DEEP REINFORCEMENT LEARNING BASED SEMI AUTONOMOUS CYBERATTACK DETECTION FOR INTERNET OF THINGS (IOT) SYSTEMS

No Thumbnail Available

Date

2026

Journal Title

Journal ISSN

Volume Title

Publisher

Saudi Digital Library

Abstract

Abstract The Internet of Things (IoT) has made today's networked world more complex and vulnerable, thus making it an appealing target for advanced cyberattacks. Limited adaptability, poor generalization and responsiveness to new and evolving attack behaviors are common problems with the traditional cybersecurity approaches that rely on static rules and supervised Machine Learning (ML). Furthermore, traditional IPSs are not equipped with the ability to adapt and learn over time in response to changing threats and vulnerabilities in the cyber landscape. To overcome the restrictions a novel Deep Reinforcement Learning (DRL) based cybersecurity framework is proposed for adaptive intrusion detection in heterogeneous enterprise-network and IoT based environment.The framework turns intrusion detection into a sequence of decisions, where a DRL agent keeps interacting with the environment and optimizes intrusion detection policies using rewards-driven learning. In order to test the diversity of the experiments and analyze the adaptive learning behavior, the framework was experimentally evaluated on two cybersecurity benchmark datasets: CICIDS2017 and TON_IoT.It was evaluated experimentally using CICIDS2017 and TON_IoT datasets, which are both widely used in the cybersecurity research community. Three DRL algorithms DDQN,PPO,DDPG were implemented and tested with various performance measures such as Accuracy, Precision, Recall, F1-Score, False positive rate (FPR) and ROC-AUC.Results of the experiments showed that the different evaluated DRL algorithms performed well in both cybersecurity test environments. However DDQN was found to be the best in terms of classification consistency, convergence stability and adaptive learning behavior in comparison to PPO and DDPG models and it was the most consistently and stably performing model. In particular, on the CICIDS2017 dataset, DDQN scored 97.3% on the Accuracy metric, 97.4% on the F1-Score metric, and 0.989 on the ROC-AUC metric, and on the TON_IoT dataset, the metrics were 95.6% for Accuracy, 95.6% for f1-score, and 0.978 for ROC-AUC. Moreover, DDQN achieved an FP rate of merely 2.1% and 3.4% in CICIDS2017 and TON_IoT respectively, suggesting a strong intrusion-classification capability under heterogeneous traffic conditions.The findings further showed that IoT environments bring in more complexity in cybersecurity with heterogeneous telemetry and dynamic communication patterns. Moreover, comparison showed that DRL-based method offers better adaptability, ongoing policy optimization, and better decision-support capability in dynamic cybersecurity scenarios.

Description

Keywords

Keywords: Deep Reinforcement Learning (DRL), Cybersecurity, Intrusion Detection System (IDS), Internet of Things (IoT), Double Deep Q-Network (DDQN), Adaptive Security, Machine Learning, Network Security, Real-Time Response.

Citation

Collections

Endorsement

Review

Supplemented By

Referenced By

Copyright owned by the Saudi Digital Library (SDL) © 2026