<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article">
 <front>
  <journal-meta>
   <journal-id journal-id-type="publisher-id">
    ojapps
   </journal-id>
   <journal-title-group>
    <journal-title>
     Open Journal of Applied Sciences
    </journal-title>
   </journal-title-group>
   <issn pub-type="epub">
    2165-3917
   </issn>
   <issn publication-format="print">
    2165-3925
   </issn>
   <publisher>
    <publisher-name>
     Scientific Research Publishing
    </publisher-name>
   </publisher>
  </journal-meta>
  <article-meta>
   <article-id pub-id-type="doi">
    10.4236/ojapps.2025.159177
   </article-id>
   <article-id pub-id-type="publisher-id">
    ojapps-145568
   </article-id>
   <article-categories>
    <subj-group subj-group-type="heading">
     <subject>
      Articles
     </subject>
    </subj-group>
    <subj-group subj-group-type="Discipline-v2">
     <subject>
      Biomedical 
     </subject>
     <subject>
       Life Sciences, Chemistry 
     </subject>
     <subject>
       Materials Science, Computer Science 
     </subject>
     <subject>
       Communications, Engineering, Physics 
     </subject>
     <subject>
       Mathematics
     </subject>
    </subj-group>
   </article-categories>
   <title-group>
    Intrusion Detection for Edge-IoT Using LSTM-Autoencoder
   </title-group>
   <contrib-group>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Bodjré Aka Hugues
      </surname>
      <given-names>
       Félix
      </given-names>
     </name> 
     <xref ref-type="aff" rid="aff1"> 
      <sup>1</sup>
     </xref>
    </contrib>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Kié Eba
      </surname>
      <given-names>
       Victoire
      </given-names>
     </name> 
     <xref ref-type="aff" rid="aff1"> 
      <sup>1</sup>
     </xref>
    </contrib>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       N’guessan N’takpé Christian
      </surname>
      <given-names>
       Placide
      </given-names>
     </name> 
     <xref ref-type="aff" rid="aff2"> 
      <sup>2</sup>
     </xref>
    </contrib>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Brou
      </surname>
      <given-names>
       Pacôme
      </given-names>
     </name> 
     <xref ref-type="aff" rid="aff1"> 
      <sup>1</sup>
     </xref>
    </contrib>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Asseu Olivier
      </surname>
      <given-names>
       Pascal
      </given-names>
     </name> 
     <xref ref-type="aff" rid="aff1"> 
      <sup>1</sup>
     </xref>
    </contrib>
   </contrib-group> 
   <aff id="aff1">
    <addr-line>
     aLaboratoire des Sciences Technologiques de l’Information et de la Communication (LASTIC), Ecole Supérieure Africaine des Technologie de l’Information et de la Communication (ESATIC), Abidjan, Côte d’Ivoire
    </addr-line> 
   </aff> 
   <aff id="aff2">
    <addr-line>
     aUnité de Recherche et d’Expertise Numérique (UREN), Université Virtuelle de Cote d’Ivoire (UVCI), Abidjan, Côte d’Ivoire
    </addr-line> 
   </aff> 
   <pub-date pub-type="epub">
    <day>
     01
    </day> 
    <month>
     09
    </month>
    <year>
     2025
    </year>
   </pub-date> 
   <volume>
    15
   </volume> 
   <issue>
    09
   </issue>
   <fpage>
    2638
   </fpage>
   <lpage>
    2647
   </lpage>
   <history>
    <date date-type="received">
     <day>
      8,
     </day>
     <month>
      August
     </month>
     <year>
      2025
     </year>
    </date>
    <date date-type="published">
     <day>
      12,
     </day>
     <month>
      August
     </month>
     <year>
      2025
     </year> 
    </date> 
    <date date-type="accepted">
     <day>
      12,
     </day>
     <month>
      September
     </month>
     <year>
      2025
     </year> 
    </date>
   </history>
   <permissions>
    <copyright-statement>
     © Copyright 2014 by authors and Scientific Research Publishing Inc. 
    </copyright-statement>
    <copyright-year>
     2014
    </copyright-year>
    <license>
     <license-p>
      This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/
     </license-p>
    </license>
   </permissions>
   <abstract>
    This work presents an innovative Intrusion Detection System (IDS) for Edge-IoT environments, based on an unsupervised architecture combining LSTM networks and Autoencoders. Deployed on Raspberry Pi 4, our solution achieves an F1-score of 0.96 with 42 ms latency and detects anomalies, including zero-day attacks, with 97.2% accuracy on the TON_IoT and NSL-KDD datasets. Compared to CNN or Random Forest-based approaches, it consumes 40% fewer resources. A comparative analysis with Snort and Bro also reveals superior energy efficiency (1.8 W vs. 3.2 W) and better adaptability to dynamic environments.
