Implementation and Web Deployment of an Anomaly Detection System for IoT Environments Using the CRISP-ML(Q) Methodology

The expansion of the Internet of Things (IoT) has intensified cyber risk in Edge deployments with limited computational resources, where conventional intrusion detection systems are unfeasible. Aiming to reduce this gap, a lightweight anomaly detection system for IoT networks has been designed and implemented, structured through the CRISP-ML(Q) (Cross-Industry Standard Process for Machine Learning with Quality Assurance) lifecycle. Unsupervised models (Isolation Forest, OCSVM, K-Means, and Autoencoder) and supervised models (Decision Tree, Extra Trees, and Random Forest) were trained and compared on the BoT-IoT dataset, validating their operational behavior through real-time traffic captures during “TCP RST Flood”, “TCP SYN Flood”, “UDP Flood”, and “ICMP Flood” attacks on a Raspberry Pi 4B platform. Isolation Forest provided the most consistent balance between detection capability and computational cost, while the Autoencoder achieved detection rates of up to 98.8%. Among the supervised models, Random Forest achieved the highest ROC–AUC, reaching 98.5%, whereas Extra Trees showed the lowest inference time under attack conditions (0.50 s). The system was deployed on a Raspberry Pi 4B with a Streamlit interface integrating traffic capture, preprocessing, inference, visualization, resource monitoring, and automated alerts. The results demonstrate the feasibility of combining complementary detection strategies in an operational Edge-based IDS, while highlighting the trade-off between detection performance and computational cost.

Authors

Institutions

Publication Details

Journal
Future Internet
Published
2026-10-05
DOI
https://doi.org/10.3390/fi18100537
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Implementation and Web Deployment of an Anomaly Detection System for IoT Environments Using the CRISP-ML(Q) Methodology

Fernando Gutiérrez-Portela, Oscar Augusto Diaz Triana, Almudena Montero Gómez, Carlos M. Paredes et al.
Future Internet
Network Security and Intrusion Detection
article

Implementation and Web Deployment of an Anomaly Detection System for IoT Environments Using the CRISP-ML(Q) Methodology

Fernando Gutiérrez-Portela, Oscar Augusto Diaz Triana, Almudena Montero Gómez, Carlos M. Paredes, Diego Martínez-Castro, Andrés Felipe Yule, Juan Camilo Galeano Bucurú
article en

Abstract

The expansion of the Internet of Things (IoT) has intensified cyber risk in Edge deployments with limited computational resources, where conventional intrusion detection systems are unfeasible. Aiming to reduce this gap, a lightweight anomaly detection system for IoT networks has been designed and implemented, structured through the CRISP-ML(Q) (Cross-Industry Standard Process for Machine Learning with Quality Assurance) lifecycle. Unsupervised models (Isolation Forest, OCSVM, K-Means, and Autoencoder) and supervised models (Decision Tree, Extra Trees, and Random Forest) were trained and compared on the BoT-IoT dataset, validating their operational behavior through real-time traffic captures during “TCP RST Flood”, “TCP SYN Flood”, “UDP Flood”, and “ICMP Flood” attacks on a Raspberry Pi 4B platform. Isolation Forest provided the most consistent balance between detection capability and computational cost, while the Autoencoder achieved detection rates of up to 98.8%. Among the supervised models, Random Forest achieved the highest ROC–AUC, reaching 98.5%, whereas Extra Trees showed the lowest inference time under attack conditions (0.50 s). The system was deployed on a Raspberry Pi 4B with a Streamlit interface integrating traffic capture, preprocessing, inference, visualization, resource monitoring, and automated alerts. The results demonstrate the feasibility of combining complementary detection strategies in an operational Edge-based IDS, while highlighting the trade-off between detection performance and computational cost.

Future InternetVol. 18(10)
University of Tolima (CO), Universidad de Ibagué (CO), Universidad Cooperativa de Colombia (CO), Universidad de San Buenaventura, Bogota (CO), Universidad Autónoma de Occidente (CO)
Openalex Percentile: Top 9%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.