Hybrid XGBoost-CNN Model for Anomaly Detection: A New Approach for IoT Wireless Sensor Networks
Article Information
Abstract
The Internet of Things (IoT) continues to expand rapidly, resulting in increasingly heterogeneous and complex wireless sensor networks (WSNs). Traditional anomaly detection approaches cannot cope with dynamic traffic patterns, high data volumes, and strict resource constraints. This study presents a hybrid XGBoost-CNN model that integrates XGBoost-based feature selection with a lightweight Convolutional Neural Network optimized for IoT environments. The proposed model was evaluated using real-world IoT traffic data and benchmarked against XGBoost, KNN, and SVM. Experimental results show that the hybrid approach improves detection accuracy by up to 2.29%, increases throughput by 8-48%, and reduces computational cost by 3%-8% compared with the baseline models. The model also demonstrated higher energy efficiency under varying attack scenarios. These results indicate that combining the feature selection capabilities of XGBoost with the pattern extraction strength of CNN yields a scalable, accurate, and resource-efficient anomaly detection solution suitable for IoT-WSN devices.
Graphical Abstract
Keywords
Data Availability Statement
Funding
Conflicts of Interest
AI Use Statement
Ethical Approval and Consent to Participate
References
- Irshad, A., Mallah, G. A., Bilal, M., Chaudhry, S. A., Shafiq, M., & Song, H. (2023). SUSIC: A secure user access control mechanism for SDN-enabled IIoT and cyber–physical systems. IEEE Internet of Things Journal, 10(18), 16504-16515.
[CrossRef] [Google Scholar] - Sajid, M., Malik, K. R., Almogren, A., Malik, T. S., Khan, A. H., Tanveer, J., & Rehman, A. U. (2024). Enhancing intrusion detection: a hybrid machine and deep learning approach. Journal of Cloud Computing, 13(1), 123.
[CrossRef] [Google Scholar] - Pramila, R. S., & VA, T. P. S. (2024). Defense Mechanisms for Vehicular Networks: Deep Learning Approaches for Detecting DDoS Attacks. International Journal of Advanced Computer Science & Applications, 15(7).
[CrossRef] [Google Scholar] - Abdullahi, M., Baashar, Y., Alhussian, H., Alwadain, A., Aziz, N., Capretz, L. F., & Abdulkadir, S. J. (2022). Detecting cybersecurity attacks in internet of things using artificial intelligence methods: A systematic literature review. Electronics, 11(2), 198.
[CrossRef] [Google Scholar] - Akif, M. A., Butun, I., & Mahgoub, I. (2024, October). Harnessing machine learning for enhanced internet of things (iot) security and attack detection. In 2024 International Symposium on Networks, Computers and Communications (ISNCC) (pp. 1-6). IEEE.
[CrossRef] [Google Scholar] - Sivaprasad Yerneni, K., Ravi Teja, A., Sri Harsha, K., & Naresh Kiran Kumar Reddy, Y. (2025). Towards Proactive Cloud Security: A Survey on ML and Deep Learning-Based Intrusion Detection Systems. J Contemp Edu Theo Artific Intel: JCETAI-116.
[CrossRef] [Google Scholar] - Manivannan, D. (2024). Recent endeavors in machine learning-powered intrusion detection systems for the internet of things. Journal of Network and Computer Applications, 229, 103925.
[CrossRef] [Google Scholar] - Adamova, A., Zhukabayeva, T., & Adamov, N. (2024). Machine Learning Algorithms for Intrusion Detection in IoT-enabled Smart Homes. Procedia Computer Science, 241, 427-432.
[CrossRef] [Google Scholar] - Khanday, S. A., Fatima, H., & Rakesh, N. (2023). Implementation of intrusion detection model for DDoS attacks in Lightweight IoT Networks. Expert Systems with Applications, 215, 119330.
[CrossRef] [Google Scholar] - Ullah, I., & Mahmoud, Q. H. (2021). Design and development of a deep learning-based model for anomaly detection in IoT networks. IEEE Access, 9, 103906-103926.
[CrossRef] [Google Scholar] - Shafiq, M., Tian, Z., Sun, Y., Du, X., & Guizani, M. (2020). Selection of effective machine learning algorithm and Bot-IoT attacks traffic identification for internet of things in smart city. Future Generation Computer Systems, 107, 433-442.
