Adaptive Anomaly Detection in IoT Networks Using Artificial Immune System Principles
Keywords:
Artificial Immune System (AIS), Network Intrusion Detection System (NIDS), Clonal Selection Algorithm, Self-Nonself Discrimination, Negative Selection AlgorithmAbstract
Conventional Network Intrusion Detection Systems (NIDS) often struggle to detect evolving cyber threats, such as zero-day exploits and polymorphic malware, while maintaining acceptable false-positive rates. These challenges are exacerbated in Internet of Things (IoT) environments because of the dynamic and resource-constrained nature of connected devices. This study presents an open-source, modular anomaly detection framework based on Artificial Immune System (AIS) principles for adaptive intrusion detection in IoT networks. The proposed framework integrates the Negative Selection Algorithm (NSA) for detector generation and the Clonal Selection Algorithm (CSA) for detector refinement, with Principal Component Analysis (PCA) for dimensionality reduction and a Streamlit-based dashboard for real-time visualisation. The system was implemented in Python and evaluated using the Numenta Anomaly Benchmark (NAB), a time-series dataset representative of IoT telemetry. A stratified 80:10:10 split for training, validation, and testing, together with five-fold cross-validation, was employed for model evaluation and hyperparameter tuning. Performance was compared with a Random Forest baseline using standard classification metrics. The AIS framework achieved 90% accuracy, 88% precision, 88% recall, an F1-score of 0.88, a false-positive rate of 4% (96% specificity), and a ROC-AUC of 0.91, slightly outperforming the Random Forest model, which achieved 88% accuracy and a ROC-AUC of 0.89. Although the performance improvement was modest, the proposed approach demonstrated the adaptability and modularity of AIS-based detection for streaming IoT telemetry. The findings indicate that AIS provides a promising foundation for adaptive anomaly detection in IoT environments, while highlighting the need for validation using additional benchmark datasets and more rigorous statistical analyses to establish broader generalisability.
References
Abbas, N. N., Ahmed, T., Shah, S. H. U., Omar, M., & Park, H. W. (2019). Investigating the applications of artificial intelligence in cybersecurity. Scientometrics, 121(3), 1189–1211.
Abd Elaziz, M., Al-qaness, M. A., Dahou, A., Ibrahim, R. A., & Abd El-Latif, A. A. (2023). Intrusion detection approach for cloud and IoT environments using deep learning and capuchin search algorithm. Advances in Engineering Software, 176, 103402.
Ahmad, I., Khan, A., & Anwar, Z. (2024). Cloud-centric intrusion detection: Challenges, trends, and future research directions. Journal of Network and Computer Applications, 242, 103703.
Ali, S. A.-A. (2024). Anomaly detection in telecommunication networks: Leveraging novel big data and machine learning techniques for proactive fault management. Educational Administration: Theory and Practice, 30(5), 4500–4515. DOI: 10.53555
Alotaibi, B., & Elleithy, K. (2022). A hybrid deep learning approach for intrusion detection in IoT networks. IEEE Access, 10, 43325–43340.
Alsaleh, S., Menai, M. E. B., & Al-Ahmadi, S. (2025). A heterogeneity-aware semi-decentralized model for a lightweight intrusion detection system for IoT networks based on federated learning and BiLSTM. Sensors, 25(4), 1039.
Alshamrani, A., Myneni, S., Chowdhary, A., & Huang, D. (2022). A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities. IEEE Communications Surveys & Tutorials, 24(2), 963–987.
Arisdakessian, S., Wahab, O. A., Mourad, A., Otrok, H., & Guizani, M. (2023). A survey on IoT intrusion detection: Federated learning, game theory, social psychology, and explainable AI as future directions. IEEE Internet of Things Journal, 10(5), 4059–4092.
Bedi, P., Gupta, R., & Jindal, V. (2024). Deep learning-based hybrid intrusion detection for network traffic analysis. Expert Systems with Applications, 238, 121643.
Chen, L., & Wang, H. (2023). Graph immune networks for advanced persistent threat detection. Computers & Security, 124, 102976.
Dasgupta, D., & Niño, L. F. (2022). Immunological computation: Theory and applications (2nd ed.). CRC Press.
Ejaita, O. A., & Okoh, O. L. (2024). Systematic review of the security impact of artificial intelligence model on code generation.
Eren, E., Yildirim Okay, F., & Özdemir, S. (2024). Unveiling anomalies: A survey on XAI-based anomaly detection for IoT. Turkish Journal of Electrical Engineering and Computer Sciences, 32(3), 358–381.
Farrukh, Y. A., Wali, S., Khan, I., & Bastian, N. D. (2024). AIS-NIDS: An intelligent and self-sustaining network intrusion detection system. Computers & Security, 144, 103982.
Garcia-Teodoro, P., Díaz-Verdejo, J., Maciá-Fernández, G., & Vázquez, E. (2022). Anomaly-based network intrusion detection: Techniques and challenges. Computers & Security, 110, 102460.
Gheni, H. Q., & Al-Yaseen, W. L. (2024). Two-step data clustering for improved intrusion detection system using CICIoT2023 dataset. e-Prime—Advances in Electrical Engineering, Electronics and Energy, 9, 100673.
Guerroumi, M., & Derhab, A. (2020). NSNAD: Negative selection-based network anomaly detection approach with relevant feature subset. Neural Computing and Applications, 32(8), 3475–3501.
