Evolutionary Feature Reduction and Edge-Optimized CNN Inference for Large-Scale IoT DDoS Detection

Authors

DOI:

https://doi.org/10.4108/airo.12940

Keywords:

Internet of Things (IoT), Distributed Denial-of-Service (DDoS), Intrusion Detection System (IDS), Genetic Algorithm, Feature Selection, Real-Valued Weight Encoding, Convolutional Neural Network (CNN), Edge Computing, ONNX Runtime, CIC-IoT-2023, Class Imbalance, Matthews Correlation Coefficient (M CC), Tail Latency, IoT Gateway Deployment

Abstract

The rapid proliferation of Internet of Things (IoT) deployments has introduced significant security vulnerabilities, particularly due to Distributed Denial-of-Service (DDoS) attacks launched through compromised IoT botnets. Real-time detection of such attacks at the network edge remains challenging because of high feature dimensionality, severe class imbalance between benign and attack traffic, and strict latency constraints of resource-constrained IoT gateways. This paper aims to design and evaluate a unified framework for large-scale IoT DDoS detection that reduces feature dimensionality, improves classification performance under imbalanced conditions, and enables low-latency edge deployment suitable for real-time gateway environments. The proposed framework employs a multi-phase pipeline integrating evolutionary feature reduction, deep learning classification, and edge-optimized deployment. A Weighted Genetic Algorithm (W-GA) is used to select a compact and importance-ranked subset of discriminative features from the original high-dimensional representation. A one-dimensional Convolutional Neural Network (CNN) is then trained on the feature set with reduced weights to capture the characteristic of local co-occurrence patterns of volumetric DDoS traffic. Finally, the trained model is exported and deployed using ONNX Runtime for efficient inference on IoT gateway hardware. Experimental evaluation on the CIC-IoT-2023 dataset demonstrates that the proposed W-GA+CNN framework consistently outperforms baseline classifiers in terms of classification effectiveness and inference throughput while maintaining sub-millisecond edge inference latency. The proposed evolutionary feature reduction and edge-optimized CNN framework provides an effective and deployment-ready solution for real-time large-scale IoT DDoS detection, making it suitable for practical intrusion detection deployment in production IoT gateway environments.

Downloads

Download data is not yet available.

References

[1] P. D. Singh and K. D. Singh, “Security and privacy in fog/cloud-based IoT systems for AI and robotics,” EAI Endorsed Transactions on AI and Robotics, vol. 2, 082023. [Online]. Available: https://publications.eai.eu/index.php/airo/article/view/3616

[2] IoT Analytics, “Iot analytics: Market insights for the internet of things,” https://iot-analytics.com/, 2024. [Online]. Available: https://iot-analytics.com/

[3] Satyajit Sinha, “State of iot 2025: Number of connectediot devices growing 14% to 21.1 billion globally,” https://iot-analytics.com/number-connected-iot-devices/, 2025. [Online]. Available: https://iot-analytics.com/number-connected-iot-devices/

[4] A. Al-Fuqaha, M. Guizani, M. Mohammadi, M. Aledhari,and M. Ayyash, “Internet of things: A survey on enabling technologies, protocols, and applications,” pp. 2347–2376, 2015. [Online]. Available: https: //ieeexplore.ieee.org/document/7123563

[5] M. Antonakakis, T. April, M. Bailey, M. Bernhard, E. Bursztein, J. Cochran, Z. Durumeric, J. A. Halderman, L. Invernizzi, M. Kallitsis, D. Kumar,C. Lever, Z. Ma, J. Mason, D. Menscher, C. Seaman, N. Sullivan, K. Thomas, and Y. Zhou, “Understanding the mirai botnet,” in Proceedings of the 26thUSENIX Conference on Security Symposium. USENIX Association, 2017, pp. 1093–1110. [Online]. Available: https://dl.acm.org/doi/10.5555/3241189.3241275

