{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T14:45:00Z","timestamp":1783521900344,"version":"3.55.0"},"reference-count":42,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T00:00:00Z","timestamp":1781568000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["MAKE"],"abstract":"<jats:p>The increasing convergence of Operational Technology (OT) and Information Technology (IT) within the Industrial Internet of Things (IIoT) brings about remarkable improvements in monitoring and automation. However, it also exposes industrial systems to large-scale Distributed Denial of Service (DDoS) attacks. Edge-based defences are essential in satisfying low-latency demands and data sovereignty rules, yet they must function under severe resource limitations and adapt to shifting traffic characteristics without cloud assistance. In this work, we introduce a lightweight hybrid deep learning architecture that fuses a Convolutional Neural Network (CNN) with a Convolutional Block Attention Module (CBAM) and a Multi-Layer Perceptron (MLP) in a single detector. A sequential transfer learning scheme is adopted, including a feature projection layer that handles differences in input dimensionality. The model is pre-trained on the CIC-DDoS2019 dataset, then adapted to the more recent CICIoT23 dataset. Evaluations are performed on both datasets while preserving their natural class imbalance. We provide extensive ablation and variance analysis under identical experimental conditions. The proposed method achieves 99.52% accuracy on CICIoT23 while maintaining 99.65% recall, which is a crucial property for critical systems. Real-time measurements on a CPU-only testbed show an average inference latency of 0.013 ms, inference-only throughput exceeding 93,000 packets\/s, and end-to-end batch throughput of approximately 38,000 packets\/s. The solution demonstrates effective domain adaptation, sub-millisecond latency, and suitability for resource-constrained IIoT edge gateways.<\/jats:p>","DOI":"10.3390\/make8060166","type":"journal-article","created":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T09:06:52Z","timestamp":1781600812000},"page":"166","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Edge-Optimized Deep and Transfer Learning for Efficient DDoS Detection in IIoT Networks"],"prefix":"10.3390","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-1180-6188","authenticated-orcid":false,"given":"Mikiyas","family":"Alemayehu","sequence":"first","affiliation":[{"name":"School of Computer Science and Mathematics, Keele University, Newcastle-Under-Lyme ST5 5AA, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7067-7848","authenticated-orcid":false,"given":"Mohamed Chahine","family":"Ghanem","sequence":"additional","affiliation":[{"name":"School of Computer Science and Mathematics, Keele University, Newcastle-Under-Lyme ST5 5AA, UK"},{"name":"Cybersecurity Institute, School of Computer Science and Informatics, University of Liverpool, Liverpool L69 3BX, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9532-2453","authenticated-orcid":false,"given":"Hamza","family":"Kheddar","sequence":"additional","affiliation":[{"name":"Laboratory of Advanced Electronic Systems LSEA, Department of Electrical Engineering, University of Medea, Medea 26000, Algeria"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2026,6,16]]},"reference":[{"key":"ref_1","first-page":"100082","article-title":"A survey on intrusion detection system in IoT networks","volume":"3","author":"Rahman","year":"2024","journal-title":"Cyber Secur. Appl."