Traffic Anomaly Detection in Fog-IoT Networks Using a Combination of Improved Reinforcement Learning and Convolutional Neural Networks
Keywords:
Anomaly Detection, Fog Computing, Internet of Things, Reinforcement Learning, Convolutional Neural Network, Dueling-Q Network, Intrusion Detection, Data Imbalance, SMOTE, Network Traffic AnalysisAbstract
Despite significant advances in machine- and deep-learning-based intrusion detection systems, existing methods still face fundamental challenges. Many of these methods either rely on static and predefined patterns and have limited efficiency in detecting unknown and low-rate attacks, or are not suitable for practical deployment in fog and IoT environments due to their high computational complexity. In addition, the issues of data imbalance, traffic pattern dynamics, and limited computational resources in fog nodes mean that a simple combination of multiple learning models alone does not meet the practical needs of this area. In this research, a novel framework for anomaly detection in Fog-IoT networks is presented, in which a convolutional neural network extracts deep representations, and the Dueling-Q reinforcement learning algorithm learns the optimal decision-making policy. Also, to adapt the IDS monitoring data to the reinforcement learning framework, a data transformation module is designed to map traffic flows from a static feature space to structured state representations for the learning agent. To increase detection accuracy, the data imbalance is addressed using SMOTE, and the stability of the learning process is improved by designing a large Replay Buffer. Also, the model reward function is designed to be highly sensitive to false-negative errors so that low-rate, hidden, and distributed attacks are detected more accurately. The evaluation of the proposed model was carried out on two benchmark datasets, UNSW-NB15 and CICIDS2017, under a fog-layer deployment scenario. The results showed that the proposed model achieved 98.8% accuracy, 95.6% attack detection accuracy, 92.4% attack recall, 93.9% attack F1 score, and 96.78% false-negative rate on the UNSW-NB15 dataset. Also, on the CICIDS2017 dataset, the model performance improved further, achieving 98.9% accuracy, 95.8% attack detection accuracy, 92.9% attack recall, and 94.3% attack F1 score. These results indicate the model's strong ability to detect complex, sequence-based, low-rate attacks. The study of originality also showed that removing any of the key components of the model, including the CNN, the Dueling structure, reinforcement learning, or the SMOTE technique, leads to significant performance degradation. Comparisons with methods proposed for fog environments, such as Autoencoder-CNN-LSTM, FFL-IDS, Fog-Edge-SVM-FL, and Whale-ELM, also showed that the proposed method is significantly superior across all critical criteria, especially the attack recall criterion, the most important security indicator. Overall, the results of this research demonstrate that the combination of CNN and Dueling-Q can provide a lightweight, accurate, and practical solution for deployment on fog nodes and serve as a reliable IDS in real Fog-IoT environments.
References
[1] A. R. Khan, M. Kashif, R. H. Jhaveri, R. Raut, T. Saba, and S. A. Bahaj, "Deep Learning for Intrusion Detection and Security of Internet of Things (IoT): Current Analysis, Challenges, and Possible Solutions," Security and Communication Networks, vol. 2022, no. 1, p. 4016073, 2022, doi: 10.1155/2022/4016073.
[2] A. Heidari and M. A. Jabraeil Jamali, "Internet of Things Intrusion Detection Systems: A Comprehensive Review and Future Directions," Cluster Computing, vol. 26, no. 6, pp. 3753-3780, 2023, doi: 10.1007/s10586-022-03776-z.
[3] A. Khraisat, I. Gondal, P. Vamplew, and J. Kamruzzaman, "Survey of Intrusion Detection Systems: Techniques, Datasets and Challenges," Cybersecurity, vol. 2, no. 1, pp. 1-22, 2019, doi: 10.1186/s42400-019-0038-7.
[4] A. Thakkar and R. Lohiya, "A Survey on Intrusion Detection System: Feature Selection, Model, Performance Measures, Application Perspective, Challenges, and Future Research Directions," Artificial Intelligence Review, vol. 55, no. 1, pp. 453-563, 2022, doi: 10.1007/s10462-021-10037-9.
