A Task-Specific Autoencoder–CatBoost Framework for Intrusion Detection in Imbalanced IIoT

Industrial Internet of Things (IIoT) intrusion detection remains challenging because of class imbalance, rare attacks, and heterogeneous evaluation protocols. This study proposes a modular intrusion-detection framework based on task-specific autoencoder representation learning and downstream CatBoost classification. The binary branch learns a 16-dimensional representation from benign traffic and combines it with reconstruction error, whereas the multiclass branch uses a separate 24-dimensional representation learned from malicious traffic. On ML-EdgeIIoT, the extended five-fold group-aware binary evaluation achieved ROC-AUC = 0.9925, AP = 0.9981, and F1 = 0.9829, with a benign FPR of 0.1113. A reconstruction-error ablation increased F1 from 0.9800 to 0.9829 and reduced FPR from 0.1311 to 0.1113. The complete 14-class evaluation achieved macro-F1 = 0.6175 and macro-AUC = 0.9549, while the 15-label cascade reached strict end-to-end attack-type success = 0.6584. External validation on WUSTL-IIoT-2021 yielded a five-label macro-F1 of 0.9408 and strict success of 0.9993. These results support the task-specific modular design while highlighting the remaining difficulty of fine-grained attack attribution and false-alarm reduction.

Authors

Institutions

Publication Details

Journal
Future Internet
Published
2026-09-30
DOI
https://doi.org/10.3390/fi18100526
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

A Task-Specific Autoencoder–CatBoost Framework for Intrusion Detection in Imbalanced IIoT

Djalila Boughareb, Yacine Lafifi, Faiza Titouna, Soumia Felkaoui
Future Internet
Network Security and Intrusion Detection
article

A Task-Specific Autoencoder–CatBoost Framework for Intrusion Detection in Imbalanced IIoT

Djalila Boughareb, Yacine Lafifi, Faiza Titouna, Soumia Felkaoui
article en

Abstract

Industrial Internet of Things (IIoT) intrusion detection remains challenging because of class imbalance, rare attacks, and heterogeneous evaluation protocols. This study proposes a modular intrusion-detection framework based on task-specific autoencoder representation learning and downstream CatBoost classification. The binary branch learns a 16-dimensional representation from benign traffic and combines it with reconstruction error, whereas the multiclass branch uses a separate 24-dimensional representation learned from malicious traffic. On ML-EdgeIIoT, the extended five-fold group-aware binary evaluation achieved ROC-AUC = 0.9925, AP = 0.9981, and F1 = 0.9829, with a benign FPR of 0.1113. A reconstruction-error ablation increased F1 from 0.9800 to 0.9829 and reduced FPR from 0.1311 to 0.1113. The complete 14-class evaluation achieved macro-F1 = 0.6175 and macro-AUC = 0.9549, while the 15-label cascade reached strict end-to-end attack-type success = 0.6584. External validation on WUSTL-IIoT-2021 yielded a five-label macro-F1 of 0.9408 and strict success of 0.9993. These results support the task-specific modular design while highlighting the remaining difficulty of fine-grained attack attribution and false-alarm reduction.

Future InternetVol. 18(10)
University of Guelma (DZ), University of Batna 2
Openalex Percentile: Top 9%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.