{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T09:32:07Z","timestamp":1780392727287,"version":"3.54.1"},"reference-count":58,"publisher":"Frontiers Media SA","license":[{"start":{"date-parts":[[2024,10,30]],"date-time":"2024-10-30T00:00:00Z","timestamp":1730246400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["frontiersin.org"],"crossmark-restriction":true},"short-container-title":["Front. Comput. Sci."],"abstract":"<jats:p>The primary objective of this paper is to enhance the security of IoT devices in Software-Defined Networking (SDN) environments against Man-in-the-Middle (MitM) attacks in smart homes using Artificial Intelligence (AI) methods as part of an Intrusion Detection and Prevention System (IDPS) framework. This framework aims to authenticate communication parties, ensure overall system and network security within SDN environments, and foster trust among users and stakeholders. The experimental analysis focuses on machine learning (ML) and deep learning (DL) algorithms, particularly those employed in Intrusion Detection Systems (IDS), such as Naive Bayes (NB), k-Nearest Neighbors (kNN), Random Forest (RF), and Convolutional Neural Networks (CNN). The CNN algorithm demonstrates exceptional performance on the training dataset, achieving 99.96% accuracy with minimal training time. It also shows favorable results in terms of detection speed, requiring only 1 s, and maintains a low False Alarm Rate (FAR) of 0.02%. Subsequently, the proposed framework was deployed in a testbed SDN environment to evaluate its detection capabilities across diverse network topologies, showcasing its efficiency compared to existing approaches.<\/jats:p>","DOI":"10.3389\/fcomp.2024.1477501","type":"journal-article","created":{"date-parts":[[2024,10,30]],"date-time":"2024-10-30T10:30:10Z","timestamp":1730284210000},"update-policy":"https:\/\/doi.org\/10.3389\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["Deep learning approaches for protecting IoT devices in smart homes from MitM attacks"],"prefix":"10.3389","volume":"6","author":[{"given":"Nader","family":"Karmous","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yassmine","family":"Ben Dhiab","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohamed","family":"Ould-Elhassen Aoueileyine","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Neji","family":"Youssef","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ridha","family":"Bouallegue","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anis","family":"Yazidi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1965","published-online":{"date-parts":[[2024,10,30]]},"reference":[{"key":"B1","doi-asserted-by":"publisher","first-page":"81","DOI":"10.48161\/qaj.v1n2a50","article-title":"Machine learning applications based on SVM classification a review","volume":"1","author":"Abdullah","year":"2021","journal-title":"Qubahan Acad. J"},{"key":"B2","doi-asserted-by":"crossref","DOI":"10.1109\/ICAECA52838.2021.9675595","article-title":"\u201cIntrusion detection and prevention in networks using machine learning and deep learning approaches: a review,\u201d","volume-title":"2021 International Conference on Advancements in Electrical, Electronics, Communication, Computing and Automation (ICAECA)","author":"Abraham","year":"2021"},{"key":"B3","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/ICCCNT54827.2022.9984509","article-title":"\u201cAn ECDH and AES based encryption approach for prevention of MiTM in SDN southbound communication interface,\u201d","volume-title":"2022 13th International Conference on Computing Communication and Networking Technologies (ICCCNT)","author":"Adhikari","year":"2022"},{"key":"B4","doi-asserted-by":"publisher","first-page":"107757","DOI":"10.1016\/j.compeleceng.2022.107757","article-title":"Ascertain the efficient machine learning approach to detect different arp