Gummadi, A. N., Napier, J. C., & Abdallah, M. (2024). XAI-IoT: An explainable AI framework for enhancing anomaly detection in IoT systems. IEEE Access, 12, 71024–71054. Hosseini, S., Seilani, H., & Heidary, M. (2025). Artificial immune systems for industrial intrusion detection: a systematic review and conceptual framework. Journal of Engineering, 2025(1), 8408209.
Huang, H., Li, T., Ding, Y., Li, B., & Liu, A. (2023). An artificial immunity based intrusion detection system for unknown cyberattacks. Applied Soft Computing, 148, 110875.
Jin, Z., Zhou, J., Li, B., Wu, X., & Duan, C. (2024). FL-IIDS: A novel federated learning-based incremental intrusion detection system. Future Generation Computer Systems, 151, 57–70. https://doi.org/10.1016/j.future.2023.09.019
Kalakoti, R., Bahsi, H., & Nõmm, S. (2024). Explainable federated learning for botnet detection in IoT networks. In 2024 IEEE International Conference on Cyber Security and Resilience (CSR) (pp. 1–8). IEEE.
Kaur, M., & Singh, D. (2022). A comprehensive review of anomaly detection techniques in network security. Journal of Information Security and Applications, 64, 103058.
Khacha, A., Aliouat, Z., Harbi, Y., Gherbi, C., Saadouni, R., & Harous, S. (2024). Landscape of learning techniques for intrusion detection system in IoT: A systematic literature review. Computers and Electrical Engineering, 120, 109725.
Khan, M. A., Islam, M. S., & Alam, M. (2022). IoT security: Issues, challenges, and future directions. Future Generation Computer Systems, 129, 44–63.
Khan, S., Khan, A., Halim, Z., & Waqas, M. (2023). NSL-KDD-2023: An evolved benchmark for immune-based intrusion detection systems. Cybersecurity, 6(1), 1–23. https://doi.org/10.1186/s42400-023-00157-4
Kim, Y. J., Nam, W., & Lee, J. (2022). Multiclass anomaly detection for unsupervised and semi-supervised data based on a combination of negative selection and clonal selection algorithms. Applied Soft Computing, 122, 108838.
Lavin, A., & Ahmad, S. (2015). Evaluating real-time anomaly detection algorithms—The Numenta Anomaly Benchmark. In 2015 IEEE 14th International Conference on Machine Learning and Applications (ICMLA) (pp. 38–44). IEEE.
Li, H., Zhang, X., & Chen, Y. (2023). A survey of signature-based intrusion detection systems and their challenges. Security and Communication Networks, 2023, 1–15.
Liu, X., et al. (2024b). A novel immune detector training method for network anomaly detection. Applied Intelligence, 54(2), 2009–2030.
Liu, Y., Xu, H., & Yu, W. (2024a). Towards resilient machine learning-based intrusion detection for cloud environments. Future Internet, 16(2), 55.
Marino, F., Leone, A., & Caricato, P. (2020). An intrusion detection and cyber-physical sensor for anomaly detection in IoT. Sensors, 20(14), Article 3925. DOI: 10.3390/s20143925
Okpako, E. A., Ikpegbu, E. O., & Chiemeke, S. C. (2023). Media and cyberbullying in political communication among Nigerians: Implications. In Digital Technologies and Applications: Proceedings of ICDTA'23, Fez, Morocco (Vol. 2, p. 669).
Om Kumar, C. U., Durairaj, J., Ahamed Ali, S. A., Justindhas, Y., & Marappan, S. (2022). Effective intrusion detection system for IoT using optimized capsule auto encoder model. Concurrency and Computation: Practice and Experience, 34(13), e6918.
Rahman, M. M., Al Shakil, S., & Mustakim, M. R. (2025). A survey on intrusion detection system in IoT networks. Cyber Security and Applications, 3.
Rahman, M., Hossain, M., & Hassan, M. (2023). Security vulnerabilities in IoT: A survey and taxonomy. Computer Networks, 229, 109725.
Scarfone, K., & Mell, P. (2021). Guide to intrusion detection and prevention systems (IDPS) (NIST Special Publication 800-94 Rev. 1). National Institute of Standards and Technology.
Sharafaldin, I., Lashkari, A. H., & Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. In Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP).
Sun, Y., Wang, X., & Liu, Q. (2023). A review of false positive reduction techniques in anomaly-based intrusion detection systems. Computers & Electrical Engineering, 107, 108644.
Thapa, C., Camtepe, S., & Foo, E. (2023). Unsupervised intrusion detection using deep generative models: A survey. IEEE Transactions on Network and Service Management, 20(1), 63–85.
Thein, T. T., Shiraishi, Y., & Morii, M. (2024). Personalized federated learning-based intrusion detection system: Poisoning attack and defense. Future Generation Computer Systems, 153, 182–192.
Ullah, I., & Mahmoud, Q. H. (2020). A scheme for generating a dataset for anomalous activity detection in IoT networks. In Advances in Artificial Intelligence: 33rd Canadian Conference on Artificial Intelligence (pp. 508–520).
Usama, M., Qadir, J., & Baig, A. (2023). Adversarial machine learning in network intrusion detection: A comprehensive survey. IEEE Access, 11, 23819–23845.
Wang, Y., Liang, X., Qiu, Q., & Li, H. (2023). Spiking neural immune models for edge security. Nature Communications Engineering, 2(1), 1–14.
Yin, C., Xu, H., & Sun, X. (2023). Random forest-based intrusion detection system for network security. International Journal of Information Security, 22(5), 903–917.
Zhang, W., Tan, Y., Jin, Y., & Yao, X. (2024). AutoAIS: Automated optimization of artificial immune systems. IEEE Transactions on Evolutionary Computation, 28(1), 112–126.