   </abstract>
   <kwd-group> 
    <kwd>
     Intrusion Detection System (IDS)
    </kwd> 
    <kwd>
      Edge Computing
    </kwd> 
    <kwd>
      Internet of Things (IoT)
    </kwd> 
    <kwd>
      LSTM
    </kwd> 
    <kwd>
      Autoencoder
    </kwd> 
    <kwd>
      Zero-Day Attack
    </kwd>
   </kwd-group>
  </article-meta>
 </front>
 <body>
  <sec id="s1">
   <title>1. Introduction</title>
   <p>Edge Computing and the Internet of Things (IoT) are redefining industrial and medical architectures, as seen in Industry 4.0 factories where sensors monitor machinery status in real time or in smart hospitals equipped with connected IoT devices. This decentralization of data processing significantly reduces latency (below 10 ms in 95% of cases, as reported by <xref ref-type="bibr" rid="scirp.145568-1">
     [1]
    </xref>, but it also exposes these networks to increasingly sophisticated cyber threats. In a context where the number of sensors and connected devices is exploding, the potential attack surface widens considerably <xref ref-type="bibr" rid="scirp.145568-2">
     [2]
    </xref>. Device heterogeneity, protocol diversity, and the lack of security standardization exacerbate vulnerabilities <xref ref-type="bibr" rid="scirp.145568-3">
     [3]
    </xref>. Embedded devices, often lacking continuous supervision or regular updates, become critical entry points for cybercriminals <xref ref-type="bibr" rid="scirp.145568-4">
     [4]
    </xref>. Consider the critical example of a connected pacemaker: a zero-day attack could alter its telemetry data via malformed TCP/IP packets, potentially inducing fatal cardiac discharges. Traditional IDSs like Snort, which rely on predefined signatures, would fail to detect such attacks. In contrast, our approach based on reconstruction deviations generated by an LSTM-Autoencoder model successfully identifies them (F1-score = 0.96 on the TON_IoT dataset).</p>
   <p>To address these challenges, we propose a self-adaptive IDS combining LSTM networks and Autoencoders, specifically designed for resource-constrained Edge environments (e.g., Raspberry Pi 4, latency = 42 ms). The system learns normal traffic behavior without supervision and detects anomalies, including novel ones, by analyzing reconstruction errors, with dynamically adjusted thresholds via the Peaks-Over-Threshold algorithm.</p>
   <p>This work aims to achieve two major objectives:</p>
   <p>1) Scientific: Demonstrate the superiority of hybrid unsupervised models over signature-based methods (accuracy gain ≥ 28% compared to Snort);</p>
   <p>2) Practical: Ensure memory consumption ≤ 200 MB and real-time detection (&lt;50 ms) on embedded devices.</p>
   <p>The remainder of this paper is organized as follows: Section 2 reviews related work on Edge-IoT IDS. Section 3 details our LSTM-Autoencoder approach. Section 4 formalizes the mathematical model. Section 5 describes the experimental setup, Section 6 analyzes results, and Section 7 concludes with future directions.</p>
  </sec><sec id="s2">
   <title>2. Related Work</title>
   <p>The state of the art in intrusion detection for Edge-IoT networks highlights a steady evolution toward lighter, more accurate solutions better suited to decentralized environments. Traditional systems like Snort <xref ref-type="bibr" rid="scirp.145568-2">
     [2]
    </xref> and Bro <xref ref-type="bibr" rid="scirp.145568-3">
     [3]
    </xref>, which rely on predefined signatures or manual rules, are effective at detecting known attacks. However, their rigidity limits their ability to identify zero-day threats or adapt to evolving IoT traffic patterns. These approaches often require regular updates and exhibit poor performance in detecting abnormal behaviors in highly heterogeneous environments.</p>
   <p>Machine learning and statistical techniques, such as those proposed in <xref ref-type="bibr" rid="scirp.145568-3">
     [3]
    </xref> using the TON_IoT dataset or <xref ref-type="bibr" rid="scirp.145568-5">
     [5]
    </xref> with the LBDMIDS model, have improved anomaly detection. However, these architectures, often complex, rarely account for Edge platform resource constraints, particularly in energy consumption or memory capacity. For instance, <xref ref-type="bibr" rid="scirp.145568-6">
     [6]
    </xref> report a power consumption of 4.2 W on Raspberry Pi 4, limiting their deployment in battery-powered sensors.</p>
   <p>Recent hybrid architectures combining LSTM networks and Autoencoders (<xref ref-type="bibr" rid="scirp.145568-7">
     [7]
    </xref> <xref ref-type="bibr" rid="scirp.145568-8">
     [8]
