article · Baghdad Science Journal
Internet of Things devices often lack inherent security because of computational resource constraints, leaving them vulnerable to zero-day attacks. While anomaly detection systems can help safeguard these networks, they typically generate high rates of false positives and produce outputs that are difficult for operators to interpret. To address this, a machine learning framework integrates large language models to identify threats and bridge this interpretation gap. The architecture employs isolation forests to detect network anomalies and random forests to assess device integrity. Findings are subsequently processed through the GPT-4o mini language model to generate statistical traffic summaries, risk scores, and plain-language explanations. This design simplifies security decision-making and lessens the need for specialised network administrators, allowing non-technical users to interpret and respond to security alerts effectively.
Connected devices are increasingly common but frequently lack built-in security, making networks vulnerable to intrusions. When security systems rely on complex technical alerts, non-specialist managers struggle to respond quickly. Translating raw technical telemetry into understandable summaries and clear risk ratings makes it easier for regular users to secure their smart devices without needing deep technical expertise or costly security teams.
The framework could enable user-friendly intrusion detection software for organisations or non-technical managers operating Internet of Things networks. By translating technical anomaly data into plain language, it reduces reliance on dedicated security staff. Based on the abstract, the system is described as an integrated framework combining specific algorithms and models, representing an early-stage research architecture that has not yet demonstrated commercial deployment.
AI-generated from the published abstract. Always read the original work before citing.
Internet of Things (IoT) devices are vulnerable to zero-day attacks because most of them have weak or no inherent security due to the resource constraints of the devices. This weakness underscores the growing need for anomaly-based intrusion detection systems tailored to IoT networks. Nevertheless, general anomaly detection traditionally has a high number of false positives that drain analysts' time. Also, a semantic difference exists between the system's results and the operators' interpretations. We introduce a machine learning-based framework to tackle these issues in traditional systems in this paper by combining large language models (LLMs). Our model is effective in identifying possible threats as well as filling the semantic gap. The framework uses isolation forests to detect anomalies and random forests to measure device integrity. To further improve the assessment of anomalies and increase interpretability, system insights are further refined using GPT-4o mini, an LLM. The model gives statistical summaries of the IoT traffic, a risk score, and an explanation in easy language, which is easy to understand and therefore makes the process of decision-making easier. Such a novel system reduces the reliance on dedicated network operators and allows non-technical users to better understand and act on the results of the system.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.21123/2411-7986.5392
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.