Fog-Deployable XGBoost Framework for DDoS Detection in IoT Networks

The rapid growth of Internet of Things (IoT) deployment has increased exposure to Distributed Denial of Service (DDoS) attacks, while the latency and bandwidth costs of cloud-centric intrusion detection constrain real-time response. This paper presents a fog-based DDoS detection framework that combines XGBoost with information-gain feature selection. The framework uses 23 of the 78 features, a 70.5% reduction, at a measured accuracy cost of 0.007 percentage points. The evaluation used a sample drawn from every file of the CICDDoS2019 release, with benign traffic retained and attack traffic sampled to an attack-to-benign ratio of approximately 10:1. Feature selection, hyperparameter tuning, and threshold calibration were confined to the training partition. Under a random stratified split, the model reached 99.98% accuracy at a 0.058% false-positive rate. Under the capture-day split designated by the dataset authors, accuracy fell to 91.61%, and the false-positive rate rose to 8.82%, equivalent to 8820 false alerts per 100,000 benign flows. Per-request inference on a two-core profile took 1.0 to 5.2 ms over three repeated runs; feature extraction and network transit were not measured. Deployment would require monitoring for distribution shift and periodic retraining.

Authors

Institutions

Publication Details

Journal
Sensors
Published
2026-09-25
DOI
https://doi.org/10.3390/s26196068
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Fog-Deployable XGBoost Framework for DDoS Detection in IoT Networks

Linda Mohaisen, Abeer Albalawi
Sensors
Network Security and Intrusion Detection
article

Fog-Deployable XGBoost Framework for DDoS Detection in IoT Networks

Linda Mohaisen, Abeer Albalawi
article en

Abstract

The rapid growth of Internet of Things (IoT) deployment has increased exposure to Distributed Denial of Service (DDoS) attacks, while the latency and bandwidth costs of cloud-centric intrusion detection constrain real-time response. This paper presents a fog-based DDoS detection framework that combines XGBoost with information-gain feature selection. The framework uses 23 of the 78 features, a 70.5% reduction, at a measured accuracy cost of 0.007 percentage points. The evaluation used a sample drawn from every file of the CICDDoS2019 release, with benign traffic retained and attack traffic sampled to an attack-to-benign ratio of approximately 10:1. Feature selection, hyperparameter tuning, and threshold calibration were confined to the training partition. Under a random stratified split, the model reached 99.98% accuracy at a 0.058% false-positive rate. Under the capture-day split designated by the dataset authors, accuracy fell to 91.61%, and the false-positive rate rose to 8.82%, equivalent to 8820 false alerts per 100,000 benign flows. Per-request inference on a two-core profile took 1.0 to 5.2 ms over three repeated runs; feature extraction and network transit were not measured. Deployment would require monitoring for distribution shift and periodic retraining.

SensorsVol. 26(19)
King Abdulaziz University (SA), Dar Al-Hekma University (SA)
Openalex Percentile: Top 9%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.