    </xref>) have demonstrated effectiveness in anomaly detection, including for time-series data, with accuracies exceeding 96%. However, these works often lack practical integration into Edge platforms, particularly regarding energy efficiency, automated threat response, or validation on real hardware. For example, <xref ref-type="bibr" rid="scirp.145568-6">
     [6]
    </xref> report 92% accuracy with 850 MB memory usage on Jetson Nano, which remains excessive compared to our model’s 195 MB on Raspberry Pi 4.</p>
   <p>While security challenges in Edge Computing remain partly theoretical <xref ref-type="bibr" rid="scirp.145568-1">
     [1]
    </xref>, integrating on-device AI through lightweight, high-performance models is critical for enabling real-time detection in heterogeneous environments. Emerging approaches, such as lightweight Transformers (FEDformer, <xref ref-type="bibr" rid="scirp.145568-9">
     [9]
    </xref>), enhance time-series modeling but face deployment barriers due to their complexity on platforms like Raspberry Pi. Similarly, federated methods (FELIDS, <xref ref-type="bibr" rid="scirp.145568-10">
     [10]
    </xref>) decentralize detection while preserving data privacy, crucial for sensitive environments.</p>
   <p>In response to these limitations, our work distinguishes itself by proposing an unsupervised LSTM-Autoencoder-based IDS specifically optimized for Edge-IoT. It achieves high accuracy (97%) while maintaining low memory usage (200 MB) and energy consumption (1.8 W), compatible with platforms like Raspberry Pi 4. Leveraging representative datasets like TON_IoT, our solution bridges the gap between efficiency, lightweight design, and robustness, while enabling zero-day attack detection without predefined signatures or labeled data.</p>
   <p>Addressing the gaps identified in existing literature, the following section details our lightweight, unsupervised LSTM-Autoencoder architecture.</p>
  </sec><sec id="s3">
   <title>3. Proposed Approach</title>
   <p>The objective of our solution is to develop a lightweight, intelligent, and self-adaptive Intrusion Detection System (IDS) capable of operating in real-time within Edge-IoT environments where resources (CPU, memory, energy) are limited. Unlike many existing works, our architecture relies on an unsupervised LSTM-Autoencoder model, optimized for deployment on resource-constrained platforms such as the Raspberry Pi 4.</p>
   <p>Our model does not require a signature database or prior data labeling, unlike traditional systems such as Snort. It autonomously learns the normal behavior of network traffic from real-time streams and identifies deviations as potentially malicious. This approach enables the effective detection of zero-day attacks, which represents a significant advancement over rule-based systems <xref ref-type="bibr" rid="scirp.145568-5">
     [5]
    </xref> <xref ref-type="bibr" rid="scirp.145568-10">
     [10]
    </xref>. The following <xref ref-type="fig" rid="fig1">
     Figure 1
    </xref> presents IoT clients and sensors transmit data to a gateway equipped with an LSTM Autoencoder. Abnormal behaviors are detected in real time and trigger an automated response mechanism.</p>
   <fig id="fig1" position="float">
    <label>Figure 1</label>
    <caption>
     <title>
      <xref ref-type="bibr" rid="scirp.145568-"></xref>Figure 1. Proposed IDS System Architecture.</title>
    </caption>
    <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/2313340-rId15.jpeg?20250915100933" />
   </fig>
  </sec><sec id="s4">
   <title>4. Mathematical Model</title>
   <sec id="s4_1">
    <title>4.1. Mathematical Model</title>
    <p>Let us consider a network data sequence:</p>
    <p>
     <math display="inline" xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mi>
         X 
       </mi> 
       <mo>
         = 
       </mo> 
       <mrow> 
        <mo>
          { 
        </mo> 
        <mrow> 
         <msub> 
          <mi>
            x 
          </mi> 
          <mn>
            1 
          </mn> 
         </msub> 
         <mo>
           , 
         </mo> 
         <msub> 
          <mi>
            x 
          </mi> 
          <mn>
            2 
          </mn> 
         </msub> 
         <mo>
           , 
         </mo> 
         <mo>
           ⋯ 
         </mo> 
         <mo>
           , 
         </mo> 
         <msub> 
          <mi>
            x 
          </mi> 
          <mi>
            t 
          </mi> 
         </msub> 
        </mrow> 
        <mo>
          } 
        </mo> 
       </mrow> 
      </mrow> 
     </math></p>
