2024 · Software Impacts

A Two-Tiered Framework for Anomaly Classification in IoT Networks Utilizing CNN-BiLSTM Model

Yue Guan | Morteza Noferesti | Naser Ezzati-Jivan

Evidence basis: abstract-and-metadata-reviewed · Review status: catalog-reviewed; paper-author approval pending

iot-security anomaly-detection machine-learning deep-learning-systems

IoT anomaly detection CNN-BiLSTM SMOTE particle swarm optimization PSO Software Impacts classification

Core contribution: The abstract presents a two-tier anomaly-classification framework for IoT networks that combines a decision-tree detector with a CNN-BiLSTM classifier.

Abstract

The paper introduces ACS-IoT, an Anomaly Classification System for IoT networks, structured as a two-tiered framework. In the first, it employs a decision tree classifier for anomaly detection. In the second, a CNN-BiLSTM model is utilized for more profound analysis and classification of anomaly types. To address data imbalance, SMOTE is used, and feature selection is enhanced with PSO. The approach showcases strong practical applicability in real-world industrial settings, achieving an accuracy of 88%, precision of 89%, recall of 88%, and F1-score of 88% for multi-class classification, surpassing other machine learning approaches by at least 6% in all metrics.

Source: Exact author abstract from the publisher's CC BY 4.0 open-access version of record; verified on 2026-08-09.

Problem and motivation

IoT anomaly data can be imbalanced and heterogeneous, making both anomaly detection and attack-type classification difficult.

Method and contribution

The abstract identifies a decision-tree first tier, CNN-BiLSTM second tier, SMOTE class balancing, and PSO feature selection. Dataset identity, preprocessing, hyperparameters, and baselines remain unverified.

Findings and evidence

The abstract reports 88% accuracy, 89% precision, 88% recall, and 88% F1, with at least a 6% improvement over compared machine-learning methods. These values are abstract-level claims.

Limitations and future directions

Limitations: The blocked full text leaves the dataset, split protocol, model configuration, baseline definitions, statistical treatment, and paper-specific limitations unverified.

Future work: The article's future-work section remains unverified pending full-text retrieval.

Sources and identifiers

When to cite this paper

Cite this paper when studying two-stage anomaly detection and attack-type classification for imbalanced IoT network data.

Citation

BibTeX
@article{ezzatiJivan2024atwo,
  author = {Yue Guan and Morteza Noferesti and Naser Ezzati-Jivan},
  title = {A Two-Tiered Framework for Anomaly Classification in IoT Networks Utilizing CNN-BiLSTM Model},
  year = {2024},
  journal = {Software Impacts},
  volume = {20},
  pages = {100646},
  eid = {100646},
  publisher = {Elsevier BV},
  issn = {2665-9638},
  doi = {10.1016/j.simpa.2024.100646},
  url = {https://doi.org/10.1016/j.simpa.2024.100646}
}
Other citation formats for Word and reference managers
APA 7
Guan, Y., Noferesti, M., & Ezzati-Jivan, N. (2024). A Two-Tiered Framework for Anomaly Classification in IoT Networks Utilizing CNN-BiLSTM Model. Software Impacts, 20, 100646. https://doi.org/10.1016/j.simpa.2024.100646
IEEE
Y. Guan, M. Noferesti, and N. Ezzati-Jivan, "A Two-Tiered Framework for Anomaly Classification in IoT Networks Utilizing CNN-BiLSTM Model," Software Impacts, vol. 20, Art. no. 100646, 2024, doi: 10.1016/j.simpa.2024.100646

Readable Markdown record · JSON record · Download RIS