Skip to main navigation Skip to search Skip to main content

Hybrid dual-head IDS: A lightweight and explainable deep learning DDOS/DOS framework for zero-day and imbalanced attack detection in IoT networks

    • Northwestern Polytechnical University
    • Quanzhou University of Information Engineering
    • Umm Al-Qura University
    • Lero
    • Department of Electrical and Electronics Engineering
    • Dogus University

    Research output: Contribution to a Journal (Peer & Non Peer)Articlepeer-review

    Abstract

    The rapid expansion of IoT has escalated security risks of DDoS and DoS for cyber-physical systems, but deep learning-based Intrusion Detection Systems (IDS) face challenges like poor handling of imbalanced datasets, inability to detect zero-day attacks, lack of transparency and scalability. This paper proposes Hybrid Dual-Head IDS, a lightweight, explainable deep learning framework to address these issues. The framework employs a dataset-adaptive Wasserstein GAN with Gradient Penalty per class (auto-selecting jitter, bootstrapping, or WGAN-GP as determined by sample size (Neff)-scaled Kolmogorov–Smirnov test) and a functionally partitioned dual-head architecture with a hybrid loss function. A ZDS Ratio that is zero-day separation for vanishing FPR and per-class SHAP values (that can be linked to the dual-head thresholds) is used by the operational analysts. Evaluated on CIC-IoT2023, BoT-IoT, and ToN-IoT datasets, Hybrid Dual-Head IDS achieves over 99.5% accuracy and F1-scores, perfect scores on the imbalanced BoT-IoT dataset, and high zero-day detection capability. The evaluation is further strengthened by introducing a true zero-day holdout protocol, a component-wise ablation study, five-seed statistical validation, direct synthetic-data fidelity analysis, and ROC-AUC and threshold-sensitivity evaluation. In true zero-day holdout setting, the model achieved ZDS ratios of 175,900.50x/1094.12x on CIC-IoT2023 (binary/multiclass), 7260,770.86x/12791298.51x on BoT-IoT, and 223.95x on ToN-IoT. Results further show stable behavior across random seeds, high-quality synthetic augmentation where needed, and very low false positive rates under ROC-based threshold selection. The compact size (≈0.5 MB) enables efficient network protection through high throughput which provides an effective practical solution for IoT network security against known and unknown threats.

    Original languageEnglish
    Article number111498
    JournalResults in Engineering
    Volume31
    DOIs
    Publication statusPublished - Sept 2026

    Keywords

    • Deep learning
    • Explainable AI (XAI)
    • Imbalanced learning
    • Intrusion detection system (IDS)
    • IoT security
    • Zero-day attack detection

    Fingerprint

    Dive into the research topics of 'Hybrid dual-head IDS: A lightweight and explainable deep learning DDOS/DOS framework for zero-day and imbalanced attack detection in IoT networks'. Together they form a unique fingerprint.

    Cite this