    <p>where 
     <math display="inline" xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          x 
        </mi> 
        <mi>
          t 
        </mi> 
       </msub> 
       <mo>
         ∈ 
       </mo> 
       <msup> 
        <mi>
          ℝ 
        </mi> 
        <mi>
          n 
        </mi> 
       </msup> 
      </mrow> 
     </math> is a feature vector at time t, composed of attributes such as:</p>
    <p>The LSTM encodes this sequence into a temporal representation:</p>
    <p>
     <math display="inline" xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          h 
        </mi> 
        <mi>
          t 
        </mi> 
       </msub> 
       <mo>
         = 
       </mo> 
       <mtext>
         LSTM 
       </mtext> 
       <mrow> 
        <mo>
          ( 
        </mo> 
        <mrow> 
         <msub> 
          <mi>
            x 
          </mi> 
          <mi>
            t 
          </mi> 
         </msub> 
         <mo>
           , 
         </mo> 
         <msub> 
          <mi>
            h 
          </mi> 
          <mi>
            t 
          </mi> 
         </msub> 
         <msub> 
          <mrow></mrow> 
          <mrow> 
           <mo>
             − 
           </mo> 
           <mn>
             1 
           </mn> 
          </mrow> 
         </msub> 
        </mrow> 
        <mo>
          ) 
        </mo> 
       </mrow> 
      </mrow> 
     </math></p>
    <p>h<sub>t</sub>: Hidden state vector at time t, encapsulating the memory of past traffic patterns.</p>
    <p>The Autoencoder compresses and reconstructs each input x<sub>t</sub>:</p>
    <p>
     <math xmlns="http://www.w3.org/1998/Math/MathML" display="inline"> <mrow> 
       <msub> 
        <mover accent="true"> 
         <mi>
           x 
         </mi> 
         <mo>
           ^ 
         </mo> 
        </mover> 
        <mi>
          t 
        </mi> 
       </msub> 
       <mo>
         = 
       </mo> 
       <mtext>
         Decoder 
       </mtext> 
       <mrow> 
        <mo>
          ( 
        </mo> 
        <mrow> 
         <mtext>
           Encoder 
         </mtext> 
         <mrow> 
          <mo>
            ( 
          </mo> 
          <mrow> 
           <msub> 
            <mi>
              x 
            </mi> 
            <mi>
              t 
            </mi> 
           </msub> 
          </mrow> 
          <mo>
            ) 
          </mo> 
         </mrow> 
        </mrow> 
        <mo>
          ) 
        </mo> 
       </mrow> 
      </mrow> 
     </math></p>
    <p>The reconstruction error is measured as:</p>
    <p>
     <math display="inline" xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <msub> 
        <mi>
          E 
        </mi> 
        <mi>
          t 
        </mi> 
       </msub> 
       <mo>
         = 
       </mo> 
       <msup> 
        <mrow> 
         <mrow> 
          <mo>
            ‖ 
          </mo> 
          <mrow> 
           <msub> 
            <mi>
              x 
            </mi> 
            <mi>
              t 
            </mi> 
           </msub> 
           <mo>
             − 
           </mo> 
           <msub> 
            <mover accent="true"> 
             <mi>
               x 
             </mi> 
             <mo>
               ^ 
             </mo> 
            </mover> 
            <mi>
              t 
            </mi> 
           </msub> 
          </mrow> 
          <mo>
            ‖ 
          </mo> 
         </mrow> 
        </mrow> 
        <mn>
          2 
        </mn> 
       </msup> 
      </mrow> 
     </math>(1)</p>
    <p>Anomaly classification follows:</p>
    <p>
     <math display="inline" xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mtext>
         Anomalie 
       </mtext> 
       <mo>
         ⇔ 
       </mo> 
       <msub> 
        <mi>
          E 
        </mi> 
        <mi>
          t 
        </mi> 
       </msub> 
       <mo>
         &gt; 
       </mo> 
       <mi>
         θ 
       </mi> 
      </mrow> 
     </math></p>
    <p>Anomaly threshold θ was computed as:</p>
    <p>
     <math display="inline" xmlns="http://www.w3.org/1998/Math/MathML"> <mrow> 
       <mi>
         θ 
       </mi> 
       <mo>
         = 
       </mo> 
       <msub> 
        <mi>
          μ 
        </mi> 
        <mi>
          e 
        </mi> 
       </msub> 
       <mo>
         + 
       </mo> 
       <mi>
         k 
       </mi> 
       <mo>
         ⋅ 
       </mo> 
       <msub> 
        <mi>
          σ 
        </mi> 
        <mi>
          e 
        </mi> 
       </msub> 
      </mrow> 
     </math>(2)</p>
