Home / Journals / CMES / Online First / doi:10.32604/cmes.2026.085678
Special Issues
Table of Content

Open Access

ARTICLE

A Family-Aware Hierarchical XGBoost Framework for Efficient IoT Intrusion Detection

Motab F. Alenezi1, Fahad M. Alotaibi1, Badraddin Alturki2, Ahmad J. Tayeb2, Abdulaziz A. Alsulami1,*, Abdullah Alhejaili1
1 Department of Information Systems, Faculty of Computing and Information Technology, King Abdulaziz University, Jeddah, Saudi Arabia
2 Department of Information Technology, Faculty of Computing and Information Technology, King Abdulaziz University, Jeddah, Saudi Arabia
* Corresponding Author: Abdulaziz A. Alsulami. Email: email
(This article belongs to the Special Issue: Emerging Technologies in Information Security: Modeling, Algorithms, and Applications)

Computer Modeling in Engineering & Sciences https://doi.org/10.32604/cmes.2026.085678

Received 06 June 2026; Accepted 13 August 2026; Published online 26 August 2026

Abstract

Machine learning-based intrusion detection for Internet of Things (IoT) networks remains difficult because modern traffic is highly imbalanced and attack behaviors are heterogeneous. Evaluation pipelines can also overestimate performance when preprocessing is performed before train-test separation. We propose a family-aware hierarchical intrusion detection framework for attack-family prediction. The proposed approach first separates normal and attack traffic, then routes attack samples into empirically defined majority and minority attack-family branches, and finally performs branch-specific family classification. Within each cross-validation fold, training-label counts define the majority/minority routing branches, while scaling, weighting, model fitting, stage diagnostics, and metric computation remain fold-local. The final implementation uses XGBoost as the base learner in the hierarchical stages and compares it with flat LightGBM, XGBoost, Random Forest, Extra Trees, and stacking baselines under matched folds and metrics. On the CICIoT2023 30% stratified development split, the proposed approach achieved a Macro-F1 of 0.8380 and Weighted-F1 of 0.9940, performing close to the best flat Random Forest baseline while improving weak rare-family F1 scores for BruteForce and Web. On Edge-IIoTset, where the full processed dataset is used, the proposed approach achieved a Macro-F1 of 0.9456 and Weighted-F1 of 0.9494, outperforming all individual flat baselines and approaching the flat stacking ensemble. The hierarchy had lower inference time than the evaluated flat baselines under the workstation protocol.

Keywords

Intrusion detection; IoT security; attack-family classification; hierarchical learning; XGBoost; class imbalance; runtime evaluation; leakage-controlled evaluation
  • 126

    View

  • 30

    Download

  • 0

    Like

Share Link