scieee AI-readable full text Open interactive document viewer

Resilient IoT Security: Early Flood Attack Detection in IoT Networks Using GRU Deep Learning Model

Bonsu, Mildred Adwubi; Akekudaga, Philip

Abstract

Securing Internet of Things (IoT) networks has become increasingly critical as their integration across essential sectors continues to expand. Among the most pressing threats are flood attacks, a form of Distributed Denial of Service (DDoS) that overwhelms network resources and causes service degradation. In this study, the detection of flood attacks in IoT environments is addressed using a deep learning model based on the Gated Recurrent Unit (GRU) architecture. Within the scope of the analysis, the CICIoT2023 dataset, which reflects realistic IoT traffic and attack behavior, was employed for training and validation. The results have shown that the flood attacks were successfully detected, and the model achieved an accuracy score of 0.98, with moderate precision, recall, and F1 scores. In this way, flood attacks in IoT can be identified early to mitigate their impact and enhance the resilience of IoT infrastructure. This study contributes to intelligent IoT security by integrating updated datasets, sequential modeling, and empirical evaluation, establishing a solid foundation for future research in threat detection systems.

Full text

 Corresponding author: Mildred Adwubi Bonsu Copyright © 2025 Author(s) retain the copyright of this article. This article is published under the terms of the Creative Commons Attribution Liscense 4.0. Resilient IoT Security: Early Flood Attack Detection in IoT Networks Using GRU Deep Learning Model Mildred Adwubi Bonsu * and Philip Akekudaga College of Emergency Preparedness, Homeland Security and Cybersecurity, University at Albany, State University of New York. USA World Journal of Advanced Research and Reviews, 2025, 27(02), 871-886 Publication history: Received on 28 June 2025; revised on 10 August 2025; accepted on 12 August 2025 Article DOI: https://doi.org/10.30574/wjarr.2025.27.2.2897 Abstract Securing Internet of Things (IoT) networks has become increasingly critical as their integration across essential sectors continues to expand. Among the most pressing threats are flood attacks, a form of Distributed Denial of Service (DDoS) that overwhelms network resources and causes service degradation. In this study, the detection of flood attacks in IoT environments is addressed using a deep learning model based on the Gated Recurrent Unit (GRU) architecture. Within the scope of the analysis, the CICIoT2023 dataset, which reflects realistic IoT traffic and attack behavior, was employed for training and validation. The results have shown that the flood attacks were successfully detected, and the model achieved an accuracy score of 0.98, with moderate precision, recall, and F1 scores. In this way, flood attacks in IoT can be identified early to mitigate their impact and enhance the resilience of IoT infrastructure. This study contributes to intelligent IoT security by integrating updated datasets, sequential modeling, and empirical evaluation, establishing a solid foundation for future research in threat detection systems. Keywords: Internet Of Things (IoT); IoT Security; Distributed Denial of Service (DDOS); Deep Learning; Gated Recurrent Unit (GRU). 1. Introduction The Internet of Things (IoT) has become an integral part of daily life, transforming how we manage our homes, communicate, and operate across various industries. With IoT devices playing a crucial role in sectors such as healthcare, transportation, energy, and smart homes, they offer unprecedented convenience and efficiency. However, as their presence grows, so do the security challenges associated with their widespread interconnectivity. Among the most critical threats to IoT networks are flood attacks, a form of Distributed Denial of Service (DDoS) attack that disrupts the normal functionality of devices and networks by overwhelming them with illegitimate traffic [1, 2]. Flood attacks targeting IoT infrastructure have escalated in recent years, presenting significant real-world implications. In 2022, the number of IoT malware attacks worldwide reached 112.29 million, marking an 87% year-over-year increase from 2021. By the fourth quarter of 2024, global DDoS attacks had risen to 512,000, up from 274,000 in the first quarter of 2023 [3]. These incidents often result in service disruptions, data loss, system downtime, and substantial reputational damage, particularly for organizations that rely on real-time data transmission. Traditional security solutions, such as signature-based intrusion detection systems and basic firewalls, have proven inadequate in the face of these evolving attack patterns. Notably, many legacy systems are not optimized for IoT environments' dynamic, resource-constrained, and heterogeneous nature [4]. As a result, there is an urgent need for more adaptive and intelligent detection methods. This study aims to provide a solution to improve the efficiency of the detection of flood attacks in IoT environments with deep learning using the Gated