[5] N. Moustafa and J. Slay, "UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection Systems (UNSW-NB15 Network Data Set)," in 2015 Military Communications and Information Systems Conference (MilCIS), 2015: IEEE, pp. 1-6, doi: 10.1109/MilCIS.2015.7348942.
[6] D. Stiawan, M. Y. B. Idris, A. M. Bamhdi, and R. Budiarto, "CICIDS-2017 Dataset Feature Analysis with Information Gain for Anomaly Detection," IEEE Access, vol. 8, pp. 132911-132921, 2020, doi: 10.1109/ACCESS.2020.3009843.
[7] A. A. Salih and A. M. Abdulazeez, "Evaluation of Classification Algorithms for Intrusion Detection System: A Review," Journal of Soft Computing and Data Mining, vol. 2, no. 1, pp. 31-40, 2021.
[8] Z. Azam, M. M. Islam, and M. N. Huda, "Comparative Analysis of Intrusion Detection Systems and Machine Learning Based Model Analysis Through Decision Tree," IEEE Access, 2023, doi: 10.1109/ACCESS.2023.3296444.
[9] N. Saran and N. Kesswani, "A Comparative Study of Supervised Machine Learning Classifiers for Intrusion Detection in Internet of Things," Procedia Computer Science, vol. 218, pp. 2049-2057, 2023, doi: 10.1016/j.procs.2023.01.181.
[10] A. V. Turukmane and R. Devendiran, "M-MultiSVM: An Efficient Feature Selection Assisted Network Intrusion Detection System Using Machine Learning," Computers & Security, vol. 137, p. 103587, 2024, doi: 10.1016/j.cose.2023.103587.
[11] R. Doshi, N. Apthorpe, and N. Feamster, "Machine Learning DDoS Detection for Consumer Internet of Things Devices," in 2018 IEEE Security and Privacy Workshops (SPW), 2018: IEEE, pp. 29-35, doi: 10.1109/SPW.2018.00013.
[12] M. Aamir and S. M. A. Zaidi, "Clustering Based Semi-Supervised Machine Learning for DDoS Attack Classification," Journal of King Saud University - Computer and Information Sciences, vol. 33, no. 4, pp. 436-446, 2021, doi: 10.1016/j.jksuci.2019.02.003.
[13] S. M. Kasongo, "A Deep Learning Technique for Intrusion Detection System Using a Recurrent Neural Networks Based Framework," Computer Communications, vol. 199, pp. 113-125, 2023, doi: 10.1016/j.comcom.2022.12.010.
[14] V. Ravi, R. Chaganti, and M. Alazab, "Recurrent Deep Learning-Based Feature Fusion Ensemble Meta-Classifier Approach for Intelligent Network Intrusion Detection System," Computers & Electrical Engineering, vol. 102, p. 108156, 2022, doi: 10.1016/j.compeleceng.2022.108156.
[15] A. Halbouni, T. S. Gunawan, M. H. Habaebi, M. Halbouni, M. Kartiwi, and R. Ahmad, "CNN-LSTM: Hybrid Deep Neural Network for Network Intrusion Detection System," IEEE Access, vol. 10, pp. 99837-99849, 2022, doi: 10.1109/ACCESS.2022.3206425.
[16] N. U. Ain, M. Sardaraz, M. Tahir, M. W. Abo Elsoud, and A. Alourani, "Securing IoT Networks Against DDoS Attacks: A Hybrid Deep Learning Approach," Sensors, vol. 25, no. 5, p. 1346, 2025, doi: 10.3390/s25051346.
[17] R. H. Hwang, M. C. Peng, C. W. Huang, P. C. Lin, and V. L. Nguyen, "An Unsupervised Deep Learning Model for Early Network Traffic Anomaly Detection," IEEE Access, vol. 8, pp. 30387-30399, 2020, doi: 10.1109/ACCESS.2020.2973023.
[18] H. Xu, Z. Sun, Y. Cao, and H. Bilal, "A Data-Driven Approach for Intrusion and Anomaly Detection Using Automated Machine Learning for the Internet of Things," Soft Computing, pp. 1-13, 2023, doi: 10.1007/s00500-023-09037-4.
