{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,20]],"date-time":"2026-07-20T11:56:35Z","timestamp":1784548595214,"version":"3.55.0"},"reference-count":50,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2022,3,24]],"date-time":"2022-03-24T00:00:00Z","timestamp":1648080000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Malicious attacks are becoming more prevalent due to the growing use of Internet of Things (IoT) devices in homes, offices, transportation, healthcare, and other locations. By incorporating fog computing into IoT, attacks can be detected in a short amount of time, as the distance between IoT devices and fog devices is smaller than the distance between IoT devices and the cloud. Machine learning is frequently used for the detection of attacks due to the huge amount of data available from IoT devices. However, the problem is that fog devices may not have enough resources, such as processing power and memory, to detect attacks in a timely manner. This paper proposes an approach to offload the machine learning model selection task to the cloud and the real-time prediction task to the fog nodes. Using the proposed method, based on historical data, an ensemble machine learning model is built in the cloud, followed by the real-time detection of attacks on fog nodes. The proposed approach is tested using the NSL-KDD dataset. The results show the effectiveness of the proposed approach in terms of several performance measures, such as execution time, precision, recall, accuracy, and ROC (receiver operating characteristic) curve.<\/jats:p>","DOI":"10.3390\/fi14040102","type":"journal-article","created":{"date-parts":[[2022,3,25]],"date-time":"2022-03-25T00:05:18Z","timestamp":1648166718000},"page":"102","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":59,"title":["Detecting IoT Attacks Using an Ensemble Machine Learning Model"],"prefix":"10.3390","volume":"14","author":[{"given":"Vikas","family":"Tomer","sequence":"first","affiliation":[{"name":"Department of Computer Science and Engineering, Graphic Era Deemed to be University, Dehradun 248002, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8358-2258","authenticated-orcid":false,"given":"Sachin","family":"Sharma","sequence":"additional","affiliation":[{"name":"School of Electrical and Electronic Engineering, Technological University Dublin, D07 EWV4 Dublin, Ireland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,3,24]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Abdulghani, H.A., Nijdam, N.A., Collen, A., and Konstantas, D. (2019). A Study on Security and Privacy Guidelines, Countermeasures, Threats: IoT Data at Rest Perspective. Symmetry, 11.","DOI":"10.3390\/sym11060774"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Chen, F., and Luo, Y. (2017). An Inside Look at IoT Malware. Industrial IoT Technologies and Applications, Springer. Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering.","DOI":"10.1007\/978-3-319-60753-5"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Razdan, S., and Sharma, S. (2021). Internet of Medical Things (IoMT): Overview, Emerging Technologies, and Case Studies. IETE Tech. Rev., 1\u201314.","DOI":"10.1080\/02564602.2021.1927863"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"25","DOI":"10.1016\/j.jnca.2017.02.009","article-title":"A survey of intrusion detection in Internet of Things","volume":"84","author":"Miani","year":"2017","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"2671","DOI":"10.1109\/COMST.2019.2896380","article-title":"Network Intrusion Detection for IoT Security Based on Learning Techniques","volume":"21","author":"Chaabouni","year":"2019","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1109\/MSP.2018.2825478","article-title":"IoT Security Techniques Based on Machine Learning: How Do IoT Devices Use AI to Enhance Security?","volume":"35","author":"Xiao","year":"2018","journal-title":"IEEE Signal Process. Mag."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"385","DOI":"10.1016\/S0167-8655(00)00006-4","article-title":"Combination of neural and statistical algorithms for supervised classification of remote-sensing images","volume":"21","author":"Giacinto","year":"2000","journal-title":"Pattern Recognit. Lett."