attacks","volume":"99","author":"Ahuja","year":"2022","journal-title":"Comp. Elect. Eng"},{"key":"B5","doi-asserted-by":"publisher","first-page":"100861","DOI":"10.1016\/j.iot.2023.100861","article-title":"Arp-probe: An arp spoofing detector for internet of things networks using explainable deep learning","volume":"23","author":"Alani","year":"2023","journal-title":"Internet of Things"},{"key":"B6","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s40537-021-00444-8","article-title":"Review of deep learning: concepts, CNN architectures, challenges, applications, future directions","volume":"8","author":"Alzubaidi","year":"2021","journal-title":"J. Big Data"},{"key":"B7","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-031-57942-4_31","article-title":"\u201cDetecting and mitigating MiTM attack on IOT devices using SDN,\u201d","volume-title":"International Conference on Advanced Information Networking and Applications","author":"Aoueileyine","year":"2024"},{"key":"B8","doi-asserted-by":"crossref","DOI":"10.1109\/ICCTAC.2018.8370397","article-title":"\u201cRYU controller's scalability experiment on software defined networks,\u201d","volume-title":"2018 IEEE international conference on current trends in advanced computing (ICCTAC)","author":"Asadollahi","year":"2018"},{"key":"B9","doi-asserted-by":"publisher","first-page":"8","DOI":"10.1016\/j.iotcps.2021.08.001","article-title":"A proactive role of iot devices in building smart cities","volume":"1","author":"Ashraf","year":"2021","journal-title":"Intern. Things Cyber-Phys. Syst"},{"key":"B10","doi-asserted-by":"publisher","first-page":"108399","DOI":"10.1016\/j.comnet.2021.108399","article-title":"DoS and DDoS mitigation using variational autoencoders","volume":"199","author":"B\u00e5rli","year":"2021","journal-title":"Comp. Networ"},{"key":"B11","doi-asserted-by":"publisher","first-page":"102490","DOI":"10.1016\/j.cose.2021.102490","article-title":"Ransomware: recent advances, analysis, challenges and future research directions","volume":"111","author":"Beaman","year":"2021","journal-title":"Comp. Security"},{"key":"B12","doi-asserted-by":"publisher","first-page":"111398","DOI":"10.1016\/j.knosys.2024.111398","article-title":"Adaptive nonstationary fuzzy neural network","volume":"288","author":"Chang","year":"2024","journal-title":"Knowl.-Based Syst"},{"key":"B13","doi-asserted-by":"publisher","first-page":"52","DOI":"10.5815\/ijcnis.2022.01.05","article-title":"Mitigation of DDoS and MiTM attacks using belief based secure correlation approach in sdn-based IoT networks","volume":"14","author":"Cherian","year":"2022","journal-title":"Int. J. Comp. Networ. Inform. Security"},{"key":"B14","doi-asserted-by":"publisher","first-page":"2027","DOI":"10.1109\/COMST.2016.2548426","article-title":"A survey of man in the middle attacks","volume":"18","author":"Conti","year":"2016","journal-title":"IEEE Commun. Surv. Tutor"},{"key":"B15","doi-asserted-by":"publisher","first-page":"1014","DOI":"10.1002\/qre.3451","article-title":"The two-sided SPRT sign charts","volume":"40","author":"Deore","year":"2024","journal-title":"Qual. Reliab. Eng. Int"},{"key":"B16","doi-asserted-by":"crossref","DOI":"10.1109\/ISPA-BDCloud-SocialCom-SustainCom52081.2021.00159","article-title":"\u201cResearch on an approach of arp flooding suppression in multi-controller sdn networks,\u201d","author":"Du","year":"2021","journal-title":"2021 IEEE Intl Conf on Parallel"},{"key":"B17","doi-asserted-by":"publisher","first-page":"17797","DOI":"10.15680\/IJIRSET.2014.0312008","article-title":"Analysis of network data encryption & decryption techniques in communication systems","volume":"3","author":"Ezeofor","year":"2014","journal-title":"Int. J. Innovat. Res. Sci. Eng. Technol"},{"key":"B18","article-title":"\u201cAttack detection in internet of things using software defined network and fuzzy neural network,\u201d","author":"Farhin","year":"2020","journal-title":"2020 Joint 9th International