<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMES</journal-id>
<journal-id journal-id-type="nlm-ta">CMES</journal-id>
<journal-id journal-id-type="publisher-id">CMES</journal-id>
<journal-title-group>
<journal-title>Computer Modeling in Engineering &#x0026; Sciences</journal-title>
</journal-title-group>
<issn pub-type="epub">1526-1506</issn>
<issn pub-type="ppub">1526-1492</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">64874</article-id>
<article-id pub-id-type="doi">10.32604/cmes.2025.064874</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>A Hybrid Wasserstein GAN and Autoencoder Model for Robust Intrusion Detection in IoT</article-title>
<alt-title alt-title-type="left-running-head">A Hybrid Wasserstein GAN and Autoencoder Model for Robust Intrusion Detection in IoT</alt-title>
<alt-title alt-title-type="right-running-head">A Hybrid Wasserstein GAN and Autoencoder Model for Robust Intrusion Detection in IoT</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Alshehri</surname><given-names>Mohammed S.</given-names></name><xref ref-type="aff" rid="aff-1">1</xref><email>msalshehry@nu.edu.sa</email></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Saidani</surname><given-names>Oumaima</given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Malwi</surname><given-names>Wajdan Al</given-names></name><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Asiri</surname><given-names>Fatima</given-names></name><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western"><surname>Latif </surname><given-names>Shahid</given-names></name><xref ref-type="aff" rid="aff-4">4</xref></contrib>
<contrib id="author-6" contrib-type="author">
<name name-style="western"><surname>Khattak</surname><given-names>Aizaz Ahmad</given-names></name><xref ref-type="aff" rid="aff-5">5</xref></contrib>
<contrib id="author-7" contrib-type="author">
<name name-style="western"><surname>Ahmad</surname><given-names>Jawad</given-names></name><xref ref-type="aff" rid="aff-6">6</xref></contrib>
<aff id="aff-1"><label>1</label><institution>Department of Computer Science, College of Computer Science and Information Systems, Najran University</institution>, <addr-line>Najran, 61441</addr-line>, <country>Saudi Arabia</country></aff>
<aff id="aff-2"><label>2</label><institution>Department of Information Systems, College of Computer and Information Sciences, Princess Nourah bint Abdulrahman University</institution>, P. O. Box 84428, <addr-line>Riyadh, 11671</addr-line>, <country>Saudi Arabia</country></aff>
<aff id="aff-3"><label>3</label><institution>Department of Informatics and Computer Systems, College of Computer Science, King Khalid University</institution>, <addr-line>Abha, 62521</addr-line>, <country>Saudi Arabia</country></aff>
<aff id="aff-4"><label>4</label><institution>School of Computing and Creative Technologies, University of the West of England</institution>, <addr-line>Bristol, BS16 1QY</addr-line>, <country>UK</country></aff>
<aff id="aff-5"><label>5</label><institution>School of Computing, Engineering &#x0026; The Built Environment, Edinburgh Napier University</institution>, <addr-line>10 Colinton Road, Edinburgh, EH10 5DT</addr-line>, <country>UK</country></aff>
<aff id="aff-6"><label>6</label><institution>Cybersecurity Center, Prince Mohammad Bin Fahd University</institution>, <addr-line>Al Khobar, 31952</addr-line>, <country>Saudi Arabia</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Mohammed S. Alshehri. Email: <email>msalshehry@nu.edu.sa</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2025</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>30</day><month>06</month><year>2025</year>
</pub-date>
<volume>143</volume>
<issue>3</issue>
<fpage>3899</fpage>
<lpage>3920</lpage>
<history>
<date date-type="received">
<day>26</day>
<month>2</month>
<year>2025</year>
</date>
<date date-type="accepted">
<day>23</day>
<month>4</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2025 The Authors.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMES_64874.pdf"></self-uri>
<abstract>
<p>The emergence of Generative Adversarial Network (GAN) techniques has garnered significant attention from the research community for the development of Intrusion Detection Systems (IDS). However, conventional GAN-based IDS models face several challenges, including training instability, high computational costs, and system failures. To address these limitations, we propose a Hybrid Wasserstein GAN and Autoencoder Model (WGAN-AE) for intrusion detection. The proposed framework leverages the stability of WGAN and the feature extraction capabilities of the Autoencoder Model. The model was trained and evaluated using two recent benchmark datasets, 5GNIDD and IDSIoT2024. When trained on the 5GNIDD dataset, the model achieved an average area under the precision-recall curve is 99.8% using five-fold cross-validation and demonstrated a high detection accuracy of <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mn>97.35</mml:mn></mml:math></inline-formula>% when tested on independent test data. Additionally, the model is well-suited for deployment on resource-limited Internet-of-Things (IoT) devices due to its ability to detect attacks within microseconds and its small memory footprint of <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:mn>60.24</mml:mn></mml:math></inline-formula> kB. Similarly, when trained on the IDSIoT2024 dataset, the model achieved an average PR-AUC of <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:mn>94.09</mml:mn></mml:math></inline-formula>% and an attack detection accuracy of <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:mn>97.35</mml:mn></mml:math></inline-formula>% on independent test data, with a memory requirement of <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:mn>61.84</mml:mn></mml:math></inline-formula> kB. Extensive simulation results demonstrate that the proposed hybrid model effectively addresses the shortcomings of traditional GAN-based IDS approaches in terms of detection accuracy, computational efficiency, and applicability to real-world IoT environments.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Autoencoder</kwd>
<kwd>cybersecurity</kwd>
<kwd>generative adversarial network</kwd>
<kwd>Internet of Things</kwd>
<kwd>intrusion detection system</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>King Khalid University</funding-source>
<award-id>RGP.2/245/46</award-id>
</award-group>
<award-group id="awg2">
<funding-source>Princess Nourah bint Abdulrahman University</funding-source>
<award-id>PNURSP2025R760</award-id>
</award-group>
<award-group id="awg3">
<funding-source>Deanship of Graduate Studies and Scientific Research at Najran University</funding-source>
<award-id>NU/GP/SERC/13/352-1</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>Intrusion detection systems (IDSs) play a very important role in protecting IoT networks from a number of cyberattacks that are mainly targeted at device and network vulnerabilities such as the use of insecure communication protocols or weak authentication mechanisms [<xref ref-type="bibr" rid="ref-1">1</xref>]. Most of these attacks are launched through malicious software or firmware updates that may result in unauthorized access to the network or control of IoT devices [<xref ref-type="bibr" rid="ref-2">2</xref>]. Cyberattacks can violate the confidentiality, integrity, and availability of the network and may result in data breaches, unauthorized access to sensitive information, and denial of service [<xref ref-type="bibr" rid="ref-3">3</xref>,<xref ref-type="bibr" rid="ref-4">4</xref>]. The main challenge in this regard is the resource-constrained nature of IoT devices that pose a challenge to implementing advanced and robust security frameworks. The increasing complexity of security algorithms results in system outages, reduced performance, or poor service quality in IoT networks [<xref ref-type="bibr" rid="ref-5">5</xref>].</p>
