{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,10]],"date-time":"2025-12-10T15:52:42Z","timestamp":1765381962272,"version":"3.46.0"},"reference-count":38,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2025,12,10]],"date-time":"2025-12-10T00:00:00Z","timestamp":1765324800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Smart farming relies heavily on IoT automation and data-driven decision making, but this growing connectivity also increases exposure to cyberattacks. Flow-based unsupervised intrusion detection is a privacy-preserving alternative to signature and payload inspection, yet it still faces three challenges: loss of subtle anomaly cues during Autoencoder (AE) compression, instability of fixed reconstruction-error thresholds, and performance degradation of clustering in noisy high-dimensional spaces. To address these issues, we propose a fog-aware two-stage hierarchical AE with latent-space gating, followed by Density-Based Spatial Clustering of Applications with Noise (DBSCAN) for attack categorization. A shallow AE compresses the input into a compact 21-dimensional latent space, reducing computational demand for fog-node deployment. A deep AE then computes reconstruction-error scores to isolate malicious behavior while denoising latent features. Only high-error latent vectors are forwarded to DBSCAN, which improves cluster separability, reduces noise sensitivity, and avoids predefined cluster counts or labels. The framework is evaluated on two benchmark datasets. On CIC IoT-DIAD 2024, it achieves 98.99% accuracy, 0.9897 F1-score, 0.895 Adjusted Rand Index (ARI), and 0.019 Davies\u2013Bouldin Index (DBI). To examine generalizability beyond smart farming traffic, we also evaluate the framework on the CSE-CIC-IDS2018 benchmark, where it achieves 99.33% accuracy, 0.9928 F1-score, 0.9013 ARI, and 0.0174 DBI. These results confirm that the proposed model can reliably detect and categorize major cyberattack families across distinct IoT threat landscapes while remaining compatible with resource-constrained fog computing environments.<\/jats:p>","DOI":"10.3390\/fi17120567","type":"journal-article","created":{"date-parts":[[2025,12,10]],"date-time":"2025-12-10T15:32:17Z","timestamp":1765380737000},"page":"567","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Fog-Aware Hierarchical Autoencoder with Density-Based Clustering for AI-Driven Threat Detection in Smart Farming IoT Systems"],"prefix":"10.3390","volume":"17","author":[{"given":"Manikandan","family":"Thirumalaisamy","sequence":"first","affiliation":[{"name":"Center for Intelligent Cloud Computing, COE for Advanced Cloud, Multimedia University, Melaka 75450, Malaysia"},{"name":"Department of Mechatronics Engineering, Rajalakshmi Engineering College, Thandalam 602105, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sumendra","family":"Yogarayan","sequence":"additional","affiliation":[{"name":"Center for Intelligent Cloud Computing, COE for Advanced Cloud, Multimedia University, Melaka 75450, Malaysia"},{"name":"Faculty of Information Science and Technology, Multimedia University, Melaka 75450, Malaysia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0052-4870","authenticated-orcid":false,"given":"Md Shohel","family":"Sayeed","sequence":"additional","affiliation":[{"name":"Faculty of Information Science and Technology, Multimedia University, Melaka 75450, Malaysia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6108-3183","authenticated-orcid":false,"given":"Siti Fatimah","family":"Abdul Razak","sequence":"additional","affiliation":[{"name":"Center for Intelligent Cloud Computing, COE for Advanced Cloud, Multimedia University, Melaka 75450, Malaysia"},{"name":"Faculty of Information Science and Technology, Multimedia University, Melaka 75450, Malaysia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ramesh","family":"Shunmugam","sequence":"additional","affiliation":[{"name":"Department of Mechatronics Engineering, Rajalakshmi Engineering College, Thandalam 602105, India"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,12,10]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"1719","DOI":"10.1007\/s10586-023-04052-4","article-title":"Intrusion detection in internet of things-based smart farming using hybrid deep learning framework","volume":"27","author":"Kethineni","year":"2024","journal-title":"Clust. Comput."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"34564","DOI":"10.1109\/ACCESS.2020.2975142","article-title":"Security and Privacy in Smart Farming: Challenges and Opportunities","volume":"8","author":"Gupta","year":"2020","journal-title":"IEEE Access"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Eleftheriadis, C., Andronikidis, G., Kyranou, K., Pechlivani, E.M., Hadjigeorgiou, I., and Batzos, Z. (2024, January 21\u201324). Machine Learning for Cybersecurity Frameworks in Smart Farming. Proceedings of the 2024 28th International Conference on Information Technology (IT), Zabljak, Montenegro.","DOI":"10.1109\/IT61232.2024.10475711"},{"key":"ref_4","unstructured":"Arai, K. (2024). Noor Muaaz and Sithungu, An Anomaly Detection Framework for IIoT-Based Smart Farming Systems. Intelligent Computing, Springer Nature."