The Internet of Things (IoT) technologies have been rapidly adopted in the field of Cyber-Physical Systems (CPS) and have greatly enhanced the automation, connectivity and operational efficiency of industrial and critical infrastructure (ICI) environments. The advent of greater device connectivity, however, has also grown the attack surface, leaving CPS environments open to many different cyber threats. The traditional methods of intrusion detection are not effective in detecting more complex and advanced attacks because the features are manually designed and cannot be easily adapted. In this publication, a Deep Learning (DL)framework for security monitoring is presented in this study, which uses CNN to improve the intrusion detection capability of the cyber-attack system in the IoT-enabled CPS environment. The intended framework accepts the network traffic data out of the UNSW-NB15 dataset to learn complicated cyber security threats and identify attacks from normal data traffic. We compared the proposed CNN model against a conventional Support Vector Machine (SVM) classifier. The experimental results demonstrate that the CNN model surpasses the others across key metrics, including precision, accuracy, F1 score and recall. The proposed approach has proved to be efficient in capturing hidden traffic characteristics and improves the reliability of cyber threat detection framework in dynamic IoT-based CPS systems. The evaluation results confirm that deep learning methods can be a scalable and efficient way to enhance the cybersecurity of next-generation cyber-physical infrastructures.
Introduction
This study proposes a Convolutional Neural Network (CNN)-based Intrusion Detection System (IDS) to improve cybersecurity in Internet of Things (IoT)-enabled Cyber-Physical Systems (CPS). As CPS applications expand into critical sectors such as healthcare, manufacturing, transportation, and smart grids, they become increasingly vulnerable to cyber-attacks, including denial-of-service, malware, reconnaissance, and network intrusion attacks. Traditional IDS techniques based on signatures and machine learning (e.g., SVM, Decision Trees, and Random Forests) are effective against known attacks but struggle with complex, high-dimensional data and require manual feature engineering.
The literature review highlights the growing importance of deep learning for intrusion detection. Previous studies show that CNNs can automatically learn hierarchical features from network traffic, making them more effective than traditional machine learning methods for detecting sophisticated cyber-attacks. The UNSW-NB15 dataset is widely recognized as a reliable benchmark for evaluating intrusion detection systems.
The proposed framework uses the UNSW-NB15 dataset containing both normal and malicious network traffic. Data preprocessing includes removing missing values and duplicates, encoding categorical features, normalizing data, and splitting it into training and testing sets. The CNN architecture automatically extracts traffic patterns through convolutional and pooling layers before classifying traffic as normal or malicious. The model's performance is compared with a Support Vector Machine (SVM) using accuracy, precision, recall, and F1-score.
The methodology consists of five stages: data collection, preprocessing, feature extraction, CNN model training, and attack classification. The detection workflow begins with data preparation, followed by feature learning, traffic classification, and performance evaluation.
Conclusion
Since the Internet of Things (IoT) is gaining popularity in the field of Cyber Physical System (CPS), there is a need to take into consideration the degree of connectivity and the type of cyber-attack. In this paper, an intrusion detection system using deep learning, with Convolutional Neural Network (CNN) method, has been proposed to detect the cyber-attack in the CPS environment using the IoT device. The proposed scheme has been designed to address the limitations of the conventional machine learning schemes.
The proposed CNN model was evaluated on the basis of UNSW-NB15 data set and its performance was compared with that of a typical Support Vector Machine (SVM) classification algorithm. For the verification of CNN model, it was tested against experimental data, and it was found that the proposed CNN model outperformed in terms of all evaluation metrics. The accuracy rate of the proposed CNN model was 99.52%, whereas the precision, recall and F1-score were 99.35%, 99.39% and 99.37% respectively which is far superior as compared to SVM model. The results demonstrate the learning of complex network traffic patterns and correct classification of normal and malicious network activities using the CNN architecture.
From the findings obtained from this study, it can be concluded that deep learning algorithms can be used effectively as a feasible and scalable solution for the intrusion detection problem in CPS.
The ability of the CNNs to perform automatic feature extraction minimizes the requirement of manually extracting the features and increases the ability to detect complicated cyber-attacks. Thus, the suggested framework will improve the security of the IoT-based CPS.
The presented framework may be employed for real-time intrusion detection in large IoT systems in the future as an extension to it. Future possible enhancements in the intrusion detection performance can be obtained through use of state-of-the-art deep learning architecture including LSTM, GRU, and the combination of CNN with LSTM models. In addition, application of the framework alongside edge computing techniques and federated learning will allow increasing its scalability, privacy preservation capability, and resistance to future cyber threats. Moreover, the proposed solution may be applied in future research using recently developed intrusion datasets that include more than one class of attack.
