An Empirical Comparative Review of Classifiers for Real-Time IoT Cyber Attack Detection
DOI:
https://doi.org/10.19139/soic-2310-5070-4092Keywords:
Artificial Intelligence, IoT Security, Machine learning, Multilayer Perceptron, Intrusion Detection, Anomaly DetectionAbstract
The rapid growth of the Internet of Things (IoT) has significantly expanded the attack surface of modern networks, generating an urgent need for robust and efficient intrusion detection mechanisms. Machine learning (ML) is a promising approach to detect cyber attacks in IoT environments by automatically learning discriminative patterns from heterogeneous, real-world traffic. In this work we provide a comparative review and a thorough empirical evaluation of ten classifiers: logistic regression, decision trees, k-nearest neighbors, support vector machines, multilayer perceptrons, Random Forests, XGBoost, LightGBM, CatBoost, and a soft-voting ensemble on the RT-IoT2022 dataset, a realistic benchmark for real-time IoT attack detection. In addition to raw performance, we measure the impact of aggressive dimensionality reduction by comparing the full 83-feature space to a compact subset of 15 features, as determined by the consensus ranking of LightGBM and CatBoost feature importances. Experiments indicate that tree-based ensembles, CatBoost, XGBoost, and LightGBM, achieve the best performance, producing accuracy and AUC values above 99.7% and 99.9%, respectively, for both feature configurations, while maintaining balanced precision and recall across different attack types. Among the non-ensemble models, k-nearest neighbours is the strongest and loses only 0.05 accuracy points under the reduction, and the multilayer perceptron is equally insensitive, whereas logistic regression and the linear SVM lose 16--17 macro-F1 points. All comparisons are supported by stratified five-fold cross-validation, 95% confidence intervals and paired McNemar and Wilcoxon tests under Holm--Bonferroni correction, by a deployment cost profile (training and per-flow inference time), by a per-class analysis of minority-attack recall after SMOTE, and by external validation on NSL-KDD. This paper summarizes the advantages, disadvantages, and deployment considerations of state-of-the-art ML techniques and provides practical guidance for the development of adaptive, lightweight, and interpretable IoT intrusion detection systems.Downloads
Published
2026-08-08
How to Cite
Boulkhiout, Y., Balbal, S., Nasri, K., & Moussaoui, A. (2026). An Empirical Comparative Review of Classifiers for Real-Time IoT Cyber Attack Detection. Statistics, Optimization & Information Computing. https://doi.org/10.19139/soic-2310-5070-4092
License
Copyright (c) 2026 Youssef Boulkhiout, Samir Balbal, Khaled Nasri, Abdelouahab Moussaoui

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).