Recurrent Unit (GRU) algorithm, which is effective in capturing temporal dependencies in sequential data. The model is trained and evaluated using the World Journal of Advanced Research and Reviews, 2025, 27(02), 871-886 872 CICIoT2023, a comprehensive dataset curated by the Canadian Institute for Cybersecurity [5], which includes a diverse set of simulated IoT traffic, encompassing both benign and malicious activities. The study has three research objectives: to improve the accuracy in detecting flood attacks in the IoT environment, develop an optimal deep learning model capable of detecting compromises in security within the IoT environment, and leverage the potential of deep learning to improve both the false positive and true positive rate metrics. The research adopts a rigorous experimental methodology grounded in deep learning principles, to assess the model's performance. Key performance metrics, such as accuracy, precision, recall, F1-score, and ROC-AUC, are used to evaluate the model's effectiveness in detecting flood attacks. This study addresses the following key research questions; 1. How can the efficiency of a deep learning-based model be improved in the detection of flood attacks in an IoT context? 2. What are the key parameters that are to be considered in developing a deep learning model to enhance its applicability in identifying security compromises in realworld IoT systems? 3. How can the proposed deep learning model be designed to improve its rate of true positives while maintaining a low rate of false alarms in flood attack detection? This study contributes to improving proactive threat detection systems in IoT environments. The findings are expected to provide valuable insights for the deployment of more robust security mechanisms in IoT systems, particularly those vulnerable to DDoS-related disruptions. Figure 1 Number of DDoS Attacks Worldwide from 1st Quater 2023 to 4th Quater 2024 (Source: Statista) Among the various flood attack and DDoS detection approaches developed in previous studies, several significant issues persist. Key challenges include the time required to identify attacks, detection accuracy, and the realism of the approach. These challenges often depend on the type of dataset and the features selected to represent the attack classes. A review of the literature reveals that many studies used outdated, small, or imbalanced datasets, which hindered the models' ability to effectively identify certain types of attacks. Additionally, some solutions sacrificed accuracy for speed of execution. These challenges are primarily due to the datasets used to train deep learning models. Training on a more current, real-time dataset could improve the model's ability to detect attacks in real-world scenarios. These limitations highlight the need for further investigation and the development of optimal solutions to enhance the efficiency of flood attack detection. Deep learning techniques have shown promising results, but several issues must be addressed. Many studies trained, tested, and validated their models on small datasets, which may not accurately reflect real-world conditions. Furthermore, some studies did not address the computational complexity of their models or provide adequate interpretation of their findings, which are critical for practical implementation. This study aims to address these challenges by improving both the false alarm rate and detection accuracy using a more recent and real-time dataset. The contribution of this work is threefold. First, it contributes to the existing body of literature by offering a comparative assessment of deep learning techniques tailored to the detection of flood-based attacks in IoT networks. The study presents quantifiable performance metrics, including accuracy, recall, and F1-score, under realistic conditions, thereby offering a reference point for future experimental replication and optimization. Second, the study provides a modeldriven perspective on integrating sequential learning into intrusion detection systems. By illustrating how GRU-based models can be tuned for pattern recognition in noisy and heterogeneous IoT traffic, the research advances the methodological foundation for low-overhead, high-accuracy detection in constrained network environments. Lastly, World Journal of Advanced Research and Reviews, 2025, 27(02), 871-886 873 this work yields practical value for the broader cybersecurity community. Network engineers, system architects, and regulatory stakeholders can utilize the findings to inform design choices in IoT network defense architectures, establish baseline detection capabilities, and align with emerging standards for secure device interoperability. The study thus contributes not only to academic inquiry but also to applied efforts aimed at strengthening the resilience of nextgeneration IoT infrastructures. The study is organized into five sections. Section 1. introduces the study, providing an overview of the research problem and questions. It also presents the need for effective detection of flood attacks in IoT networks. Section 2. presents the background of the study, reviews the relevant literature, and summarizes existing related work. Section 3. presents the conceptual framework and methodology employed in this study, including the research design, data collection procedures, pre-processing strategies, model architecture, training and testing protocols, and performance evaluation criteria. Section 4. presents the results and discusses the findings, while Section 5. concludes the paper by discussing the study’s limitations and directions for future research. 