[6] W. W. Lo, S. Layeghy, M. Sarhan, M. Gallagher, and M. Portmann, “E-Graph SAGE: A graph neural network based intrusion detection system for IoT,” NOMS 2022-2022 IEEE/IFIP Network Operations and Management Symposium, 2022. [Online]. Available: https://ieeexplore.ieee.org/document/9789878

[7] E. Neto, S. Dadkhah, R. Ferreira, A. Zohourian, R. Lu, andA. A. Ghorbani, “CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment,” Sensors 2023, vol. 23, p. 5941, 2023. [Online]. Available: https://www.mdpi.com/1424-8220/23/13/5941

[8] M. A. Ferrag, L. Maglaras, S. Moschoyiannis, and H. Janicke, “Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study,” Journal of Information Security and Applications, vol. 50, p. 102419, 2020. [Online]. Available: https://www.sciencedirect.com/science/article/abs/pii/S2214212619305046

[9] S. Tharewal, M. Ashfaque, S. Banu, U. Perumal, S. Hassen, and D. M. Shabaz, “Intrusion detection system for industrial internet of things based on deep reinforcement learning,” Wireless Communications and Mobile Computing, vol. 2022, pp. 1–8, 3 2022.

[10] M. Sarhan, S. Layeghy, and M. Portmann, “Towards a standard feature set for network intrusion detection system datasets,” Mobile Networks and Applications, vol. 27, 2021. [Online]. Available: https://link.springer.com/article/10.1007/s11036-021-01843-0

[11] J. H. Holland, Adaptation in Natural and Artificial Systems. The MIT Press, 4 1992. [Online]. Available: https://mitpress.mit.edu/9780262082136/adaptation-in-natural-and-artificial-systems/

[12] N. A. S. V. K. Ivanov, D. S. Dumina, “Determination of weight coefficients for additive fitness function of genetic algorithm,” Scientific and practical journal Software products and systems, vol. Software & Systems 2020, vol. 33, no. 1, p. 47–53, Feb. 2020. [Online]. Available: http://dx.doi.org/10.15827/0236-235X.129.047-053

[13] B. Han, L.-N. Qiao, J.-L. Chen, X.-D. Zhang, Y.-X. Zhang, and Y.-H. Zhao, “Genetic KNN: a weighted KNN approach supported by genetic algorithm for photometric redshift estimation of quasars,” Research in Astronomy and Astrophysics, vol. 21, no. 1, p. 017, 1 2021. [Online]. Available: https://doi.org/10.1088/1674-4527/21/1/17

[14] O. A. Basir, “Pascal-Weighted Genetic Algorithms: a Binomially-Structured recombination Framework,” arXiv (Cornell University), 12 2025. [Online]. Available: http://arxiv.org/abs/2512.01249

[15] ONNX Runtime Contributors, “ONNX runtime: Cross-platform, high performance ML inferencing and training accelerator.” [Online]. Available: https: //onnxruntime.ai/docs/

[16] M. Rehman, R. Kalakoti, and H. Bahşi, “Comprehensive feature selection for machine learning-based intrusion detection in healthcare IoMT networks,” Proceedings of the 11th International Conference on Information Systems Security and Privacy, pp. 248–259, 2025. [Online]. Available: https://www.scitepress.org/Papers/2025/133136/133136.pdf

[17] G. Balhareth and M. Ilyas, “Optimized intrusion detection for IoMT networks with tree based machine learning and filter based feature selection,” Sensors, vol. 24, p. 5712, 2024. [Online]. Available: https://www.mdpi.com/1424-8220/24/17/5712

[18] M. Saied, S. Guirguis, and M. Madbouly, “A comparative analysis of using ensemble trees for botnet detection and classification in IoT,” Scientific Reports, vol. 13, p. 21632, 2023. [Online]. Available: https://doi.org/10.1038/s41598-023-48681-6