<p>Over the past few years, GANs have received great attention because of their ability to learn data distribution and generate synthetic data that can mimic possible attack patterns [<xref ref-type="bibr" rid="ref-6">6</xref>]. Traditional signature-based approaches are also ineffective in identifying new and unexpected cyberattacks, whereas GANs learn to generate adversarial examples to identify outliers [<xref ref-type="bibr" rid="ref-7">7</xref>]. However, there are several shortcomings of the traditional GAN variants as well. For example, vanilla GAN [<xref ref-type="bibr" rid="ref-8">8</xref>] has some drawbacks such as model collapse and training instability that limit its effectiveness in generating diverse and representative samples. Conditional GANs [<xref ref-type="bibr" rid="ref-9">9</xref>] are more context-sensitive than their counterparts but they need labeled data. CycleGANs [<xref ref-type="bibr" rid="ref-10">10</xref>] are very efficient in the domain translation task, even in the absence of paired data, but they are usually slow and not very accurate in identifying small anomalies. The Wasserstein GAN [<xref ref-type="bibr" rid="ref-11">11</xref>] also improves the stability and diversity but at the expense of increasing the model complexity.</p>
<p>To overcome these issues, this paper proposes a Wasserstein GAN with Autoencoders (WGAN-AE) that integrates the best aspects of WGANs and autoencoders to develop a more efficient and effective intrusion detection system for IoT networks. The WGAN-AE can produce stable and diverse samples by leveraging the Wasserstein distance, which measures the difference between two probability distributions. Unlike traditional distance metrics, it provides a smoother and more meaningful way to compare real and generated data, leading to better training stability and improved detection of various attack types [<xref ref-type="bibr" rid="ref-12">12</xref>]. Autoencoders assist in detecting the changes that are likely to be a sign of a cyberattack by learning the detailed patterns of the normal IoT traffic [<xref ref-type="bibr" rid="ref-13">13</xref>]. This approach is less dependent on large datasets suitable for dynamic IoT environments. Furthermore, the WGAN-AE offers a complete solution that entails the reconstruction and anomaly identification of any input by comparing it with the learned normal behavior. This makes training more stable and enhances the novel attack detection rate that may not be detected by other models. A comparison of the proposed WGAN-AE with state-of-the-art GAN variants is presented in <xref ref-type="table" rid="table-1">Table 1</xref>. The major contributions of the article are summarized as follows.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>A comparison of state-of-the-art GAN variants with the proposed WGAN-AE in the context of IDS</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th align="center">Feature</th>
<th colspan="5">GAN variants</th>
</tr>
<tr>
<th/>
<th>Vanilla GAN</th>
<th>Conditional GAN</th>
<th>Cycle GAN</th>
<th>Wasserstein GAN</th>
<th>WGAN-AE</th>
</tr>
</thead>
<tbody>
<tr>
<td>Training stability</td>
<td>Low</td>
<td>Moderate</td>
<td>Moderate</td>
<td>High</td>
<td>Very high</td>
</tr>
<tr>
<td>Mode collapse</td>
<td>High</td>
<td>Moderate</td>
<td>Moderate</td>
<td>Low</td>
<td>Very low</td>
</tr>
<tr>
<td>Feature learning</td>
<td>Limited</td>
<td>Good</td>
<td>Good</td>
<td>Strong</td>
<td>Strong</td>
</tr>
<tr>
<td>Anomaly detection</td>
<td>Poor</td>
<td>Moderate</td>
<td>Good</td>
<td>Good</td>
<td>Excellent</td>
</tr>
<tr>
<td>Training complexity</td>
<td>Moderate</td>
<td>High</td>
<td>High</td>
<td>Moderate</td>
<td>Moderate</td>
</tr>
<tr>
<td>Robustness</td>
<td>Low</td>
<td>Moderate</td>
<td>Moderate</td>
<td>High</td>
<td>Very high</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><list list-type="simple">
<list-item><label>1.</label><p>A hybrid intrusion detection framework, WGAN-AE, is proposed by utilizing the key strengths of WGAN and AE. The model enhances the detection of emerging attack vectors by using Wasserstein distance for more stable training and autoencoder-based feature extraction.</p></list-item>
<list-item><label>2.</label><p>The research introduces an unsupervised GAN-based approach that learns the normal operation of the system and identifies changes as possible cyberattacks. It also achieves this by properly distinguishing between the normal and attack behaviors through the use of adversarial training of the generator to generate diverse attack types.</p></list-item>
<list-item><label>3.</label><p>A comprehensive evaluation framework is developed to assess the computational efficiency and effectiveness of the proposed scheme by using two advanced and comprehensive IDS benchmark datasets.</p></list-item>
</list></p>
<p>The remainder of the article is organized as follows. In <xref ref-type="sec" rid="s2">Section 2</xref>, we present some latest contributions related to GAN-based IDS frameworks and describe some preliminaries. In <xref ref-type="sec" rid="s3">Section 3</xref>, we elaborate on the research methodology and the design of the proposed framework. In <xref ref-type="sec" rid="s4">Section 4</xref>, we present a brief discussion of the experimental setup and outcomes. Finally, in <xref ref-type="sec" rid="s5">Section 5</xref>, we conclude the research with future research directions.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Work</title>
<p>This section overviews some significant contributions related to GAN-based IDS architectures. Rahman et al. [<xref ref-type="bibr" rid="ref-6">6</xref>] explored the potential of GAN for intrusion detection in IoT. The proposed scheme significantly decreased the dependency on real-world data. To analyze the effectiveness of designed model, the authors conducted extensive experiments on three open-source datasets including UNSW-NB15, NSL-KDD and BoT-IoT datasets. Message Queuing Telemetry Transport (MQTT) is a widely adapted network protocol in IoT infrastructures because of its lightweight and flexible nature. Boppana and Bagade [<xref ref-type="bibr" rid="ref-14">14</xref>] proposed a novel unsupervised GAN and autoencoder-based model GAN-AE, to detect unknown intrusions in MQTT-based IoT applications. The experimental results demonstrate the effectiveness of the proposed method against various modern IDS approaches. In another study, Li et al. [<xref ref-type="bibr" rid="ref-15">15</xref>] proposed a hybrid IDS model to detect Denial of Service (DoS)/botnet attacks in IoT systems. The authors designed an anomaly-based detection model called CL-GAN (CNN-LSTM GNN), combining a Convolutional Neural Network (CNN) and Long Short-Term Memory (LSTM) with GAN to define a baseline of normal activity and identify malicious traffic. The proposed architecture was evaluated with NSL-KDD, CICIDS2018, and Bot-IoT datasets.</p>
<p>de Araujo-Filho et al. [<xref ref-type="bibr" rid="ref-16">16</xref>] presented a novel fog-based unsupervised IDS using GANs. The proposed IDS was developed for a fog architecture to meet the low-latency requirements of cyberphysical systems. Experimental outcomes indicated the higher detection rates and superior performance of the proposed approach over baseline models using three datasets. Zeghida et al. [<xref ref-type="bibr" rid="ref-17">17</xref>] proposed GAN-based methods to achieve a balanced dataset for greater attack detection accuracy. Additionally, they introduced three dedicated IDSs for attack detection using the MQTT protocol based on hybrid deep learning (DL) algorithms: Convolutional Neural Network with Recurrent Neural Network (CNN-RNN), CNN with Long Short-Term Memory (CNN-LSTM), and CNN with Gated Recurrent Unit (CNN-GRU). The experimental results demonstrated that the generated dataset had a superior performance in multiclass configuration. In another study, Das et al. [<xref ref-type="bibr" rid="ref-18">18</xref>] proposed two models: a Feedforward Neural Network (FNN) network and a CNN. The proposed models have been trained and tested on standard datasets as well as synthetic datasets. The generation of this synthetic data employs a Conditional Tabular Generative Adversarial Network (CTGAN). The experimental outcomes indicated less training time and memory utilization than several baseline models.</p>
