{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,8]],"date-time":"2026-03-08T23:50:38Z","timestamp":1773013838154,"version":"3.50.1"},"reference-count":45,"publisher":"Institution of Engineering and Technology (IET)","issue":"1","license":[{"start":{"date-parts":[[2025,9,24]],"date-time":"2025-09-24T00:00:00Z","timestamp":1758672000000},"content-version":"vor","delay-in-days":266,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/doi.wiley.com\/10.1002\/tdm_license_1.1"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62402520"],"award-info":[{"award-number":["62402520"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012456","name":"National Social Science Fund of China","doi-asserted-by":"publisher","award":["2022-SKJJ-B-057"],"award-info":[{"award-number":["2022-SKJJ-B-057"]}],"id":[{"id":"10.13039\/501100012456","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100007128","name":"Natural Science Foundation of Shaanxi Province","doi-asserted-by":"publisher","award":["2024JC-YBQN-0620"],"award-info":[{"award-number":["2024JC-YBQN-0620"]}],"id":[{"id":"10.13039\/501100007128","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["ietresearch.onlinelibrary.wiley.com"],"crossmark-restriction":true},"short-container-title":["IET Information Security"],"published-print":{"date-parts":[[2025,1]]},"abstract":"<jats:p>The Internet of Things (IoT) is an emerging technology that has attracted significant attention and triggered a technical revolution in recent years. Numerous IoT devices are directly connected to the physical world, such as security cameras and medical equipment, making IoT security a critical issue. Artificial intelligence (AI) based intrusion detection technology for IoT can rapidly detect network attacks and improve security performance. However, this technology is vulnerable to backdoor attacks. As an important form of adversarial machine learning (ML), backdoor attacks can allow malicious traffic to evade detection of the intrusion detection system, posing a significant threat to the IoT security. This study focuses on backdoor attack and defense methods for AI\u2013based IoT intrusion detection system. Specifically, we first use different ML and deep learning (DL) classification models to classify IoT traffic data, thereby achieving intrusion detection within IoT. Additionally, we employ data poisoning techniques to implant backdoors into models, enabling backdoor attacks on classification models. For backdoor defense, we propose backdoor detection and mitigate methods: (1) The proposed backdoor detection method is achieved by leveraging the strong correlation between the backdoor trigger and the target classification; (2) we utilize the unlearning method to mitigate the backdoor effect, enhancing the robustness of classification networks. Extensive experiments were conducted on the CICIOT2023 dataset to evaluate the effectiveness of IoT intrusion detection, backdoor attack, and defense.<\/jats:p>","DOI":"10.1049\/ise2\/6664900","type":"journal-article","created":{"date-parts":[[2025,9,24]],"date-time":"2025-09-24T15:04:57Z","timestamp":1758726297000},"update-policy":"https:\/\/doi.org\/10.1002\/crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Backdoor Attack and Defense Methods for AI\u2013Based IoT Intrusion Detection System"],"prefix":"10.1049","volume":"2025","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-1424-0980","authenticated-orcid":false,"given":"Bowen","family":"Ma","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-6193-0854","authenticated-orcid":false,"given":"Jiangwei","family":"Shi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-2558-5387","authenticated-orcid":false,"given":"Ning","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0326-8737","authenticated-orcid":false,"given":"Chen","family":"Fang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5882-9431","authenticated-orcid":false,"given":"Yongjin","family":"Hu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"265","published-online":{"date-parts":[[2025,9,24]]},"reference":[{"key":"e_1_2_9_1_2","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2012.111412.00158"},{"key":"e_1_2_9_2_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10796-014-9492-7"},{"key":"e_1_2_9_3_2","doi-asserted-by":"publisher","DOI":"10.1155\/2013\/794326"},{"key":"e_1_2_9_4_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2017.04.002"},{"key":"e_1_2_9_5_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2012.09.004"},{"key":"e_1_2_9_6_2","doi-asserted-by":"crossref","unstructured":"ZhangX. LiJ. ZhangD. GaoJ. andJiangH. Research