Full text
INTERNATIONAL JOURNAL OF MULTIDISCIPLINARY RESEARCH AND ANALYSIS ISSN(print): 2643-9840, ISSN(online): 2643-9875 Volume 08 Issue 11 November 2025 DOI: 10.47191/ijmra/v8-i11-25, Impact Factor: 8.266 Page No. 6120-6129 IJMRA, Volume 08 Issue 11 November 2025 www.ijmra.in Page 6120 Efficient Intrusion Detection using Feature Engineering Based on Deep Spectral Artificial Neural Network for IOT Network Sri Sai Krishna Mukkamala Senior Software developer, T-Mobile, Phoenix, Arizona, USA ABSTRACT: Recently, the Internet of Things (IoT) and its wide range of applications have become one of the most popular and most researched areas. By implementing appropriate safety features and efficient security management techniques, as well as by efficiently monitoring Internet traffic with intrusion detection systems, IoT settings offer an additional defense against attacks on the Internet and connected devices. Detecting new threats, preserving massive data centers, and responding to real-time threat detection are all complex tasks for traditional Intrusion Detection Systems (IDS). However, IoT devices present the highest security challenges due to their lower cost and accuracy. To solve this problem, we propose a Deep Spectral Artificial Neural Network (DSANN) algorithm to detect attacks for IoT networks and provide an efficient IDS. Furthermore, the Z-Score Min-Max Normalization (ZSM2N) model can pre-process data by removing redundant data and mitigating the impact of outliers. Additionally, the best feature subset can be selected from a high-dimensional NSL-KDD dataset using the Enhanced Particle Swarm Optimization (EPSO) algorithm. Finally, the accuracy can be improved by classifying the attacks on IoT networks into normal and abnormal traffic and building an efficient IDS using the proposed DSANN algorithm. Furthermore, using the proposed DSANN model to classify IoT network threats has increased to 97.32% by improving the performance evaluation, such as accuracy, precision, recall, and time complexity. KEYWORDS: Internet of Things, IDS, NSL-KDD dataset network traffic, DSANN and EPSO. I. INTRODUCTION In recent decades, a revolution in computing has led to the development of advanced technology and communication between smart devices. The IoT facilitates in-house communication using sensor devices, a technology that is also gaining popularity in everyday life in the modern world [1]. The IoT devices rely on the Internet as their primary communication channel and transmit extensive data within the network with the minimum amount of human intervention. The effects of international interconnection and the exchange of information have far-reaching consequences in the field of education, commerce, health systems, military strength, international trade, farming, and internal use. Extraordinary security dilemmas characterize the IoT because of the enormous connectivity of mixed devices, insecure network infrastructure, and international data disclosure. The concept of the IoT is used as a set of many interconnected devices and networks to connect people and things, creating favorable conditions for transportation systems, communities, health, energy, and other potential applications [2]. Therefore, the role of IDS is crucial, as it is the only means to detect anomalies and attacks within the system. Distributed computing is proposed as an effective and scalable security solution for detecting abnormalities in the IoT phase. In the recent times, the use of IDS based on artificial intelligence (AI) in the IoT has also begun to emerge. Such systems are capable of auto learning and identifying common behavioral patterns of a network and can successfully identify abnormal behaviors [3]. An IDS has the capability of preventing attacks on IoT devices through the identification of intrusions and alerting the attackers to abnormal procedures before they can intrude on the IoT. Furthermore, it can detect attack signatures through automatic and intelligent means to detect possible security threats. Deep learning models are based on massive traffic data that is used to generate effective IDS models and distinguish normal and abnormal network activities. Nevertheless, the IoT and distributed networks pose threats to IDS due to their intricate data processing and discrepancies [4]. Specifically, intrusion detection traditions face challenges with the spatiotemporal characteristics of features and the inequity of data. Therefore, they are not suitable for the problematic intrusion detection in complex network traffic. IoT's ease of use makes it vulnerable to cyberattacks, necessitating robust security measures [5]. As the technology evolves, vulnerability detection and