<p>Wang et al. [<xref ref-type="bibr" rid="ref-19">19</xref>] proposed a Multi-Critics GAN to address the data imbalance issues in IDS systems. The authors analyzed the generated data quality by using Principal Component Analysis (PCA) plots and correlation heatmaps. Subsequently, they incorporated a hybrid CNN-LSTM model to analyze the clusters to achieve the promising performance of IDS systems. The experimental results confirmed the higher attack detection rate with better generalization. Dong et al. [<xref ref-type="bibr" rid="ref-20">20</xref>] presented a novel IDS framework MasqueradeGAN-GP (Generative Adversarial Networks with Gradient Penalty), for 6G networks by integrating a WGAN with a Gradient Penalty. In the proposed architecture, a generator transforms the anomalous traffic into a semblance of benign activity and the discriminator discerns the genuine and adversarial traffic. The efficacy of the designed models was investigated by conducting extensive experiments using two open-source datasets. Brabin et al. [<xref ref-type="bibr" rid="ref-21">21</xref>] presented a Cycle-Consistent GAN-based attack detection and secure data transmission framework for smart cities. The designed framework incorporated a Wild horse optimizer for feature extraction. Subsequently, the selected features are provided to the cycle-consistent GAN classifier to distinguish normal and malicious traffic. Furthermore, to ensure a secure data transmission, the authors incorporated Advanced Encryption Standard (AES) with Chameleon Swarm Algorithm.</p>
<p>The aforementioned works present a significant contribution towards GAN-based IDSs. However, the existing studies have a few shortcomings, including reliance on outdated datasets that fail to capture real-time IoT security challenges and a primary focus on attack detection accuracy while neglecting critical constraints such as memory requirements and computational efficiency. While some approaches address data imbalance using advanced GAN variants like Multi-Critics GAN, CTGAN, and WGAN with Gradient Penalty, others integrate federated learning for enhanced security in Fog-assisted IoT networks. However, these studies lack a holistic evaluation framework. To overcome these shortcomings, this article proposes a WGAN-AE, which is trained and evaluated using two real-time benchmark datasets. The proposed approach ensures a comprehensive performance analysis, including accuracy, memory consumption, system latency, and cross-validation, making it a more robust solution for modern IoT-based IDS.</p>
</sec>
<sec id="s3">
<label>3</label>
<title>Research Methodology and the Proposed Framework</title>
<p>This section briefly describes the dataset description, the design of the proposed architecture, and the training process. The workflow of the proposed architecture is presented in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Block diagram of the proposed architecture</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_64874-fig-1.tif"/>
</fig>
<sec id="s3_1">
<label>3.1</label>
<title>Dataset Description</title>
<p>To train and evaluate the proposed architecture&#x2019;s performance, we utilized three of the latest and most comprehensive datasets. The following provides a detailed description.</p>
<sec id="s3_1_1">
<label>3.1.1</label>
<title>5G-NIDD Dataset</title>
<p>The 5G-NIDD dataset is a fully labeled collection of network traffic data generated from a functional 5G test network at the University of Oulu, Finland [<xref ref-type="bibr" rid="ref-22">22</xref>]. The dataset includes various attack scenarios, such as Denial of Service (DoS) attacks, Internet Control Message Protocol (ICMP) Flood, synchronize (SYN) Flood, User Datagram Protocol (UDP) Flood, Hypertext Transfer Protocol (HTTP) Flood, and Slowrate and port scans, including Transmission Control Protocol (TCP) Connect Scan, SYN Scan, and UDP Scan. The detailed distribution of the 5G-NIDD dataset is presented in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Distribution of 5G-NIDD dataset</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_64874-fig-2.tif"/>
</fig>
</sec>
<sec id="s3_1_2">
<label>3.1.2</label>
<title>IDSIoT2024 Dataset</title>
<p>The IDSIoT2024 dataset [<xref ref-type="bibr" rid="ref-23">23</xref>] is a comprehensive, real-time collection of network traffic data from an Internet of Things (IoT) environment comprising seven diverse smart devices: a smartwatch, surveillance camera, smartphone, laptop, smart vacuum, smart TV, and smart light. In this setup, the laptop serves a dual role: continuously monitoring and logging network traffic for analysis and actively executing various network-based attacks to simulate potential security threats. The dataset includes seven main categories: DoS, Injection, Man-in-the-Middle (MITM), malware, normal, routing, and vulnerability analysis. The detailed distribution of the IDSIoT2024 dataset is presented in <xref ref-type="fig" rid="fig-3">Fig. 3</xref>.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Distribution of IDSIoT2024 dataset</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_64874-fig-3.tif"/>
</fig>
</sec>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>The Proposed Architecture</title>
<p>This section provides a detailed description of each module of the proposed architecture.</p>
<sec id="s3_2_1">
<label>3.2.1</label>
<title>Data Preprocessing</title>
<p>The preprocessing of the dataset <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mo>{</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>y</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>}</mml:mo></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>N</mml:mi></mml:msubsup></mml:math></inline-formula> is an essential step to prepare both the input features<italic>X</italic> and target labels <inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:mi>y</mml:mi></mml:math></inline-formula> for the hybrid WGAN-AE and autoencoder model. This stage typically involves scaling the features and encoding the categorical target labels for classification tasks.</p>
<p><bold>Feature Scaling (Standardization):</bold> The first step is to normalize the feature data so that each feature has zero mean and unit variance. This ensures that all features contribute equally during training, preventing features with larger ranges from dominating the optimization process.</p>
<p>Given a feature matrix <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:mi>X</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mrow><mml:mi>N</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>d</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>, where <italic>N</italic> is the number of samples and <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:mi>d</mml:mi></mml:math></inline-formula> is the number of features, each feature column <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:msub><mml:mi>x</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mi>N</mml:mi></mml:msup></mml:math></inline-formula> is standardized using z -score normalization. The transformation is performed as follows <xref ref-type="disp-formula" rid="eqn-1">(1)</xref>:
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:msubsup><mml:mi>x</mml:mi><mml:mi>j</mml:mi><mml:mrow><mml:mtext>scaled</mml:mtext></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:msub><mml:mi>x</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>&#x03BC;</mml:mi><mml:mi>j</mml:mi></mml:msub></mml:mrow><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>j</mml:mi></mml:msub></mml:mfrac><mml:mo>,</mml:mo></mml:math></disp-formula>where:
<list list-type="bullet">
<list-item>
<p><inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:msub><mml:mi>&#x03BC;</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mi>N</mml:mi></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>N</mml:mi></mml:munderover><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is the mean of the <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:mi>j</mml:mi></mml:math></inline-formula>-th feature across all samples.</p></list-item>
<list-item>
<p><inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msqrt><mml:mfrac><mml:mn>1</mml:mn><mml:mi>N</mml:mi></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>N</mml:mi></mml:munderover><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>&#x03BC;</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup></mml:msqrt></mml:math></inline-formula> is the standard deviation of the <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:mi>j</mml:mi></mml:math></inline-formula>-th feature.</p></list-item>
</list></p>
<p>This process ensures that the scaled feature <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:msubsup><mml:mi>x</mml:mi><mml:mi>j</mml:mi><mml:mrow><mml:mtext>scaled</mml:mtext></mml:mrow></mml:msubsup></mml:math></inline-formula> has <xref ref-type="disp-formula" rid="eqn-2">(2)</xref>:
