[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-122640-en":3,"doc-seo-122640-105":29,"detail-sidebar-cat-0-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":11,"language":21,"language_code":22,"site_id":23,"html_lang":22,"table_of_contents":24,"faqs":25,"seo_title":26,"seo_description":14,"update_tm":27,"read_time":28},122640,687197100911,"Himbo","https://ap-avatar.wpscdn.com/avatar/a000239b6f1da00475?x-image-process=image/resize,m_fixed,w_180,h_180&k=1785132997149421697",8,"Research & Report","Machine Learning Based Classification of IoT Traffic","Rapid growth and widespread adoption of the Internet of Things (IoT) make secure communication among active devices difficult, especially because constrained devices cannot run complex protection tasks and are exposed to multiple attack types. Large volumes of daily traffic further increase the difficulty of spotting anomalous behavior. A study evaluates four machine learning algorithms and three neural networks using a pipeline that applies random undersampling to simulate network traffic data loss. Results show near-100% accuracy on original data for the best classic model (XGBoost) and strong performance from a 2-layer NN; undersampling reduces accuracy, most sharply for deeper NNs.","Machine Learning Based Classiﬁcation ofIoT Traﬃc  \nBojana VELICHKOVSKA, Ana CHOLAKOSKA, Vladimir ATANASOVSKI  \nFaculty of Electrical Engineering and Information Technologies, Ss. Cyril and Methodius University, Ruger Boshkovikj 18, 1000 Skopje, North Macedonia  \n{bojanav, acholak, [vladimir}@feit.ukim.edu.mk](vladimir}@feit.ukim.edu.mk)  \nSubmitted January 11, 2023 / Accepted May 2, 2023 / Online ﬁrst May 17, 2023  \nAbstract. With the rapid expansion and widespread adoption of the Internet of Things (IoT), maintaining secure connections among active devices can be challenging. Since IoT devices are limited in power and storage, they cannot perform complex tasks, which makes them vulnerable to diﬀerent types of attacks. Given the volume of data generated daily, detecting anomalous behavior can be demanding. However, machine learning (ML) algorithms have proven successful in extracting complex patterns from big data, which has led to active applications in IoT.  \nIn this paper, we perform a comprehensive analysis, including 4 ML algorithms and 3 neural networks (NNs), and propose a pipeline which analyzes the inﬂuence data reduction (loss) has on the performance of these algorithms. We use random undersampling as a data reduction technique, which simulates reduced network traﬃc data. The pipeline investigates several degrees of data loss. The results show that models trained on the original data distribution obtain accuracy that verges on 100% . XGBoost performs best from the classic ML algorithms. From the deep learning models, the 2-layered NN provides excellent results and has suﬃcient depth for practical application. On the other hand, when the models are trained on the undersampled data, there is a decrease in performance, most notably in the case of NNs. The most prominent change is seen in the 4-layered NN, where the model trained on the original dataset detects attacks with a success of 93. 53%, whereas the model trained on the maximally reduced data has a success of only 39.39%.  \nKeywords  \nMachine learning, deep learning, Internet of Things (IoT), intrusion detection, traﬃc modelling  \n1. Introduction  \nThe continuous and exponential growth of the Internet of Things (IoT) created an automation-driven society, where unique devices are interconnected in order to improve the quality of healthcare, industry, transportation, etc. [1],[2] .  \nIoT networks vary from the traditional approach of networking, which reﬂects in their traﬃc patterns [3] . Namely, IoT is characterized by highly homogeneous traﬃc, meaning all devices running the same application will exhibit similar behavior patterns. Additionally, since IoT networks are comprised of many devices, they generate massive amounts of data. Each device in the network is sensitive to an attack that causes a variation in the standard behavior of the network and creates signiﬁcant problems for end-users. This is a time-sensitive issue, and therefore, it is essential to detect these network anomalies quickly.  \nTechniques to detect anomalous behavior are being extensively developed for many applications [4] . Certain techniques are based on analyzing network traﬃc characteristics essential to understanding speciﬁc traﬃc patterns, such as protocol design, network management, and resource distribution. This task can be time-consuming, limiting realtime device monitoring and requiring extreme expertise and knowledge. Consequently, this becomes a problem when it is necessary to address potential traﬃc anomalies swiftly. In the past few years, machine learning (ML) has slowly taken its place as an alternative approach to human-assisted traditional intrusion detection systems [5] . The main reason is that ML allows development of portable algorithms.  \nHowever, next-generation security systems should be able to oﬀer real-time anomaly detection and adjust their knowledge according to changes in daily network traﬃc. Therefore, ML algorithms should be reinforced through time, accordin","cbCainOZXeqBUa4Q","https://ap.wps.com/l/cbCainOZXeqBUa4Q","pdf",768193,1,"English","en",105,"# Introduction\n## IoT traffic characteristics and anomaly detection needs\n## Motivation for ML/DL-based intrusion detection\n## Study scope and approach","[{\"question\":\"Why is IoT traffic intrusion/anomaly detection challenging in practice?\",\"answer\":\"IoT devices are resource constrained and cannot perform complex tasks, making them vulnerable to attacks. At the same time, massive daily traffic volumes make detecting anomalous behavior time-sensitive and demanding.\"},{\"question\":\"What approach does the paper use to study the impact of data reduction on classification?\",\"answer\":\"It proposes a pipeline that applies random undersampling to simulate reduced network traffic data, testing several degrees of loss and measuring how this affects model performance.\"},{\"question\":\"How do classic ML and deep learning models perform with full vs undersampled data?\",\"answer\":\"Models trained on the original data distribution achieve accuracy close to 100%. XGBoost performs best among classic ML, while a 2-layer NN performs strongly; performance drops for undersampled data, with the most pronounced decline observed for the 4-layer NN.\"}]","Machine Learning Based Classification of IoT Traffic | PDF",1785811879,20,{"code":4,"msg":30,"data":31},"ok",{"site_id":23,"language":22,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":27},"machine-learning-based-classification-of-iot-traffic","",{"@graph":35,"@context":84},[36,53,67],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/machine-learning-based-classification-of-iot-traffic/122640/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":22,"description":14,"dateModified":61,"datePublished":61,"encodingFormat":60,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":64,"interactionType":65,"userInteractionCount":4},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"Why is IoT traffic intrusion/anomaly detection challenging in practice?","Question",{"text":74,"@type":75},"IoT devices are resource constrained and cannot perform complex tasks, making them vulnerable to attacks. At the same time, massive daily traffic volumes make detecting anomalous behavior time-sensitive and demanding.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"What approach does the paper use to study the impact of data reduction on classification?",{"text":79,"@type":75},"It proposes a pipeline that applies random undersampling to simulate reduced network traffic data, testing several degrees of loss and measuring how this affects model performance.",{"name":81,"@type":72,"acceptedAnswer":82},"How do classic ML and deep learning models perform with full vs undersampled data?",{"text":83,"@type":75},"Models trained on the original data distribution achieve accuracy close to 100%. XGBoost performs best among classic ML, while a 2-layer NN performs strongly; performance drops for undersampled data, with the most pronounced decline observed for the 4-layer NN.","https://schema.org",{"og:url":51,"og:type":86,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":88,"canonical":51},"index,follow",{"doc_id":7,"site_id":23},{"code":4,"msg":5,"data":91},[92,96,100,104,109,114,119,122,126,129,133],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":93,"show_sort_weight":94,"slug":95},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":97,"show_sort_weight":98,"slug":99},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":101,"show_sort_weight":102,"slug":103},"Exam",70,"exam",{"id":105,"doc_module":4,"doc_module_name":45,"category_name":106,"show_sort_weight":107,"slug":108},5,"Comic",60,"comic",{"id":110,"doc_module":4,"doc_module_name":45,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":45,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":28,"slug":125},9,"Religion & Spirituality","religion-spirituality",{"id":28,"doc_module":4,"doc_module_name":45,"category_name":127,"show_sort_weight":28,"slug":128},"World Cup","world-cup",{"id":130,"doc_module":4,"doc_module_name":45,"category_name":131,"show_sort_weight":130,"slug":132},10,"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":45,"category_name":135,"show_sort_weight":105,"slug":136},19,"General","general"]