Traffic-Aware Imbalance Learning Network for Lightweight IoT Intrusion Detection
DOI:
https://doi.org/10.37965/jait.2026.1482Keywords:
Class imbalance, deep learning, Intrusion detection system, Internet of Things (IoT), severity analysisAbstract
The rapid growth of internet of things (IoT) networks has significantly increased cybersecurity risks due to heterogeneous traffic characteristics, large-scale connectivity, and highly imbalanced attack distributions. Existing intrusion detection approaches primarily focus on improving overall detection performance through computationally expensive deep learning architectures or synthetic oversampling techniques. However, such methods often overlook semantic relationships among traffic features, increase computational complexity, and exhibit a limited capability to learn minority attack patterns. This paper presents a Traffic-Aware Imbalance Learning Network (TAIL-Net) for lightweight and imbalance-aware IoT intrusion detection. The proposed framework introduces a traffic-aware semantic feature mapping mechanism that reorganizes network traffic attributes according to their semantic relationships to improve feature representation learning. The mapped features are processed through a lightweight convolutional neural network (CNN)-GRU architecture integrated with a minority-aware attention and an Adaptive Class-Balanced Focal Loss (ACB-FL) function to enhance minority attack discrimination without relying on synthetic oversampling. Experimental evaluation on the Botnet-internet of things (BoT-IoT) dataset demonstrates that the proposed framework achieved 99% detection accuracy and 99% weighted F1-score. Furthermore, TAIL-Net requires only 81,866 trainable parameters with a model size of 0.3122 MB and achieves an average inference latency of 0.0041 ms/sample.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Authors

This work is licensed under a Creative Commons Attribution 4.0 International License.
