Saved in:
Bibliographic Details
Main Authors: Al-Qudah, Mohammed, AlMahamid, Fadi
Format: Preprint
Published: 2025
Subjects:
Online Access:https://arxiv.org/abs/2505.16872
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909620334755840
author Al-Qudah, Mohammed
AlMahamid, Fadi
author_facet Al-Qudah, Mohammed
AlMahamid, Fadi
contents The rapid expansion of Internet of Things (IoT) devices has introduced critical security challenges, underscoring the need for accurate anomaly detection. Although numerous studies have proposed machine learning (ML) methods for this purpose, limited research systematically examines how different preprocessing steps--normalization, transformation, and feature selection--interact with distinct model architectures. To address this gap, this paper presents a multi-step evaluation framework assessing the combined impact of preprocessing choices on three ML algorithms: RNN-LSTM, autoencoder neural networks (ANN), and Gradient Boosting (GBoosting). Experiments on the IoTID20 dataset shows that GBoosting consistently delivers superior accuracy across preprocessing configurations, while RNN-LSTM shows notable gains with z-score normalization and autoencoders excel in recall, making them well-suited for unsupervised scenarios. By offering a structured analysis of preprocessing decisions and their interplay with various ML techniques, the proposed framework provides actionable guidance to enhance anomaly detection performance in IoT environments.
format Preprint
id arxiv_https___arxiv_org_abs_2505_16872
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle A Multi-Step Comparative Framework for Anomaly Detection in IoT Data Streams
Al-Qudah, Mohammed
AlMahamid, Fadi
Machine Learning
The rapid expansion of Internet of Things (IoT) devices has introduced critical security challenges, underscoring the need for accurate anomaly detection. Although numerous studies have proposed machine learning (ML) methods for this purpose, limited research systematically examines how different preprocessing steps--normalization, transformation, and feature selection--interact with distinct model architectures. To address this gap, this paper presents a multi-step evaluation framework assessing the combined impact of preprocessing choices on three ML algorithms: RNN-LSTM, autoencoder neural networks (ANN), and Gradient Boosting (GBoosting). Experiments on the IoTID20 dataset shows that GBoosting consistently delivers superior accuracy across preprocessing configurations, while RNN-LSTM shows notable gains with z-score normalization and autoencoders excel in recall, making them well-suited for unsupervised scenarios. By offering a structured analysis of preprocessing decisions and their interplay with various ML techniques, the proposed framework provides actionable guidance to enhance anomaly detection performance in IoT environments.
title A Multi-Step Comparative Framework for Anomaly Detection in IoT Data Streams
topic Machine Learning
url https://arxiv.org/abs/2505.16872