Zada Islam, Omran Esraa, Jan Salman, Alfraihi Hessa, Alsalamah Seetah, Alshahrani Abdullah, Hayat Shaukat, Phi Nguyen
Department of Software Engineering, Faculty of computing, International Islamic University Islamabad, Islamabad, Pakistan.
Department of Computer Science, Gulf University for Science and Technology and Member in GEAR Research Center, Mubarak Al-Abdullah, Kwait.
PLoS One. 2025 Jul 21;20(7):e0328050. doi: 10.1371/journal.pone.0328050. eCollection 2025.
The dynamical growth of cyber threats in IoT setting requires smart and scalable intrusion detection systems. In this paper, a Lean-based hybrid Intrusion Detection framework using Particle Swarm Optimization and Genetic Algorithm (PSO-GA) to select the features and Extreme Learning Machine and Bootstrap Aggregation (ELM-BA) to classify the features is introduced. The proposed framework obtains high detection rates on the CICIDS-2017 dataset, with 100 percent accuracy on important attack categories, like PortScan, SQL Injection, and Brute Force. Statistical verification and visual evaluation metrics are used to validate the model, which can be interpreted and proved to be solid. The framework is crafted following Lean ideals; thus, it has minimal computational overhead and optimal detection efficiency. It can be efficiently ported to the real-world usage in smart cities and industrial internet of things systems. The suggested framework can be deployed in smart cities and industrial Internet of Things (IoT) systems in real time, and it provides scalable and effective cyber threat detection. By adopting it, false positives can be greatly minimized, the latency of the decision-making process can be decreased, as well as the IoT critical infrastructure resilience against the ever-changing cyber threats can be increased.
物联网环境中网络威胁的动态增长需要智能且可扩展的入侵检测系统。本文介绍了一种基于精益的混合入侵检测框架,该框架使用粒子群优化算法和遗传算法(PSO-GA)来选择特征,并使用极限学习机和自助聚合算法(ELM-BA)对特征进行分类。所提出的框架在CICIDS - 2017数据集上获得了高检测率,在诸如端口扫描、SQL注入和暴力破解等重要攻击类别上的准确率达到了100%。使用统计验证和可视化评估指标来验证模型,该模型可以被解释且被证明是可靠的。该框架是按照精益理念构建的;因此,它具有最小的计算开销和最佳的检测效率。它可以有效地移植到智慧城市和工业物联网系统的实际应用中。所建议的框架可以实时部署在智慧城市和工业物联网(IoT)系统中,并提供可扩展且有效的网络威胁检测。通过采用该框架,可以极大地减少误报,降低决策过程的延迟,并提高物联网关键基础设施抵御不断变化的网络威胁的能力。