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Nagini, R.V.S.S.S., Prabhakar, P.B.E., Balsem, Z.A., Soni, S., Mukuntharaj, C., and Hadi, A.A.A.K. (2025). Lightweight Intrusion Detection Algorithm for Edge Computing in Industrial IoT Applications. Proceedings of the 2025 3rd International Conference on Cyber Resilience (ICCR), Dubai, United Arab Emirates, 3\u20134 July 2025, IEEE.","DOI":"10.1109\/ICCR67387.2025.11292417"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Alemayehu, M., Ghanem, M.C., Kheddar, H., Dunsin, D., Kerrache, C.A., and Rathee, G. (2026). Low-Latency DDoS Detection for IIoT and SCADA Networks Using Proximal Policy Optimisation and Deep Reinforcement Learning. Information, 17.","DOI":"10.20944\/preprints202601.0081.v1"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., Hakak, S., and Ghorbani, A.A. (2019). Developing Realistic Distributed Denial of Service (DDoS) Attack Dataset and Taxonomy. Proceedings of the 2019 International Carnahan Conference on Security Technology (ICCST), Chennai, India, 1\u20133 October 2019, IEEE.","DOI":"10.1109\/CCST.2019.8888419"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Neto, E.C.P., Dadkhah, S., Ferreira, R., Zohourian, A., Lu, R., and Ghorbani, A.A. (2023). CICIoT2023: A Real-Time Dataset and Benchmark for Large-Scale Attacks in IoT Environment. Sensors, 23.","DOI":"10.20944\/preprints202305.0443.v1"},{"key":"ref_6","first-page":"209","article-title":"A Comparative Analysis of Signature-Based and Anomaly-Based Intrusion Detection Systems","volume":"14","author":"Ravindran","year":"2025","journal-title":"Int. J. Latest Technol. Eng. Manag. Appl. Sci."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"103962","DOI":"10.1016\/j.cose.2024.103962","article-title":"Robust DDoS attack detection with adaptive transfer learning","volume":"144","author":"Anley","year":"2024","journal-title":"Comput. Secur."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"143","DOI":"10.1007\/s11227-026-08253-7","article-title":"DDoS attack detection using deep transfer learning and FFT-based data transformation","volume":"82","author":"Shen","year":"2026","journal-title":"J. Supercomput."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Bakar, R.A., Castoldi, P., Paolucci, F., and Cugini, F. (2025). Next-Generation Intrusion Prevention System Using Hardware-Accelerated Data Processing Units (DPUs). Proceedings of the 2025 IEEE International Conference on Communications Workshops (ICC Workshops), Montreal, QC, Canada, 8\u201312 June 2025, IEEE.","DOI":"10.1109\/ICCWorkshops67674.2025.11162329"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"1510","DOI":"10.1038\/s41598-025-31614-w","article-title":"Transfer learning and AI technology for family school community collaborative model research in university network security management","volume":"16","author":"Feng","year":"2026","journal-title":"Sci. Rep."},{"key":"ref_11","unstructured":"Anaga, V., Ibiang, U.U., Akpanesen, E.M., Stephen, B.U., Enang, I.O., Essien, G.D., Chidimma, C.C., Ekanem, A.J., and Etuk, A.S. (2026). Comparative Analysis of Hybrid CNN Architectures for Detection of Distributed Denial of Service Attacks in Software Defined Networks, Department of Computer Engineering, University of Uyo. Available online: https:\/\/www.researchgate.net\/publication\/400929104_Comparative_Analysis_of_Hybrid_CNN_Architectures_for_Detection_of_Distributed_Denial_of_Service_Attacks_in_Software_Defined_Networks."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"107927","DOI":"10.1016\/j.comcom.2024.107927","article-title":"DTL-5G: Deep Transfer Learning-based DDoS Attack Detection in 5G and Beyond Networks","volume":"228","author":"Farzaneh","year":"2024","journal-title":"Comput. Commun."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Ghanem, M.C., and Ratnayake, D.N. (2016). Enhancing WPA2-PSK four-way handshaking after re-authentication to deal with de-authentication followed by brute-force attack a novel re-authentication protocol. Proceedings of the 2016 International Conference On Cyber Situational Awareness, Data Analytics And Assessment (CyberSA), London, UK, 13\u201314 June 2016, IEEE.","DOI":"10.1109\/CyberSA.2016.7503286"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1186\/s42400-019-0038-7","article-title":"Survey of Intrusion Detection Systems: Techniques, Datasets and Challenges","volume":"2","author":"Khraisat","year":"2019","journal-title":"Cybersecurity"},{"key":"ref_15","first-page":"102419","article-title":"Deep Learning for Cyber Security Intrusion Detection: Approaches, Datasets, and Comparative Study","volume":"50","author":"Ferrag","year":"2020","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1109\/TETCI.2017.2772792","article-title":"A Deep Learning Approach to Network Intrusion Detection","volume":"2","author":"Shone","year":"2018","journal-title":"IEEE Trans. Emerg. Top. Comput. Intell."