GCTAuto-encoder: A Cross modal Framework for Security Flaw Detection in IoT Networks
Organizations: Department of Computational Linguistics, University of Stuttgart, Stuttgart, Germany.
Abstract
IoT encompasses diverse physical entities, from smart home devices to autonomous vehicles, creating a complex environment with heterogeneous security models. This heterogeneity makes IoT sub-systems vulnerable to various network attacks. Modern security systems must therefore be more robust to ensure security and privacy for IoT applications. A highly secure IoT system also demands real time insight, requiring data collection at the edge of the computing layer. This diversity calls for a unified security model applied at the foundational level. Edge intelligence offers a direct approach to handling device diversity. A key goal of edge intelligence in IoT is to extract insight from local data; security models can then use this data to build local node protections, and integrating AI models yields an advanced security solution. This research proposes a novel deep learning algorithm for effective intrusion detection at the edge, supported by a cloud-based IoT framework. We evaluate the proposed cross modal deep learning algorithm against baseline models. The contribution is a cross domain Deep Neural Network (DNN) algorithm for intrusion detection. The objective is to assess a multi-method deep learning model to detect intrusions in IoT systems at the edge via community detection with modeled attention. We evaluate GCT auto-encoder, a novel framework integrating edge intelligence to identify security flaws. The model significantly improves performance and efficiency. On a network intrusion IoT dataset covering multiple attack scenarios, it achieved 0.908 accuracy, reduced learning loss to 0.00156, and outperformed existing approaches.
Figures & tables
| Model | Precision | Recall | F1-Score | Accuracy | AUC-ROC | Specificity | Sensitivity |
|---|---|---|---|---|---|---|---|
| GCN Autoencoder | 0.847 | 0.823 | 0.835 | 0.879 | 0.894 | 0.891 | 0.823 |
| Sparse Autoencoder | 0.812 | 0.789 | 0.800 | 0.851 | 0.863 | 0.867 | 0.789 |
| Deep Autoencoder | 0.876 | 0.854 | 0.865 | 0.904 | 0.921 | 0.921 | 0.854 |
| LSTM Autoencoder | 0.791 | 0.767 | 0.779 | 0.834 | 0.841 | 0.849 | 0.767 |
| Deep Belief AE Network | 0.859 | 0.836 | 0.847 | 0.892 | 0.909 | 0.909 | 0.836 |
| Adversarial AE | 0.894 | 0.869 | 0.881 | 0.918 | 0.938 | 0.938 | 0.869 |
| Model | Mean Error | Std Dev | Min | Max | 90th %ile | IQR |
|---|---|---|---|---|---|---|
| GCN Autoencoder | 0.001843 | 0.003521 | 0.000012 | 0.047291 | 0.004562 | 0.002145 |
| Sparse Autoencoder | 0.002156 | 0.004012 | 0.000018 | 0.052847 | 0.005124 | 0.002687 |
| Deep Autoencoder | 0.001567 | 0.003124 | 0.000008 | 0.041256 | 0.003987 | 0.001834 |
| LSTM Autoencoder | 0.002341 | 0.004567 | 0.000025 | 0.058912 | 0.005687 | 0.003124 |
| Deep Belief AE Network | 0.001892 | 0.003687 | 0.000014 | 0.045632 | 0.004789 | 0.002234 |
| Adversarial AE | 0.001634 | 0.003245 | 0.000011 | 0.043214 | 0.004123 | 0.001967 |
| Model | Total Nodes | Normal | Anomaly | Detection Rate | False Positives | False Negatives |