Efficient Intrusion Detection Using Feature Engineering Based on Deep Spectral Artificial Neural Network for IOT Network IJMRA, Volume 08 Issue 11 November 2025 www.ijmra.in Page 6121 awareness become increasingly important. IoT's open nature and resource limitations create unique security challenges, predisposing it to breaches and targeted attacks. A. Organization of the research • The main contribution of this paper is that we can classify IoT network traffic attacks using the NSL-KDD IDS dataset collected from Kaggle. • Furthermore, we can pre-process the data by removing redundant data using ZSM2N technique with input features in the dataset and reducing the impact of outliers. • After that, the EPSO algorithm is used to select an optimal feature subset from the NSL-KDD dataset, reducing computational cost. • In addition, we can improve accuracy by building an efficient IDS that classifies attacks on IoT networks into normal and abnormal traffic. B. Objective of the research This paper objective to develop efficient IDS for IoT networks using NSL-KDD dataset. It uses ZSM2N preprocessing to remove redundant data and reduce the influence of outliers, and then uses the EPSO algorithm to select the most relevant features. This study aims to improve the accuracy of classifying IoT network traffic into normal and abnormal types by reducing the computational cost and focusing on the main features. C. Motivation of the Research • This paper enhances IDS for IoT networks by tackling challenges related to high-dimensional data, redundant features, and outliers within the NSL-KDD dataset. • The intelligent IDS model employs ZSM2N preprocessing for data cleaning and normalization. • Uses the EPSO algorithm to select key features, reducing computational overhead. • The system classifies IoT network traffic to protect against cyberattacks and improve the reliability of IoT environments. II. LITERATURE SURVEY Introduces a comprehensive comparison of experimental designs, analysis, and IDS techniques based on Deep Learning (DL) models, such as datasets, feature extraction, and classifiers [6]. Additionally, the suggested technique can detect attacks more quickly than the standard algorithm, according to the results of comparing the new DL model to the device-based IDS (DIDS) standard algorithm [7]. The use of a standard dataset for IoT intrusion detection is evaluated using a DL model [8] based on Convolutional Neural Networks (CNNs). To improve anomaly detection in IoT, Feature Extraction using CNN implementation in IoT (FECNNIoT) is designed. Moreover, two key datasets, such as NSL-KDD and TON-IoT, are implemented for detecting IDS attacks [9]. Smart IDSs can detect IoT attacks by using DL algorithms to identify malicious network traffic [10]. To enhance each Deep Neural Network (DNN) model's distinct strengths and raise the overall capabilities of IDS, several strategies are presented. Interconnected systems, however, present serious security risks and decreased accuracy, even though they are convenient and efficient [11]. To increase accuracy in detecting IDS attacks and preventing security issues, a total of 21 neural network models were created and trained using the BoT-IoT dataset [12]. However, advanced analysis of data is required due to traditional security limits in attack and system variability. To improve intrusion detection, this study [13] proposed a realtime threat detection system for IoT based on DL, using 1D-CNN and Recurrent Neural Network (RNN) algorithms. The novel suggested an SDN-enabled IDS for IoT networks that uses a Long-Short-Term Memory (LSTM)-based method to identify network attacks [14]. Therefore, the existence of IoT devices complicates network management. Table I. IOT NETWORK FOR IDS USING DEEP LEARNING ALGORITHM SS Year Classification Method Dataset Performance Evaluation Limitations A.Fatani [15] 2025 CNN KDDCup-99 Recall-78.2%, accuracy-71.22% Cyber-attacks are growing at a rapid pace as security mechanisms fail to provide effective solutions. Ali, M.A [16] 2025 Support Vector Machine (SVM) MitM attack traffic dataset highest accuracy (94%), false These attacks threaten the integrity of
