.

[3] Y. M. Hussain et al., “Smartphone’s off grid communication network by using Arduino microcontroller and microstrip antenna,” TELKOMNIKA (Telecommunication Comput. Electron. Control., vol. 19, no. 4, p. 1100, Aug. 2021, doi: 10.12928/telkomnika.v19i4.15949.

[4] B. B. Zarpelão, R. S. Miani, C. T. Kawakani, and S. C. de Alvarenga, “A survey of intrusion detection in Internet of Things,” J. Netw. Comput. Appl., vol. 84, pp. 25–37, Apr. 2017, doi: 10.1016/j.jnca.2017.02.009.

[5] D. Barwal et al., “The impact of netflix recommendation engine on customer experience,” 2023, p. 060005, doi: 10.1063/5.0170916.

[6] M. Y. Zeain et al., “A New Technique of FSS-Based Novel Chair-Shaped Compact MIMO Antenna to Enhance the Gain for Sub-6GHz 5G Applications,” IEEE Access, vol. 12, pp. 49489–49507, 2024, doi: 10.1109/ACCESS.2024.3380013.

[7] A. Choudhary, “Internet of Things: a comprehensive overview, architectures, applications, simulation tools, challenges and future directions,” Discov. Internet Things, vol. 4, no. 1, p. 31, Dec. 2024, doi: 10.1007/s43926-024-00084-3.

[8] A. A. Abdulbari et al., “Single-Layer Planar Monopole Antenna-Based Artificial Magnetic Conductor (AMC),” Int. J. Antennas Propag., vol. 2022, pp. 1–9, Jul. 2022, doi: 10.1155/2022/6724175.

[9] L. Yan, Y. Diao, Z. Lang, and K. Gao, “Corrosion rate prediction and influencing factors evaluation of low-alloy steels in marine atmosphere using machine learning approach,” Sci. Technol. Adv. Mater., vol. 21, no. 1, pp. 359–370, Jan. 2020, doi: 10.1080/14686996.2020.1746196.

[10] Y. K. Saheed, “Performance Improvement of Intrusion Detection System for Detecting Attacks on Internet of Things and Edge of Things,” 2022, pp. 321–339, doi: 10.1007/978-3-030-80821-1_15.

[11] A. Adiwijaya and N. G. Ramadhan, “Analyzing risk factors and handling imbalanced data for predicting stroke risk using machine learning,” Int. J. Adv. Intell. Informatics, vol. 11, no. 1, p. 39, Feb. 2025, doi: 10.26555/ijain.v11i1.1678.

[12] A. S. Issa, Y. H. Ali, and T. A. Rashid, “BCDDO: Binary Child Drawing Development Optimization,” J. Supercomput., vol. 80, no. 11, pp. 16202–16221, Jul. 2024, doi: 10.1007/s11227-024-06088-8.

[13] A. F. Al-zubidi, A. K. Farhan, and E.-S. M. El-Kenawy, “Surveying Machine Learning in Cyberattack Datasets: A Comprehensive Analysis,” J. Soft Comput. Comput. Appl., vol. 1, no. 1, Jun. 2024, doi: 10.70403/3008-1084.1000.

[14] A. S. Issa, Y. H. Ali, and T. A. Rashid, “Review on Hybrid Swarm Algorithms for Feature Selection,” Iraqi J. Sci., pp. 5331–5344, Oct. 2023, doi: 10.24996/ijs.2023.64.10.38.

[15] A. A. Mosslah, R. H. Mahdi, and S. M. Al-Barzinji, “Performance Evaluation Of The Deep Learning System For Weed Recognization.” pp. 1–10, Dec. 28, 2023, doi: 10.21203/rs.3.rs-3791687/v1.

[16] H.-Y. Kwon, T. Kim, and M.-K. Lee, “Advanced Intrusion Detection Combining Signature-Based and Behavior-Based Detection Methods,” Electronics, vol. 11, no. 6, p. 867, Mar. 2022, doi: 10.3390/electronics11060867.

