SE-IADM: an optimized stacked ensemble model for smart IoT attack detection using hybrid feature selection

As the Internet of Things (IoT) has expanded rapidly, many devices are now connected and exchanging large volumes of data. Current intrusion detection systems (IDS) struggle with the complexity, heterogeneity, and dynamism of IoT-based attacks, which demand more powerful and intelligent detection models. Although machine learning (ML) has delivered encouraging outcomes in identifying malicious behavior by detecting suspicious trends in data, a single model may not be as effective at addressing the complexity and variety of threats posed by the IoT. This motivates the need for a robust and adaptive detection framework that can handle various attack patterns in IoT scenarios while minimizing false negatives. To address this, we present SE-IADM (Stacking Ensemble-based IoT Attack Detection Model) an optimized stacking ensemble that integrates the capabilities of three well-known classifiers, namely: Extreme Gradient Boosting (XGBoost), Decision Tree (DT), and Adaptive Boosting (AdaBoost). The model is optimized by employing a hybrid feature selection method in which Greedy and Genetic Algorithms are used to identify the most relevant attributes. To address the issue of class imbalance, we combine the Synthetic Minority Oversampling Technique (SMOTE), which ensures a balanced representation of attack classes in the dataset, leading to model stability and better detection performance. Our model has been assessed using the University of New South Wales Network Behaviour 15 (UNSW-NB15) data and TONIoT data. SE-IADM is tested on two classification scenarios, binary and multiclass. Using the UNSW-NB15 dataset, the model achieves 95.07% accuracy for binary classification and 82.78% with multiclass. In the case of ToNIoT, the model achieves 99.41% accuracy for binary classification and 96.64% for multiclass classification. The findings clearly indicate that our ensemble-based method can go a long way in helping to detect cyber threats in IoT applications. The model can improve accuracy and provide increased flexibility in detecting various kinds of attacks by taking advantage of hybrid selection and data balancing. Various classifiers are combined to create a better model and to provide greater robustness in terms of accuracy and the ability to detect various types of attacks. This is a practical solution that can be deployed in the field of protecting connected systems.

Authors

Institutions

Publication Details

Journal
Journal of Cloud Computing Advances Systems and Applications
Published
2026-09-30
DOI
https://doi.org/10.1186/s13677-026-00995-2
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

SE-IADM: an optimized stacked ensemble model for smart IoT attack detection using hybrid feature selection

Mahfooz Alam, Mohammad Ubaidullah Bokhari, Zubair Ashraf, Mohammad Zunnun Khan et al.
Journal of Cloud Computing Advances Systems and Applications
Network Security and Intrusion Detection
article

SE-IADM: an optimized stacked ensemble model for smart IoT attack detection using hybrid feature selection

Mahfooz Alam, Mohammad Ubaidullah Bokhari, Zubair Ashraf, Mohammad Zunnun Khan, Mohd Zain Khan, Faheem Syeed Masoodi, Mohd Shahid Husain
article en

Abstract

As the Internet of Things (IoT) has expanded rapidly, many devices are now connected and exchanging large volumes of data. Current intrusion detection systems (IDS) struggle with the complexity, heterogeneity, and dynamism of IoT-based attacks, which demand more powerful and intelligent detection models. Although machine learning (ML) has delivered encouraging outcomes in identifying malicious behavior by detecting suspicious trends in data, a single model may not be as effective at addressing the complexity and variety of threats posed by the IoT. This motivates the need for a robust and adaptive detection framework that can handle various attack patterns in IoT scenarios while minimizing false negatives. To address this, we present SE-IADM (Stacking Ensemble-based IoT Attack Detection Model) an optimized stacking ensemble that integrates the capabilities of three well-known classifiers, namely: Extreme Gradient Boosting (XGBoost), Decision Tree (DT), and Adaptive Boosting (AdaBoost). The model is optimized by employing a hybrid feature selection method in which Greedy and Genetic Algorithms are used to identify the most relevant attributes. To address the issue of class imbalance, we combine the Synthetic Minority Oversampling Technique (SMOTE), which ensures a balanced representation of attack classes in the dataset, leading to model stability and better detection performance. Our model has been assessed using the University of New South Wales Network Behaviour 15 (UNSW-NB15) data and TONIoT data. SE-IADM is tested on two classification scenarios, binary and multiclass. Using the UNSW-NB15 dataset, the model achieves 95.07% accuracy for binary classification and 82.78% with multiclass. In the case of ToNIoT, the model achieves 99.41% accuracy for binary classification and 96.64% for multiclass classification. The findings clearly indicate that our ensemble-based method can go a long way in helping to detect cyber threats in IoT applications. The model can improve accuracy and provide increased flexibility in detecting various kinds of attacks by taking advantage of hybrid selection and data balancing. Various classifiers are combined to create a better model and to provide greater robustness in terms of accuracy and the ability to detect various types of attacks. This is a practical solution that can be deployed in the field of protecting connected systems.

Journal of Cloud Computing Advances Systems and Applications
Aligarh Muslim University (IN), University of Bisha (SA), University of Technology and Applied Sciences - Ibra (OM), University of Technology and Applied Sciences — Ibri (OM), Bahrain Polytechnic (BH)
Peace, Justice and strong institutions
Openalex Percentile: Top 9%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.