2024 · Software Impacts
A Two-Tiered Framework for Anomaly Classification in IoT Networks Utilizing CNN-BiLSTM Model
Evidence basis: abstract-and-metadata-reviewed · Review status: catalog-reviewed; paper-author approval pending
iot-security anomaly-detection machine-learning deep-learning-systems
IoT anomaly detection CNN-BiLSTM SMOTE particle swarm optimization PSO Software Impacts classification
Core contribution: The abstract presents a two-tier anomaly-classification framework for IoT networks that combines a decision-tree detector with a CNN-BiLSTM classifier.
Abstract
The paper introduces ACS-IoT, an Anomaly Classification System for IoT networks, structured as a two-tiered framework. In the first, it employs a decision tree classifier for anomaly detection. In the second, a CNN-BiLSTM model is utilized for more profound analysis and classification of anomaly types. To address data imbalance, SMOTE is used, and feature selection is enhanced with PSO. The approach showcases strong practical applicability in real-world industrial settings, achieving an accuracy of 88%, precision of 89%, recall of 88%, and F1-score of 88% for multi-class classification, surpassing other machine learning approaches by at least 6% in all metrics.
Source: Exact author abstract from the publisher's CC BY 4.0 open-access version of record; verified on 2026-08-09.
Problem and motivation
IoT anomaly data can be imbalanced and heterogeneous, making both anomaly detection and attack-type classification difficult.
Method and contribution
The abstract identifies a decision-tree first tier, CNN-BiLSTM second tier, SMOTE class balancing, and PSO feature selection. Dataset identity, preprocessing, hyperparameters, and baselines remain unverified.
Findings and evidence
The abstract reports 88% accuracy, 89% precision, 88% recall, and 88% F1, with at least a 6% improvement over compared machine-learning methods. These values are abstract-level claims.
Limitations and future directions
Limitations: The blocked full text leaves the dataset, split protocol, model configuration, baseline definitions, statistical treatment, and paper-specific limitations unverified.
Future work: The article's future-work section remains unverified pending full-text retrieval.
Sources and identifiers
- Published version published
- Open-access publisher PDF · PDF public_full_text
When to cite this paper
Cite this paper when studying two-stage anomaly detection and attack-type classification for imbalanced IoT network data.
- Decision-tree anomaly detection followed by CNN-BiLSTM multi-class attack classification.
- SMOTE-based class balancing and particle-swarm-optimization feature selection for IoT intrusion data.
- Reported 88% accuracy, 89% precision, 88% recall, and 88% F1 for multi-class classification.
Citation
@article{ezzatiJivan2024atwo,
author = {Yue Guan and Morteza Noferesti and Naser Ezzati-Jivan},
title = {A Two-Tiered Framework for Anomaly Classification in IoT Networks Utilizing CNN-BiLSTM Model},
year = {2024},
journal = {Software Impacts},
volume = {20},
pages = {100646},
eid = {100646},
publisher = {Elsevier BV},
issn = {2665-9638},
doi = {10.1016/j.simpa.2024.100646},
url = {https://doi.org/10.1016/j.simpa.2024.100646}
}Other citation formats for Word and reference managers
Guan, Y., Noferesti, M., & Ezzati-Jivan, N. (2024). A Two-Tiered Framework for Anomaly Classification in IoT Networks Utilizing CNN-BiLSTM Model. Software Impacts, 20, 100646. https://doi.org/10.1016/j.simpa.2024.100646Y. Guan, M. Noferesti, and N. Ezzati-Jivan, "A Two-Tiered Framework for Anomaly Classification in IoT Networks Utilizing CNN-BiLSTM Model," Software Impacts, vol. 20, Art. no. 100646, 2024, doi: 10.1016/j.simpa.2024.100646