2. Materials And Methods This section presents the methodology used in the study, including the research design, conceptual framework, data collection, preparation and pre-processing, cross-validation, suggested model creation, training and testing processes, performance evaluation, and methodological overview are all covered in detail. Figures 4 and 9 show Python code used for the experiments. 2.1. Research Design This study's experimental research design entails the creation and assessment of a deep learning-based model. The purpose of the study is to develop a superior model based on a Gated Recurrent Unit (GRU) that enhances the rate at which flood attacks in IoT are detected. 2.2. Conceptual Framework The conceptual framework encompasses the various stages of the research process. It includes data acquisition and description, data preparation and pre-processing, development of the proposed model, training and testing procedures, cross-validation, and performance metrics. These components form the foundation for the development and evaluation of the proposed optimized neural network model. Figure 2 Conceptual Framework 2.3. Dataset Acquisition The model proposed in this study was trained and tested using the CICIoT2023. This dataset was created to represent as closely as possible, real-world DDOS attack scenarios, especially those of flood attacks. It contains a balanced set of World Journal of Advanced Research and Reviews, 2025, 27(02), 871-886 874 seven categories of DDoS attacks in the IoT context. The CICIoT2023 is publicly available on the Canadian Institute for Cybersecurity website[5]. In Figure 3, a complete breakdown of the CICIoT2023 with the various types of classes is presented. Source: Canadian Institute for Cybersecurity website Figure 3 The complete dataset breakdown. Neto et al. [5] set up several devices that imitate a real-world installation of IoT devices and services and configure traffic monitors on them to capture attack data. Each attack involves a unique experiment that involves all relevant devices. In the end, the count for each of the thirty-three categories of attack is illustrated as seen in Figure 3. It is clear from this graph that the authors gathered an extensive amount of flood attacks, making this dataset an ideal choice for training the deep learning model. 2.4. Data Preparation, Cleaning, and Pre-processing Data pre-processing is essential for preparing raw data for deep learning models, especially when the data is incomplete or inconsistent. In this study, the dataset was first cleaned by removing irrelevant, redundant, or erroneous entries, handling missing values through removal, and discarding outliers or infinite values to ensure data integrity. Once cleaned, the data was transformed and normalized to fit the Gated Recurrent Unit (GRU) model's input requirements. Normalization standardizes the data, ensuring that all features are on a comparable scale, which helps improve model efficiency and accuracy. The pre-processing steps were executed using Python libraries such as Pandas and NumPy. Key tasks involved: Standard Scaling: Each feature was scaled to have a mean of 0 and a standard deviation of 1, optimizing activation functions like sigmoid and tanh, which perform best with scaled inputs. This ensures improved model convergence. Label Mapping: Categorical data in the CICIoT2023 was converted into numerical form by assigning a unique integer to each category. This transformation enabled the neural network to process the data and make predictions. Data Conversion: The extracted features and labels were converted into NumPy arrays, making the dataset compatible with the proposed GRU model for training. 2.5. Model Building and Training The proposed recurrent model is trained with the TensorFlow framework. The model was also trained and validated using K-fold cross-validation. After scaling and mapping the labels to be used, the model is developed. A sequential neural network is defined with a GRU layer for the model. This layer returns a linear sequence of data and has 64 units. After this layer, a batch normalization layer is added to normalize the output from the first layer, hence ensuring that the training process remains stable. A new GRU layer of 32 units that returns a single output with a batch normalization layer is then added to the model's architecture. A fully connected dense layer with a "softmax" activation function is World Journal of Advanced Research and Reviews, 2025, 27(02), 871-886 875 now applied since the model will classify multi-classes. Now, the k-fold validation process is initialized to five with the shuffle option