    <p>μ<sub>e</sub> is the mean of the reconstruction error over normal traffic;</p>
    <p>σ<sub>e</sub> is the standard deviation of that error;</p>
    <p>k is an empirical coefficient set to 1.5, based on validation performance.</p>
    <p>This technique is aligned with best practices in anomaly detection using autoencoders, as described by <xref ref-type="bibr" rid="scirp.145568-11">
      [11]
     </xref> and more recently by <xref ref-type="bibr" rid="scirp.145568-12">
      [12]
     </xref>.</p>
    <p>To further refine anomaly detection beyond a fixed threshold, we also integrate the Peaks-Over-Threshold (POT) algorithm. This method models the tail distribution of reconstruction errors and dynamically adjusts θ based on extreme value theory. POT is particularly effective in capturing rare but significant deviations in unsupervised learning scenarios. A detailed discussion of its implementation and impact is presented in Section 6.4.</p>
    <p>We also integrate the Peaks-Over-Threshold (POT) method to automatically adjust the detection threshold based on the error distribution. This approach is applied in the work of <xref ref-type="bibr" rid="scirp.145568-13">
      [13]
     </xref> for a distributed anomaly detection system based on federated autoencoders, where POT is used to dynamically select a threshold suited to the data.</p>
   </sec>
   <sec id="s4_2">
    <title>4.2. Pseudo Code</title>
    <p>Algorithm: Real-Time Anomaly Detection via LSTM-Autoencoder</p>
    <p>Inputs:</p>
    <p>Outputs:</p>
    <p>1) Begin Algorithm:</p>
    <p>2) Continuous Loop:</p>
    <p>a) Extract and normalize features (vector X)</p>
    <p>b) Pass sequence through LSTM → obtain temporal representation h<sub>t</sub></p>
    <p>c) Compress (Encoder) and reconstruct (Decoder) via Autoencoder</p>
    <p>d) Compute reconstruction error E</p>
    <p>e) Compare E to threshold θ:</p>
    <p>f) Wait for delay Δt before next sequence (e.g., 500 ms)</p>
    <p>3) End Algorithm</p>
    <fig id="fig2" position="float">
     <label>Figure 2</label>
     <caption>
      <title>
       <xref ref-type="bibr" rid="scirp.145568-"></xref>Figure 2. Flowchart of the anomaly detection process.</title>
     </caption>
     <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/2313340-rId30.jpeg?20250915100934" />
    </fig>
    <p>
     <xref ref-type="fig" rid="fig2">
      Figure 2
     </xref> presents, the Real-time anomaly detection flow diagram based on the LSTM-Autoencoder model. Network packets are collected, transformed into sequences, processed by the LSTM, and reconstructed by the Autoencoder. The reconstruction error is compared to a threshold to generate an alert if an anomaly is detected.</p>
   </sec>
  </sec><sec id="s5">
   <title>5. Experimental Setup</title>
   <p>Our approach was evaluated in a realistic Edge-IoT setting using low-resource hardware. Platforms Used:</p>
   <p>Software Tools:</p>
   <p>Datasets:</p>
   <p>Evaluation Metrics:</p>
   <p>With the experimental setup defined, we now present the obtained results and a comparative discussion.</p>
  </sec><sec id="s6">
   <title>6. Results and Discussion</title>
   <p>This section presents the experimental performance of our LSTM-Autoencoder model, primarily evaluated on the TON_IoT dataset, and compared to classical approaches such as Snort, CNN, and Random Forest in an Edge context (Raspberry Pi 4).</p>
   <sec id="s6_1">
    <title>6.1. Model Training Curve</title>
    <p>The first curve (see <xref ref-type="fig" rid="fig3">
      Figure 3
     </xref>) illustrates the evolution of the loss function MSE (Mean Squared Error) over 50 training epochs. A steady decrease in MSE is observed for both training and validation phases, indicating the model’s strong learning capability. The gap between the two curves remains narrow and stable, suggesting no overfitting. This confirms that the model generalizes well to normal network traffic sequences, a critical prerequisite for reliable anomaly detection.</p>
    <fig id="fig3" position="float">
     <label>Figure 3</label>
     <caption>
      <title>
       <xref ref-type="bibr" rid="scirp.145568-"></xref>Figure 3. Learning curve of the LSTM Autoencoder.</title>
     </caption>
     <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/2313340-rId31.jpeg?20250915100934" />
    </fig>
   </sec>
   <sec id="s6_2">
    <title>6.2. Reconstruction Error and Anomaly Detection</title>
    <p>The second curve (<xref ref-type="fig" rid="fig4">
      Figure 4