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:mrow><mml:mi mathvariant="double-struck">E</mml:mi></mml:mrow><mml:mrow><mml:mo>[</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mi>j</mml:mi><mml:mrow><mml:mtext>scaled</mml:mtext></mml:mrow></mml:msubsup><mml:mo>]</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mn>0</mml:mn><mml:mspace width="1em" /><mml:mtext>&#xA0;and&#xA0;</mml:mtext><mml:mspace width="1em" /><mml:mi>Var</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mi>j</mml:mi><mml:mrow><mml:mtext>scaled</mml:mtext></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mn>1.</mml:mn></mml:math></disp-formula></p>
<p>The entire feature matrix <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:msub><mml:mi>X</mml:mi><mml:mrow><mml:mtext>scaled</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula> is then used as the input for the model.</p>
<p><bold>Label Encoding:</bold> In classification tasks, the target labels are often categorical, so we need to convert the labels into a numerical form that can be used by machine learning models. Label encoding is a common method for transforming categorical labels into integers.</p>
<p>Let <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:msub><mml:mi>y</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> be the categorical class label of the <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mi>i</mml:mi></mml:math></inline-formula>-th sample, where <italic>C</italic> is the number of classes. The goal is to map each class label to an integer, so the transformation is defined as <xref ref-type="disp-formula" rid="eqn-3">(3)</xref>:
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:msubsup><mml:mi>y</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mtext>encoded</mml:mtext></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mi>LabelEncoder</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>y</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:msubsup><mml:mi>y</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mtext>encoded</mml:mtext></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> represents the corresponding index of the label in a sorted list of unique classes.</p>
<p>The resulting encoded labels are stored in a vector <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:msup><mml:mi>y</mml:mi><mml:mrow><mml:mtext>encoded</mml:mtext></mml:mrow></mml:msup><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mi>N</mml:mi></mml:msup></mml:math></inline-formula>, where each <inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:msubsup><mml:mi>y</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mtext>encoded</mml:mtext></mml:mrow></mml:msubsup></mml:math></inline-formula> represents the integer value corresponding to the original class label.</p>
<p><bold>One-Hot Encoding:</bold> While label encoding is a simple way of converting categorical labels into integers, for many classification tasks, especially in neural networks, it is more effective to represent each class label as a one-hot encoded vector. In one-hot encoding, each class label is represented as a vector where only the index corresponding to the label is 1, and all other indices are 0.</p>
<p>For a given encoded label <inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:msubsup><mml:mi>y</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mtext>encoded</mml:mtext></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, we convert it into a one-hot vector <inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:msubsup><mml:mi>y</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mtext>onehot</mml:mtext></mml:mrow></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mi>C</mml:mi></mml:msup></mml:math></inline-formula>. The one-hot encoding is given by <xref ref-type="disp-formula" rid="eqn-4">(4)</xref>:
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:msubsup><mml:mi>y</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mtext>onehot</mml:mtext></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">]</mml:mo></mml:math></disp-formula>where the 1 appears at the index <inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:msubsup><mml:mi>y</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mtext>encoded</mml:mtext></mml:mrow></mml:msubsup></mml:math></inline-formula>, and all other positions are 0.</p>
<p>The entire matrix of one-hot encoded labels is represented as <inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:msup><mml:mi>Y</mml:mi><mml:mrow><mml:mtext>onehot</mml:mtext></mml:mrow></mml:msup><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mrow><mml:mi>N</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mi>C</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>, where each row <inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:msubsup><mml:mi>y</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mtext>onehot</mml:mtext></mml:mrow></mml:msubsup></mml:math></inline-formula> corresponds to the one-hot encoded vector for the <inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:mi>i</mml:mi></mml:math></inline-formula>-th sample.</p>
</sec>
<sec id="s3_2_2">
<label>3.2.2</label>
<title>Hybrid WGAN-AE Model</title>
<p>The WGAN-AE is an upgraded model that combines the best features of autoencoders with GANs to offer superior attack detection in IoT networks. The model has two main modules: Autoencoder and Discriminator. In addition to that, the Wasserstein loss helps improve the training stability since the overall model learned to reconstruct the input data and distinguish between real and that which has been simulated. Mathematical formulation of the Hybrid WGAN-AE model is presented in this section.</p>
<p><italic>A. Generator Architecture (Autoencoder)</italic></p>
<p>A combination of an encoder and a decoder module constitutes the generator using the autoencoder structure. The autoencoder learns to accurately compress/input data into a low-dimensional representation, able to reconstruct the same input data from low-dimensionality space.
<list list-type="bullet">
<list-item>
<p>Encoder: The encoder maps the input data <inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> from the input space <inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mi>d</mml:mi></mml:msup></mml:math></inline-formula> to a lower-dimensional latent space. The encoder can be defined by a function <inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:msub><mml:mi>f</mml:mi><mml:mi>&#x03B8;</mml:mi></mml:msub><mml:mo>:</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mi>d</mml:mi></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mi>z</mml:mi></mml:msup></mml:math></inline-formula>, where <inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:mi>&#x03B8;</mml:mi></mml:math></inline-formula> represents the parameters of the encoder, and <inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:mi>z</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mi>z</mml:mi></mml:msup></mml:math></inline-formula> is the latent representation. Mathematically, the encoder can be expressed as:
<disp-formula id="ueqn-5"><mml:math id="mml-ueqn-5" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:msub><mml:mi>z</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>&#x03B8;</mml:mi></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>where <inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:msub><mml:mi>z</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is the compressed representation of <inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>.</p></list-item>
<list-item>
<p>Decoder: The decoder is responsible for reconstructing the original input <inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> from the latent vector <inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:msub><mml:mi>z</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>. The decoder function <inline-formula id="ieqn-37"><mml:math id="mml-ieqn-37"><mml:msub><mml:mi>g</mml:mi><mml:mi>&#x03D5;</mml:mi></mml:msub><mml:mo>:</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mi>z</mml:mi></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mi>d</mml:mi></mml:msup></mml:math></inline-formula> is parameterized by <inline-formula id="ieqn-38"><mml:math id="mml-ieqn-38"><mml:mi>&#x03D5;</mml:mi></mml:math></inline-formula>, and the reconstruction <inline-formula id="ieqn-39"><mml:math id="mml-ieqn-39"><mml:msub><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is given by:
