Lightweight Machine Learning Models for Real-Time Intrusion Detection at the Edge in IoT Networks

Authors

  • Sakunaveeti Vishnu Author
  • S. Ramesh Author

Keywords:

edge computing, IIoT security, internet of things, intrusion detection system, lightweight models, machine learning, TinyML

Abstract

The rapid proliferation of Internet of Things (IoT) devices across smart homes, industrial automation, and healthcare has significantly expanded the attack surface available to malicious actors, while the resource-constrained nature of these devices, in terms of processing power, memory, and energy, makes traditional cloud-dependent security solutions impractical for real-time threat detection. Edge computing has emerged as a promising paradigm to address this gap by enabling data processing and intrusion detection closer to the source, thereby reducing latency, bandwidth consumption, and dependency on continuous cloud connectivity. This paper examines the design and performance of lightweight machine learning (ML) models for real-time intrusion detection deployed at the network edge in IoT environments. The study reviews recent literature on Edge-IoT intrusion detection datasets, lightweight classifier architectures, and hybrid feature-learning approaches, with particular attention to the trade-offs between detection accuracy, inference latency, memory footprint, and energy consumption. The paper also discusses benchmark datasets developed specifically for edge and industrial IoT (IIoT) security research, and evaluates classifier choices such as Random Forest, XGBoost, and lightweight neural architectures against these constraints. Findings from the reviewed literature indicate that tree-based ensemble models offer a favourable balance between accuracy and computational efficiency for edge deployment, while deep learning-based approaches, though often more accurate, incur substantially higher energy and memory costs that limit their suitability for extreme edge devices such as microcontrollers. The paper concludes by identifying open research challenges, including the need for standardised edge-IoT benchmarking frameworks, federated learning approaches for privacy-preserving distributed detection, and model compression techniques to enable broader deployment of intelligent security on constrained IoT hardware.

Published

2026-09-02