     </xref>) illustrates the reconstruction error across the captured network traffic. The anomaly threshold (dashed red line) was empirically defined as the mean reconstruction error plus a standard deviation factor. Points above this threshold are classified as anomalies. This visualization demonstrates the model’s sensitivity to abnormal network behaviors. Most traffic falls below the threshold, indicating sequences classified as normal. Conversely, notable peaks above the threshold, particularly in later phases, highlight the model’s ability to detect anomalies, including potential Zero-Day attacks.</p>
    <fig id="fig4" position="float">
     <label>Figure 4</label>
     <caption>
      <title>
       <xref ref-type="bibr" rid="scirp.145568-"></xref>Figure 4. Reconstruction Error with Anomaly Threshold.</title>
     </caption>
     <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/2313340-rId32.jpeg?20250915100934" />
    </fig>
   </sec>
   <sec id="s6_3">
    <title>6.3. Quantitative Performance</title>
    <p>
     <xref ref-type="table" rid="table1">
      Table 1
     </xref> below, presents a comparison between our proposed LSTM-Autoencoder model and three classical IDS systems: Snort, CNN, and Random Forest. The results highlight the superiority of our approach in terms of precision (97.2%), F1-Score (96.0%), and false positive rate (1.2%). Moreover, our model exhibits very low detection latency (0.9 s) and optimized resource usage (38% CPU usage and only 195 MB of memory). Finally, the system demonstrates excellent capabilities in detecting zero-day attacks, unlike traditional solutions. These performances make our model particularly suitable for energy- and memory-constrained Edge-IoT environments.</p>
    <table-wrap id="table1">
     <label>
      <xref ref-type="table" rid="table1">
       Table 1
      </xref></label>
     <caption>
      <title>
       <xref ref-type="bibr" rid="scirp.145568-"></xref>Table 1. Comparing our Approach with classical IDS Systems.</title>
     </caption>
     <table class="MsoTableGrid custom-table" border="0" cellspacing="0" cellpadding="0"> 
      <tr> 
       <td class="custom-bottom-td acenter" width="28.42%"><p style="text-align:center">Model</p></td> 
       <td class="custom-bottom-td acenter" width="16.95%"><p style="text-align:center">Precision</p></td> 
       <td class="custom-bottom-td acenter" width="16.34%"><p style="text-align:center">F1-Score</p></td> 
       <td class="custom-bottom-td acenter" width="14.79%"><p style="text-align:center">FP Rate</p></td> 
       <td class="custom-bottom-td acenter" width="14.87%"><p style="text-align:center">Latency</p></td> 
       <td class="custom-bottom-td acenter" width="19.98%"><p style="text-align:center">CPU Usage</p></td> 
       <td class="custom-bottom-td acenter" width="15.27%"><p style="text-align:center">RAM</p></td> 
       <td class="custom-bottom-td acenter" width="31.85%"><p style="text-align:center">Zero-Day Detection</p></td> 
      </tr> 
      <tr> 
       <td class="custom-top-td acenter" width="28.42%"><p style="text-align:center">Snort</p></td> 
       <td class="custom-top-td acenter" width="16.95%"><p style="text-align:center">80.2%</p></td> 
       <td class="custom-top-td acenter" width="16.34%"><p style="text-align:center">77.4%</p></td> 
       <td class="custom-top-td acenter" width="14.79%"><p style="text-align:center">5.8%</p></td> 
       <td class="custom-top-td acenter" width="14.87%"><p style="text-align:center">&gt;2 s</p></td> 
       <td class="custom-top-td acenter" width="19.98%"><p style="text-align:center">55%</p></td> 
       <td class="custom-top-td acenter" width="15.27%"><p style="text-align:center">320 MB</p></td> 
       <td class="custom-top-td acenter" width="31.85%"><p style="text-align:center">Low</p></td> 
      </tr> 
      <tr> 
       <td class="acenter" width="28.42%"><p style="text-align:center">CNN</p></td> 
       <td class="acenter" width="16.95%"><p style="text-align:center">89.1%</p></td> 
       <td class="acenter" width="16.34%"><p style="text-align:center">86.9%</p></td> 
       <td class="acenter" width="14.79%"><p style="text-align:center">3.6%</p></td> 
       <td class="acenter" width="14.87%"><p style="text-align:center">1.6 s</p></td> 
       <td class="acenter" width="19.98%"><p style="text-align:center">50%</p></td> 
       <td class="acenter" width="15.27%"><p style="text-align:center">400 MB</p></td> 
       <td class="acenter" width="31.85%"><p style="text-align:center">Moderate</p></td> 
      </tr> 
      <tr> 
       <td class="acenter" width="28.42%"><p style="text-align:center">Random Forest</p></td> 
       <td class="acenter" width="16.95%"><p style="text-align:center">91.3%</p></td> 