<disp-formula id="ueqn-6"><mml:math id="mml-ueqn-6" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:msub><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>g</mml:mi><mml:mi>&#x03D5;</mml:mi></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>z</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>where <inline-formula id="ieqn-40"><mml:math id="mml-ieqn-40"><mml:msub><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is the reconstructed input.</p>
<p>The loss function for the autoencoder is typically the reconstruction loss, which measures how well the decoder can approximate the original input <inline-formula id="ieqn-41"><mml:math id="mml-ieqn-41"><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> from the latent code <inline-formula id="ieqn-42"><mml:math id="mml-ieqn-42"><mml:msub><mml:mi>z</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>. The reconstruction loss is given by:
<disp-formula id="ueqn-7"><mml:math id="mml-ueqn-7" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd /><mml:mtd><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mtext>recon</mml:mtext></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mo symmetric="true">&#x2016;</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo symmetric="true">&#x2016;</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mn>2</mml:mn></mml:msubsup><mml:mo>,</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>where <inline-formula id="ieqn-43"><mml:math id="mml-ieqn-43"><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mo fence="false" stretchy="false">&#x2016;</mml:mo><mml:mn>2</mml:mn><mml:mn>2</mml:mn></mml:msubsup></mml:math></inline-formula> denotes the squared Euclidean distance.</p></list-item>
</list></p>
<p><italic>B. Discriminator Architecture</italic></p>
<p>The discriminator is a neural network that distinguishes between real data (from the dataset) and fake data (generated by the autoencoder). It is defined as a binary classifier <inline-formula id="ieqn-44"><mml:math id="mml-ieqn-44"><mml:msub><mml:mi>D</mml:mi><mml:mi>&#x03C8;</mml:mi></mml:msub><mml:mo>:</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mi>d</mml:mi></mml:msup><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-45"><mml:math id="mml-ieqn-45"><mml:msub><mml:mi>D</mml:mi><mml:mi>&#x03C8;</mml:mi></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> indicates that <inline-formula id="ieqn-46"><mml:math id="mml-ieqn-46"><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is real and <inline-formula id="ieqn-47"><mml:math id="mml-ieqn-47"><mml:msub><mml:mi>D</mml:mi><mml:mi>&#x03C8;</mml:mi></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula> indicates that <inline-formula id="ieqn-48"><mml:math id="mml-ieqn-48"><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is fake.</p>
<p>For the input data <inline-formula id="ieqn-49"><mml:math id="mml-ieqn-49"><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>, the discriminator outputs a scalar <inline-formula id="ieqn-50"><mml:math id="mml-ieqn-50"><mml:msub><mml:mi>D</mml:mi><mml:mi>&#x03C8;</mml:mi></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> representing the probability that <inline-formula id="ieqn-51"><mml:math id="mml-ieqn-51"><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is real. The discriminator is trained to maximize this probability when the data is real and minimize it when the data is fake. Thus, the loss for the discriminator can be described as <xref ref-type="disp-formula" rid="eqn-5">(5)</xref>:
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mtext>disc</mml:mtext></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">E</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi><mml:mo>&#x223C;</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>real</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo>[</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mi>&#x03C8;</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>]</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">E</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mo>&#x223C;</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>gen</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo>[</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mi>&#x03C8;</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>]</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-52"><mml:math id="mml-ieqn-52"><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>real</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula> indicates the distribution of real data and <inline-formula id="ieqn-53"><mml:math id="mml-ieqn-53"><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>gen</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula> represents the distribution of generated data.</p>
<p>The goal of the discriminator is to correctly classify real data as 1 and fake data as 0, minimizing the above loss function.</p>
<p><italic>C. Wasserstein Loss for WGAN-AE</italic></p>
<p>A key component of the Hybrid WGAN-AE is the Wasserstein loss, which is used to stabilize the training process, and to generate better samples.</p>
<p>The Wasserstein loss [<xref ref-type="bibr" rid="ref-24">24</xref>] for the discriminator is given by <xref ref-type="disp-formula" rid="eqn-6">(6)</xref>:
<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mtext>Wasserstein</mml:mtext></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">E</mml:mi></mml:mrow><mml:mrow><mml:mi>x</mml:mi><mml:mo>&#x223C;</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>real</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo>[</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mi>&#x03C8;</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>]</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">E</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mo>&#x223C;</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mtext>gen</mml:mtext></mml:mrow></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo>[</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mi>&#x03C8;</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>]</mml:mo></mml:mrow><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>This loss function trains the discriminator to give high values to real data and low values to the generated data, thus trying to increase the distance between the two distributions. The Wasserstein loss has smoother gradients and solves the vanishing gradient problem that is typical for standard GANs.</p>
<p>The generator is trained to minimize the Wasserstein loss in the opposite direction, i.e., to minimize <inline-formula id="ieqn-54"><mml:math id="mml-ieqn-54"><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mtext>Wasserstein,</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula> which ensures that the generated data distribution approaches the real data distribution.</p>
<p><italic>D. Combined Model</italic></p>
<p>In the Hybrid WGAN-AE, the combined model is trained alongside both the generator and the discriminator. The purpose of the combined model is to train the generator to create data that looks realistic enough to fool the discriminator. Nevertheless, the generator tries to minimize the reconstruction error as well so that the produced data is both realistic and consistent with the input data.</p>
<p>The total loss for the combined model is a weighted sum of the reconstruction loss and the Wasserstein loss. The combined loss can be written as follows:
<disp-formula id="ueqn-2255"><mml:math id="mml-ueqn-2255" display="block"><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mtext>combined&#xA0;</mml:mtext></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>&#x03BB;</mml:mi><mml:mrow><mml:mtext>recon&#xA0;</mml:mtext></mml:mrow></mml:msub><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mtext>recon&#xA0;</mml:mtext></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:msub><mml:mi>&#x03BB;</mml:mi><mml:mrow><mml:mtext>Wasserstein&#xA0;</mml:mtext></mml:mrow></mml:msub><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mtext>Wasserstein&#xA0;</mml:mtext></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-55"><mml:math id="mml-ieqn-55"><mml:msub><mml:mi>&#x03BB;</mml:mi><mml:mrow><mml:mtext>recon</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-56"><mml:math id="mml-ieqn-56"><mml:msub><mml:mi>&#x03BB;</mml:mi><mml:mrow><mml:mtext>Wasserstein</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula> are hyperparameters controlling the relative importance of the reconstruction loss and the Wasserstein loss. The generator is trained to minimize this combined loss. The workflow of WGAN-AE is summarized in Algorithm 1.</p>
