U. S. Kumar, Vikas Vikas
Abstract
The intensive growth of Internet of Things (IoT) devices has exponentially increased cyber-attack surfaces, and the resource-constrained nature of IoT-based devices strongly restricts the ability to deploy traditional deep-intrusion detection systems (IDS). In this paper, a lightweight hybrid IDS is proposed, which consists of a light convolutional neural network (CNN) combined with bidirectional long short-term memory (BiLSTM) and Incremental Principal Component Analysis (IPCA) to perform online dimensionality reduction on features. The offered method is considered in detail using both real-world datasets of IoT intrusion, namely CICIoT2023 (large-scale lab-generated IoT attacks with 33 attack types) and IoT-23 (realistic long-duration malware scenarios on commercial IoT devices). The model achieves a detection accuracy of 98.23% and a recall of 98.6% on CICIoT2023. On the IoT-23 dataset, it yields a detection accuracy of 97.15% and a recall of 97.1%, indicating that it can generalize more strongly across different distributions of IoT traffic. The method reduces model size by 60% and inference time by 65% compared to full-feature deep baselines, and achieves better accuracy than the current state-of-the-art lightweight
Citation format
KUMAR, U. S.; VIKAS, Vikas. Performance-efficient intrusion detection for iot using CNN-BiLSTM and incremental principal component analysis. International Journal of Performability Engineering, 2026, 22(3): 128.