inner-banner-bg

Advances in Neurology and Neuroscience(AN)

ISSN: 2690-909X | DOI: 10.33140/AN

Impact Factor: 1.12

A Lightweight, Label-Free Deep Autoencoder for Real-Time Anomaly Detection in Resource-Constrained IoT Network Traffic

Abstract

Samuel Yao Sebuabe, Stephen Kofi Dotse, Harriet K. O. Lamptey, Ezekiel Okoe Annan, Martin Doe, Rebecca Amponsah, Ezra Tablaje Baabotin and Kwame Assa-Agyei

The proliferation of Internet of Things (IoT) devices has dramatically widened the cyber-attack surface of modern networks, while the limited computational resources and protocol heterogeneity of these devices render conventional signature-based and supervised intrusion detection systems impractical at scale. This paper presents a lightweight, label-free anomaly-detection framework built on a deep autoencoder and optimised explicitly for deployment at the IoT edge. The model is trained exclusively on benign network-flow records, so anomalies are identified through reconstruction error rather than through labelled attack signatures, removing the dependence on curated attack labels that constrain supervised detectors. Principal Component Analysis is embedded in the pipeline to compress the feature space and shrink the model footprint, and the anomaly decision boundary is derived analytically from the 95th percentile of the benign reconstruction-error distribution rather than tuned by trial and error. The framework is evaluated across two complementary public benchmarks, IoT-23 and ToN_IoT, and is benchmarked against Random Forest and Support Vector Machine classifiers. The autoencoder attains 98.3% and 97.1% precision with false-positive rates of 4.8% and 5.1% on the two datasets, respectively, together with ROC-AUC values above 0.90, while occupying only 0.06 MB and sustaining an inference latency of 0.156 ms per flow, a footprint roughly 46 times smaller than the Random Forest baseline. Although supervised models achieve higher recall when labelled data are available, the proposed approach detects previously unseen and zero-day patterns without retraining and with a negligible memory budget, making it a practical building block for real-time, on-device intrusion detection in constrained IoT environments. The study also characterises the recall-false-alarm trade-off governed by the threshold, providing actionable guidance for operators who must balance detection sensitivity against alert fatigue.

PDF