[CrossRef] [Google Scholar] - Al-Garadi, M. A., Mohamed, A., Al-Ali, A. K., Du, X., Ali, I., & Guizani, M. (2020). A survey of machine and deep learning methods for internet of things (IoT) security. IEEE Communications Surveys & tutorials, 22(3), 1646-1685.
[CrossRef] [Google Scholar] - Hasan, M., Islam, M. M., Zarif, M. I. I., & Hashem, M. M. A. (2019). Attack and anomaly detection in IoT sensors in IoT sites using machine learning approaches. Internet of Things, 7, 100059.
[CrossRef] [Google Scholar] - Moustafa, N., & Slay, J. (2015, November). UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In 2015 military communications and information systems conference (MilCIS) (pp. 1-6). IEEE.
[CrossRef] [Google Scholar] - Li, R., Li, Q., Zhou, J., & Jiang, Y. (2021). ADRIoT: An edge-assisted anomaly detection framework against IoT-based network attacks. IEEE Internet of Things Journal, 9(13), 10576-10587.
[CrossRef] [Google Scholar] - Nguyen, X. H., & Le, K. H. (2023). Robust detection of unknown DoS/DDoS attacks in IoT networks using a hybrid learning model. Internet of Things, 23, 100851.
[CrossRef] [Google Scholar] - Almaiah, M. A., Almomani, O., Alsaaidah, A., Al-Otaibi, S., Bani-Hani, N., Hwaitat, A. K. A., ... & Aldhyani, T. H. (2022). Performance investigation of principal component analysis for intrusion detection system using different support vector machine kernels. Electronics, 11(21), 3571.
[CrossRef] [Google Scholar] - Talukder, M. A., Khalid, M., & Sultana, N. (2025). A hybrid machine learning model for intrusion detection in wireless sensor networks leveraging data balancing and dimensionality reduction. Scientific reports, 15(1), 4617.
[CrossRef] [Google Scholar] - Ullah, I., & Mahmoud, Q. H. (2021). A framework for anomaly detection in IoT networks using conditional generative adversarial networks. IEEE Access, 9, 165907-165931.
[CrossRef] [Google Scholar] - Rosero-Montalvo, P. D., István, Z., Tözün, P., & Hernandez, W. (2023). Hybrid anomaly detection model on trusted IoT devices. IEEE Internet of Things Journal, 10(12), 10959–10969.
[CrossRef] [Google Scholar] - Halbouni, A., Gunawan, T. S., Habaebi, M. H., Halbouni, M., Kartiwi, M., & Ahmad, R. (2022). CNN-LSTM: hybrid deep neural network for network intrusion detection system. IEEE Access, 10, 99837-99849.
[CrossRef] [Google Scholar] - Behiry, M. H., & Aly, M. (2024). Cyberattack detection in wireless sensor networks using a hybrid feature reduction technique with AI and machine learning methods. Journal of Big Data, 11(1), 16.
[CrossRef] [Google Scholar] - Otoum, Y., Liu, D., & Nayak, A. (2022). DL‐IDS: a deep learning–based intrusion detection framework for securing IoT. Transactions on Emerging Telecommunications Technologies, 33(3), e3803.
[CrossRef] [Google Scholar] - Nayak, J., Naik, B., Dash, P. B., Vimal, S., & Kadry, S. (2022). Hybrid Bayesian optimization hypertuned catboost approach for malicious access and anomaly detection in IoT nomalyframework. Sustainable Computing: Informatics and Systems, 36, 100805.
[CrossRef] [Google Scholar] - Khraisat, A., Gondal, I., Vamplew, P., & Kamruzzaman, J. (2019). Survey of intrusion detection systems: techniques, datasets and challenges. Cybersecurity, 2(1), 1-22.
[CrossRef] [Google Scholar] - Chen, T., & Guestrin, C. (2016, August). Xgboost: A scalable tree boosting system. In Proceedings of the 22nd acm sigkdd international conference on knowledge discovery and data mining (pp. 785-794).
[CrossRef] [Google Scholar] - Kasongo, S. M., & Sun, Y. (2020). A deep learning method with wrapper based feature extraction for wireless intrusion detection system. Computers & Security, 92, 101752.
[CrossRef] [Google Scholar]
Cited By (2)
-
Inam Ullah, Zeeshan Ali Haider, Xin Su, Chang Choi, Ali Arishi, Hazrat Bilal. Vehicular communications for autonomous and intelligent transportation systems: a comprehensive survey.
