[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-85473-en":3,"doc-seo-85473-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},85473,549758146520,"Patrick","https://ap-avatar.wpscdn.com/avatar/80002397d8c0411e94?_k=1775819394049821470",8,"Research & Report","Green Deep Reinforcement Learning for IoT Edge Intrusion Detection","The rapid expansion of the Internet of Things (IoT) intensifies cybersecurity, especially at the network edge where Distributed Denial-of-Service (DDoS) attacks can overwhelm constrained gateways and disrupt services. Existing IDS approaches are limited by static signatures, reliance on labeled data, poor adaptability to evolving and zero-day threats, and high computational overhead. Two carbon-aware DRL IDS methods are proposed: DeepEdgeIDS (label-free Autoencoder-DQN) and AutoDRL-IDS (supervised LSTM-DQN), using multi-objective rewards covering security, latency, energy, memory, and carbon estimates. Evaluations on physical IoT edge gateways show 94% detection accuracy for AutoDRL-IDS and 98% offline accuracy with stronger adaptation for DeepEdgeIDS.","Green Deep Reinforcement Learning for IoT Edge  \nIntrusion Detection  \nSaeid Jamshidi, Foutse Khomh, Rolando Herrero, Omar Abdul-Wahab, and Martine Bellaiche  \narXiv :2511 . 18240v4 [ cs .CR] 11 Jul 2026  \nAbstract—The rapid expansion of the Internet of Things (IoT) has intensified cybersecurity challenges, particularly in detecting and mitigating Distributed Denial-of-Service (DDoS) attacks atthe network edge. Traditional Intrusion Detection Systems (IDSs) remain limited by static signatures, dependence on labeled data, poor adaptability to evolving and zero-day attacks, and high computational overhead on resource-constrained edge gateways. Moreover, most Deep Reinforcement Learning (DRL)-based IDS studies prioritize detection performance while overlooking energy consumption and carbon impact. To address these limitations, this paper proposes two carbon-aware DRL-based IDS: DeepEdgeIDS, a label-free Autoencoder-DQN architecture for anomaly-guided online mitigation, and AutoDRL-IDS, a supervised LSTM-DQN model for temporally informed detection and response. Both systems incorporate multi-objective reward functions that jointly consider security performance, response latency, energy consumption, memory utilization, and estimated carbon emissions, while using learning-paradigm-specific detection feedback. AutoDRL-IDS employs ground-truth-dependent detection metrics during supervised training, whereas DeepEdgeIDS relies on anomaly confidence and post-mitigation traffic stabilization for label-free online learning. The proposed systems are analyzed theoretically and evaluated experimentally on physical IoT edge gateways under DDoS traffic. Results show that AutoDRL-IDS achieves 94% detection accuracy, while DeepEdgeIDS attains 98% offline evaluation accuracy and demonstrates stronger adaptability to previously unseen attack patterns.  \nIndex Terms—Internet of Things, intrusion detection system, deep reinforcement learning, autoencoder, long short-term memory, DDoS detection, edge computing, sustainable cybersecurity, carbon-aware artificial intelligence.  \nI. INTRODUCTION  \nThe Internet of Things (IoT) has become a pervasive computing paradigm, connecting billions of devices across domains such as healthcare, smart cities, transportation, and industrial automation [1], [2] . Despite its benefits, the rapid expansion of IoT has introduced substantial cybersecurity challenges because IoT environments are decentralized, heterogeneous, dynamically configured, and often composed of devices with limited processing, memory, and energy resources [3],[4] . Among the threats targeting these environments, Distributed Denial-of-Service (DDoS) attacks remain particularly severe because they can overwhelm resource-constrained devices and edge gateways, exhaust network capacity, and disrupt critical services [5], [6] . Traditional Intrusion Detection Systems (IDSs) have limited effectiveness against rapidly  \nSaeid Jamshidi, Foutse Khomh, Omar Abdul-Wahab, and Martine Bellaiche are with the Department of Computer and Software Engineering, Polytechnique Montral, 2500 Chemin de Polytechnique, Montral, Qubec H3T 1J4, Canada.  \nRolando Herrero is with the College of Engineering, Northeastern University, Boston, Massachusetts, USA.  \nCorresponding author: Saeid Jamshidi (email: [saeid.jamshidi@polymtl.ca](saeid.jamshidi@polymtl.ca)).  \nevolving and zero-day attacks 1 [7] . Signature-based IDSs rely on predefined attack patterns and therefore often fail to detect previously unseen and adversarially modified threats. Anomaly-based IDSs can identify deviations from normal behavior and are consequently more suitable for detecting novel attacks; however, they may generate excessive false positives when normal traffic patterns are highly variable. These limitations are especially problematic at IoT edge gateways, where defensive mechanisms must operate under strict computational and energy constraints while responding to attacks in real time [8], [9] . The","cbCaiajWgSn8vTfk","https://ap.wps.com/l/cbCaiajWgSn8vTfk","pdf",12397517,3,1,17,"English","en",105,"# Introduction\n## Threats and limitations of traditional IDS\n## DRL for adaptive detection and mitigation\n## Trade-offs at resource-constrained edge gateways\n## Carbon-aware objective gap in existing research","[{\"question\":\"Why do traditional intrusion detection systems perform poorly for IoT edge DDoS scenarios?\",\"answer\":\"They depend on static signatures and often require labeled data, which limits detection of previously unseen or evolving attacks. At the edge, they may also incur high computational overhead under strict resource constraints.\"},{\"question\":\"What are the two proposed carbon-aware DRL-based IDS systems and how do they differ?\",\"answer\":\"DeepEdgeIDS is a label-free Autoencoder-DQN architecture using anomaly confidence and stabilization for online learning. AutoDRL-IDS is a supervised LSTM-DQN model that uses temporally informed detection and ground-truth-dependent metrics during training.\"},{\"question\":\"How do the systems account for both security performance and sustainability?\",\"answer\":\"They use multi-objective reward functions that jointly consider security effectiveness, response latency, energy consumption, memory utilization, and estimated carbon emissions, rather than optimizing for security metrics alone.\"}]",1784203846,43,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"green-deep-reinforcement-learning-for-iot-edge-intrusion-detection","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/green-deep-reinforcement-learning-for-iot-edge-intrusion-detection/85473/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why do traditional intrusion detection systems perform poorly for IoT edge DDoS scenarios?","Question",{"text":75,"@type":76},"They depend on static signatures and often require labeled data, which limits detection of previously unseen or evolving attacks. At the edge, they may also incur high computational overhead under strict resource constraints.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What are the two proposed carbon-aware DRL-based IDS systems and how do they differ?",{"text":80,"@type":76},"DeepEdgeIDS is a label-free Autoencoder-DQN architecture using anomaly confidence and stabilization for online learning. AutoDRL-IDS is a supervised LSTM-DQN model that uses temporally informed detection and ground-truth-dependent metrics during training.",{"name":82,"@type":73,"acceptedAnswer":83},"How do the systems account for both security performance and sustainability?",{"text":84,"@type":76},"They use multi-objective reward functions that jointly consider security effectiveness, response latency, energy consumption, memory utilization, and estimated carbon emissions, rather than optimizing for security metrics alone.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]