Conference on Informatics, Electronics"},{"key":"B19","doi-asserted-by":"crossref","DOI":"10.1109\/ICAIS50930.2021.9395852","article-title":"\u201cA survey on network packet inspection and arp poisoning using wireshark and ettercap,\u201d","volume-title":"2021 International Conference on Artificial Intelligence and Smart Systems (ICAIS)","author":"Fathima","year":"2021"},{"key":"B20","doi-asserted-by":"crossref","DOI":"10.23919\/FPL.2017.8056840","article-title":"\u201cVoltage drop-based fault attacks on fpgas using valid bitstreams,\u201d","volume-title":"2017 27th International Conference on Field Programmable Logic and Applications (FPL)","author":"Gnad","year":"2017"},{"key":"B21","first-page":"1","article-title":"\u201cDetection and prevention of arp attack in software defined networks,\u201d","volume-title":"2023 14th International Conference on Computing Communication and Networking Technologies (ICCCNT)","author":"Gowda","year":"2023"},{"key":"B22","unstructured":"HaakegaardR.\n            LangJ.\n          The Elliptic Curve Diffie-Hellman (ECDH)2015"},{"key":"B23","doi-asserted-by":"crossref","DOI":"10.1109\/ICSSD47982.2019.9002770","article-title":"\u201cA survey of methods and tools used for interpreting random forest,\u201d","volume-title":"2019 1st International Conference on Smart Systems and Data Science (ICSSD)","author":"Haddouchi","year":"2019"},{"key":"B24","doi-asserted-by":"publisher","first-page":"100129","DOI":"10.1016\/j.teler.2024.100129","article-title":"Enhancing security in software-defined networks: an approach to efficient arp spoofing attacks detection and mitigation","volume":"14","author":"Hnamte","year":"2024","journal-title":"Telemat. Inform. Reports"},{"key":"B25","first-page":"120","article-title":"\u201cFinding optimal model parameters by discrete grid search,\u201d","volume-title":"Innovations in Hybrid Intelligent Systems","author":"Jim\u00e9nez","year":"2008"},{"key":"B26","doi-asserted-by":"publisher","first-page":"5022","DOI":"10.3390\/s24155022","article-title":"Software-defined-networking-based one-versus-rest strategy for detecting and mitigating distributed denial-of-service attacks in smart home internet of things devices","volume":"24","author":"Karmous","year":"2024","journal-title":"Sensors"},{"key":"B27","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-031-28694-0_6","article-title":"\u201cEnhanced machine learning-based sdn controller framework for securing iot networks,\u201d","volume-title":"Advanced Information Networking and Applications, 2023","author":"Karmous","year":"2023"},{"key":"B28","first-page":"138","article-title":"\u201cNetwork programmability using pox controller,\u201d","author":"Kaur","year":"2014","journal-title":"ICCCS International Conference on Communication, Computing"},{"key":"B29","doi-asserted-by":"publisher","first-page":"3552","DOI":"10.3390\/math11163552","article-title":"P4-hldmc: A novel framework for ddos and arp attack detection and mitigation in SD-IoT networks using machine learning, stateful p4, and distributed multi-controller architecture","volume":"11","author":"Khedr","year":"2023","journal-title":"Mathematics"},{"key":"B30","doi-asserted-by":"crossref","DOI":"10.1109\/CETIC4.2018.8531042","article-title":"\u201cBlockchain based security framework for iot implementations,\u201d","volume-title":"2018 International CET Conference on Control, Communication, and Computing (IC4)","author":"Krishnan","year":"2018"},{"key":"B31","first-page":"399","volume-title":"Implementation of Internet of Things with Blockchain Using Machine Learning Algorithm: Enhancement of Security with Blockchain","author":"Manoharan","year":"2023"},{"key":"B32","doi-asserted-by":"crossref","DOI":"10.1109\/ICSCN.2017.8085417","article-title":"\u201cA survey on arp cache poisoning and techniques for detection and mitigation,\u201d","volume-title":"2017 Fourth International Conference on Signal