MARATTO

conference paper

UG-NET: An Integration of U-Net and GRU for IoT Intrusion Detection

In plain language

The rapid growth of the Internet of Things has created highly distributed, heterogeneous networks connecting diverse devices, operating systems, and communication protocols. Standard intrusion detection systems are not tailored for these environments, leaving such platforms vulnerable to modern cyber attacks. To address these vulnerabilities, a hybrid intrusion detection system named UG-Net has been designed specifically for IoT networks. The architecture pairs a one-dimensional U-Net network to extract hierarchical features with a Gated Recurrent Unit layer to capture sequential dependencies in network data. Evaluated on the benchmark CIC-IDS2017 and Bot-IoT datasets, the system demonstrates high performance across accuracy, precision, recall, and F1-score metrics compared to existing approaches, significantly improving both the detection rate and the identification of varied attack types.

Key takeaways

  • Conventional intrusion detection systems are ill-suited for the heterogeneity and evolving threats found in IoT networks.
  • UG-Net integrates a 1D U-Net for hierarchical feature extraction with a GRU layer for sequential dependency modelling.
  • Tests on the CIC-IDS2017 and Bot-IoT datasets showed superior accuracy, precision, recall, and F1-score relative to related methods.
  • The hybrid architecture improves overall intrusion detection rates and the classification of distinct attack types.

Why it matters

Connected everyday devices and industrial equipment are increasingly targeted by sophisticated cyber threats. Because IoT systems use varied and specialised software, standard security tools frequently miss emerging intrusions. Establishing specialised detection models ensures network disruptions and unauthorised access can be identified quickly, protecting critical connected infrastructure from costly and damaging cyber attacks.

Commercialisation angle

UG-Net offers potential utility for network security vendors and IoT platform operators seeking specialised threat detection tools. The model has been validated on standard benchmark datasets, indicating an applied research stage that requires further testing and integration into operational edge or network monitoring environments before commercial deployment.

AI-generated from the published abstract. Always read the original work before citing.

Abstract

The emergence of the Internet of Things has created a specific highly distributed platforms that connect and exchange information continuously and permanently. Their heterogeneity reflected in a variety of devices, architectures, operating systems, protocols, etc., makes them different of other networks. Therefore, well known IDSs are not appropriate for these platforms and their use makes them easy targets for cyber attackers. It means that actual Intrusion Detection Systems (IDSs) are not really specific to IoT platforms and/or are not up to date with new type of attacks. Hence, the need to propose an up to date and specific IDS to protect IoT platforms is an absolute requirement. In this article, we present UG-Net, a hybrid IDS for real IoT platforms. It combines a 1D U-Net network for hierarchical feature extraction and a GRU layer for modeling sequential dependencies. Our proposed IDS is trained, tested, and evaluated on the CIC-IDS2017 and Bot-IoT datasets. The results demonstrate very encouraging performance compared to related works in terms of accuracy, precision, recall, and F1-score. It means that it significantly improves the intrusion detection rate and the intrusions types.

Research topics

  • Network Security and Intrusion Detection
  • Smart Grid Security and Resilience
  • IoT and Edge/Fog Computing

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/ictaacs69003.2025.11399407

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.