Efficient Intrusion Detection Using Feature Engineering Based on Deep Spectral Artificial Neural Network for IOT Network IJMRA, Volume 08 Issue 11 November 2025 www.ijmra.in Page 6122 positive rates85.7% intercepting communications Elnakib [18] 2023 Generative Adversarial Network (GAN), CNN and LSTM CICIDS2017 dataset accuracy of 95% IoT network attacks require adaptation of defenses due to resource constraints. Islam [19] 2021 DNN, Deep Belief Network (DBN) IoTDevNet, DS2OS, IoTID20, and IoT Botnet dataset. Recall-92.3%, F1score-87.28% Node diversity in IoT raises security concerns. Khan [20] 2021 k-Nearest Neighbour (kNN), Naive Bayes (NB) MQTT-IoTIDS2020 highest accuracy of 79.13% Low bandwidths and memory Musleh [21] 2023 VGG-16 and DenseNet. Dataport dataset. Highest accuracy of 88.3%. Focuses on protecting vulnerable devices from malicious traffic. Bhavsar, [22] 2023 PearsonCorrelation Coefficient - CNN (PCC-CNN) NSL-KDD, CICIDS2017 misclassification rate-0.02, 0.02, and 0.00 Securing IoT devices is critical due to increasing cybersecurity threats. Idrissi [23] 2021 RNN, CNN Bot-IoT dataset validation loss0.58% and prediction execution time0.34 ms The rise of botnet attacks presents many challenges to developing IDS. As shown in Table 1, the classification method, performance valuation of the dataset, and threshold value are used to predict IoT network attacks for IDS based on the DL method. Experimental results using an ANN based on existing DL models showed better results compared to leading methods and achieved 94.12% accuracy [24]. Similarly, experimental results show that compared to known classification methods [25], the Gaverage of the offered method is 78%, that of KNN is 75%, and the G-average of other methods is less than 50%. III. PROPOSED METHODOLOGY The proposed method constructs a DSANN to develop an efficient IDS for IoT networks. First, we pre-process the data using the ZSM2N method to remove redundancy and minimise outliers. Then, we use the EPSO algorithm to select the most relevant features from the NSL-KDD dataset. Finally, the DSANN model can classify IoT traffic into normal or abnormal categories, improving detection accuracy and system reliability.
Efficient Intrusion Detection Using Feature Engineering Based on Deep Spectral Artificial Neural Network for IOT Network IJMRA, Volume 08 Issue 11 November 2025 www.ijmra.in Page 6123 Fig. 1. Proposed DSANN Method based on Architecture Diagram As shown in Figure 1, a new method is proposed in IoT networks that focuses on constructing a specially designed DSANN to develop an efficient IDS. Protecting the integrity and availability of IoT devices and data, the primary objective is to accurately and reliably distinguish normal and abnormal network traffic. The method begins with an essential data pre-processing step, where the ZSM2N method is used to carefully prepare the NSL-KDD dataset, which serves as the basis for training and evaluating the IDS. ZSM2N techniques play a key role in refining datasets by removing redundant information and reducing the influence of outliers, thereby ensuring that subsequent analyses are based on high-quality and representative data. Following the pre-processing step, feature selection is performed to identify the most suitable features from the NSL-KDD dataset. This is achieved by using a sophisticated optimization technique called the EPSO algorithm. The EPSO algorithm intelligently selects a subset of the most relevant features to accurately classify network traffic, thereby reducing the computational complexity of the DSANN model and improving its generalization performance. The model is designed to categorize IoT network traffic into two distinct categories: normal and abnormal. DSANN models leverage the power of the DSANN algorithm within network traffic data, helping to detect malicious activity accurately. A. Dataset Collection This dataset shows the design and features of the NSL-KDD dataset, a benchmark for evaluating IDSs. It contains 4431 network traffic records, each of which is described by 41 attributes related to connections, protocol behaviour, and timeand contentbased traffic patterns. Furthermore, the accuracy is improved by evaluating the training and testing set, which includes 3,503 records and 928 records from the total records collected through the NSL-KDD dataset. Moreover, the NSL-KDD dataset can be accessed through the website https://www.kaggle.com/datasets/programmer3/nsl-kdd-intrusion-detection-dataset. Fig. 2. Dataset Feature Collection