on Feature Selection for Cyber Attack Detection in Industrial Internet of Things Proceedings of the 2020 International Conference on Cyberspace Innovation of Advanced Technologies 2020 Association for Computing Machinery 256\u2013262.","DOI":"10.1145\/3444370.3444581"},{"key":"e_1_2_9_7_2","first-page":"60","article-title":"Network Intrusion Detection Based on rough Set and k-Nearest Neighbour","volume":"2","author":"Adetunmbi A. O.","year":"2008","journal-title":"International Journal of Computing and ICT Research"},{"key":"e_1_2_9_8_2","doi-asserted-by":"crossref","unstructured":"WangW. ZhangB. YuZ. andGaoX. Anomaly Detection Method of Unknown Protocol in Power Industrial Control System Based on RNN 2022 5th International Conference on Renewable Energy and Power Engineering (REPE) 2022 IEEE 68\u201372.","DOI":"10.1109\/REPE55559.2022.9950033"},{"key":"e_1_2_9_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSUSC.2024.3492290"},{"key":"e_1_2_9_10_2","unstructured":"ZhuP. PanZ. LiuY. TianJ. TangK. andWangZ. A General Black-Box Adversarial Attack on Graph-Based Fake News Detectors 33th International Joint Conference on Artificial Intelligence 2024 IJCAI 568\u2013576."},{"key":"e_1_2_9_11_2","first-page":"10546","article-title":"BackdoorBench: A Comprehensive Benchmark of Backdoor Learning","volume":"35","author":"Wu B.","year":"2022","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_2_9_12_2","unstructured":"GuT. Dolan-GavittB. andGargS. Badnets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain 2017 arXiv preprint arXiv: 1708.06733."},{"key":"e_1_2_9_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3182979"},{"key":"e_1_2_9_14_2","first-page":"1487","volume-title":"30th USENIX Security Symposium (USENIX security 21)","author":"Severi G.","year":"2021"},{"key":"e_1_2_9_15_2","doi-asserted-by":"crossref","unstructured":"NingR. XinC. andWuH. Trojanflow: A Neural Backdoor Attack to Deep Learning-Based Network Traffic Classifiers IEEE INFOCOM 2022-IEEE Conference on Computer Communications 2022 IEEE 1429\u20131438.","DOI":"10.1109\/INFOCOM48880.2022.9796878"},{"key":"e_1_2_9_16_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10586-022-03776-z"},{"key":"e_1_2_9_17_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11831-020-09496-0"},{"key":"e_1_2_9_18_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2019.01.023"},{"key":"e_1_2_9_19_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2020.113864"},{"key":"e_1_2_9_20_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2020.12.007"},{"key":"e_1_2_9_21_2","doi-asserted-by":"publisher","DOI":"10.32604\/cmc.2023.041186"},{"key":"e_1_2_9_22_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2021.100379"},{"key":"e_1_2_9_23_2","doi-asserted-by":"publisher","DOI":"10.3390\/s19112528"},{"key":"e_1_2_9_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2019.2927886"},{"key":"e_1_2_9_25_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2020.07.020"},{"key":"e_1_2_9_26_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2021.115524"},{"key":"e_1_2_9_27_2","doi-asserted-by":"crossref","unstructured":"GohJ. AdepuS. TanM. andLeeZ. S. Anomaly Detection in Cyber Physical Systems Using Recurrent Neural Networks 2017 IEEE 18th International Symposium on High Assurance Systems Engineering (HASE) 2017 IEEE 140\u2013145.","DOI":"10.1109\/HASE.2017.36"},{"key":"e_1_2_9_28_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2023.10.005"},{"key":"e_1_2_9_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/3651306"},{"key":"e_1_2_9_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3353302"},{"key":"e_1_2_9_31_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.asr.2024.11.054"},{"key":"e_1_2_9_32_2","first-page":"16216","volume-title":"International Conference on Machine Learning","author":"Khaddaj A.","year":"2023"},{"key":"e_1_2_9_33_2","unstructured":"KandpalN. JagielskiM. Tram\u00e8rF. andCarliniN. Backdoor Attacks for in-Context Learning With Language Models 2023 arXiv preprint arXiv: 2307.14692."