SE-IADM: an optimized stacked ensemble model for smart IoT attack detection using hybrid feature selection
As the Internet of Things (IoT) has expanded rapidly, many devices are now connected and exchanging large volumes of data. Current intrusion detection systems (IDS) struggle with the complexity, heterogeneity, and dynamism of IoT-based attacks, which demand more powerful and intelligent detection models. Although machine learning (ML) has delivered encouraging outcomes in identifying malicious behavior by detecting suspicious trends in data, a single model may not be as effective at addressing the complexity and variety of threats posed by the IoT. This motivates the need for a robust and adaptive detection framework that can handle various attack patterns in IoT scenarios while minimizing false negatives. To address this, we present SE-IADM (Stacking Ensemble-based IoT Attack Detection Model) an optimized stacking ensemble that integrates the capabilities of three well-known classifiers, namely: Extreme Gradient Boosting (XGBoost), Decision Tree (DT), and Adaptive Boosting (AdaBoost). The model is optimized by employing a hybrid feature selection method in which Greedy and Genetic Algorithms are used to identify the most relevant attributes. To address the issue of class imbalance, we combine the Synthetic Minority Oversampling Technique (SMOTE), which ensures a balanced representation of attack classes in the dataset, leading to model stability and better detection performance. Our model has been assessed using the University of New South Wales Network Behaviour 15 (UNSW-NB15) data and TONIoT data. SE-IADM is tested on two classification scenarios, binary and multiclass. Using the UNSW-NB15 dataset, the model achieves 95.07% accuracy for binary classification and 82.78% with multiclass. In the case of ToNIoT, the model achieves 99.41% accuracy for binary classification and 96.64% for multiclass classification. The findings clearly indicate that our ensemble-based method can go a long way in helping to detect cyber threats in IoT applications. The model can improve accuracy and provide increased flexibility in detecting various kinds of attacks by taking advantage of hybrid selection and data balancing. Various classifiers are combined to create a better model and to provide greater robustness in terms of accuracy and the ability to detect various types of attacks. This is a practical solution that can be deployed in the field of protecting connected systems.
Authors
- Mahfooz Alam (ORCID: https://orcid.org/0000-0003-0668-9796)
- Mohammad Ubaidullah Bokhari (ORCID: https://orcid.org/0000-0002-3413-9014)
- Zubair Ashraf (ORCID: https://orcid.org/0000-0001-7122-2856)
- Mohammad Zunnun Khan (ORCID: https://orcid.org/0000-0002-1552-315X)
- Mohd Zain Khan
- Faheem Syeed Masoodi
- Mohd Shahid Husain
Institutions
- Aligarh Muslim University (IN)
- University of Bisha (SA)
- University of Technology and Applied Sciences - Ibra (OM)
- University of Technology and Applied Sciences — Ibri (OM)
- Bahrain Polytechnic (BH)
Publication Details
- Journal
- Journal of Cloud Computing Advances Systems and Applications
- Published
- 2026-09-30
- DOI
- https://doi.org/10.1186/s13677-026-00995-2
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00