<fig id="fig-12">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_64874-fig-12.tif"/>
</fig>
<p><italic>E. Training Procedure</italic></p>
<p>The training procedure alternates between updating the discriminator and the generator:
<list list-type="simple">
<list-item><label>1.</label><p>Discriminator Update: The discriminator is trained to distinguish between real and fake data by minimizing <inline-formula id="ieqn-69"><mml:math id="mml-ieqn-69"><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mtext>disc&#xA0;</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula>. The real data samples <inline-formula id="ieqn-70"><mml:math id="mml-ieqn-70"><mml:msub><mml:mi>x</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> are drawn from the dataset, and the fake data samples <inline-formula id="ieqn-71"><mml:math id="mml-ieqn-71"><mml:msub><mml:mrow><mml:mover><mml:mi>x</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> are generated by the autoencoder.</p></list-item>
<list-item><label>2.</label><p>Generator Update: The generator is updated to minimize the combined loss <inline-formula id="ieqn-72"><mml:math id="mml-ieqn-72"><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mtext>combined,&#xA0;</mml:mtext></mml:mrow></mml:msub></mml:math></inline-formula> which includes both the reconstruction error and the Wasserstein loss. This is done by training the generator to fool the discriminator and simultaneously reconstruct the input data accurately.</p></list-item>
</list></p>
<p>The discriminator&#x2019;s parameters <inline-formula id="ieqn-73"><mml:math id="mml-ieqn-73"><mml:mi>&#x03C8;</mml:mi></mml:math></inline-formula> are updated using a standard optimization algorithm, while the generator&#x2019;s parameters <inline-formula id="ieqn-74"><mml:math id="mml-ieqn-74"><mml:mi>&#x03B8;</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-75"><mml:math id="mml-ieqn-75"><mml:mi>&#x03D5;</mml:mi></mml:math></inline-formula> are updated jointly. The training process is summarized in the Algorithm 2.</p>
<fig id="fig-13">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_64874-fig-13.tif"/>
</fig>
</sec>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Experiments and Results</title>
<p>The proposed WGAN-AE architecture is implemented and evaluated in the Google Colab Pro platform. To ensure the optimal training of WGAN-AE, we selected the range of suitable hyperparameters through the hit and trial method. The customized and default hyperparameters utilized in training are presented in <xref ref-type="table" rid="table-2">Tables 2</xref> and <xref ref-type="table" rid="table-3">3</xref>, respectively. The following provides a brief discussion of the experimental procedures and an in-depth analysis of experimental outcomes.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Customized hyperparameters for the training of proposed WGAN-AE</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Parameter</th>
<th>Value</th>
</tr>
</thead>
<tbody>
<tr>
<td>Encoding dimension</td>
<td>14</td>
</tr>
<tr>
<td>Discriminator layers</td>
<td>128, 64 neurons (ReLU activation)</td>
</tr>
<tr>
<td>Generator activation</td>
<td>ReLU (encoding), Sigmoid (decoding)</td>
</tr>
<tr>
<td>Loss function (GAN)</td>
<td>Wasserstein Loss</td>
</tr>
<tr>
<td>Loss function (Final Model)</td>
<td>Mean squared error, Categorical Crossentropy (loss weights: 0.5, 0.5)</td>
</tr>
<tr>
<td>Optimizer</td>
<td>Adam</td>
</tr>
<tr>
<td>Batch size</td>
<td>256</td>
</tr>
<tr>
<td>Epochs (GAN Training)</td>
<td>10</td>
</tr>
<tr>
<td>Epochs (K-Fold Training)</td>
<td>5</td>
</tr>
<tr>
<td>K-Fold splits</td>
<td>5</td>
</tr>
<tr>
<td>Random seed</td>
<td>42</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Default hyperparameters for the training of proposed WGAN-AE</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Parameter</th>
<th>Default value</th>
</tr>
</thead>
<tbody>
<tr>
<td>Learning rate (Adam Optimizer)</td>
<td>0.001</td>
</tr>
<tr>
<td>Beta1 (Adam Optimizer)</td>
<td>0.9</td>
</tr>
<tr>
<td>Beta2 (Adam Optimizer)</td>
<td>0.999</td>
</tr>
<tr>
<td>Epsilon (Adam Optimizer)</td>
<td>1e-7</td>
</tr>
<tr>
<td>Weight initialization (Dense Layers)</td>
<td>Xavier initialization</td>
</tr>
</tbody>
</table>
</table-wrap>
<sec id="s4_1">
<label>4.1</label>
<title>Performance Evaluation with 5G-NIDD Dataset</title>
<p>The 5G-NIDD dataset is an important benchmark for evaluating the performance of intrusion detection systems in next-generation 5G-enabled IoT networks, characterized by speed, low latency, and a variety of threats. The following presents a brief discussion of the experimental results.</p>
<sec id="s4_1_1">
<label>4.1.1</label>
<title>Cross-Validation Performance</title>
<p>To ensure robustness, the model was subjected to five-fold cross validation to prevent overfitting on a single dataset. The five-fold cross-validation results are shown in <xref ref-type="fig" rid="fig-4">Fig. 4</xref>. The experimental outcomes delivered quite impressive Precision-Recall AUC scores ranging from <inline-formula id="ieqn-89"><mml:math id="mml-ieqn-89"><mml:mn>99.79</mml:mn></mml:math></inline-formula>% to <inline-formula id="ieqn-90"><mml:math id="mml-ieqn-90"><mml:mn>99.91</mml:mn></mml:math></inline-formula>%, with an average of <inline-formula id="ieqn-91"><mml:math id="mml-ieqn-91"><mml:mn>99.8</mml:mn></mml:math></inline-formula>7%. This is because the model is very precise, with low false positive and false negative rates for high accuracy. The scores for the Balanced Accuracy ranged from <inline-formula id="ieqn-92"><mml:math id="mml-ieqn-92"><mml:mn>98.79</mml:mn></mml:math></inline-formula>% to <inline-formula id="ieqn-93"><mml:math id="mml-ieqn-93"><mml:mn>98.97</mml:mn></mml:math></inline-formula>% with an average of <inline-formula id="ieqn-94"><mml:math id="mml-ieqn-94"><mml:mn>98.91</mml:mn></mml:math></inline-formula>%. These cross validation results show that the model is highly generalizable with stable performance across different data splits.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>5-fold cross validation with 5G-NIDD dataset</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_64874-fig-4.tif"/>
</fig>
</sec>
<sec id="s4_1_2">
<label>4.1.2</label>
<title>Test Set Performance</title>
<p>To further assess the model&#x2019;s effectiveness, it was evaluated on an independent test set, where it achieved a notable performance score. The accuracy was <inline-formula id="ieqn-95"><mml:math id="mml-ieqn-95"><mml:mn>97.35</mml:mn></mml:math></inline-formula>%, with precision, recall and F1-score all being very close to each other at <inline-formula id="ieqn-96"><mml:math id="mml-ieqn-96"><mml:mn>97.39</mml:mn></mml:math></inline-formula>%, <inline-formula id="ieqn-97"><mml:math id="mml-ieqn-97"><mml:mn>97.35</mml:mn></mml:math></inline-formula>%, and <inline-formula id="ieqn-98"><mml:math id="mml-ieqn-98"><mml:mn>97.35</mml:mn></mml:math></inline-formula>, respectively. These almost equal values across the different metrics indicate that the model has a good center that helps it avoid false positives and negatives. The high F1 score further confirms that both precision and recall are good, so the model does not give many false positives while also detecting malicious traffic effectively.</p>
</sec>
<sec id="s4_1_3">
<label>4.1.3</label>
<title>Multiclass Performance Analysis</title>
<p>The confusion matrix presented in <xref ref-type="fig" rid="fig-5">Fig. 5</xref> provides deeper insights into the model&#x2019;s classification performance. It shows that the model made few misclassifications, particularly for well-defined attack patterns such as UDP Flood, HTTP Flood, and SYN Scan. However, some minor misclassifications were observed between attacks with similar characteristics, such as SYN Flood and TCP Connect Scan, where the model occasionally confused connection-based attacks due to their similar network behavior profiles. Despite these minor misclassifications, the overall error rate was low, reinforcing the model&#x2019;s high reliability. <xref ref-type="fig" rid="fig-6">Fig. 6</xref> presents a detailed multiclass performance evaluation.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Confusion matrix for 5G-NIDD dataset</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_64874-fig-5.tif"/>
