Implementation and Web Deployment of an Anomaly Detection System for IoT Environments Using the CRISP-ML(Q) Methodology
The expansion of the Internet of Things (IoT) has intensified cyber risk in Edge deployments with limited computational resources, where conventional intrusion detection systems are unfeasible. Aiming to reduce this gap, a lightweight anomaly detection system for IoT networks has been designed and implemented, structured through the CRISP-ML(Q) (Cross-Industry Standard Process for Machine Learning with Quality Assurance) lifecycle. Unsupervised models (Isolation Forest, OCSVM, K-Means, and Autoencoder) and supervised models (Decision Tree, Extra Trees, and Random Forest) were trained and compared on the BoT-IoT dataset, validating their operational behavior through real-time traffic captures during “TCP RST Flood”, “TCP SYN Flood”, “UDP Flood”, and “ICMP Flood” attacks on a Raspberry Pi 4B platform. Isolation Forest provided the most consistent balance between detection capability and computational cost, while the Autoencoder achieved detection rates of up to 98.8%. Among the supervised models, Random Forest achieved the highest ROC–AUC, reaching 98.5%, whereas Extra Trees showed the lowest inference time under attack conditions (0.50 s). The system was deployed on a Raspberry Pi 4B with a Streamlit interface integrating traffic capture, preprocessing, inference, visualization, resource monitoring, and automated alerts. The results demonstrate the feasibility of combining complementary detection strategies in an operational Edge-based IDS, while highlighting the trade-off between detection performance and computational cost.
Authors
- Fernando Gutiérrez-Portela (ORCID: https://orcid.org/0000-0003-3722-3809)
- Oscar Augusto Diaz Triana (ORCID: https://orcid.org/0000-0001-7781-449X)
- Almudena Montero Gómez (ORCID: https://orcid.org/0009-0007-5979-8650)
- Carlos M. Paredes (ORCID: https://orcid.org/0000-0002-8951-5259)
- Diego Martínez-Castro (ORCID: https://orcid.org/0000-0002-2618-0834)
- Andrés Felipe Yule (ORCID: https://orcid.org/0009-0000-6129-4418)
- Juan Camilo Galeano Bucurú (ORCID: https://orcid.org/0009-0002-3658-0628)
Institutions
- University of Tolima (CO)
- Universidad de Ibagué (CO)
- Universidad Cooperativa de Colombia (CO)
- Universidad de San Buenaventura, Bogota (CO)
- Universidad Autónoma de Occidente (CO)
Publication Details
- Journal
- Future Internet
- Published
- 2026-10-05
- DOI
- https://doi.org/10.3390/fi18100537
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00