[19] S. Mukherjee and N. Sharma, “Intrusion detection using naive bayes classifier with feature reduction,” Procedia Technology, vol. 4, pp. 119–128, 2012. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S2212017312002964

[20] H. Yao, D. Fu, P. Zhang, M. Li, and Y. Liu, “MSML: A novel multilevel semi-supervised machine learning framework for intrusion detection system,” IEEE Internet of Things Journal, vol. 6, pp. 1949–1959, 2019. [Online]. Available: https://ieeexplore.ieee.org/document/8477001

[21] W. Siedlecki and J. Sklansky, “A note on genetic algorithms for large-scale feature selection,” Pattern Recognition Letters, vol. 10, pp. 335–347, 1989.[Online]. Available: https://www.sciencedirect.com/science/article/pii/0167865589900378

[22] G. I. Sayed, A. Darwish, and A. E. Hassanien, “Anew chaotic whale optimization algorithm for features selection,” Journal of Classification, vol. 35, pp. 300–344,2018. [Online]. Available: https://link.springer.com/article/10.1007/s00357-018-9261-2X.

[23] X. Liu and Y. Du, “Towards effective feature selection forIoT botnet attack detection using a genetic algorithm, ”Electronics, vol. 12, p. 1260, 2023. [Online]. Available: https://www.mdpi.com/2079-9292/12/5/1260

[24] O. A. Aldabash and M. F. Akay, “WS-AWRE: Intrusion detection using optimized whale sine feature selection and artificial neural network(ANN) weighted random forest classifier,” Applied Sciences, vol. 14, p. 2172, 2024. [Online]. Available: https://www.mdpi.com/2076-3417/14/5/2172

[25] Y. Fang, Y. Yao, X. Lin, J. Wang, and H. Zhai, “A feature selection based on genetic algorithm for intrusion detection of industrial control systems,” Computers & Security, vol. 139, p. 103675, 2024. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S0167404823005850

[26] H. A. Alsalamah and W. N. Ismail, “Evolutionary computation for feature optimization and image-based dimensionality reduction in IoT intrusion detection, ”Mathematics, vol. 13, p. 3869, 2025. [Online]. Available: https://www.mdpi.com/2227-7390/13/23/3869

[27] W. Wang, M. Zhu, X. Zeng, X. Ye, and Y. Sheng, “Malware traffic classification using convolutional neural network for representation learning,” in 2017International Conference on Information Networking(ICOIN), 2017, pp. 712–717. [Online]. Available: https://ieeexplore.ieee.org/document/7899588

[28] H. Liu, B. Lang, M. Liu, and H. Yan, “CNN and RNN based payload classification methods for attack detection,” Knowledge-Based Systems, vol. 163, pp. 332–341, 2019. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S0950705118304325

[29] B. Hussain, Q. Du, B. Sun, and Z. Han, “Deep learning-based DDoS-attack detection for cyber–physical system over 5g network,” IEEE Transactions on Industrial Informatics, vol. 17, pp.860–870, 2021. [Online]. Available: https://ieeexplore.ieee.org/document/9000893

[30] I. Ullah and Q. H. Mahmoud, “Design and development of a deep learning-based model for anomaly detection in IoT networks,” IEEE Access, vol. 9, pp. 103 906–103 926, 2021. [Online]. Available: https://ieeexplore.ieee.org/document/9469914

[31] S. Agrawal, S. Sarkar, O. Aouedi, G. Yenduri, K. Piamrat, M. Alazab, S. Bhattacharya, P. K. R. Maddikunta, and T. R. Gadekallu, “Federated learning for intrusion detection system: Concepts, challenges and future directions,” Computer Communications, vol. 195, pp. 346–361,2022. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S0140366422003516

[32] A. Yazdinejad, R. M. Parizi, A. Dehghantanha, Q. Zhang, and K. R. Choo, “An energy-efficient SDN controller architecture for IoT networks with blockchain-based security,” IEEE Transactions on Services Computing, vol. 13,pp. 625–638, 2020. [Online]. Available: http://doi.ieeecomputersociety.org/10.1109/TSC.2020.2966970