</fig><fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Multiclass performance evaluation with 5G-NIDD dataset</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_64874-fig-6.tif"/>
</fig>
</sec>
<sec id="s4_1_4">
<label>4.1.4</label>
<title>Computational Performance Analysis</title>
<p>The computational performance analysis of the proposed WGAN-AE model on the 5G-NIDD dataset demonstrates efficient processing capabilities. The training phase was completed in <inline-formula id="ieqn-99"><mml:math id="mml-ieqn-99"><mml:mn>59.20913</mml:mn></mml:math></inline-formula> s, indicating that the model can handle complex data with moderate computational requirements. During the inference stage, the model processed the entire test set in <inline-formula id="ieqn-100"><mml:math id="mml-ieqn-100"><mml:mn>81.51074</mml:mn></mml:math></inline-formula> s, reflecting its capacity to analyze and generate predictions efficiently. The per-sample latency was measured at <inline-formula id="ieqn-101"><mml:math id="mml-ieqn-101"><mml:mn>0.06704</mml:mn></mml:math></inline-formula> ms, ensuring minimal delay during inference. Moreover, the throughput of the model was recorded at <inline-formula id="ieqn-102"><mml:math id="mml-ieqn-102"><mml:mn>14</mml:mn><mml:mo>,</mml:mo><mml:mn>916.93066</mml:mn></mml:math></inline-formula> samples per second, highlighting its capability to process a large volume of data in heterogeneous IoT networks.</p>
</sec>
<sec id="s4_1_5">
<label>4.1.5</label>
<title>Attack Detection Time Analysis</title>
<p>In real-world applications, fast detection of attacks is crucial to mitigate threats in real time. The proposed model demonstrated impressive low-latency performance across various attack types, processing most attacks within <inline-formula id="ieqn-103"><mml:math id="mml-ieqn-103"><mml:mn>0.06</mml:mn></mml:math></inline-formula> to <inline-formula id="ieqn-104"><mml:math id="mml-ieqn-104"><mml:mn>0.08</mml:mn></mml:math></inline-formula> milliseconds. This ensures that it can quickly identify and respond to malicious activities without causing significant delays. However, the ICMP Flood attack took slightly longer to detect at <inline-formula id="ieqn-105"><mml:math id="mml-ieqn-105"><mml:mn>0.29605</mml:mn></mml:math></inline-formula> ms, likely due to its bursty nature and the larger packet sizes involved, which required additional computational resources. Despite this, all other attack detection times remained within sub-millisecond latencies, confirming that the model is well-suited for real-time intrusion detection in 5G-enabled IoT networks. <xref ref-type="fig" rid="fig-7">Fig. 7</xref> illustrates each class&#x2019;s attack detection time.</p>
<fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>Detection time of each individual class in 5G-NIDD dataset</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_64874-fig-7.tif"/>
</fig>
</sec>
<sec id="s4_1_6">
<label>4.1.6</label>
<title>Model Size and Deployment Feasibility</title>
<p>Considering the limited storage and computational resources available on many IoT devices, the model&#x2019;s memory footprint is a key factor for deployment feasibility. The proposed model has a compact size of just <inline-formula id="ieqn-106"><mml:math id="mml-ieqn-106"><mml:mn>60.24</mml:mn></mml:math></inline-formula> kB, making it highly efficient for deployment on resource-constrained IoT devices. The smaller memory footprint, high detection accuracy, and low latency make it an ideal choice for deployment in real-world IoT networks.</p>
</sec>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Performance Evaluation with IDSIoT2024 Dataset</title>
<p>The IDSIoT2024 dataset contains diverse IoT traffic data to evaluate IDSs in dynamic and resource-constrained IoT networks. The following provides a detailed analysis of experimental results with the IDS IoT 2024 dataset.</p>
<sec id="s4_2_1">
<label>4.2.1</label>
<title>Cross-Validation Performance</title>
<p>The five-fold cross-validation results are presented in <xref ref-type="fig" rid="fig-8">Fig. 8</xref>. The Precision-Recall AUC scores for the five folds were very high, with an average of <inline-formula id="ieqn-107"><mml:math id="mml-ieqn-107"><mml:mn>94.09</mml:mn></mml:math></inline-formula>%, ranging from <inline-formula id="ieqn-108"><mml:math id="mml-ieqn-108"><mml:mn>91.81</mml:mn></mml:math></inline-formula>% to <inline-formula id="ieqn-109"><mml:math id="mml-ieqn-109"><mml:mn>95.66</mml:mn></mml:math></inline-formula>%. This shows that the model is capable of a good precision-recall tradeoff, i.e., it can avoid many false positives and false negatives. The Balanced Accuracy values were also very good, with a range of <inline-formula id="ieqn-110"><mml:math id="mml-ieqn-110"><mml:mn>88.54</mml:mn></mml:math></inline-formula>%&#x2013;<inline-formula id="ieqn-111"><mml:math id="mml-ieqn-111"><mml:mn>91.59</mml:mn></mml:math></inline-formula>% and an average of <inline-formula id="ieqn-112"><mml:math id="mml-ieqn-112"><mml:mn>90.53</mml:mn></mml:math></inline-formula>%. These results show that the model performs reliably in distinguishing attack and benign traffic without bias and thus is likely to be deployable in a generalizable manner across IoT networks.</p>
<fig id="fig-8">
<label>Figure 8</label>
<caption>
<title>5-fold cross validation with IDSIoT2024 dataset</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_64874-fig-8.tif"/>
</fig>
</sec>
<sec id="s4_2_2">
<label>4.2.2</label>
<title>Test Set Performance</title>
<p>After training the model using the training dataset and validating its efficiency using the validation set, it performed exceptionally on an independent test set with high accuracy of <inline-formula id="ieqn-113"><mml:math id="mml-ieqn-113"><mml:mn>98.38</mml:mn></mml:math></inline-formula>% to distinguish between normal and malicious traffic. All other metrics like precision, recall and F1 scores were also very close to each other, with values of <inline-formula id="ieqn-114"><mml:math id="mml-ieqn-114"><mml:mn>98.34</mml:mn></mml:math></inline-formula>%, <inline-formula id="ieqn-115"><mml:math id="mml-ieqn-115"><mml:mn>98.38</mml:mn></mml:math></inline-formula>% and <inline-formula id="ieqn-116"><mml:math id="mml-ieqn-116"><mml:mn>98.27</mml:mn></mml:math></inline-formula>%, respectively. This indicates that the model performs well without being too sensitive or ignoring real anomalies. Furthermore, the decision-making process of the model is straightforward, making it easy to interpret and trust the results.</p>
</sec>
<sec id="s4_2_3">
<label>4.2.3</label>
<title>Multiclass Performance Analysis</title>
<p>The confusion matrix in <xref ref-type="fig" rid="fig-9">Fig. 9</xref> gives a more accurate view of the model&#x2019;s classification accuracy. When the multi-class evaluation was performed, the model&#x2019;s performance was found to be consistent across all the other classes except the &#x2018;Injection&#x2019; class. This means that although the model is very good at identifying different attacks, there could be some difficulties in distinguishing between some of the attacks, especially Injection attacks, which may have attack patterns that are similar to those of other malicious activities. The low performance in this case can be ascribed to the characteristics of Injection attacks which are often quiet and their traffic is not easily distinguishable. Nonetheless, the general multiclass performance is good which indicates that the model is well positioned to deal with different kinds of attacks. The multiclass performance is detailed in <xref ref-type="fig" rid="fig-10">Fig. 10</xref>.</p>
<fig id="fig-9">
<label>Figure 9</label>
<caption>
<title>Confusion matrix for IDSIoT2024 dataset</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_64874-fig-9.tif"/>
</fig><fig id="fig-10">
<label>Figure 10</label>
<caption>
<title>Multiclass performance evaluation with IDSIoT2024 dataset</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_64874-fig-10.tif"/>
</fig>
</sec>
<sec id="s4_2_4">
<label>4.2.4</label>
<title>Computational Performance Analysis</title>
