A Two-Tier Hybrid Intrusion Detection System for IoT Networks
DOI:
https://doi.org/10.54938/ijemdcsai.2026.04.2.660Keywords:
Intrusion Detection System (IDS), Internet of Things (IoT), Hybrid Machine Learning, Random Forest, Neural NetworkAbstract
The rapid growth of Internet of Things (IoT) devices has made modern attacks more vulnerable to cyberattacks. Traditional signature-based Intrusion Detection Systems (IDS) are no longer enough to keep up with new and evolving threats. Although machine learning and deep learning have improved detection accuracy, many AI-driven IDS models still face major issues. They often struggle to detect zero-day attacks, produce high false-positive rates and perform poorly with imbalanced datasets. Some models are also too computationally heavy to run efficiently in real time. To address these weaknesses, this research proposes a two-tier hybrid IDS that uses a Random Forest model for quick initial detection and a Neural Network for deeper analysis of suspicious traffic. A confidence threshold of 0.8 is used to decide whether traffic should be accepted or sent for further inspection. Using the NSL-KDD dataset, the system includes preprocessing steps such as binary mapping and structured feature extraction to support both detection stages. Our comparative analysis shows that this hybrid approach can achieve better accuracy, fewer false alarms, and stronger detection of unknown attacks compared to existing Machine Learning / Deep Learning IDS methods. It is more practical for large, diverse IoT environments because it reduces computational load while maintaining strong detection capability. Overall, the proposed architecture provides a balanced and efficient solution that overcomes key limitations of existing IDS models and offers a pathway towards a more robust real-time IoT intrusion detection.
Downloads
Published
How to Cite
Issue
Section
Categories
License
Copyright (c) 2026 International Journal of Emerging Multidisciplinaries: Computer Science & Artificial Intelligence

This work is licensed under a Creative Commons Attribution 4.0 International License.






