[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-127810-en":3,"doc-seo-127810-105":31,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},127810,1099523882367,"Hazel","https://ap-avatar.wpscdn.com/davatar_9964176cb1d06d4a9deccf72a44ae3dc",8,"Research & Report","Optimizing IoT Intrusion Detection Using Balanced Class Distribution - Feature Selection - Ensemble Machine Learning Techniques","Internet of Things (IoT) platforms expand innovation, efficiency, and sustainability, but the rapid increase in connected devices raises intrusion risk and threatens cybersecurity. Intrusion detection systems (IDSs) mitigate these threats by identifying malicious behavior in networks, yet traditional signature or rule-based approaches struggle with novel attacks. Machine learning and deep learning can improve detection, but face issues such as overfitting and irrelevant features. This work optimizes IoT IDS by applying class balancing and feature selection during preprocessing, then evaluating ensemble models on UNSW-NB15 and NSL-KD datasets.","sensors   \nArticle  \nOptimizing IoT Intrusion Detection Using Balanced Class Distribution, Feature Selection, and Ensemble Machine Learning Techniques  \nMuhammad Bisri Musthafa 1, *, Samsul Huda 2, *, Yuta Kodera 1, Md. Arshad Ali 3, Shunsuke Araki 4, Jedidah Mwaura 4 and Yasuyuki Nogami 1, *  \nCitation: Musthafa, M.B.; Huda, S.; Kodera, Y.; Ali, M.A.; Araki, S.; Mwaura, J.; Nogami, Y. Optimizing IoT Intrusion Detection Using Balanced Class Distribution, Feature Selection, and Ensemble Machine Learning Techniques. Sensors 2024, 24, 4293. [https://doi.org/10.3390/](https://doi.org/10.3390/)[ ](https://doi.org/10.3390/)s24134293  \nAcademic Editors: Rongxing Lu, Xichen Zhang and Yunguo Guan  \nReceived: 29 May 2024  \nRevised: 26 June 2024  \nAccepted: 27 June 2024  \nPublished: 1 July 2024  \nCopyright: © 2024 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license ([https://](https://)[ ](https://)[creativecommons.org/licenses/by/](creativecommons.org/licenses/by/)[ ](creativecommons.org/licenses/by/)[4.0/](4.0/)) .  \n1 Graduate School of Environmental, Life, Natural Science and Technology, Okayama University, Okayama 700-8530, Japan  \n2 Green Innovation Center, Okayama University, Okayama 700-8530, Japan  \n3 Faculty of CSE, Hajee Mohammad Danesh Science and Technology University, Dinajpur 5200, Bangladesh  \n4 Graduate School of Computer Science and Systems Engineering, Kyushu Institute of Technology, Fukuoka 804-8550, Japan  \n* [Correspondence: bisrimusthafa@s.okayama-u.ac.jp](Correspondence: bisrimusthafa@s.okayama-u.ac.jp) (M.B.M.); [shuda@okayama-u.ac.jp](shuda@okayama-u.ac.jp) (S.H.); [yasuyuki.nogami@okayama-u.ac.jp](yasuyuki.nogami@okayama-u.ac.jp) (Y.N.)  \nAbstract: Internet of Things (IoT) devices are leading to advancements in innovation, efficiency, and sustainability across various industries. However, as the number of connected IoT devices increases, the risk of intrusion becomes a major concern in IoT security. To prevent intrusions, it is crucial to implement intrusion detection systems (IDSs) that can detect and prevent such attacks. IDSs are a critical component of cybersecurity infrastructure. They are designed to detect and respond to malicious activities within a network or system. Traditional IDS methods rely on predefined signatures or rules to identify known threats, but these techniques may struggle to detect novel or sophisticated attacks. The implementation of IDSs with machine learning (ML) and deep learning (DL) techniques has been proposed to improve IDSs’ ability to detect attacks. This will enhance overall cybersecurity posture and resilience. However, ML and DL techniques face several issues that may impact the models’ performance and effectiveness, such as overfitting and the effects of unimportant features on finding meaningful patterns. To ensure better performance and reliability of machine learning models in IDSs when dealing with new and unseen threats, the models need to be optimized. This can be done by addressing overfitting and implementing feature selection. In this paper, we propose a scheme to optimize IoT intrusion detection by using class balancing and feature selection for preprocessing. We evaluated the experiment on the UNSW-NB15 dataset and the NSL-KD dataset by implementing two different ensemble models: one using a support vector machine (SVM) with bagging and another using long short-term memory (LSTM) with stacking. The results of the performance and the confusion matrix show that the LSTM stacking with analysis of variance (ANOVA) feature selection model is a superior model for classifying network attacks. It has remarkable accuracies of 96.92% and 99.77% and overfitting values of 0.33% and 0.04% on the two datasets, respectively. The model’s ROC is also shaped with a sharp bend, with AUC values of 0.9665 and 0.9971 for the UNSW-NB15 dataset and the N","cbCaiesVJG6DoSQK","https://ap.wps.com/l/cbCaiesVJG6DoSQK","pdf",987037,2,1,19,"English","en",105,"# Introduction\n## IoT and security challenges\n## Intrusion detection systems and limitations of traditional methods\n## Machine learning-based approaches and optimization needs\n# Proposed approach and evaluation\n## Class balancing and feature selection preprocessing\n## Ensemble models and datasets used\n## Experimental results and comparative performance","[{\"question\":\"Why is optimizing IoT intrusion detection necessary when using machine learning models?\",\"answer\":\"Optimization is needed to address overfitting and the negative impact of unimportant features, which can reduce reliability when handling new and unseen threats.\"},{\"question\":\"What techniques does the paper use to improve intrusion detection performance?\",\"answer\":\"It proposes preprocessing based on class balancing and feature selection, and evaluates ensemble learning strategies to strengthen classification capability.\"},{\"question\":\"Which ensemble models are evaluated and what datasets are used?\",\"answer\":\"The study evaluates an SVM with bagging and an LSTM with stacking, using the UNSW-NB15 and NSL-KD datasets.\"}]","Optimizing IoT Intrusion Detection Using Balanced Class Distribution - Feature Selection - Ensemble Machine Learning Techniques | PDF",1785941963,48,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":29},"optimizing-iot-intrusion-detection-using-balanced-class-distribution-feature-selection-ensemble-machine-learning-techniques","",{"@graph":37,"@context":86},[38,54,69],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,48,51],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":20},"https://docshare.wps.com/document/","Document",{"item":49,"name":12,"@type":44,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":44,"position":53},"https://docshare.wps.com/document/optimizing-iot-intrusion-detection-using-balanced-class-distribution-feature-selection-ensemble-machine-learning-techniques/127810/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":42,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-22","2026-08-05",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"Why is optimizing IoT intrusion detection necessary when using machine learning models?","Question",{"text":76,"@type":77},"Optimization is needed to address overfitting and the negative impact of unimportant features, which can reduce reliability when handling new and unseen threats.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What techniques does the paper use to improve intrusion detection performance?",{"text":81,"@type":77},"It proposes preprocessing based on class balancing and feature selection, and evaluates ensemble learning strategies to strengthen classification capability.",{"name":83,"@type":74,"acceptedAnswer":84},"Which ensemble models are evaluated and what datasets are used?",{"text":85,"@type":77},"The study evaluates an SVM with bagging and an LSTM with stacking, using the UNSW-NB15 and NSL-KD datasets.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":47,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":47,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":47,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":22,"doc_module":4,"doc_module_name":47,"category_name":137,"show_sort_weight":107,"slug":138},"General","general"]