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"3326","DOI":"10.11591\/eei.v13i5.7928","article-title":"Portable internet of things-based soil nutrients monitoring for precision and efficient smart farming","volume":"13","author":"Hartono","year":"2024","journal-title":"Bull. Electr. Eng. Inform."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"103754","DOI":"10.1016\/j.cose.2024.103754","article-title":"Agriculture 4.0 and beyond: Evaluating cyber threat intelligence sources and techniques in smart farming ecosystems","volume":"140","author":"Bui","year":"2024","journal-title":"Comput. Secur."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"3955514.","DOI":"10.1155\/2022\/3955514","article-title":"Intrusion Detection Using Machine Learning for Risk Mitigation in IoT-Enabled Smart Irrigation in Smart Farming","volume":"2022","author":"Raghuvanshi","year":"2022","journal-title":"J. Food Qual."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"16621","DOI":"10.1109\/ACCESS.2024.3359043","article-title":"Enhanced Black Widow Optimization With Hybrid Deep Learning Enabled Intrusion Detection in Internet of Things-Based Smart Farming","volume":"12","author":"Aburasain","year":"2024","journal-title":"IEEE Access"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Sajid, J., Hayawi, K., Malik, A.W., Anwar, Z., and Trabelsi, Z. (2023). A Fog Computing Framework for Intrusion Detection of Energy-Based Attacks on UAV-Assisted Smart Farming. Appl. Sci., 13.","DOI":"10.3390\/app13063857"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"260","DOI":"10.1016\/j.compag.2018.04.001","article-title":"AgroDSS: A decision support system for agriculture and farming","volume":"161","author":"Rupnik","year":"2019","journal-title":"Comput. Electron. Agric."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"100709","DOI":"10.1016\/j.iot.2023.100709","article-title":"An optimized CNN-based intrusion detection system for reducing risks in smart farming","volume":"22","author":"Darwish","year":"2023","journal-title":"Internet Things"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"110431","DOI":"10.1016\/j.compeleceng.2025.110431","article-title":"Enhancing cybersecurity in Agriculture 4.0: A high-performance hybrid deep learning-based framework for DDoS attack detection","volume":"126","author":"Kaliyaperumal","year":"2025","journal-title":"Comput. Electr. Eng."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Yazdinejad, A., Zolfaghari, B., Azmoodeh, A., Dehghantanha, A., Karimipour, H., Fraser, E., Green, A.G., Russell, C., and Duncan, E. (2021). A review on security of smart farming and precision agriculture: Security aspects, attacks, threats and countermeasures. Appl. Sci., 11.","DOI":"10.3390\/app11167518"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Padhy, S., Alowaidi, M., Dash, S., Alshehri, M., Malla, P.P., Routray, S., and Alhumyani, H. (2023). AgriSecure: A Fog Computing-Based Security Framework for Agriculture 4.0 via Blockchain. Processes, 11.","DOI":"10.3390\/pr11030757"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Prodanovi\u0107, R., Ran\u010di\u0107, D., Vuli\u0107, I., Zori\u0107, N., Bogi\u0107evi\u0107, D., Ostoji\u0107, G., Sarang, S., and Stankovski, S. (2020). Wireless sensor network in agriculture: Model of cyber security. Sensors, 20.","DOI":"10.3390\/s20236747"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Ara\u00fajo, S.O., Peres, R.S., Ramalho, J.C., Lidon, F., and Barata, J. (2023). Machine Learning Applications in Agriculture: Current Trends, Challenges, and Future Perspectives. Agronomy, 13.","DOI":"10.3390\/agronomy13122976"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"2037254","DOI":"10.1080\/08839514.2022.2037254","article-title":"The Emerging Threat of Ai-driven Cyber Attacks: A Review","volume":"36","author":"Guembe","year":"2022","journal-title":"Appl. Artif. Intell."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Demestichas, K., Peppes, N., and Alexakis, T. (2020). Survey on Security Threats in Agricultural IoT and Smart Farming. Sensors, 20.","DOI":"10.3390\/s20226458"},{"key":"ref_19","first-page":"4781","article-title":"Security Analysis in Smart Agriculture: Insights from a Cyber-Physical System Application","volume":"79","author":"Mahlous","year":"2024","journal-title":"Comput. Mater. Contin."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"173","DOI":"10.1109\/ACCESS.2024.3513279","article-title":"AI-Enhanced Robotic Process Automation: A Review of Intelligent Automation Innovations","volume":"13","author":"Afrin","year":"2025","journal-title":"IEEE Access"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"15371","DOI":"10.1038\/s41598-023-42678-x","article-title":"Prediction of DDoS attacks in agriculture 4.0 with the help of prairie dog optimization algorithm with IDSNet","volume":"13","author":"Vatambeti","year":"2023","journal-title":"Sci. Rep."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"108579","DOI":"10.1016\/j.engappai.2024.108579","article-title":"Novel intrusion detection system based on a downsized kernel method for cybersecurity in smart agriculture","volume":"133","author":"Zidi","year":"2024","journal-title":"Eng. Appl. Artif. Intell."