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Woo, S., Park, J., Lee, Y.K., and Kweon, I.S. (2018). CBAM: Convolutional Block Attention Module. Proceedings of the European Conference on Computer Vision (ECCV), Springer.","DOI":"10.1007\/978-3-030-01234-2_1"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"19339","DOI":"10.1038\/s41598-024-70094-2","article-title":"An improved intrusion detection method for IIoT using attention mechanisms, BiGRU, and Inception-CNN","volume":"14","author":"Yang","year":"2024","journal-title":"Sci. Rep."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"43","DOI":"10.1109\/JPROC.2020.3004555","article-title":"A Comprehensive Survey on Transfer Learning","volume":"109","author":"Zhuang","year":"2021","journal-title":"Proc. IEEE"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1006","DOI":"10.1109\/TII.2022.3164770","article-title":"Dependable Intrusion Detection System for IoT: A Deep Transfer Learning-Based Approach","volume":"19","author":"Mehedi","year":"2023","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"103869","DOI":"10.1016\/j.adhoc.2025.103869","article-title":"DTKD-IDS: A dual-teacher knowledge distillation intrusion detection model for the industrial internet of things","volume":"162","author":"Xie","year":"2025","journal-title":"Ad Hoc Netw."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"447","DOI":"10.1109\/TWC.2019.2946140","article-title":"Edge AI: On-Demand Accelerating Deep Neural Network Inference via Edge Computing","volume":"19","author":"Li","year":"2020","journal-title":"IEEE Trans. Wirel. Commun."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Alemayehu, M., Ghanem, M.C., Ouazzane, K., Kheddar, H., and Lacerda, M.J. (2026). A Systematic Analysis on the Use of AI Techniques in Industrial IoT DDoS Attacks Detection, Mitigation and Prevention. MDPI IoT.","DOI":"10.36227\/techrxiv.174495047.75842155\/v1"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1109\/TCE.2022.3213872","article-title":"IEEE P2668-Compliant Multi-Layer IoT-DDoS Defense System Using Deep Reinforcement Learning","volume":"69","author":"Liu","year":"2023","journal-title":"IEEE Trans. Consum. Electron."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"He, J., Guo, W., Tan, Y., and Xian, M. (2020). A Small Sample DDoS Attack Detection Method Based on Deep Transfer Learning. Proceedings of the 2020 International Conference on Computer, Network and Network Security (CCNS), Xi\u2019an, China, 21\u201323 August 2020, IEEE.","DOI":"10.1109\/CCNS50731.2020.00019"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"103760","DOI":"10.1016\/j.jnca.2023.103760","article-title":"Deep transfer learning for intrusion detection in industrial control networks: A comprehensive review","volume":"220","author":"Kheddar","year":"2023","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_27","unstructured":"(2022). IEEE Standard for Maturity Index of the Internet of Things\u2014Evaluation, Grading, and Ranking (Standard No. IEEE Standard 2668-2022)."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Gueriani, A., Kheddar, H., Mazari, A.C., and Ghanem, M.C. (2025). A robust cross-domain IDS using BiGRU-LSTM-attention for medical and industrial IoT security. ICT Express.","DOI":"10.1016\/j.icte.2025.08.011"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"6243","DOI":"10.1109\/JIOT.2019.2960033","article-title":"Deep-Reinforcement-Learning-Based QoS-Aware Secure Routing for SDN-IoT","volume":"7","author":"Guo","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"8491","DOI":"10.1109\/JIOT.2022.3196942","article-title":"An Efficient Hybrid-DNN for DDoS Detection and Classification in Software-Defined IIoT Networks","volume":"10","author":"Zainudin","year":"2023","journal-title":"IEEE Internet Things J."