       <td class="acenter" width="16.34%"><p style="text-align:center">89.7%</p></td> 
       <td class="acenter" width="14.79%"><p style="text-align:center">3.1%</p></td> 
       <td class="acenter" width="14.87%"><p style="text-align:center">1.3 s</p></td> 
       <td class="acenter" width="19.98%"><p style="text-align:center">48%</p></td> 
       <td class="acenter" width="15.27%"><p style="text-align:center">360 MB</p></td> 
       <td class="acenter" width="31.85%"><p style="text-align:center">Moderate</p></td> 
      </tr> 
      <tr> 
       <td class="acenter" width="28.42%"><p style="text-align:center">LSTM-AE (Ours)</p></td> 
       <td class="acenter" width="16.95%"><p style="text-align:center">97.2%</p></td> 
       <td class="acenter" width="16.34%"><p style="text-align:center">96.0%</p></td> 
       <td class="acenter" width="14.79%"><p style="text-align:center">1.2%</p></td> 
       <td class="acenter" width="14.87%"><p style="text-align:center">0.9 s</p></td> 
       <td class="acenter" width="19.98%"><p style="text-align:center">38%</p></td> 
       <td class="acenter" width="15.27%"><p style="text-align:center">195 MB</p></td> 
       <td class="acenter" width="31.85%"><p style="text-align:center">Excellent</p></td> 
      </tr> 
     </table>
    </table-wrap>
   </sec>
   <sec id="s6_4">
    <title>6.4. Mathematical Error Analysis</title>
    <p>An analysis of false positives (FP) and false negatives (FN) reveals the following:</p>
   </sec>
   <sec id="s6_5">
    <title>6.5. Discussion</title>
    <p>The low resource usage of the proposed IDS has significant practical benefits for real-world deployment. With a power consumption of only 1.8 W, the system can operate efficiently on battery-powered IoT devices, even in remote or resource-constrained environments where continuous power supply is unavailable. Additionally, the lightweight memory footprint (&lt;200 MB) allows the system to be deployed on fog nodes or embedded devices within dense sensor networks without overloading their computational capacity. These characteristics make the model highly suitable for scalable and autonomous security solutions in Edge-IoT infrastructures.</p>
   </sec>
  </sec><sec id="s7">
   <title>7. Conclusion and Future Work</title>
   <p>In this paper, we proposed a lightweight, intelligent, and self-adaptive intrusion detection system (IDS) specifically designed for Edge-IoT environments. By combining the temporal capabilities of LSTM networks with the reconstruction power of Autoencoders in an unsupervised architecture, our approach effectively detects anomalies, including zero-day attacks, without requiring predefined signatures or labeled data.</p>
   <p>Experimental results, obtained on the TON_IoT and NSL-KDD datasets and validated on embedded platforms like Raspberry Pi 4, confirm the model’s robustness and relevance. Compared to classical approaches such as Snort, CNN, or Random Forest, our solution demonstrates superior accuracy, reduced latency, and significantly optimized resource consumption.</p>
   <p>This work contributes to the broader effort to secure embedded systems in critical domains (healthcare, industry, energy), where performance and reliability constraints are particularly stringent.</p>
   <p>Future Work: Future research will focus on automating attack responses via smart contracts, enabling continuous adaptation to dynamic environments, and validating the system on real-world data.</p>
  </sec><sec id="s8">
   <title>Acknowledgements</title>
   <p>The authors would like to thank the Laboratoire LASTIC (ESATIC) and the Université Virtuelle de Côte d’Ivoire (UVCI) for their institutional support during this research.</p>
   <p>Special thanks are extended to colleagues from the Edge-IoT Security Research Group for their valuable insights and constructive discussions throughout the experimental phase.</p>
   <p>This work received no specific grant from any funding agency in the public, commercial, or not-for-profit sectors.</p>
  </sec>
 </body><back>
  <ref-list>
   <title>References</title>
   <ref id="scirp.145568-ref1">
    <label>1</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Zhang, J., Chen, B., Zhao, Y., Cheng, X. and Hu, F. (2018) Data Security and Privacy-Preserving in Edge Computing Paradigm: Survey and Open Issues. IEEE Access, 6, 18209-18237. &gt;https://doi.org/10.1109/access.2018.2820162
    </mixed-citation>
   </ref>
   <ref id="scirp.145568-ref2">
    <label>2</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Roesch, M. (1999) Snort-Lightweight Intrusion Detection for Networks.