set to true. The hyperparameters, which are the learning rate, batch size, and the number of epochs, for training the model are specified. The epoch specifies how many times the training process is to be iterated. A third dimension is added to change the shape of the model. The model is trained with the Keras framework. It has to do with compiling the model, defining its metrics, loss, and optimizer, and training the model with the training and validation data. In the compilation phase, the loss, optimizer, and metrics of the model are configured. The Sparse Categorical Cross-entropy is the typical loss function used in this study. For the optimizer, the Adam algorithm is used on the specified learning rate. This algorithm adjusts the learning rate during training. During evaluation and training, the accuracy metric will be determined and communicated. The model is now trained using the training and validation data (X_train, X_val) and its corresponding target labels (y_train, y_val). The performance of the model on the training and validation data is assessed after each epoch, keeping a record of the accuracy metric. 2.5.1. The Gated Recurrent Unit Gated Recurrent Units (GRUs) are designed to capture model dependencies in sequential data. With sequential data, every input depends on the ones before it. So, GRUs have a hidden state (ht) that extracts information from the previous time step, for updating this state at each time step. GRUs are composed mainly of two gates which are the Update (zt) and Reset gates (rt) which decides how much of the past information is to be passed along and those that are to be forgotten, respectively. The new hidden state (ht) is a combination of the previous hidden state (ht-1) and a candidate hidden state (~ht) whereas the ~ht is a weighted combination of the previous hidden state (ht-1) and the current input (xt). These weights are given by the reset gate. The mathematical expressions of how the candidate hidden state (~ht), update gate (zt), and reset gate (rt) are calculated are shown below: In the expressions, the W and U are the weight matrices, (ʘ) denotes element-wise multiplication and (σ) is the sigmoid activation function. The final hidden state (ht) is then derived from combining the ht-1 and the ~ht, which are weighted by the update gate. 2.5.2. Cross-validation This process is carried out to accurately estimate the performance of a deep learning model and its ability to be generalized. This is done to take care of overfitting. For this study, the K-fold cross-validation method was employed. The dataset is split into five subsets (K folds), and the model is repeatedly trained and assessed on portions of the subsets. To take care of bias, the data is first shuffled before it is partitioned into folds. 2.5.3. Model Evaluation The trained model is now tested on the validation dataset. With the input features of the validation data (X_val) and the target labels of the validation data (y_val), the performance of the model is calculated, returning the validation loss and validation accuracy as its results. For this study, we accumulate and keep track of the different validation accuracy and validation losses at each iteration of the cross-validation. 2.6. Performance Metrics The trained model is tested on the validation dataset, using the input features (X_val) and target labels (y_val) to calculate validation loss and accuracy. These metrics are tracked across iterations during cross-validation. The model's performance is assessed using accuracy, precision, F1-score, and the ROC curve. Key performance indicators include true positives (TP), true negatives (TN), false positives (FP), and false negatives (FN). TP refers to correctly predicted positive data points, TN to correctly predicted negative data points, FP to incorrect positive predictions, and FN to World Journal of Advanced Research and Reviews, 2025, 27(02), 871-886 876 incorrect negative predictions. Accuracy, precision, F1-score, and ROC curve are metrics that offer quantitative evaluations of how well the model can spot flood attacks. • Accuracy score refers to the ratio of true predicted labels to the total number of labels. It measures how efficiently the model performs. 𝐴𝑐𝑐𝑢𝑟𝑎𝑐𝑦 = (𝑇𝑃 + 𝑇𝑁) (𝑇𝑃 + 𝑇𝑁 + 𝐹𝑃 + 𝐹𝑁) ---------- (1) Source: G.Ahmed,[39] • Precision focuses on the number of the model's predicted true positives that are really, true positives. 𝑃𝑟𝑒𝑐𝑖𝑠𝑖𝑜𝑛 = 𝑇𝑃 (𝑇𝑃 + 𝐹𝑃) ----------- (2) Source: G.Ahmed, [39] • Receiver Operating Characteristic Curve (AUC) is a metric that gives a quantitative value of the overall classification performance at all thresholds by the model. Source: Yousuf and Mir [35] • Recall score provides a quantitative measure of the proportion of true positives predicted by the model against the actual positive cases. 𝑅𝑒𝑐𝑎𝑙𝑙 = 𝑇𝑃 (𝑇𝑃 + 𝐹𝑁) ---------- (3) Source: G.Ahmed,[39] • F1-score provides an evaluation of the performance of the model by calculating the mean between precision and recall. 