Processing, Communication and Networking (ICSCN)","author":"Meghana","year":"2017"},{"key":"B33","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-319-95171-3_47","article-title":"\u201cPerformance evaluation of MQTT broker servers,\u201d","volume-title":"International Conference on Computational Science and Its Applications","author":"Mishra","year":"2018"},{"key":"B34","doi-asserted-by":"publisher","first-page":"101689","DOI":"10.1016\/j.sysarc.2019.101689","article-title":"A survey on modeling and improving reliability of dnn algorithms and accelerators","volume":"104","author":"Mittal","year":"2020","journal-title":"J. Syst. Architect"},{"key":"B35","doi-asserted-by":"publisher","first-page":"8162","DOI":"10.3390\/app12168162","article-title":"A survey of cnn-based network intrusion detection","volume":"12","author":"Mohammadpour","year":"2022","journal-title":"Appl. Sci"},{"key":"B36","doi-asserted-by":"publisher","first-page":"63","DOI":"10.25130\/tjps.v29i3.1553","article-title":"Using machine learning algorithms in intrusion detection systems: a review","volume":"29","author":"Mohammed","year":"2024","journal-title":"Tikrit J. Pure Sci"},{"key":"B37","doi-asserted-by":"crossref","DOI":"10.1109\/ISDFS60797.2024.10527296","article-title":"\u201cAndroid trojan horse spyware attack: a practical implementation,\u201d","volume-title":"2024 12th International Symposium on Digital Forensics and Security","author":"Mwange","year":"2024"},{"key":"B38","doi-asserted-by":"publisher","first-page":"1829","DOI":"10.1007\/s11277-021-08725-4","article-title":"Grow of artificial intelligence to challenge security in iot application","volume":"127","author":"Padmaja","year":"2022","journal-title":"Wireless Pers. Commun"},{"key":"B39","doi-asserted-by":"crossref","DOI":"10.1109\/IRASET60544.2024.10548107","article-title":"\u201cIoT intrusion detection: a review of ml and dl-based approaches,\u201d","volume-title":"2024 4th International Conference on Innovative Research in Applied Science, Engineering and Technology (IRASET)","author":"Rakine","year":"2024"},{"key":"B40","doi-asserted-by":"publisher","first-page":"6077","DOI":"10.3233\/JIFS-230917","article-title":"Review on positional significance of lstm and cnn in the multilayer deep neural architecture for efficient sentiment classification","volume":"45","author":"Ramaswamy","year":"2023","journal-title":"J. Intellig. Fuzzy Syst"},{"key":"B41","doi-asserted-by":"publisher","DOI":"10.1201\/9781003164265-1","article-title":"\u201cIntroduction to naive bayes and a review on its subtypes with applications,\u201d","author":"Reddy","year":"2022","journal-title":"Bayesian Reasoning and Gaussian Processes for Machine Learning Applications"},{"key":"B42","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1186\/s13677-024-00651-7","article-title":"An overview of qos-aware load balancing techniques in sdn-based iot networks","volume":"13","author":"Rostami","year":"2024","journal-title":"J. Cloud Comp"},{"key":"B43","doi-asserted-by":"publisher","first-page":"68","DOI":"10.47760\/ijcsmc.2024.v13i04.008","article-title":"A survey on the advanced encryption standard (AES): a pillar of modern cryptography","volume":"13","author":"Saha","year":"2024","journal-title":"Int. J. Comp. Sci. Mobile Comp"},{"key":"B44","unstructured":"SankarR.\n          MAC flooding with MACOF & some major countermeasures. Kali Linux Tutorials2022"},{"key":"B45","article-title":"\u201cDetection and mitigation of MiTM attack in software defined networks,\u201d","volume-title":"Proceedings of the First International Conference on Combinatorial and Optimization, ICCAP 2021","author":"Saritakumar","year":"2021"},{"key":"B46","first-page":"422","article-title":"\u201cDetection of arp spoofing attacks in software defined networks,\u201d","volume-title":"2023 International Conference on Intelligent Systems for Communication, IoT and Security (ICISCoIS)","author":"Saritakumar","year":"2023"},{"key":"B47","doi-asserted-by":"publisher","first-page":"5875","DOI":"10.1007\/s12652-020-02099-4","article-title":"MiTM detection and defense mechanism cbna-rf based on machine learning for large-scale sdn context","volume":"11","author":"Sebbar","year":"2020","journal-title":"J. Ambient Intell. Humaniz. Comput"},{"key":"B48","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1186\/s13677-023-00412-y","article-title":"An artificial intelligence lightweight blockchain security model for security and privacy in iiot systems","volume":"12","author":"Selvarajan","year":"2023","journal-title":"J. Cloud Comp"},{"key":"B49","doi-asserted-by":"publisher","first-page":"34","DOI":"10.38094\/jastt501186","article-title":"A comparative analysis of intrusion detection systems: Leveraging algorithm classifications and feature selection techniques","volume":"5","author":"Shakir","year":"2024","journal-title":"J. Appl. Sci. Technol. Trends"},{"key":"B50","doi-asserted-by":"crossref","first-page":"119","DOI":"10.1007\/978-3-031-28150-1_6","article-title":"\u201cIntelligent intrusion detection algorithm based on multi-attack for edge-assisted internet of things,\u201d","volume-title":"Security and Risk Analysis for Intelligent Edge Computing","author":"Shitharth","year":"2023"},{"key":"B51","article-title":"\u201cZero trust architecture,\u201d","author":"Stafford","year":"2020","journal-title":"NIST Special Publication 800"},{"key":"B52","doi-asserted-by":"publisher","first-page":"4947","DOI":"10.1038\/s41598-024-55044-2","article-title":"Dickson polynomial-based secure group authentication scheme for internet of things","volume":"14","author":"Syed","year":"2024","journal-title":"Sci. Rep"},{"key":"B53","doi-asserted-by":"crossref","DOI":"10.1109\/ELECTRONICS.2019.8765692","article-title":"\u201cMQTT quality of service versus energy consumption,\u201d","volume-title":"2019 23rd International Conference Electronics","author":"Toldinas","year":"2019"},{"key":"B54","doi-asserted-by":"publisher","first-page":"578","DOI":"10.1016\/j.procs.2024.03.042","article-title":"Machine learning-based intrusion detection on multi-class imbalanced dataset using smote","volume":"234","author":"Widodo","year":"2024","journal-title":"Procedia Comput. Sci"},{"key":"B55","doi-asserted-by":"crossref","DOI":"10.1109\/ICIRCA.2018.8597401","article-title":"\u201cComparison with HTTP and MQTT in internet of things (IoT),\u201d","volume-title":"2018 International Conference on Inventive Research in Computing Applications (ICIRCA)","author":"Wukkadada","year":"2018"},{"key":"B56","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1002\/cjs.11765","article-title":"PCA rerandomization","volume":"52","author":"Zhang","year":"2024","journal-title":"Can. J. Statist"},{"key":"B57","doi-asserted-by":"publisher","first-page":"4663","DOI":"10.1109\/TKDE.2021.3049250","article-title":"Challenges in knn classification","volume":"34","author":"Zhang","year":"2021","journal-title":"IEEE Trans. Knowl. Data Eng"},{"key":"B58","doi-asserted-by":"publisher","DOI":"10.21227\/8rpg-qt98","article-title":"\u201cNSL-KDD,\u201d","author":"Zhao","year":"2022","journal-title":"IEEE Dataport"}],"container-title":["Frontiers in Computer Science"],"original-title":[],"link":[{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fcomp.2024.1477501\/full","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,30]],"date-time":"2024-10-30T10:30:45Z","timestamp":1730284245000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fcomp.2024.1477501\/full"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,30]]},"references-count":58,"alternative-id":["10.3389\/fcomp.2024.1477501"],"URL":"https:\/\/doi.org\/10.3389\/fcomp.2024.1477501","relation":{},"ISSN":["2624-9898"],"issn-type":[{"value":"2624-9898","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,10,30]]},"article-number":"1477501"}}