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Bansal, A., and Mahapatra, S. (2017, January 13\u201315). A Comparative Analysis of Machine Learning Techniques for Botnet Detection. Proceedings of the 10th International Conference on Security of Information and Networks SIN \u201917, New York, NY, USA.","DOI":"10.1145\/3136825.3136874"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"3221","DOI":"10.1007\/s10586-020-03082-6","article-title":"FCM\u2013SVM based intrusion detection system for cloud computing environment","volume":"23","author":"Jaber","year":"2020","journal-title":"Clust. Comput."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Ren, Y., Wang, J., and Fang, L. (2007, January 15\u201319). Network forensic computing based on ANN-PCA. Proceedings of the 2007 International Conference on Computational Intelligence and Security Workshops (CISW 2007), Harbin, China.","DOI":"10.1109\/CISW.2007.4425651"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"3679","DOI":"10.1007\/s12652-019-01647-x","article-title":"Effective feature selection technique in an integrated environment using enhanced principal component analysis","volume":"12","author":"Hemavathi","year":"2021","journal-title":"J. Ambient. Intell. Humaniz. Comput."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"164","DOI":"10.1016\/j.comnet.2018.11.010","article-title":"Dimensionality reduction with IG-PCA and ensemble classifier for network intrusion detection","volume":"148","author":"Salo","year":"2019","journal-title":"Comput. Netw."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"107168","DOI":"10.1016\/j.comnet.2020.107168","article-title":"New hybrid method for attack detection using combination of evolutionary algorithms, SVM, and ANN","volume":"173","author":"Hosseini","year":"2020","journal-title":"Comput. Netw."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Amor, N.B., Benferhat, S., and Elouedi, Z. (2004, January 14\u201317). Naive bayes vs. decision trees in intrusion detection systems. Proceedings of the 2004 ACM Symposium on Applied Computing, Nicosia, Cyprus.","DOI":"10.1145\/967900.967989"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Ingre, B., and Yadav, A. (2015, January 2\u20133). Performance analysis of NSL-KDD dataset using ANN. Proceedings of the 2015 International Conference on Signal Processing and Communication Engineering Systems, Guntur, India.","DOI":"10.1109\/SPACES.2015.7058223"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Zhang, C., Ruan, F., Yin, L., Chen, X., Zhai, L., and Liu, F. (2019, January 25\u201327). A Deep Learning Approach for Network Intrusion Detection Based on NSL-KDD Dataset. Proceedings of the 2019 IEEE 13th International Conference on Anti-counterfeiting, Security, and Identification (ASID), Xiamen, China.","DOI":"10.1109\/ICASID.2019.8925239"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Wang, H., Sayadi, H., Sasan, A., Rafatirad, S., Mohsenin, T., and Homayoun, H. (2020). Comprehensive Evaluation of Machine Learning Countermeasures for Detecting Microarchitectural Side-Channel Attacks, Association for Computing Machinery. GLSVLSI'20.","DOI":"10.1145\/3386263.3407586"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"100365","DOI":"10.1016\/j.iot.2021.100365","article-title":"Machine learning approaches to IoT security: A systematic literature review","volume":"14","author":"Ahmad","year":"2021","journal-title":"Int. Things (IoT)"},{"key":"ref_19","first-page":"25","article-title":"Detection of probe attacks using machine learning techniques","volume":"2","author":"Ambedkar","year":"2015","journal-title":"Int. J. Res. Stud. Comput. Sci. Eng. (IJRSCSE)"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"403","DOI":"10.3233\/IDA-2004-8406","article-title":"Why machine learning algorithms fail in misuse detection on KDD intrusion detection data set","volume":"8","author":"Sabhnani","year":"2004","journal-title":"Intell. Data Anal."