Skip to main navigation Skip to search Skip to main content

Real-Time eBPF/XDP-based Deep Learning Framework for Anomaly Traffic Detection in IoT Networks

  • Macao Polytechnic University

Research output: Contribution to journalArticlepeer-review

Abstract

IoT networks face resource constraints yet require real-time anomaly detection across diverse protocols. We propose a dynamic, feature-selective framework for heterogeneous IoT networks. It integrates eBPF/XDP in the driver path with a pre-trained lightweight deep learning model in user space, enabling two-stage adaptive feature selection. The feature-selective engine dynamically identifies the most discriminative traffic characteristics under evolving attacks. We validate generalizability using CICDDoS2019, IoT-23, and TON_IoT datasets. For example, on CICDDoS2019, our model trims 77 features down to only 5 while maintaining nearly identical accuracy (93.30% versus 92.73%). On a Raspberry Pi 4B, packet interception averages 1.85 μs and inference 10.38 ms, with negligible CPU overhead. Results confirm both responsiveness and accuracy, addressing security challenges in IoT networks and edge computing systems.

Original languageEnglish
JournalIEEE Internet Computing
DOIs
Publication statusAccepted/In press - 2026

Fingerprint

Dive into the research topics of 'Real-Time eBPF/XDP-based Deep Learning Framework for Anomaly Traffic Detection in IoT Networks'. Together they form a unique fingerprint.

Cite this