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"40281","DOI":"10.1109\/ACCESS.2022.3165809","article-title":"Edge-IIoTset: A New Comprehensive Realistic Cyber Security Dataset of IoT and IIoT Applications for Centralized and Federated Learning","volume":"10","author":"Ferrag","year":"2022","journal-title":"IEEE Access"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"441","DOI":"10.1016\/j.future.2022.05.008","article-title":"RKD-VNE: Virtual network embedding algorithm assisted by resource knowledge description and deep reinforcement learning in IIoT scenario","volume":"135","author":"Zhang","year":"2022","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"165130","DOI":"10.1109\/ACCESS.2020.3022862","article-title":"TON_IoT Telemetry Dataset: A New Generation Dataset of IoT and IIoT for Data-Driven Intrusion Detection Systems","volume":"8","author":"Alsaedi","year":"2020","journal-title":"IEEE Access"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"117354","DOI":"10.1109\/ACCESS.2020.3004711","article-title":"A Secure Industrial Internet of Things (IIoT) Framework for Resource Management in Smart Manufacturing","volume":"8","author":"Abuhasel","year":"2020","journal-title":"IEEE Access"},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"1048","DOI":"10.1109\/TCCN.2021.3102971","article-title":"Federated Deep Reinforcement Learning for Traffic Monitoring in SDN-Based IoT Networks","volume":"7","author":"Nguyen","year":"2021","journal-title":"IEEE Trans. Cogn. Commun. Netw."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1109\/TNSM.2019.2960202","article-title":"Per-Host DDoS Mitigation by Direct-Control Reinforcement Learning","volume":"17","author":"Simpson","year":"2019","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"123808","DOI":"10.1016\/j.eswa.2024.123808","article-title":"Deep Learning Enabled Intrusion Detection System for Industrial IoT Environment","volume":"249","author":"Nandanwar","year":"2024","journal-title":"Expert Syst. Appl."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"164097","DOI":"10.1109\/ACCESS.2024.3493384","article-title":"Survey: Intrusion Detection System in Software-Defined Networking","volume":"12","author":"Janabi","year":"2024","journal-title":"IEEE Access"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Shao, Z., Zhang, L., Sun, J., Lu, J., Wang, B., and Xu, D. (2024). Explainable Deep Learning-Based Feature Selection and Intrusion Detection for IoT Encrypted Traffic. Sensors, 24.","DOI":"10.3390\/s24165223"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"199903","DOI":"10.1109\/ACCESS.2025.3635541","article-title":"The Impact of Feature Scaling In Machine Learning: Effects on Regression and Classification Tasks","volume":"13","author":"Pinheiro","year":"2025","journal-title":"IEEE Access"},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Paul, D., Poovaiah, S.A.D., Nurullayeva, B., Kishore, A., Tankani, V.S.K., and Meylikulov, S. (2025). SHO-Xception: An Optimized Deep Learning Framework for Intelligent Intrusion Detection in Network Environments. Proceedings of the 2025 International Conference on Innovations in Intelligent Systems: Advancements in Computing, Communication, and Cybersecurity (ISAC3), Bhubaneswar, India, 25\u201326 July 2025, IEEE.","DOI":"10.1109\/ISAC364032.2025.11156610"},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"46","DOI":"10.1145\/321738.321743","article-title":"Scheduling Algorithms for Multiprogramming in a Hard-Real-Time Environment","volume":"20","author":"Liu","year":"1973","journal-title":"J. ACM"}],"container-title":["Machine Learning and Knowledge Extraction"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2504-4990\/8\/6\/166\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T11:14:57Z","timestamp":1781608497000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2504-4990\/8\/6\/166"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,16]]},"references-count":42,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2026,6]]}},"alternative-id":["make8060166"],"URL":"https:\/\/doi.org\/10.3390\/make8060166","relation":{},"ISSN":["2504-4990"],"issn-type":[{"value":"2504-4990","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,16]]}}}