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Abdelkefi, A., Jiang, Y., and Sharma, S. (2018, January 24\u201326). SENATUS: An Approach to Joint Traffic Anomaly Detection and Root Cause Analysis. Proceedings of the 2018 2nd Cyber Security in Networking Conference (CSNet), Paris, France.","DOI":"10.1109\/CSNET.2018.8602689"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Khare, N., Devan, P., Chowdhary, C.L., Bhattacharya, S., Singh, G., Singh, S., and Yoon, B. (2020). Smo-dnn: Spider monkey optimization and deep neural network hybrid classifier model for intrusion detection. Electronics, 9.","DOI":"10.3390\/electronics9040692"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"103261","DOI":"10.1016\/j.micpro.2020.103261","article-title":"Intrusion detection in networks using crow search optimization algorithm with adaptive neuro-fuzzy inference system","volume":"79","author":"Manimurugan","year":"2020","journal-title":"Microprocess. Microsyst."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Kasliwal, B., Bhatia, S., Saini, S., Thaseen, I.S., and Kumar, C.A. (2014, January 21\u201322). A hybrid anomaly detection model using G-LDA. Proceedings of the 2014 IEEE International Advance Computing Conference (IACC), Gurgaon, India.","DOI":"10.1109\/IAdCC.2014.6779336"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1016\/j.neucom.2019.11.016","article-title":"A novel statistical analysis and autoencoder driven intelligent intrusion detection approach","volume":"387","author":"Ieracitano","year":"2020","journal-title":"Neurocomputing"},{"key":"ref_26","first-page":"259","article-title":"Biostatistics 305. Multinomial logistic regression","volume":"46","author":"Chan","year":"2005","journal-title":"Singap. Med. J."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Liu, J., Kantarci, B., and Adams, C. (2020, January 13). Machine learning-driven intrusion detection for contiki-NG-based IoT networks exposed to NSL-KDD dataset. Proceedings of the 2nd ACM Workshop on Wireless Security and Machine Learning, Linz, Austria.","DOI":"10.1145\/3395352.3402621"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"29575","DOI":"10.1109\/ACCESS.2020.2972627","article-title":"BAT: Deep learning methods on network intrusion detection using NSL-KDD dataset","volume":"8","author":"Su","year":"2020","journal-title":"IEEE Access"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Abu Al-Haija, Q., and Al-Badawi, A. (2022). Attack-Aware IoT Network Traffic Routing Leveraging Ensemble Learning. Sensors, 22.","DOI":"10.3390\/s22010241"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Yong, B., Wei, W., Li, K.C., Shen, J., Zhou, Q., Wozniak, M., Po\u0142ap, D., and Dama\u0161evi\u010dius, R. (2020). Ensemble machine learning approaches for webshell detection in Internet of things environments. Transactions on Emerging Telecommunications Technologies, Wiley.","DOI":"10.1002\/ett.4085"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Rashid, M.M., Kamruzzaman, J., Hassan, M.M., Imam, T., and Gordon, S. (2020). Cyberattacks Detection in IoT-Based Smart City Applications Using Machine Learning Techniques. Int. J. Environ. Res. Public Health, 17.","DOI":"10.3390\/ijerph17249347"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Maglogiannis, I., Iliadis, L., and Pimenidis, E. (2020). SDN-Enabled IoT Anomaly Detection Using Ensemble Learning. Artificial Intelligence Applications and Innovations, Springer International Publishing.","DOI":"10.1007\/978-3-030-49186-4"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Magaia, N., Mastorakis, G., Mavromoustakis, C., Pallis, E., and Markakis, E.K. (2021). Towards Artificial Intelligence Assisted Software Defined Networking for Internet of Vehicles. Intelligent Technologies for Internet of Vehicles, Springer International Publishing.","DOI":"10.1007\/978-3-030-76493-7"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"274","DOI":"10.1016\/j.comcom.2021.09.029","article-title":"AI-empowered, blockchain and SDN integrated security architecture for IoT network of cyber physical systems","volume":"181","author":"Latif","year":"2022","journal-title":"Comput. Commun."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"107444","DOI":"10.1016\/j.compeleceng.2021.107444","article-title":"Ensemble classification using traffic flow metrics to predict distributed denial of service scope in the Internet of Things (IoT) networks","volume":"96","author":"Rambabu","year":"2021","journal-title":"Comput. Electr. Eng."