References
[1] M. Conti, A. Dehghantanha, K. Franke, and S. Watson, “Internet of Things security and forensics: Challenges and opportunities,” Future Generation Computer Systems, vol. 78, pp. 544–546, 2018.
[2] D. Evans, “The Internet of Things: How the next evolution of the Internet is changing everything,” Cisco Internet Business Solutions Group, pp. 1–11, 2011.
[3] A. A. Cárdenas, S. Amin, and S. Sastry, “Research challenges for the security of cyber physical systems,” in Proc. 3rd USENIX Workshop on Hot Topics in Security, 2008, pp. 1–6.
[4] E. Hodo, X. Bellekens, A. Hamilton, P. Dubouilh, and E. Iorkyase, “Threat analysis of IoT networks using artificial neural network intrusion detection system,” in Proc. IEEE Int. Symposium on Networks, Computers and Communications, 2016, pp. 1–6.
[5] N. Moustafa and J. Slay, “UNSW-NB15: A comprehensive data set for network intrusion detection systems,” in Proc. Military Communications and Information Systems Conference, 2015, pp. 1–6.
[6] N. Moustafa and J. Slay, “The evaluation of network anomaly detection systems: Statistical analysis of the UNSW-NB15 dataset,” Information Security Journal, vol. 25, no. 1–3, pp. 18–31, 2016.
[7] I. Sharafaldin, A. Habibi Lashkari, and A. A. Ghorbani, “Toward generating a new intrusion detection dataset and intrusion traffic characterization,” in Proc. ICISSP, 2018, pp. 108–116.
[8] W. Wang, M. Zhu, X. Zeng, X. Ye, and Y. Sheng, “Malware traffic classification using convolutional neural network for representation learning,” in Proc. International Conference on Information Networking,2017, pp. 712–717.
[9] Y. LeCun, Y. Bengio, and G. Hinton, “Deep learning,” Nature, vol. 521, no. 7553, pp. 436–444, 2015.
[10] A. Krizhevsky, I. Sutskever, and G. E. Hinton, “ImageNet classification with deep convolutional neural networks,” Communications of the ACM, vol. 60, no. 6, pp. 84–90, 2017.
[11] M. Tavallaee, E. Bagheri, W. Lu, and A. Ghorbani, “A detailed analysis of the KDD CUP 99 dataset,” in Proc. IEEE Symposium on Computational Intelligence for Security and Defense Applications, 2009, pp. 1–6.
[12] G. Apruzzese, M. Colajanni, L. Ferretti, A. Guido, and M. Marchetti, “On the effectiveness of machine and deep learning for cyber security,” in Proc. IEEE International Conference on Cyber Conflict, 2018, pp. 371–390.
[13] J. Kim, J. Kim, H. L. T. Thu, and H. Kim, “Long short term memory recurrent neural network classifier for intrusion detection,” in Proc. International Conference on Platform Technology and Service, 2016, pp. 1–5.
[14] S. Potluri and C. Diedrich, “Accelerated deep neural networks for enhanced intrusion detection system,” IEEE Access, vol. 8, pp. 21928–21938, 2020.
[15] M. Al-Hawawreh, N. Moustafa, and E. Sitnikova, “Identification of malicious activities in industrial internet of things using deep learning models,” Journal of Information Security and Applications, vol. 47, pp. 241–254, 2019.
[16] H. Hindy, D. Brosset, E. Bayne, A. Seeam, C. Tachtatzis, R. Atkinson, and X. Bellekens, “A taxonomy and survey of intrusion detection system design techniques, network threats and datasets,” ACM Computing Surveys, vol. 54, no. 5, pp. 1–36, 2021.
[17] K. Shaukat, S. Luo, V. Varadharajan, I. A. Hameed, and M. Xu, “Performance comparison and current challenges of using machine learning techniques in cyber security,” Energies, vol. 13, no. 10, pp. 2509–2525, 2020.
[18] A. Javaid, Q. Niyaz, W. Sun, and M. Alam, “A deep learning approach for network intrusion detection system,” in Proc. EAI International Conference on Bio-inspired Information and Communications Technologies, 2016, pp. 21–26.
[19] M. Roopak, G. Y. Tian, and J. Chambers, “Deep learning models for cyber security in IoT networks,” in Proc. IEEE International Instrumentation and Measurement Technology Conference, 2019, pp. 1–6.
[20] S. Otoum, B. Kantarci, and H. Mouftah, “On the feasibility of deep learning in sensor network intrusion detection,” IEEE Networking Letters, vol. 1, no. 2, pp. 68–71, 2019.