Published May 14, 2026 | Version v1

Behavioral Anomaly Detection in IoT Networks Using Artificial Intelligence

Description

IoT networks are difficult to secure; devices are resource-constrained and heterogeneous, and they generate traffic volumes that make manual monitoring impractical. Because of this, it remains challenging to tell normal behavior apart from malicious activity. In this work, we focus on detecting anomalies in IoT network traffic using an autoencoder-based approach. The model is trained only on normal network behavior and learns to recognize typical patterns. Any significant difference from these patterns is then treated as a potential anomaly. The experiments were performed on a public dataset that included more than 86000 normal network flows alongside 16696 MQTT brute-force attack samples. The model detected 87.73% of attacks. However, a subset of attack flows was not detected – specifically those whose statistical properties closely resembled normal traffic, which the model had no basis to flag as suspicious. Overall, the results show that reconstruction-based detection is effective in practice, but has clear limitations. Using reconstruction error alone is insufficient to detect subtle or well-disguised attacks, so additional methods should be explored in future work.

Originally published in: International Journal of Innovative Solutions in Engineering (IJISE), Vol. 2, No. 2, 2026. Official URL: https://ijise.ba/article/20/

Files

Vol. 2 No. 2 Article 20.pdf

Files (493.3 kB)

Name Size Download all
md5:e8d8690c2f8255589d4aef39e15be327
493.3 kB Preview Download

Additional details

Related works

Is identical to
Journal article: https://ijise.ba/article/20/ (URL)
Is published in
Journal article: 3029-3200 (ISSN)

References