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"109892","DOI":"10.1016\/j.compeleceng.2024.109892","article-title":"Farm-flow dataset: Intrusion detection in smart agriculture based on network flows","volume":"121","author":"Ferreira","year":"2025","journal-title":"Comput. Electr. Eng."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"123","DOI":"10.1186\/s13677-024-00685-x","article-title":"Enhancing intrusion detection: A hybrid machine and deep learning approach","volume":"13","author":"Sajid","year":"2024","journal-title":"J. Cloud Comput."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"30906","DOI":"10.1038\/s41598-024-81442-7","article-title":"Secure cloud computing: Leveraging GNN and leader K-means for intrusion detection optimization","volume":"14","author":"Dugyala","year":"2024","journal-title":"Sci. Rep."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"134","DOI":"10.1109\/TCSS.2021.3063538","article-title":"Intrusion Detection for Secure Social Internet of Things Based on Collaborative Edge Computing: A Generative Adversarial Network-Based Approach","volume":"9","author":"Nie","year":"2022","journal-title":"IEEE Trans. Comput. Soc. Syst."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"513","DOI":"10.1049\/ntw2.12134","article-title":"An unsupervised approach for the detection of zero-day distributed denial of service attacks in Internet of Things networks","volume":"13","author":"Roopak","year":"2024","journal-title":"IET Networks"},{"key":"ref_28","first-page":"409","article-title":"Adaptive DBSCAN with Grey Wolf Optimizer for Botnet Detection","volume":"16","author":"Mustafa","year":"2023","journal-title":"Int. J. Intell. Eng. Syst."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Al-Sabbagh, A., Hamze, K., Khan, S., and Elkhodr, M. (2024). An Enhanced K-Means Clustering Algorithm for Phishing Attack Detections. Electronics, 13.","DOI":"10.3390\/electronics13183677"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Aziz, Z., and Bestak, R. (2024). Insight into Anomaly Detection and Prediction and Mobile Network Security Enhancement Leveraging K-Means Clustering on Call Detail Records. Sensors, 24.","DOI":"10.3390\/s24061716"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"100727","DOI":"10.1016\/j.atech.2024.100727","article-title":"Efficient federated transfer learning-based network anomaly detection for cooperative smart farming infrastructure","volume":"10","author":"Praharaj","year":"2025","journal-title":"Smart Agric. Technol."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"459","DOI":"10.1177\/18761364251359885","article-title":"A hybrid feature selection method for anomaly detection using shallow and deep ANN classifiers in smart farming","volume":"17","author":"Ileri","year":"2025","journal-title":"J. Ambient. Intell. Smart Environ."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"13625","DOI":"10.1109\/JIOT.2024.3522863","article-title":"Device Identification and Anomaly Detection in IoT Environments","volume":"12","author":"Rabbani","year":"2025","journal-title":"IEEE Internet Things J."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., and Ghorbani, A.A. (2018, January 22\u201324). Toward generating a new intrusion detection dataset and intrusion traffic characterization. Proceedings of the ICISSP 2018\u2014The 4th International Conference on Information Systems Security and Privacy, Madeira, Portugal.","DOI":"10.5220\/0006639801080116"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Kumar, A., Radhakrishnan, R., Sumithra, M., Kaliyaperumal, P., Balusamy, B., and Benedetto, F. (2025). A Scalable Hybrid Autoencoder\u2013Extreme Learning Machine Framework for Adaptive Intrusion Detection in High-Dimensional Networks. Future Internet, 17.","DOI":"10.3390\/fi17050221"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Prabu, K., Sudhakar, P., Thirumalaisamy, M., Balusamy, B., and Benedetto, F. (2024). A Novel Hybrid Unsupervised Learning Approach for Enhanced Cybersecurity in the IoT. Future Internet, 16.","DOI":"10.3390\/fi16070253"},{"key":"ref_37","first-page":"23","article-title":"A Modified DBSCAN Algorithm for Anomaly Detection in Time-series Data with Seasonality","volume":"19","author":"Jain","year":"2022","journal-title":"Int. Arab. J. Inf. Technol."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"3345","DOI":"10.11591\/eei.v13i5.8135","article-title":"Harnessing DBSCAN and auto-encoder for hyper intrusion detection in cloud computing","volume":"13","author":"Prabu","year":"2024","journal-title":"Bull. Electr. Eng. Inform."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/12\/567\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,10]],"date-time":"2025-12-10T15:43:03Z","timestamp":1765381383000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/12\/567"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,10]]},"references-count":38,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["fi17120567"],"URL":"https:\/\/doi.org\/10.3390\/fi17120567","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12,10]]}}}