Document Type : Original/Review Paper
Authors
1 University of Zanjan
2 zanjan university
Abstract
The rapid growth of Internet of Things (IoT) deployments has increased the prevalence of attack-dominant network conditions, where malicious traffic constitutes the majority of network flows. In such scenarios, intrusion detection systems (IDSs) often become biased toward the attack class, leading to frequent misclassification of benign traffic. This study investigates reliable benign-traffic detection under extreme class imbalance using two IoT datasets: IoT-23 (86.3% attacks) and N-BaIoT (up to 95.1% attacks). Several machine learning models—including classical, ensemble, and deep learning approaches—are evaluated using imbalance-handling strategies, such as Random UnderSampling (RUS), Random Over Sampling(ROS), Synthetic Minority Over-sampling Technique(SMOTE), Adaptive Synthetic Sampling (ADASYN), and class weighting. Across the evaluated configurations, lightweight strategies—particularly RUS and class weighting with tree-based models—provide favorable trade-offs between benign recall and computational cost without substantially compromising other performance metrics. In contrast, synthetic oversampling methods offer limited additional benefits and often impose considerably greater computational overhead. A comparative evaluation across the two datasets further indicates that the effectiveness of imbalance mitigation depends largely on feature separability and dataset characteristics rather than on a universally optimal strategy, offering practical insights into IDS design for attack-dominant IoT environments.
Keywords
Main Subjects