Towards a systemic approach to fitness-based feature optimization under limited resources for IoT attack detectors
Purpose The paper aims to propose, through feature extraction/selection techniques, a systematic approach for the optimization of features based on fitness and allowing IoT attack detectors to operate efficiently with limited resources. Design/methodology/approach Through a systematic approach, we optimized the attack detection model while minimizing resource consumption. Using the TON IoT Dataset, we perform several experiments which show that feature selection methods outperformed feature extraction, with Recursive Feature Elimination (RFE) and Information Gain (IG) emerging as highly effective. We modelled a fitness function that balanced detection rate, false alarm rate and feature count, enabling the identification of optimal feature subsets where tree-based feature selection performs the best score. Additionally, resource management was a core consideration, showcasing that model with fewer features, reduced memory and CPU usage, making it suitable for resource limited IoT devices. Findings Whereas the RFE and IG resulting machine learning models stood out as the top-performing models, achieving high fitness and detection accuracy, only the IG model is suitable for high-end IoT devices. Likewise, Linear Discriminant Analysis (LDA) and LASSO models are the cheapest, with minimal resource overhead, using the TON IoT dataset, and therefore make them suitable for low-end IoT devices. Research limitations/implications This research has limitations, focusing primarily on the TON IoT and CICIoT2023 datasets for testing and validating the approach. Practical implications The paper includes implications for the development of models that can be embedded in devices with low resources. Originality/value This research contributes to feature optimization for attack detection in IoT by providing a framework for resource-aware IoT smart systems. As IoT evolves, the findings can improve the security and efficiency of devices.
Authors
- Claude Fachkha (ORCID: https://orcid.org/0000-0003-2863-4817)
- Franklin Tchakounté (ORCID: https://orcid.org/0000-0003-0723-2640)
- Floriane Mefo Kue
- William Shu
- Marcellin Atemkeng (ORCID: https://orcid.org/0000-0002-9020-3885)
- Ismael Abbo (ORCID: https://orcid.org/0009-0003-4834-8962)
- Jean Marie Kuate Fotso
Institutions
- University of Dubai (AE)
- Université de Yaoundé I (CM)
- University of Buea (CM)
- Rhodes University (ZA)
- University of Ngaoundéré (CM)
Publication Details
- Journal
- Data Technologies and Applications
- Published
- 2026-09-25
- DOI
- https://doi.org/10.1108/dta-01-2025-0032
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00