𝐹1 𝑆𝑐𝑜𝑟𝑒 = 2 ∗ (𝑃𝑟𝑒𝑐𝑖𝑠𝑖𝑜𝑛 ∗ 𝑅𝑒𝑐𝑎𝑙𝑙) (𝑃𝑟𝑒𝑐𝑖𝑠𝑖𝑜𝑛 + 𝑅𝑒𝑐𝑎𝑙𝑙) ---------- (4) Source: Brownlee,[45] The accuracy (1) of the model is obtained by dividing the overall number of the model's correctly predicted cases (TP + TN) by the total number of predictions (TN + TP + FP + FN) it made. For the precision (2) of the model, the focus is set only on the ratio of correct positive predictions (TP) out of the total positive predictions (TP + FP) by the model. Regarding the recall metric (3), the total number of correctly predicted positive instances (TP) is divided by the sum of the number of correctly predicted positive instances and the number of wrongly predicted negative instances (TP + FN). Lastly, the F1-score (4) presents quantitative data on the balance between the model's precision (2) and recall (3). After several experiments, the performance of the model was measured based on accuracy, precision, recall, ROC, and F1score. World Journal of Advanced Research and Reviews, 2025, 27(02), 871-886 877 Figure 4 Python Code showing model performance per epoch World Journal of Advanced Research and Reviews, 2025, 27(02), 871-886 878 Figure 5 Calculation of the performance metrics and confusion matrix Table 1 The performance metrics of the model and their corresponding values. Performance Metrics Value Recall 0.61 Precision 0.63 Accuracy 0.98 F1 score 0.61 3. Results and Discussion The evaluation of the proposed methodology, its performance, and how it compares to other related works in detecting flood attacks show that the recall obtained is 0.61, the precision obtained was 0.63, the accuracy obtained is 0.98, and the F1 Score is 0.61. The proposed model was tested on the CICIoT2023, and the results of the experiments were analyzed. The Gated Recurrent Unit (GRU) algorithm was implemented along with Python, Keras, and the Sklearn libraries. 3.1. Model's Performance on the CICIoT2023 The CICIoT2023 used for the experiments was the most ideal. This dataset is new and an improvement on its previous versions in terms of size and generalizability. Neto et al.[5] employed an extensive topology of real-world IoT devices to obtain the dataset hence making it very realistic and real-time. It is worth noting that using such a dataset for training the model improves its robustness. Now, with this improved level of robustness and, consequently, reliability, the model can be used in real-world scenarios to add to the security of IoT devices. On training and evaluating the proposed GRUbased model on this improved and realistic dataset for flood attack detection, it was observed that the model performed very well in terms of its accuracy. This method could be the first of several that employ deep learning for detecting flood World Journal of Advanced Research and Reviews, 2025, 27(02), 871-886 879 attacks on such a real-time dataset. Based on the findings from Table 1, the model suffered a little in its precision, recall, and F1-score. This may be because of the many classes it had to identify and correctly place. However, it had a nearly perfect score in accuracy. This means that the model correctly predicted most of the instances out of the total in the dataset. In simpler terms, the model made more correct predictions and thus enhanced the detection of flood attacks in the IoT environment. 3.1.1. Model Validation Metrics The performance of the model in detecting the various flood attacks was evaluated using accuracy and model loss. The accuracy of the model measured how effective the model's prediction was as compared to the actual data. The loss function of the model was used to measure its optimality. The loss function also shows the level of errors in the training or validation of the model. Accordingly, a greater loss function denotes a model iteration that underwent poor model optimization, whereas a lower one denotes better model optimization. Figures 6 and 7 show the model's training and validation accuracy and loss function results, respectively. Figure 6 The training and validation accuracy of the model Figure 7 The training and validation loss of the model In Figure 6, it is seen that the training accuracy steadily rises from the first epoch to the second, slightly falls at the third, and begins a steady rise from there to the fourth epoch. From here it sharply rises to the seventh epoch and then maintains a steady rise through to the tenth epoch. The validation accuracy of the model gently rises from the first epoch to the third. It then sharply falls from this epoch to the fourth while maintaining a steady level until the fifth epoch. The World Journal of Advanced Research and Reviews, 2025, 27(02), 871-886 886 [44] Procopiou, A., Komninos, N., & Douligeris, C. (2019). ForChaos: Real time application DDoS detection using forecasting and chaos theory in smart home IoT network. Wireless Communications and Mobile Computing, 1– 14. https://doi.org/10.1155/2019/8469410 [45] Brownlee, J. (2022, August 19). How to calculate precision, recall, F1, and more for deep learning models. Retrieved from https://machinelearningmastery.com/how-to-calculate-precision-recall-f1-and-more-for-deeplearning-models/ [46] Pei, W., et al. (2019). A survey on network intrusion detection techniques for DDoS attacks. Journal of Computer Networks and Communications.