Efficient Intrusion Detection Using Feature Engineering Based on Deep Spectral Artificial Neural Network for IOT Network IJMRA, Volume 08 Issue 11 November 2025 www.ijmra.in Page 6124 As shown in Figure 2, each record obtained through the dataset feature collection represents normal and stable network activity. Also, traffic collected from the dataset can be labeled as DoS, Probe, U2R, or R2L, which categorizes normal and abnormal traffic attacks. B. Z-score Min-Max Normalizztion (Z-SM2N) In this section, the Z-SM2N model is used to preprocess the data, remove redundant data in the dataset, and reduce the impact of extreme values. In NSL-KDD, a feature measurement step is used when preprocessing network traffic data to analyze the input dataset. In addition, during min-max normalization, feature values in the dataset can be rescaled to a fixed range [0,1]. Additionally, the Z-SM2N model accelerates the convergence of input values within a fixed range and increases stability. As shown in Equation 1, the eigenvalues are calculated by minimum-maximum normalization of the rescaling to a fixed range. Let’s assume a−original feature value, a′−normalized data, amax −amin −minimum and maximum value. a′=a−amin amax−amin (1) The estimated standard deviation between the z-score standards is characterized by a mean of zero and a variance of one, as shown in Equation 2. Let’s assume μ −mean value, σ−standard deviation. a′=a−μ σ (2) The ZSM2N model detects outliers and removes unwanted features, reducing the influence of extreme values and ensuring that all features are centered at zero. C. Enhanced Particle Swarm Optimization (EPSO) This section uses the EPSO algorithm to select the optimal feature subset from the high-dimensional NSL-KDD dataset to improve the IDS detection performance and reduce the computational cost. Using the dataset of IoT-based IDS, each particle of the EPSO technique chooses an appropriate subset of 41 features, including period, protocol_type, service, src_bytes, dst_bytes, and statistical features like count and srv_count. The search space is guided by neighborhood information to analyze its own best position (pBest), swarm best position (gBest), and best feature combination. The fitness function optimizes feature selection for IDS classification accuracy, while the EPSO model minimizes computational cost. Similarly, the best subset of features can be selected by choosing the most appropriate features to detect normal and attack traffic in IoT networks. Compute a candidate feature subset of 41 features for each particle in the particle representation, as shown in Equation 4. Let’s assume am− position vector of particle. am=a′[am1,am2,am3 …,am41] (4) As illustrated in Equation 5, estimate the fitness function to maximize the improvement in IDS classification accuracy for a subset of the selected features. Let’s assume SF−selected feature, C−classifier, F−fitness function. F(xi)=Acc(C(SF(am))) (5) Update global, neighbour, and personal best velocities as shown in Equation 6. Let’s assume dm l+1 −current velocity of particle, m−iteration, am l−current position, z − inertia weight, C−coefficients, r−random number, Pbestm−particle position, gbestm−global best position, Nbestm−neighbour position. dm l+1 =z.dm l+C1.r1(Pbestm.am l)+C2.r2(gbestm.am l)+C3.r3(Nbestm.am l) (6) As shown in Equations 7and 8, use a sigmoid function to convert the velocity into a binary feature selection to update the position. Let’s assume amn l+1 −updated selection of feature particle, rand () −random number between 0 and 1 amn l+1 ={1, if sigmoid (dmn l+1)>rand () 0 otherwise (7) Sigmoid(v)=1 1+ev (8) As shown in Equation 9, the optimal feature subset is calculated by iterating through fitness evaluation, velocity update, and position update for a maximum number of iterations. Let’s assume aoptimal −selected features maximize IDS accuracy. aoptimal =gbest (9) The EPSO is used to demonstrate particle representation, fitness assessment, velocity/position updating, and convergence on the NSL-KDD dataset. D. Deep Spectral Artificial Neural Network (DSANN) This section developed an efficient IDS using the proposed DSANN algorithm to detect and classify attacks for IoT networks. The DSANN method combines spectral feature extraction with deep neural learning to capture frequency-based and non-linear relationships in the data. By applying DSANN to the NSL-KDD dataset, the model can automatically learn meaningful