},{"key":"e_1_2_9_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"e_1_2_9_35_2","first-page":"3611","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Pan X.","year":"2022"},{"key":"e_1_2_9_36_2","doi-asserted-by":"crossref","unstructured":"WangL. JavedZ. WuX. GuoW. XingX. andSongD. BACKDOORL: Backdoor Attack Against Competitive Reinforcement Learning 2021 arXiv preprint arXiv: 2105.00579https:\/\/doi.org\/10.24963\/ijcai.2021\/509.","DOI":"10.24963\/ijcai.2021\/509"},{"key":"e_1_2_9_37_2","unstructured":"ChenB. CarvalhoW. andBaracaldoN. et al.Detecting Backdoor Attacks on Deep Neural Networks by Activation Clustering 2018 arXiv preprint arXiv: 1811.03728."},{"key":"e_1_2_9_38_2","doi-asserted-by":"crossref","unstructured":"GaoY. XuC. WangD. ChenS. RanasingheD. C. andNepalS. Strip: A Defence Against Trojan Attacks on Deep Neural Networks Proceedings of the 35th Annual Computer Security Applications Conference 2019 Association for Computing Machinery 113\u2013125.","DOI":"10.1145\/3359789.3359790"},{"key":"e_1_2_9_39_2","unstructured":"WangW. TianZ. andYuS. Machine Unlearning: A Comprehensive Survey 2024 arXiv preprint arXiv: 2405.07406."},{"key":"e_1_2_9_40_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_2_9_41_2","doi-asserted-by":"crossref","unstructured":"HolodnakJ. T. BrownO. MattererJ. andLemkeA. Backdoor Poisoning of Encrypted Traffic Classifiers 2022 IEEE International Conference on Data Mining Workshops (ICDMW) 2022 577\u2013585.","DOI":"10.1109\/ICDMW58026.2022.00080"},{"key":"e_1_2_9_42_2","doi-asserted-by":"crossref","unstructured":"SeveriG. BoboilaS. OpreaA. HolodnakJ. KratkiewiczK. andMattererJ. Poisoning Network Flow Classifiers Proceedings of the 39th Annual Computer Security Applications Conference 2023 Association for Computing Machinery 337\u2013351.","DOI":"10.1145\/3627106.3627123"},{"key":"e_1_2_9_43_2","doi-asserted-by":"crossref","unstructured":"BachlM. HartlA. FabiniJ. andZsebyT. Walling up Backdoors in Intrusion Detection Systems Proceedings of the 3rd ACM CoNEXT Workshop on Big Data Machine Learning and Artificial Intelligence for Data Communication Networks 2019 Association for Computing Machinery 8\u201313.","DOI":"10.1145\/3359992.3366638"},{"key":"e_1_2_9_44_2","doi-asserted-by":"crossref","unstructured":"WangB. et al.Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural Networks 2019 IEEE symposium on Security and Privacy (SP) 2019 IEEE 707\u2013723.","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_2_9_45_2","doi-asserted-by":"publisher","DOI":"10.3390\/s23135941"}],"container-title":["IET Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/pdf\/10.1049\/ise2\/6664900","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/full-xml\/10.1049\/ise2\/6664900","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/pdf\/10.1049\/ise2\/6664900","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,8]],"date-time":"2026-03-08T22:35:58Z","timestamp":1773009358000},"score":1,"resource":{"primary":{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/10.1049\/ise2\/6664900"}},"subtitle":[],"editor":[{"given":"Bohui","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]}],"short-title":[],"issued":{"date-parts":[[2025,1]]},"references-count":45,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,1]]}},"alternative-id":["10.1049\/ise2\/6664900"],"URL":"https:\/\/doi.org\/10.1049\/ise2\/6664900","archive":["Portico"],"relation":{},"ISSN":["1751-8709","1751-8717"],"issn-type":[{"value":"1751-8709","type":"print"},{"value":"1751-8717","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1]]},"assertion":[{"value":"2024-11-22","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-08-30","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-09-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"6664900"}}