[19] M. Soltani, B. Ousat, M. J. Siavoshani, and A. H. Jahangir, "An Adaptable Deep Learning-Based Intrusion Detection System to Zero-Day Attacks," Journal of Information Security and Applications, vol. 76, p. 103516, 2023, doi: 10.1016/j.jisa.2023.103516.
[20] M. A. Lawal, R. A. Shaikh, and S. R. Hassan, "A DDoS Attack Mitigation Framework for IoT Networks Using Fog Computing," Procedia Computer Science, vol. 182, pp. 13-20, 2021, doi: 10.1016/j.procs.2021.02.003.
[21] Q. Shafi, A. Basit, S. Qaisar, A. Koay, and I. Welch, "Fog-Assisted SDN Controlled Framework for Enduring Anomaly Detection in an IoT Network," IEEE Access, vol. 6, pp. 73713-73723, 2018, doi: 10.1109/ACCESS.2018.2884293.
[22] A. Samy, H. Yu, and H. Zhang, "Fog-Based Attack Detection Framework for Internet of Things Using Deep Learning," IEEE Access, vol. 8, pp. 74571-74585, 2020, doi: 10.1109/ACCESS.2020.2988854.
[23] J. K. A. Sinaeepourfard and S. A. Petersen, "A Distributed-to-Centralized Smart Technology Management (D2C-STM) Model for Smart Cities: A Use Case in the Zero Emission Neighborhoods," in Fifth IEEE Annual International Smart Cities Conference (ISC2 2019), Casablanca, Morocco, 2019, doi: 10.1109/ISC246665.2019.9071762.
[24] R. Devendiran and A. V. Turukmane, "Dugat-LSTM: Deep Learning Based Network Intrusion Detection System Using Chaotic Optimization Strategy," Expert Systems with Applications, vol. 245, p. 123027, 2024, doi: 10.1016/j.eswa.2023.123027.
[25] N. O. Aljehane, "Golden Jackal Optimization Algorithm with Deep Learning Assisted Intrusion Detection System for Network Security," Alexandria Engineering Journal, vol. 86, pp. 415-424, 2024, doi: 10.1016/j.aej.2023.11.078.
[26] D. P. Sahu, B. Tripathy, and L. Samantaray, "Optimized Intrusion Detection System in Fog Computing Environment Using Automatic Termination-Based Whale Optimization with ELM," International Journal of Computer Network and Information Security, vol. 16, no. 2, pp. 79-91, 2024, doi: 10.5815/ijcnis.2024.02.07.
[27] T. Rehman, N. Tariq, F. A. Khan, and S. U. Rehman, "FFL-IDS: A FOG-Enabled Federated Learning-Based Intrusion Detection System to Counter Jamming and Spoofing Attacks for the Industrial Internet of Things," Sensors, vol. 25, no. 1, p. 10, 2024, doi: 10.3390/s25010010.
[28] N. Tariq, A. Alsirhani, M. Humayun, F. Alserhani, and M. Shaheen, "A Fog-Edge-Enabled Intrusion Detection System for Smart Grids," Journal of Cloud Computing, vol. 13, no. 1, p. 43, 2024, doi: 10.1186/s13677-024-00609-9.
[29] M. Tawfik, "Optimized Intrusion Detection in IoT and Fog Computing Using Ensemble Learning and Advanced Feature Selection," PLOS ONE, vol. 19, no. 8, p. e0304082, 2024, doi: 10.1371/journal.pone.0304082.
[30] Z. Qin, Q. Luo, X. Nong, X. Chen, H. Zhang, and C. U. I. Wong, "MAS-LSTM: A Multi-Agent LSTM-Based Approach for Scalable Anomaly Detection in IIoT Networks," Processes, vol. 13, no. 3, p. 753, 2025, doi: 10.3390/pr13030753.
Downloads
Publication Timeline
- Submitted
- Revised
- Accepted
Issue
Section
License
Copyright (c) 2025 Ahmed Mhmood Abbood AlTameemi (Corresponding author); Sima Emadi, Hayder Ghanim Murad, Mohammadreza SoltanAghaie (Author)

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.