[17] M. Al-Kubaisi, A. S. Ahmed, S. M. Al-Barzinji, and A. M. Khaleel, “Advanced Estimation of Brain Age Using Pre-trained 2D Convolutional Neural Networks on a Public Dataset,” J. Robot. Control, vol. 5, no. 4, pp. 981–991, May 2024. [Online]. Available at: https://journal.umy.ac.id/index.php/jrc/article/view/22006

[18] Y. Xu, Y. Zhou, P. Sekula, and L. Ding, “Machine learning in construction: From shallow to deep learning,” Dev. Built Environ., vol. 6, p. 100045, May 2021, doi: 10.1016/j.dibe.2021.100045.

[19] R. Setiawan and T. K. A. Rahman, “Machine learning-based B2C software project success prediction model in Indonesia,” Int. J. Adv. Intell. Informatics, vol. 11, no. 3, p. 480, Aug. 2025, doi: 10.26555/ijain.v11i3.2123.

[20] S. P. R.M. et al., “An effective feature engineering for DNN using hybrid PCA-GWO for intrusion detection in IoMT architecture,” Comput. Commun., vol. 160, pp. 139–149, Jul. 2020, doi: 10.1016/j.comcom.2020.05.048.

[21] A. S. Issa, Y. H. Ali, and T. A. Rashid, “Enhanced Harris Hawks Optimization (EHHO) for Detecting COVID-19 Using Chest X-Ray,” in 2022 2nd International Conference on Advances in Engineering Science and Technology (AEST), Oct. 2022, pp. 361–365, doi: 10.1109/AEST55805.2022.10413107.

[22] S. F. Pane, M. D. Sulistiyo, A. A. Gozali, and A. Adiwijaya, “PSO-Enhanced ensemble techniques for pandemic prediction and feature importance analysis,” Int. J. Adv. Intell. Informatics, vol. 11, no. 4, p. 653, Nov. 2025, doi: 10.26555/ijain.v11i4.2091.

[23] Y. Miao, C. Chen, L. Pan, Q.-L. Han, J. Zhang, and Y. Xiang, “Machine Learning–based Cyber Attacks Targeting on Controlled Information,” ACM Comput. Surv., vol. 54, no. 7, pp. 1–36, Sep. 2022, doi: 10.1145/3465171.

[24] H. Qiu, T. Dong, T. Zhang, J. Lu, G. Memmi, and M. Qiu, “Adversarial Attacks Against Network Intrusion Detection in IoT Systems,” IEEE Internet Things J., vol. 8, no. 13, pp. 10327–10335, Jul. 2021, doi: 10.1109/JIOT.2020.3048038.

[25] T. Miller et al., “Integrating Artificial Intelligence Agents with the Internet of Things for Enhanced Environmental Monitoring: Applications in Water Quality and Climate Data,” Electronics, vol. 14, no. 4, p. 696, Feb. 2025, doi: 10.3390/electronics14040696.

[26] J. D. Gadze, A. A. Bamfo-Asante, J. O. Agyemang, H. Nunoo-Mensah, and K. A.-B. Opare, “An Investigation into the Application of Deep Learning in the Detection and Mitigation of DDOS Attack on SDN Controllers,” Technologies, vol. 9, no. 1, p. 14, Feb. 2021, doi: 10.3390/technologies9010014.

[27] R. Mishra and A. Mishra, “Current research on Internet of Things (IoT) security protocols: A survey,” Comput. Secur., vol. 151, p. 104310, Apr. 2025, doi: 10.1016/j.cose.2024.104310.

[28] Y.-W. Chen, J.-P. Sheu, Y.-C. Kuo, and N. Van Cuong, “Design and Implementation of IoT DDoS Attacks Detection System based on Machine Learning,” in 2020 European Conference on Networks and Communications (EuCNC), Jun. 2020, pp. 122–127, doi: 10.1109/EuCNC48522.2020.9200909.