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"110","DOI":"10.1016\/j.comcom.2020.12.003","article-title":"An ensemble learning and fog-cloud architecture-driven cyber-attack detection framework for IoMT networks","volume":"166","author":"Kumar","year":"2021","journal-title":"Comput. Commun."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Khare, S., and Totaro, M. (2020, January 24\u201326). Ensemble Learning for Detecting Attacks and Anomalies in IoT Smart Home. Proceedings of the 2020 3rd International Conference on Data Intelligence and Security (ICDIS), South Padre Island, TX, USA.","DOI":"10.1109\/ICDIS50059.2020.00014"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Hung, Y.H. (2021). Improved Ensemble-Learning Algorithm for Predictive Maintenance in the Manufacturing Process. Appl. Sci., 11.","DOI":"10.3390\/app11156832"},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3214306","article-title":"Edge cloud offloading algorithms: Issues, methods, and perspectives","volume":"52","author":"Wang","year":"2019","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/j.future.2018.05.008","article-title":"Security and trust issues in Fog computing: A survey","volume":"88","author":"Zhang","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"27","DOI":"10.1016\/j.jnca.2017.09.002","article-title":"Survey on fog computing: Architecture, key technologies, applications and open issues","volume":"98","author":"Hu","year":"2017","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Tariq, N., Asim, M., Al-Obeidat, F., Zubair Farooqi, M., Baker, T., Hammoudeh, M., and Ghafir, I. (2019). The Security of Big Data in Fog-Enabled IoT Applications Including Blockchain: A Survey. Sensors, 19.","DOI":"10.3390\/s19081788"},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"e145","DOI":"10.1002\/spy2.145","article-title":"Fog computing security and privacy for the Internet of Thing applications: State-of-the-art","volume":"4","author":"Alzoubi","year":"2021","journal-title":"Secur. Priv."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"9131","DOI":"10.1109\/ACCESS.2017.2705076","article-title":"An attribute-based encryption scheme to secure fog communications","volume":"5","author":"Alrawais","year":"2017","journal-title":"IEEE Access"},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"1143","DOI":"10.1109\/JIOT.2017.2659783","article-title":"Security and privacy preservation scheme of face identification and resolution framework using fog computing in internet of things","volume":"4","author":"Hu","year":"2017","journal-title":"IEEE Int. Things J."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"180","DOI":"10.1109\/CC.2017.7839768","article-title":"A non-cooperative differential game-based security model in fog computing","volume":"14","author":"Li","year":"2017","journal-title":"China Commun."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"8284","DOI":"10.1109\/ACCESS.2017.2692960","article-title":"From cloud to fog computing: A review and a conceptual live VM migration framework","volume":"5","author":"Osanaiye","year":"2017","journal-title":"IEEE Access"},{"key":"ref_48","unstructured":"(2022, March 20). ATLANTIC-eVISION: Cross-Atlantic Experimental Validation of Intelligent SDN-controlled IoT Networks 2021\u20132022. Available online: https:\/\/ngiatlantic.eu\/funded-experiments\/atlantic-evision-cross-atlantic-experimental-validation-intelligent-sdn."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"78","DOI":"10.1145\/2699392","article-title":"Future Internets Escape the Simulator","volume":"58","author":"Berman","year":"2015","journal-title":"Commun. ACM"},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"132","DOI":"10.1016\/j.bjp.2013.10.015","article-title":"Design and implementation of the OFELIA FP7 facility: The European OpenFlow testbed","volume":"61","author":"Bergesio","year":"2014","journal-title":"Comput. Netw."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/4\/102\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:42:21Z","timestamp":1760136141000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/4\/102"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,24]]},"references-count":50,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2022,4]]}},"alternative-id":["fi14040102"],"URL":"https:\/\/doi.org\/10.3390\/fi14040102","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,3,24]]}}}