An Information-Driven Lightweight Hybrid Intrusion Detection Framework with Dynamic Entropy Early Exit for Industrial Internet of Things Networks

Authors

  • Rupali Ramdas Shevale
  • Dr. Monika Sharad Deshmukh

Keywords:

Industrial Internet of Things, Network Intrusion Detection, Dynamic Early Exit, feature selection, Probability Calibration.

Abstract

Industrial Internet of Things (IIoT) edge gateways operate under strict cycle deadlines and tight memory budgets while inspecting high throughput telemetry under severe class imbalance. Standard deep neural networks incur excessive computational overhead, whereas tabular ensembles suffer from multi-millisecond inference latencies on embedded hardware. This paper presents an information driven, lightweight hybrid intrusion detection framework designed for resource-aware edge inference and streaming telemetry ingestion. A two stage Minimum Redundancy Maximum Relevance and Joint Mutual Information (mRMR-JMI) pipeline purges non-generalizing host identifiers and reduces candidate inputs from 61 to 22 features (a 63.93% reduction). The neural architecture integrates 1D depthwise separable convolutions, Ghost linear expansions, and Squeeze-and-Excitation attention with an intermediate classifier governed by normalized Shannon predictive entropy (). Ambiguous samples pass to a bidirectional gated recurrent unit (BiGRU) and multi-head self-attention block modeling 16 pooled latent representations. Evaluated on the 23,548 sample Edge-IIoTset held out test partition, the primary model achieves 95.66% accuracy, 94.68% macro-F1 (95% bootstrap CI: [94.26%, 95.06%]), a 0.31% macro false positive rate, and 99.16% F1 on rare Man-in-the-Middle attacks with under 371k parameters. Dynamic routing discharges 97.97% of traffic via the fast path at 0.052 ms median latency, sacrificing less than 0.03% accuracy versus full execution. Finally, streaming benchmarks with a local C++ Redpanda message broker demonstrate 58,900 events/second at zero message loss with a 7.10 ms P95 end-to-end latency.

Downloads

Published

2026-09-01

How to Cite

Shevale, R. R., & Deshmukh, D. M. S. (2026). An Information-Driven Lightweight Hybrid Intrusion Detection Framework with Dynamic Entropy Early Exit for Industrial Internet of Things Networks. International Journal of Artificial Intelligence and Machine Learning, 6(3), 712–728. Retrieved from https://mail.svedbergopen.com/index.php/ijaiml/article/view/2119