[29] N. Islam et al., “Towards Machine Learning Based Intrusion Detection in IoT Networks,” Comput. Mater. Contin., vol. 69, no. 2, pp. 1801–1821, 2021, doi: 10.32604/cmc.2021.018466.

[30] N. Imtiaz et al., “A Deep Learning-Based Approach for the Detection of Various Internet of Things Intrusion Attacks Through Optical Networks,” Photonics, vol. 12, no. 1, p. 35, Jan. 2025, doi: 10.3390/photonics12010035.

[31] Y. Kayode Saheed, A. Idris Abiodun, S. Misra, M. Kristiansen Holone, and R. Colomo-Palacios, “A machine learning-based intrusion detection for detecting internet of things network attacks,” Alexandria Eng. J., vol. 61, no. 12, pp. 9395–9409, Dec. 2022, doi: 10.1016/j.aej.2022.02.063.

[32] T. S. Othman and S. M. Abdullah, “An Intelligent Intrusion Detection System for Internet of Things Attack Detection and Identification Using Machine Learning,” ARO-THE Sci. J. KOYA Univ., vol. 11, no. 1, pp. 126–137, May 2023, doi: 10.14500/aro.11124.

[33] R. Iranzad and X. Liu, “A review of random forest-based feature selection methods for data science education and applications,” Int. J. Data Sci. Anal., pp. 1–15, Feb. 2024, doi: 10.1007/s41060-024-00509-w.

[34] M. Altalhan, A. Algarni, and M. Turki-Hadj Alouane, “Imbalanced Data Problem in Machine Learning: A Review,” IEEE Access, vol. 13, pp. 13686–13699, 2025, doi: 10.1109/ACCESS.2025.3531662.

[35] J. Li et al., “Application of XGBoost algorithm in the optimization of pollutant concentration,” Atmos. Res., vol. 276, p. 106238, Oct. 2022, doi: 10.1016/j.atmosres.2022.106238.

[36] Z. Fan, J. Gou, and S. Weng, “Complementary CatBoost based on residual error for student performance prediction,” Pattern Recognit., vol. 161, p. 111265, May 2025, doi: 10.1016/j.patcog.2024.111265.

[37] C. K. K. Reddy et al., “Twined ensemble framework for network security: integrating Random Forest, AdaBoost, and Gradient Boosting for enhanced intrusion detection,” Discov. Internet Things, vol. 5, no. 1, p. 107, Oct. 2025, doi: 10.1007/s43926-025-00199-1.

[38] A. M. Elshewey, E. Selem, and A. H. Abed, “Improved CKD classification based on explainable artificial intelligence with extra trees and BBFS,” Sci. Rep., vol. 15, no. 1, p. 17861, May 2025, doi: 10.1038/s41598-025-02355-7.

[39] “The UNSW-NB15 Dataset,” UNSW Research. [Online]. Available at: https://research.unsw.edu.au/projects/unsw-nb15-dataset.

[40] WittigenZ, “IoTNet24 Dataset for IDS,” 2024. [Online]. Available at: https://www.kaggle.com/datasets/wittigenz/hydras.

[41] M. Hamsa Ahmed and M. Shokhan Al-Barzinji, “Integrated Computer Vision and Adaptive Machine Learning for Real-Time Fall Detection and Personalized Elderly Care,” Sci. Res. J. Eng. Comput. Sci., vol. 6, no. 1, pp. 1–5, Jan. 2026, doi: 10.47310/srjecs.2026.v06i01.003.




Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

___________________________________________________________
International Journal of Advances in Intelligent Informatics
ISSN 2442-6571  (print) | 2548-3161 (online)
Organized by UAD and ASCEE Computer Society
Published by Universitas Ahmad Dahlan
W: http://ijain.org
E: info@ijain.org (paper handling issues)
 andri.pranolo.id@ieee.org (publication issues)

View IJAIN Stats

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0