Intrusion detection is the process of monitoring network traffic or system activity to identify unauthorized access, policy violations, or malicious behavior. Intrusion detection systems are generally classified as signature-based, which match activity against known attack patterns, or anomaly-based, which flag deviations from an established baseline of normal behavior and can therefore detect previously unseen attacks. Deployment architectures include network-based systems that inspect traffic at chokepoints and host-based systems that monitor activity on individual machines, often combined in layered defense strategies. Recent research combining machine learning with IoT network traffic has reported detection accuracy above 99 percent on benchmark datasets such as IoTID20, alongside a broader shift toward deep learning architectures, including transformers, for more effective pattern recognition. Other active areas include federated learning approaches and detecting intrusions in encrypted traffic and industrial control systems. As an open-access intrusion detection journal, IJACSA publishes research evaluating intrusion detection models against benchmark datasets, alongside applied detection systems for specific network environments.
Published in International Journal of Advanced Computer Science and Applications (IJACSA)
· list last refreshed October 2026
Machine learning-based network intrusion detection systems (NIDS) increasingly operate in environments where adversaries can adapt their behavior in response to deployed defenses. However, most empirical IDS studies eval…
With the emergence of smart homes based on the Internet of Things, network-based attacks have become more prevalent and require effective and lightweight intrusion detection (ID). In this study, a Correlation-Aware Hybri…
Modern network environments generate large-scale, high-dimensional traffic data that can be effectively interpreted as complex temporal signals. Efficiently analyzing such data requires robust feature selection and accur…
Federated learning (FL) enables distributed intrusion detection without centralizing raw Internet of Things (IoT), Industrial IoT (IIoT), or Internet of Medical Things (IoMT) traffic. Secure aggregation protects update c…
Conventional Internet-of-Things (IoT) intrusion detection typically maps a model score directly to an alert, although autonomous defense must also determine whether the evidence is reliable, whether suspicious behavior p…
Machine-learning intrusion detectors are usually reported with accuracy or F1 on a single train and test split, and their confidence scores are often read operationally as probabilities without an explicit calibration ch…
Machine learning-based intrusion detection systems are often constrained by severe class imbalance, while generative augmentation may memorize distinctive network-flow records and expose membership information. This stud…
Comparative studies of feature selection (FS) and feature extraction (FE) for IoT intrusion detection rely almost universally on random train/test splits, which let temporally adjacent, highly similar records appear on b…
Smart hospitals deploy Internet of Medical Things (IoMT) sensors and MQTT brokers to stream clinical telemetry over resource-constrained edge gateways. Centralized network intrusion detection systems (NIDS) expose sensit…
The swift deployment of IoT-based smart home appliances has increased the attack surface for the smart environment and exposed it to attacks like botnet command-and-control communications, brute force attacks, denial-of-…