Metaheuristic-driven two-stage hybrid feature selection and deep learning optimization for security in IoT systems


Gül M. F., Bakır H.

KNOWLEDGE-BASED SYSTEMS, cilt.352, ss.1-14, 2026 (SCI-Expanded, Scopus)

  • Yayın Türü: Makale / Tam Makale
  • Cilt numarası: 352
  • Basım Tarihi: 2026
  • Doi Numarası: 10.1016/j.knosys.2026.116935
  • Dergi Adı: KNOWLEDGE-BASED SYSTEMS
  • Derginin Tarandığı İndeksler: Applied Science & Technology Source, Information Science & Technology Abstracts (LISTA), Academic Search Ultimate (EBSCO), Engineering Source (EBSCO), Scopus, Technology Collection (ProQuest), Aerospace Database, Science Citation Index Expanded (SCI-EXPANDED), Compendex, INSPEC, Library, Information Science & Technology Abstracts (LISTA)
  • Sayfa Sayıları: ss.1-14
  • Sivas Cumhuriyet Üniversitesi Adresli: Evet

Özet

Intrusion detection in Internet of Things (IoT) systems poses significant challenges due to high-dimensional, heterogeneous, and rapidly evolving network traffic. To address these issues, this study proposes a novel two-stage hybrid framework aimed at enhancing the performance and scalability of intrusion detection systems. In the initial stage, the Random Forest algorithm ranks features by importance and retains the top 50%. In the second stage, five metaheuristic algorithms refine the feature space: Genetic Algorithm, Particle Swarm Optimization, Whale Optimization Algorithm, Sine Cosine Algorithm (SCA), and Harris Hawk Optimization. The final feature subsets are combined to build a robust and compact input set. These same algorithms are then used to automatically optimize DL model architectures and hyperparameters. Experiments conducted on the RT-IoT 2022 dataset show that the SCA-optimized model achieved the best results, with 99.38% accuracy, 2.63% loss, and a consistent F1 score of 99.40% under stratified 5-fold cross-validation. These results are particularly notable given the imbalanced and complex nature of IoT traffic, and they indicate the model’s ability to accurately detect both frequent and rare intrusion types. The proposed framework addresses the challenges of high-dimensional, heterogeneous IoT traffic by enabling fully automated, high-performance model design. These findings highlight its potential for real-world deployment in scalable and adaptive IoT intrusion detection systems. Future work will explore its applicability to broader IoT environments and integration with emerging paradigms such as federated and quantum machine learning.