|---|---|---|---|---|---|---|
| GCN Autoencoder | 1547 | 1391 | 156 | 10.1% | 25 | 29 |
| Sparse Autoencoder | 1547 | 1421 | 126 | 8.1% | 32 | 38 |
| Deep Autoencoder | 1547 | 1373 | 174 | 11.3% | 18 | 21 |
| LSTM Autoencoder | 1547 | 1433 | 114 | 7.4% | 38 | 42 |
| Deep Belief AE Network | 1547 | 1384 | 163 | 10.5% | 21 | 26 |
| Adversarial AE | 1547 | 1363 | 184 | 11.9% | 12 | 15 |
| Model | Epochs | Conv. Speed | Train Time (s) | Inference (ms) | Memory (MB) | Parameters | Batch Size |
|---|---|---|---|---|---|---|---|
| GCN Autoencoder | 100 | Fast | 47.3 | 2.1 | 156 | 12,547 | 32 |
| Sparse Autoencoder | 50 | Very Fast | 23.8 | 1.8 | 89 | 8,234 | 16 |
| Deep Autoencoder | 100 | Fast | 51.2 | 2.3 | 178 | 18,456 | 16 |
| LSTM Autoencoder | 30 | Slow | 78.4 | 5.6 | 267 | 34,128 | 16 |
| Deep Belief AE Network | 100 | Medium | 62.5 | 3.2 | 201 | 21,345 | 16 |
| Adversarial AE | 150 | Medium | 89.7 | 3.8 | 234 | 25,678 | 16 |
| Model | Train Loss | Val Loss | Test Loss | Generalization Gap | Overfitting Score | Stability |
|---|---|---|---|---|---|---|
| GCN Autoencoder | 0.00291 | 0.00387 | 0.00421 | 0.00130 | Low | High |
| Sparse Autoencoder | 0.00412 | 0.00568 | 0.00634 | 0.00222 | Medium | Medium |
| Deep Autoencoder | 0.00198 | 0.00267 | 0.00312 | 0.00114 | Low | High |
| LSTM Autoencoder | 0.00534 | 0.00821 | 0.00934 | 0.00400 | High | Low |
| Deep Belief AE Network | 0.00267 | 0.00356 | 0.00389 | 0.00122 | Low | High |
| Adversarial AE | 0.00187 | 0.00245 | 0.00278 | 0.00091 | Very Low | Very High |
| Rank | Model | F1-Score | AUC-ROC | Speed | Robustness | Overall Score |
|---|---|---|---|---|---|---|
| 1 | GCT Autoencoder | 0.908 | 0.956 | 7/10 | 9/10 | 8.43 / 10 |
| 2 | Adversarial AE | 0.881 | 0.938 | 6/10 | 9/10 | 8.08 / 10 |
| 3 | Deep Autoencoder | 0.865 | 0.921 | 8/10 | 8/10 | 7.98 / 10 |
| 4 | Contractive AE | 0.863 | 0.928 | 8/10 | 8/10 | 7.97 / 10 |
| 5 | Deep Belief AE Network | 0.847 | 0.909 | 7/10 | 8/10 | 7.65 / 10 |
| 6 | GCN Autoencoder | 0.835 | 0.894 | 8/10 | 8/10 | 7.57 / 10 |
| Model | DoS Attacks | Port Scanning | Data Exfiltration | Unusual Flows | Protocol Abuse | Avg Detection |
|---|---|---|---|---|---|---|
| GAT Autoencoder | 96.2% | 94.1% | 91.3% | 87.4% | 89.2% | 91.6% |
| Adversarial AE | 94.5% | 92.3% | 89.7% | 85.2% | 87.8% | 89.9% |
| Deep Autoencoder | 92.8% | 90.7% | 87.4% | 83.1% | 85.9% | 88.0% |
| Contractive AE | 92.1% | 89.4% | 86.2% | 82.5% | 84.7% | 87.0% |
| Deep Belief AE Network | 91.3% | 88.9% | 84.8% | 81.2% | 83.6% | 86.0% |
| GCN Autoencoder | 90.1% | 87.6% | 83.5% | 79.8% | 82.1% | 84.6% |
| Requirement | Best Choice | Runner-up | Score Diff | Trade-off |
|---|---|---|---|---|
| Highest Accuracy | GCT Autoencoder | Adversarial AE | +0.35% | Slightly slower |
| Fastest Inference | Sparse AE | GCN AE | -2.1% acc | 10ms faster |
| Best Robustness | GCT Autoencoder | Adversarial AE | +0.09% | More compute |
| Lowest FP Rate | GCT Autoencoder | Adversarial AE | -4 FP | Better precision |
| Lowest FN Rate | GCT Autoencoder | Adversarial AE | -6 FN | Better recall |
| Least Overfitting | Adversarial AE | GCT AE | +0.008 gap | -0.02 F1 |