Digital Communications and Networks, 2026 .
[CrossRef] -
Jiazhou Sun, Peng Zhang. MSCA-Deeplabv3+: A fine-grained optical image segmentation model based on multi-scale channel attention.
Alexandria Engineering Journal, 2026 , 145 .
[CrossRef]
Cite This Article
TY - JOUR AU - Dashdondov, Khongorzul AU - Chamazkoti, Mahjoobe Nazari AU - Abdusalomov, Akmalbek AU - Ullah, Habib AU - Khan, Muhammad Zubair AU - Ali, Bakht Sher PY - 2026 DA - 2026/01/12 TI - Hybrid XGBoost-CNN Model for Anomaly Detection: A New Approach for IoT Wireless Sensor Networks JO - ICCK Transactions on Advanced Computing and Systems T2 - ICCK Transactions on Advanced Computing and Systems JF - ICCK Transactions on Advanced Computing and Systems VL - 2 IS - 1 SP - 42 EP - 52 DO - 10.62762/TACS.2025.354651 UR - https://www.icck.org/article/abs/TACS.2025.354651 KW - IoT wireless sensor networks KW - anomaly detection KW - XGBoost KW - convolutional neural networks KW - feature selection KW - hybrid model KW - real-time detection AB - The Internet of Things (IoT) continues to expand rapidly, resulting in increasingly heterogeneous and complex wireless sensor networks (WSNs). Traditional anomaly detection approaches cannot cope with dynamic traffic patterns, high data volumes, and strict resource constraints. This study presents a hybrid XGBoost-CNN model that integrates XGBoost-based feature selection with a lightweight Convolutional Neural Network optimized for IoT environments. The proposed model was evaluated using real-world IoT traffic data and benchmarked against XGBoost, KNN, and SVM. Experimental results show that the hybrid approach improves detection accuracy by up to 2.29%, increases throughput by 8-48%, and reduces computational cost by 3%-8% compared with the baseline models. The model also demonstrated higher energy efficiency under varying attack scenarios. These results indicate that combining the feature selection capabilities of XGBoost with the pattern extraction strength of CNN yields a scalable, accurate, and resource-efficient anomaly detection solution suitable for IoT-WSN devices. SN - 3068-7969 PB - Institute of Central Computation and Knowledge LA - English ER -
@article{Dashdondov2026Hybrid,
author = {Khongorzul Dashdondov and Mahjoobe Nazari Chamazkoti and Akmalbek Abdusalomov and Habib Ullah and Muhammad Zubair Khan and Bakht Sher Ali},
title = {Hybrid XGBoost-CNN Model for Anomaly Detection: A New Approach for IoT Wireless Sensor Networks},
journal = {ICCK Transactions on Advanced Computing and Systems},
year = {2026},
volume = {2},
number = {1},
pages = {42-52},
doi = {10.62762/TACS.2025.354651},
url = {https://www.icck.org/article/abs/TACS.2025.354651},
abstract = {The Internet of Things (IoT) continues to expand rapidly, resulting in increasingly heterogeneous and complex wireless sensor networks (WSNs). Traditional anomaly detection approaches cannot cope with dynamic traffic patterns, high data volumes, and strict resource constraints. This study presents a hybrid XGBoost-CNN model that integrates XGBoost-based feature selection with a lightweight Convolutional Neural Network optimized for IoT environments. The proposed model was evaluated using real-world IoT traffic data and benchmarked against XGBoost, KNN, and SVM. Experimental results show that the hybrid approach improves detection accuracy by up to 2.29\%, increases throughput by 8-48\%, and reduces computational cost by 3\%-8\% compared with the baseline models. The model also demonstrated higher energy efficiency under varying attack scenarios. These results indicate that combining the feature selection capabilities of XGBoost with the pattern extraction strength of CNN yields a scalable, accurate, and resource-efficient anomaly detection solution suitable for IoT-WSN devices.},
keywords = {IoT wireless sensor networks, anomaly detection, XGBoost, convolutional neural networks, feature selection, hybrid model, real-time detection},
issn = {3068-7969},
publisher = {Institute of Central Computation and Knowledge}
}
Article Metrics
Publisher's Note
ICCK stays neutral with regard to jurisdictional claims in published maps and institutional affiliations.
Rights and Permissions
Copyright © 2026 by the Author(s). Published by Institute of Central Computation and Knowledge. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/), which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made.
Portico