A Mutual Information-Driven Hybrid 1D-CNN and XGBoost Framework for Network Intrusion Detection in IoT
Downloads
There are a growing number of Internet of Things (IoT) interconnected systems in critical infrastructures that have made these systems vulnerable to increasingly advanced and diverse cyberattacks. However, typical intrusions systems face serious obstacles in operation due to the high dimensional telemetry data, inadequately extracting those non-linear structural patterns, and the inherent class imbalance in network traffic. To overcome these drawbacks, this paper presents an intelligent hybrid model based on Mutual Information (MI), One-Dimensional Convolutional Neural Network (1D-CNN) and eXtreme Gradient Boosting (XGBoost). First, redundant features are removed from the proposed pipeline by using an MI metric and the most discriminative flow attributes are selected by using an elbow heuristic. Later, an optimized 1D-CNN feature extractor is used to obtain non-linear representations, which are mapped to a compact deep feature manifold. Finally, a gradient boosted decision tree (GBDT) classifier is adapted to minimize the class imbalance and achieved a good separation between the benign and malicious flows. The proposed framework achieved an overall accuracy of 98.91%, an Area under the ROC Curve (AUC) of 0.9986, an intrusion class precision of 99.35%, an intrusion class recall of 99.27%, and an F1F_1-score of 99.31% by doing extensive empirical evaluations on the latest ToN-IoT benchmark dataset containing 37,979 independent test flow instances. Comparative analysis validates the effectiveness and reliability of this framework with the basic machine learning and deep learning approaches, giving a proper balance between discrimination and avoiding the majority class bias.
S. A. Bakhsh, M. A. Khan, F. Ahmed, M. S. Alshehri, H. Ali, and J. Ahmad, “Enhancing IoT network security through deep learning-powered intrusion detection system,” Internet of Things, vol. 24, p. 100936, 2023.
A. Awajan, “A novel deep learning-based intrusion detection system for IoT networks,” Computers, vol. 12, no. 2, p. 34, 2023.
R. Jablaoui, O. Cheikhrouhou, M. Hamdi, and N. Liouane, “Deep learning enabled intrusion detection system for IoT security: R. Jablaoui et al.,” EURASIP Journal on Wireless Communications and Networking, vol. 2025, no. 1, p. 66, 2025.
H. Zhang, “Development of an intelligent intrusion detection system for IoT networks using deep learning,” Discover Internet of Things, vol. 5, no. 1, p. 74, 2025.
B. Sharma, L. Sharma, C. Lal, and S. Roy, “Anomaly based network intrusion detection for IoT attacks using deep learning technique,” Computers and Electrical Engineering, vol. 107, p. 108626, 2023.
M. A. Hossain, “Deep learning-based intrusion detection for IoT networks: A scalable and efficient approach,” EURASIP Journal on Information Security, vol. 2025, no. 1, p. 28, 2025.
P. M. Jadhav, “Intrusion detection using IoT with deep learning,” International Journal of Scientific and Advanced Technology, vol. 16, no. 3, 2025.
K. Alam, M. F. Monir, Z. Hassan, and M. T. Habib, “Optimizing IoT network intrusion detection: A deep learning approach,” in Proc. 2024 7th Conf. Cloud and Internet of Things (CIoT), Oct. 2024, pp. 1–5.
P. Rachana, M. Talakoti, and V. S. N. Reddy, “Development of hybrid intrusion detection systems for IoT enabled devices utilizing resource constraint learning frameworks,” Journal of Smart Internet of Things, vol. 2024, no. 1, pp. 60–76, 2024.
M. Pradeep and S. Gopalakrishnan, “Enhancing intrusion detection systems in IoT networks: A hybrid approach using CNN, ANN, LSTM, GRU for improved security,” in Proc. 2024 8th Int. Conf. Inventive Systems and Control (ICISC), Jul. 2024, pp. 487–492.
R. H. Altaie and H. K. Hoomod, “An intrusion detection system using a hybrid lightweight deep learning algorithm,” Engineering, Technology & Applied Science Research, vol. 14, no. 5, pp. 16740–16743, 2024.
A. Qaddos, M. U. Yaseen, A. S. Al-Shamayleh, M. Imran, A. Akhunzada, and S. Z. Alharthi, “A novel intrusion detection framework for optimizing IoT security,” Scientific Reports, vol. 14, no. 1, p. 21789, 2024.
M. Obeidat and R. Shehab, “Network-based intrusion detection in IoT environments using hybrid machine learning techniques,” Babylonian Journal of Networking, vol. 2025, pp. 116–125, 2025.
A. B. Abdulkareem, “Advances in IoT intrusion detection: Deploying hybrid deep learning and metaheuristic algorithms for optimal feature selection,” Ingénierie des Systèmes d'Information, vol. 30, no. 4, p. 1027, 2025.
S. Qawasmeh, A. Habboush, B. Elzaghmouri, Q. Kharma, and D. A. Albalawneh, “Hybrid convolutional neural network-based intrusion detection system for secure IoT networks,” Tikrit Journal of Engineering Sciences, vol. 32, no. SP1, pp. 1–11, 2025.
R. A. Elsayed, R. A. Hamada, M. I. Abdalla, and S. A. Elsaid, “Securing IoT and SDN systems using deep-learning based automatic intrusion detection,” Ain Shams Engineering Journal, vol. 14, no. 10, p. 102211, 2023.
H. Kamal and M. Mashaly, “Hybrid deep learning-based autoencoder-DNN model for intelligent intrusion detection system in IoT networks,” in Proc. 2025 15th Int. Conf. Electrical Engineering (ICEENG), May 2025, pp. 1–6.
S. M. Ahmed, S. S. Islam, and M. S. Ullah, “Hybrid machine learning and deep learning approaches for anomaly detection using KD99 and TON_IoT datasets,” in Proc. 2025 Int. Conf. Electrical, Computer and Communication Engineering (ECCE), Feb. 2025, pp. 1–6.




3.png)