Efficient Intrusion Detection Using Feature Engineering Based on Deep Spectral Artificial Neural Network for IOT Network IJMRA, Volume 08 Issue 11 November 2025 www.ijmra.in Page 6125 patterns from the selected features and improve its ability to distinguish normal traffic from various types of network attacks. This DSANN approach minimizes manual feature engineering and improves the accuracy and reliability of IDS in IoT environment. The spectral function is evaluated to optimize the frequency-based or correlation-based methods as described in Equation 10. Let’s assume q−spectral feature, Φ− spectral transformation function. q= aoptimal Φ(a) (10) Calculate the weighted shift for each hidden layer as described in Equation 11. Let’s assume f(t)−output of hidden layer, z(t),y(t)−weights and bias of layer, h−activation function. f(t)=h(z(t)ft−1 +y(t)) (11) The output layer is evaluated, and the final softmax layer traffic is classified as either normal (0) or attacked, as presented in Equation 12. Let’s assume bt −predicted probability of class, o − number of output classes. bt =gwm ∑gwm o n=1 , w= Z(t)f(t−1)+y(t)(12) As shown in Equation 13, the loss function is estimated using cross-entropy loss, and the model parameters are optimized. Let’s assume t−loss function, bm−true class label. T = −∑bm o m=1 log(bt ) (13) Update the optimization parameters using gradient descent as shown in Equation 14. Let’s assume θ− network parameters, η− learning rate. θ←θ−η.∇θT (14) By combining spectral feature extraction with deep neural learning, DSANN can effectively develop an IDS for IoT networks. This approach automatically learns traffic patterns from the NSL-KDD dataset, which enables accurate classification of network traffic as normal or attack. IV. RESULT AND DISCUSSION Using performance parameters including accuracy, precision, recall, and time complexity, this part improves the IDS for IoT network traffic detection using the suggested DSANN model. Furthermore, when compared to earlier techniques like DenseNet, LSTM, and PCC-CNN, the suggested DSANN method greatly increases accuracy. Table II. SIMULATION PARAMETER Simulation Variable Dataset Name NSL-KDD Intrusion Detection Dataset Number of dataset 4431 Language Python Tool Jupyter Training 3503 Testing 928 The parameters described in Table 2 were used to simulate the suggested system. Using Python and the NSL-KDD Intrusion Detection Dataset, which had 101 records from various sources, experiments were carried out in a Jupyter environment. Table III. PERFORMANCE OF PRECISION Number of Records DenseNet LSTM PCC-CNN DSANN 1,107 71.12 73.14 74.21 76.10 2,214 74.3 76.12 79.11 81.09 3,321 76.1 79.05 82.48 86.02 4,431 79.16 83.28 86.11 90.23
Efficient Intrusion Detection Using Feature Engineering Based on Deep Spectral Artificial Neural Network for IOT Network IJMRA, Volume 08 Issue 11 November 2025 www.ijmra.in Page 6126 Fig. 3. Analysis of Precision Figure 3 and Table 3 demonstrate that the proposed DSANN method accurately measures precision compared to traditional approaches, thereby enhancing IDS performance through the detection of IoT network traffic. When compared to the conventional DenseNet, LSTM, and PCC-CNN techniques, the PSO-KNN approach achieved precision rates of 79.16%, 83.28%, and 86.11%, respectively, during classification. Furthermore, the DSANN method improves analysis efficiency and increases precision by 90.23% for IDS in IoT network traffic detection. Table IV. PERFORMANCE OF RECALL Number of Records DenseNet LSTM PCC-CNN DSANN 1,107 73.16 76.2 79.25 83.12 2,214 76.22 79.18 82.9 86.3 3,321 79.15 81.9 84.10 89.47 4,431 81.28 84.11 87.15 93.13 Fig. 4. Analysis of Recall Figure 4 and Table 4 show that the proposed DSANN method can accurately measure recall compared to traditional approaches and boost IDS performance by detecting IoT network traffic. When compared to the conventional DenseNet, LSTM, and PCC-CNN techniques, the PSO-KNN approach achieved recall rates of 81.28%, 84.11%, and 87.15%, respectively, during classification. 0 10 20 30 40 50 60 70 80 90 100 1,107 2,214 3,321 4,431 Performance in % Number of Records Precision DenseNet LSTM PCC-CNN DSANN 73.16 76.22 79.15 81.28 76.2 79.18 81.9 84.11 79.25 82.9 84.1 87.15 83.12 86.3 89.47 93.13 1,107 2,214 3,321 4,431 PERFORMANCE IN % NUMBER OF RECORDS RECALL DenseNet LSTM PCC-CNN DSANN
