Kalifati E., Küçük K., Şolpan Ş., Eren K. K., Konyar M. Z.
JUCS - Journal of Universal Computer Science, cilt.32, sa.8, ss.1223-1257, 2026 (Hakemli Dergi)
Özet
Imbalanced class distributions in Internet of Things (IoT) attack datasets limit the ability of machine learning (ML) models to detect minority intrusions and lead to high false-negative rates. This study investigates the effectiveness of the Synthetic Minority Oversampling Technique (SMOTE) in improving multi-class attack detection across seven IoT devices from the TON_IoT dataset. Four ML algorithms —K-Nearest Neighbor, Support Vector Machine, Logistic Regression, and Multi-Layer Perceptron— are evaluated both with and without SMOTE using accuracy, precision, recall, and F1-score.
Results show that SMOTE substantially improves minority-class detection, particularly in devices with severe imbalance. On the Garage Door dataset, KNN accuracy increases from 0.952 to 0.982, and MLP from 0.555 to 0.978, while SVM exhibites modest gains. The largest recall improvement is observed for Modbus with KNN, rising from 0.52 to 0.84.
Overall, SMOTE enhances IoT intrusion detection without degrading majority-class performance, although its impact varies across algorithms and device characteristics. Future research is planned to explore hybrid resampling and deep learning-based approaches to further improved detection under extreme imbalance.