[33] P. Li, X. Wang, K. Huang, Y. Huang, S. Li, and M. Iqbal, “Multi-model running latency optimization in an edge computing paradigm,” Sensors, vol. 22, p. 6097, 2022. [Online]. Available: https://doi.org/10.3390/s22166097

[34] L.-H. Wang, Q. Dai, T. Du, and L. fang Chen, “Lightweight intrusion detection model based on CNN and knowledge distillation,” Applied Soft Computing, vol. 165, p. 112118,2024. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S1568494624008925

[35] A. Diab, A. Chehade, E. Ragusa, P. Gastaldo, R. Zunino, A. Baghdadi, and M. Rizk, “Intrusion detection on resource-constrained IoT devices with hardware aware ML and DL,” in 2025 IEEE International Conference on Emerging Trends in Engineering and Computing (ETECOM), 2025, pp. 1–6. [Online]. Available: https://ieeexplore.ieee.org/document/11319100

[36] A. M. Banaamah and I. Ahmad, “Intrusion detection in IoT using deep learning,” Sensors, vol. 22, p. 8417, 2022. [Online]. Available: https://doi.org/10.3390/s22218417

[37] S. Dadkhah, H. Mahdikhani, P. K. Danso, A. Zohourian, K. A. Truong, and A. A. Ghorbani, “Towards the development of a realistic multidimensional IoT profiling dataset,” in 2022 19th Annual International Conference on Privacy, Security &Trust (PST), 2022, pp. 1–11. [Online]. Available: https://ieeexplore.ieee.org/document/9851966

[38] B. W. Matthews, “Comparison of the predicted and observed secondary structure of t4 phagelysozyme,” Biochimica et Biophysica Acta (BBA) -Protein Structure, vol. 405, pp. 442–451, 1975. [Online]. Available: https://www.sciencedirect.com/science/article/pii/0005279575901099

[39] B. P. Welford, “Note on a method for calculating corrected sums of squares and products,” Technometrics, vol. 4, no. 3, pp. 419–420, 1962. [Online].Available: https://www.tandfonline.com/doi/abs/10.1080/00401706.1962.10490022

[40] “Apache parquet: Columnar storage for the people,”2023. [Online]. Available: https://parquet.apache.org/

[41] C. M. Bishop, "Pattern Recognition and Machine Learning". New York: Springer, 2006. [Online]. Available: https://link.springer.com/book/9780387310732

[42] M. Beniwal, “Adaptive weighted genetic algorithm optimized svr for robust long-term forecasting of global stock indices for investment decisions,” 2025. [Online].Available: https://arxiv.org/abs/2512.15113

[43] S. H. Taheri, H. Kosarirad, I. Adrover Gallego, and N. Taheri, “A Deep Learning Based Optical Character Recognition Model for Old Turkic,” EAI Endorsed Transactions on AI and Robotics, vol. 4, 04 2025. [Online].Available: https://publications.eai.eu/index.php/airo/article/view/8460

[44] K. Vayadande, A. Mishra, G. R. Patil, Y. Bodhe, P. Nooji,N. Kale, A. Katariya, A. Kharade, P. Supekar, and L. Patil, “Cutting-edge techniques for detecting fake reviews,” EAI Endorsed Transactions on AI and Robotics, vol. 4, 072025. [Online]. Available: https://publications.eai.eu/index.php/airo/article/view/8945

[45] U. Tank, S. Arirangan, A. R. Paduri, and N. Darapaneni, “A study towards building content aware models in nlp using genetic algorithms,” EAI Endorsed Transactions on AI and Robotics, vol. 2, 11 2023. [Online]. Available: https://publications.eai.eu/index.php/airo/article/view/4078