Efficient Intrusion Detection Using Feature Engineering Based on Deep Spectral Artificial Neural Network for IOT Network IJMRA, Volume 08 Issue 11 November 2025 www.ijmra.in Page 6127 Furthermore, the DSANN method improves analysis efficiency and increases recall by 93.13% for IDS in IoT network traffic detection. Table V. PERFORMANCE OF TIME COMPLEXITY Number of Records DenseNet LSTM PCC-CNN DSANN 1,107 39.21 34.03 31.12 25.11 2,214 36.17 32.05 25.14 19.09 3,321 33.2 29.06 21.09 14.05 4,431 30.14 27.15 20.10 10.05 Fig. 5. Analysis of Time Complexity Figure 5 and Table 5 show that the proposed DSANN method accurately measures the time complexity compared to traditional approaches and improves the IDS performance through IoT network traffic detection. Compared to the traditional DENSNET, LSTM, and PCC-CNN techniques, the BSO-KNN approach achieved 79.16%, 83.28%, and 86.11% of the time in problem classification, respectively. Moreover, the DSANN method improves the analysis efficiency and increases the time complexity of IDS by 90.23% in IoT network traffic detection. Table VI. PERFORMANCE OF ACCURACY Number of Records DenseNet LSTM PCC-CNN DSANN 1,107 73.2 77.56 80.5 83.25 2,214 76.4 80.28 83.26 86.17 3,321 80.36 84.9 86.14 90.12 4,431 84.24 89.13 90.26 94.28 0 5 10 15 20 25 30 35 40 45 1,107 2,214 3,321 4,431 PERFORMANCE IN % NUMBER OF RECORDS TIME COMPLEXITY DenseNet LSTM PCC-CNN DSANN
Efficient Intrusion Detection Using Feature Engineering Based on Deep Spectral Artificial Neural Network for IOT Network IJMRA, Volume 08 Issue 11 November 2025 www.ijmra.in Page 6128 Fig. 6. Analysis of Accuracy Figure 6 and Table 6 validate the effectiveness of the proposed DSANN method in assessing accuracy and improving IDS for IoT network traffic detection. In classification, DSANN achieved accuracy rates of 84.24%, 89.13%, and 90.26% compared to DenseNet, LSTM, and PCC-CNN, respectively. DSANN also enhances analysis efficiency and improves accuracy by 94.28% for IDS in IoT network traffic detection. V. CONCLUSION In conclusion, this paper demonstrates the value of classifying attacks targeting IoT network traffic by using the valuable resource NSL-KDD Intrusion Detection dataset obtained from Kaggle. This study highlights the importance of data preprocessing, particularly using ZSM2N techniques to remove redundant data in the input features of the dataset. This preprocessing step plays a vital role in reducing the negative impact of outliers, thereby improving the quality of data used for subsequent analysis. Furthermore, we use the EPSO algorithm as a means to select the most relevant and influential subset of features from the NSLKDD dataset. This feature selection process helps in reducing the overall computational cost associated with the classification task. The proposed DSANN method has been proven to be very effective in accurate estimation and significantly improves the IDS functionality for IoT network traffic detection. In attack classification, DSANN shows its superiority by achieving better accuracy rates of 84.24%, 89.13%, and 90.26%, respectively, compared to alternative deep learning architectures such as DenseNet, LSTM, and PCC-CCNN. DSANN contributes to improving not only the accuracy but also the analysis capability, significantly improving the overall accuracy of IDS in IoT network traffic detection, helping to achieve an accuracy of 94.28%. A. Limitation of the research • The complexity and variability of actual IoT traffic may not be well captured by using benchmark datasets. • This system relies heavily on predefined capabilities, which can lead to performance variations when applied to dynamic and evolving attack patterns. • This approach can be computationally intensive when scaling to very large or heterogeneous IoT environments. • These limitations highlight the need for further efforts to improve adaptability, scalability and real-time performance in practical deployment scenarios. B. Future Work • The application of intelligent IDS to IoT networks with dynamic topologies will be the primary focus of future research. • This IDS model can serve as a benchmark for the network and security research community in developing DL-based IDS solutions. • Furthermore, a real-time assistance tool could be developed to enhance IoT network performance. REFERENCES 1) Jayalaxmi, P. L. S., et al. "Machine and deep learning solutions for intrusion detection and prevention in IoTs: A survey." IEEe Access 10 (2022): 121173-121192. 2) Karne, RadhaKrishna and Mounika, S. and V, KarthikKumar and Dr. Nookala, Venu, Applications of IoT on Intrusion Detection System with Deep Learning Analysis (July 2022). International Journal from Innovative Engineering and Management Research (IJIEMR) 2022, Available at SSRN: https://ssrn.com/abstract=4232107 0 20 40 60 80 100 1,107 2,214 3,321 4,431 Performance in % Number of Records Accuracy DenseNet LSTM PCC-CNN DSANN