    </mixed-citation>
   </ref>
   <ref id="scirp.145568-ref3">
    <label>3</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Paxson, V. (1999) Bro: A System for Detecting Network Intruders in Real-Time. Computer Networks, 31, 2435-2463. &gt;https://doi.org/10.1016/s1389-1286(99)00112-7
    </mixed-citation>
   </ref>
   <ref id="scirp.145568-ref4">
    <label>4</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Alsaedi, A., Moustafa, N., Tari, Z., Mahmood, A. and Anwar, A. (2020) TON_IoT Telemetry Dataset: A New Generation Dataset of IoT and IIoT for Data-Driven Intrusion Detection Systems. IEEE Access, 8, 165130-165150. &gt;https://doi.org/10.1109/access.2020.3022862
    </mixed-citation>
   </ref>
   <ref id="scirp.145568-ref5">
    <label>5</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Saurabh, K., Sood, S., Kumar, P.A., Singh, U., Vyas, R., Vyas, O.P., et al. (2022) LBDMIDS: LSTM Based Deep Learning Model for Intrusion Detection Systems for IoT Networks. 2022 IEEE World AI IoT Congress (AIIoT), Seattle, 6-9 June 2022, 753-759. &gt;https://doi.org/10.1109/aiiot54504.2022.9817245
    </mixed-citation>
   </ref>
   <ref id="scirp.145568-ref6">
    <label>6</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Paira, S. and Bhattacharya, U. (2018) Efficient Dynamic Survivable Multicasting in WDM Mesh Networks. 2018 10th International Conference on Communication Systems &amp; Networks (COMSNETS), Bengaluru, 3-7 January 2018, 525‑527. &gt;https://doi.org/10.1109/comsnets.2018.8328262
    </mixed-citation>
   </ref>
   <ref id="scirp.145568-ref7">
    <label>7</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Raihan, A.S. and Ahmed, I. (2023) A Bi-LSTM Autoencoder Framework for Anomaly Detection—A Case Study of a Wind Power Dataset. 2023 IEEE 19th International Conference on Automation Science and Engineering (CASE), Auckland, 26-30 August 2023, 1-6. &gt;https://doi.org/10.1109/case56687.2023.10260331
    </mixed-citation>
   </ref>
   <ref id="scirp.145568-ref8">
    <label>8</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Varghese, B., Wang, N., Barbhuiya, S., Kilpatrick, P. and Nikolopoulos, D.S. (2016) Challenges and Opportunities in Edge Computing. 2016 IEEE International Conference on Smart Cloud (SmartCloud), New York, 18-20 November 2016, 20-26. &gt;https://doi.org/10.1109/smartcloud.2016.18
    </mixed-citation>
   </ref>
   <ref id="scirp.145568-ref9">
    <label>9</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Zhou, T., Ma, Z., Wen, Q., Wang, X., Sun, L. and Jin, R. (2022) FEDformer: Frequency Enhanced Decomposed Transformer for Long-Term Series Forecasting.
    </mixed-citation>
   </ref>
   <ref id="scirp.145568-ref10">
    <label>10</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Chen, X., Zhu, S., Chen, D., Hu, S., Li, C. and Zhu, Z. (2015) On Efficient Protection Design for Dynamic Multipath Provisioning in Elastic Optical Networks. 2015 International Conference on Optical Network Design and Modeling (ONDM), Pisa, 11-14 May 2015, 251‑256. &gt;https://doi.org/10.1109/ondm.2015.7127307
    </mixed-citation>
   </ref>
   <ref id="scirp.145568-ref11">
    <label>11</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Malhotra, P., Ramakrishnan, A., Anand, G., Vig, L., Agarwal, P. and Shroff, G. (2016) LSTM-Based Encoder-Decoder for Multi-Sensor Anomaly Detection.
    </mixed-citation>
   </ref>
   <ref id="scirp.145568-ref12">
    <label>12</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Rhachi, H., Balboul, Y. and Bouayad, A. (2025) Enhanced Anomaly Detection in IoT Networks Using Deep Autoencoders with Feature Selection Techniques. Sensors, 25, Article No. 3150. &gt;https://doi.org/10.3390/s25103150
    </mixed-citation>
   </ref>
   <ref id="scirp.145568-ref13">
    <label>13</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Kea, K., Han, Y. and Kim, T.-K. (2023) Enhancing Anomaly Detection in Distributed Power Systems Using Autoencoder-Based Federated Learning. PLOS ONE, 18, e0290337. &gt;https://doi.org/10.1371/journal.pone.0290337
    </mixed-citation>
   </ref>
  </ref-list>
 </back>
</article>