[46] J. Li, H. Chen, M. S. Othman, N. Salim, L. M. Yusuf, and S. R. Kumaran, “NFIoT-GATE-DTL IDS: Genetic algorithm-tuned ensemble of deep transfer learning for netflow-based intrusion detection system for internet of things,” Engineering Applications of Artificial Intelligence, vol. 143, p. 110046, 2025. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S0952197625000466

[47] H. Bakir and O. Ceviz, “Empirical enhancement of intrusion detection systems: A comprehensive approach with genetic algorithm based hyperparameter tuning and hybrid feature selection,” Arabian Journal for Science and Engineering, vol. 49, pp. 13 025–13 043, 2024. [Online].Available: https://doi.org/10.1007/s1336902408949z

[48] N. Alkhafaji, T. Viana, and A. Al-Sherbaz, “Integrated genetic algorithm and deep learning approach for effective cyber-attack detection and classification in industrial internet of things (IIoT) environments,” Arabian Journal for Science and Engineering, vol. 50,10 2024. [Online]. Available: https://link.springer.com/article/10.1007/s13369-024-09663-6

[49] K. Deb and R. B. Agrawal, “Simulated binary crossover for continuous search space,” Complex Syst., vol. 9, 1995. [Online]. Available: https://api.semanticscholar.org/CorpusID:18860538

[50] I. Sharafaldin, A. H. Lashkari, and A. A. Ghorbani,“ Toward generating a new intrusion detection dataset and intrusion traffic characterization,” Proceedings of the 4th International Conference on Information Systems Security and Privacy, pp. 108–116, 2018. [Online].Available: https://www.scitepress.org/Link.aspx?doi=10.5220/0006639801080116

[51] R. O. Duda, P. E. Hart, and D. G. Stork, Pattern Classification, 2Nd Edition, 2nd ed. Wiley, 11 2000.[Online]. Available: https://www.wiley.com/en-us/shop/general-introductory-electrical-electronics-engineering/pattern-classification-2nd-edition-p-9780471056690

[52] L. Breiman, “Random forests,” Machine Learning, vol. 45,no. 1, pp. 5–32, 2001. [Online]. Available: https: //link.springer.com/article/10.1023/A:1010933404324

[53] H. Hotelling, The Generalization of Student’s Ratio. Springer New York, 1992, pp. 54–65. [Online].Available: https://link.springer.com/chapter/10.1007/978-1-4612-0919-5_4

[54] C. Zhang, J. Zhou, J. He, Z. Xu, J. Jin, C. Kong, Y. Xu, B. Guo, and Q. Gai, “A platform independent model design and adaptation for edge intelligence,” in2024 29th International Conference on Automation and Computing (ICAC), 2024, pp. 1–6. [Online]. Available: https://ieeexplore.ieee.org/document/10718820

[55] N. Srivastava, G. Hinton, A. Krizhevsky, I. Sutskever, and R. Salakhutdinov, “Dropout: A simple way to prevent neural networks from overfitting,” Journal of Machine Learning Research, vol. 15,no. 56, pp. 1929–1958, 2014. [Online]. Available: http://jmlr.org/papers/v15/srivastava14a.html

[56] D. P. Kingma and J. Ba, “Adam: A method for stochastic optimization,” CoRR, vol. abs/1412.6980, 2014. [Online].Available: https://api.semanticscholar.org/CorpusID:6628106

[57] L. N. Smith and N. Topin, “Super-Convergence: Very Fast Training of Neural Networks Using Large Learning Rates,” 2018. [Online]. Available: https://arxiv.org/abs/1708.07120

Downloads

Published

10-08-2026

How to Cite

1.
Chitre P, Sivakumar P. Evolutionary Feature Reduction and Edge-Optimized CNN Inference for Large-Scale IoT DDoS Detection. EAI Endorsed Trans AI Robotics [Internet]. 2026 Aug. 10 [cited 2026 Aug. 11];5. Available from: https://publications.eai.eu/index.php/airo/article/view/12940