<p>For the IDSIoT2024 dataset, the proposed WGAN-AE model exhibited a significantly lower training time of 10.67866 s, suggesting that the model adapts efficiently to this dataset. The inference time for the complete test set was remarkably fast at 6.43554 s, emphasizing the model&#x2019;s ability to handle large-scale IoT data effectively. The latency per sample was recorded at 0.06684 ms, demonstrating minimal delay during prediction. Additionally, the throughput achieved was 14,960.67771 samples per second, reflecting a high data processing rate, which is crucial for real-time IoT applications. These results affirm that the WGAN-AE model is computationally efficient across diverse datasets, making it well-suited for high-throughput environments.</p>
</sec>
<sec id="s4_2_5">
<label>4.2.5</label>
<title>Attack Detection Time Analysis</title>
<p>The model demonstrated impressive efficiency with attack detection times, processing most attacks in sub-millisecond times, ranging from <inline-formula id="ieqn-117"><mml:math id="mml-ieqn-117"><mml:mn>0.05841</mml:mn></mml:math></inline-formula> to <inline-formula id="ieqn-118"><mml:math id="mml-ieqn-118"><mml:mn>0.11560</mml:mn></mml:math></inline-formula> ms. The shortest detection times were observed for normal traffic and attacks like DoS and Routing, indicating the model&#x2019;s ability to detect these traffic types quickly. The slightly longer detection times for more complex attacks, such as Injection (0.10729 ms) and MITM (0.11560 ms), still remained well within acceptable thresholds for real-time monitoring. These results highlight the model&#x2019;s suitability for use in environments where prompt threat detection is essential. <xref ref-type="fig" rid="fig-11">Fig. 11</xref> illustrates each class&#x2019;s attack detection time.</p>
<fig id="fig-11">
<label>Figure 11</label>
<caption>
<title>Detection time of each individual class in IDSIoT2024 dataset</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_64874-fig-11.tif"/>
</fig>
</sec>
<sec id="s4_2_6">
<label>4.2.6</label>
<title>Model Size and Deployment Feasibility</title>
<p>The model&#x2019;s compact size of 61.84 kB makes it highly suitable for deployment in resource-constrained IoT environments. This small memory footprint ensures that the model can be easily integrated into IoT devices with limited computational resources. The model&#x2019;s lightweight nature, high detection accuracy, and low detection latency demonstrate its potential for deployment in real-world IoT networks, where both efficiency and security are critical. Given the increasing demand for effective and resource-efficient intrusion detection in IoT systems, this model offers a promising solution for ensuring the security of IoT devices.</p>
</sec>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>Performance Comparison of Proposed WGAN-AE with State-of-the-Art GAN Variants</title>
<p>To analyze the efficacy of the proposed WGAN-AE, we compared the performance with state-of-the-art GAN variants, including vanilla GAN, conditional GAN, least square GAN, Information Maximizing Generative Adversarial Networks (info GAN), and boundary equilibrium GAN. To ensure a fair comparison, we implemented all these GAN models on similar experimentation platforms with similar datasets. The following presents a detailed comparative analysis.</p>
<sec id="s4_3_1">
<label>4.3.1</label>
<title>Detection Rate and False Alarm Rate</title>
<p>The WGAN-AE consistently outperforms other GAN variants in detection accuracy while maintaining lower false alarm rates across different attack classes. <xref ref-type="table" rid="table-4">Table 4</xref> presents comparative evaluation results for the 5G-NIDD dataset. The proposed scheme achieved a remarkable 100% detection rate for ICMPFlood attacks with zero false alarms, a stark contrast to Vanilla GAN&#x2019;s 29.69% detection rate. Similarly, for SYNFlood and SYNScan attacks, WGAN-AE achieves near-perfect detection, significantly surpassing alternatives such as Least Squares GAN and Boundary Equilibrium GAN. The improvement is also evident in benign traffic classification, where WGAN-AE attains a detection rate of 95.84% with a reduced false alarm rate of 1.93%, demonstrating its robustness in distinguishing normal and attack traffic.</p>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Comparative analysis of detection rate (DR) vs. false alarm rate (FAR) for 5GNIDD Dataset (all values are in percentage, %)</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th align="center">Class</th>
<th colspan="2">Vanilla GAN</th>
<th align="center" colspan="2">Conditional GAN</th>
<th align="center" colspan="2">Least Squares GAN</th>
<th colspan="2">Info GAN</th>
<th align="center" colspan="2">Boundary Equilibrium GAN</th>
<th align="center" colspan="2">WGAN-AE (Proposed Scheme)</th>
</tr>
<tr>
<th></th>
<th>DR</th>
<th>FAR</th>
<th>DR</th>
<th>FAR</th>
<th>DR</th>
<th>FAR</th>
<th>DR</th>
<th>FAR</th>
<th>DR</th>
<th>FAR</th>
<th>DR</th>
<th>FAR</th>
</tr>
</thead>
<tbody>
<tr>
<td><bold>Benign</bold></td>
<td>87.094</td>
<td>6.529</td>
<td>82.563</td>
<td>8.047</td>
<td>79.527</td>
<td>6.197</td>
<td>93.227</td>
<td>3.683</td>
<td>87.942</td>
<td>4.784</td>
<td>95.847</td>
<td>1.927</td>
</tr>
<tr>
<td><bold>HTTPFlood</bold></td>
<td>97.532</td>
<td>0.635</td>
<td>98.203</td>
<td>1.074</td>
<td>97.016</td>
<td>0.753</td>
<td>98.455</td>
<td>0.338</td>
<td>97.566</td>
<td>0.517</td>
<td>99.471</td>
<td>0.135</td>
</tr>
<tr>
<td><bold>ICMPFlood</bold></td>
<td>29.697</td>
<td>0.002</td>
<td>0.000</td>
<td>0.000</td>
<td>0.087</td>
<td>0.000</td>
<td>98.788</td>
<td>0.002</td>
<td>61.385</td>
<td>0.005</td>
<td>100.00</td>
<td>0.000</td>
</tr>
<tr>
<td><bold>SYNFlood</bold></td>
<td>85.876</td>
<td>0.019</td>
<td>82.636</td>
<td>0.028</td>
<td>83.870</td>
<td>0.025</td>
<td>86.092</td>
<td>0.010</td>
<td>85.639</td>
<td>0.011</td>
<td>99.928</td>
<td>0.003</td>
</tr>
<tr>
<td><bold>SYNScan</bold></td>
<td>95.375</td>
<td>0.019</td>
<td>92.616</td>
<td>0.050</td>
<td>92.840</td>
<td>0.043</td>
<td>99.606</td>
<td>0.008</td>
<td>97.296</td>
<td>0.016</td>
<td>99.776</td>
<td>0.006</td>
</tr>
<tr>
<td><bold>SlowrateDoS</bold></td>
<td>90.687</td>
<td>0.331</td>
<td>84.521</td>
<td>0.239</td>
<td>88.885</td>
<td>0.375</td>
<td>94.907</td>
<td>0.181</td>
<td>92.338</td>
<td>0.300</td>
<td>98.009</td>
<td>0.065</td>
</tr>
<tr>
<td><bold>TCPConnectScan</bold></td>
<td>98.499</td>
<td>0.188</td>
<td>96.225</td>
<td>0.252</td>
<td>96.848</td>
<td>0.245</td>
<td>98.998</td>
<td>0.116</td>
<td>98.768</td>
<td>0.160</td>
<td>99.771</td>
<td>0.002</td>
</tr>
<tr>
<td><bold>UDPFlood</bold></td>
<td>89.609</td>
<td>8.205</td>
<td>87.211</td>
<td>11.147</td>
<td>90.233</td>
<td>13.147</td>
<td>94.137</td>
<td>4.249</td>
<td>92.384</td>
<td>7.627</td>
<td>96.912</td>
<td>2.604</td>
</tr>
<tr>
<td><bold>UDPScan</bold></td>
<td>93.015</td>
<td>0.019</td>
<td>87.583</td>
<td>0.044</td>
<td>85.924</td>
<td>0.019</td>
<td>99.453</td>
<td>0.005</td>
<td>96.259</td>
<td>0.020</td>
<td>99.642</td>
<td>0.002</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="table" rid="table-5">Table 5</xref> presents the comparative analysis for the IDSIoT2024 dataset. A similar trend is observed in the IDSIoT2024 dataset, where WGAN-AE exhibited high detection rates for Routing (<inline-formula id="ieqn-119"><mml:math id="mml-ieqn-119"><mml:mn>99.35</mml:mn></mml:math></inline-formula>%) and DoS (<inline-formula id="ieqn-120"><mml:math id="mml-ieqn-120"><mml:mn>99.05</mml:mn></mml:math></inline-formula>%) attacks, outperforming all other models. The false alarm rate remains consistently low, reinforcing its reliability for real-world deployment. However, a noticeable weakness emerges in detecting Injection attacks, where it underperformed compared to Information Maximising Generative Adversarial Networks (InfoGAN).</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Comparative analysis of detection rate (DR) vs. false alarm rate (FAR) for IDSIoT2024 Dataset (all values are in percentage, %)</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th rowspan="2" align="center">Class</th>
<th colspan="2">Vanilla GAN</th>
<th align="center" colspan="2">Conditional GAN</th>
<th align="center" colspan="2">Least squares GAN</th>
<th colspan="2">Info GAN</th>
<th align="center" colspan="2">Boundary equilibrium GAN</th>
<th align="center" colspan="2">WGAN-AE (Proposed Scheme)</th>
</tr>
<tr>
<th></th>
<th>DR</th>
<th>FAR</th>
<th>DR</th>
<th>FAR</th>
<th>DR</th>
<th>FAR</th>
<th>DR</th>
<th>FAR</th>
<th>DR</th>
<th>FAR</th>
<th>DR</th>
<th>FAR</th>
</tr>
</thead>
<tbody>
<tr>
<td><bold>DoS</bold></td>
<td>94.093</td>
<td>8.451</td>
<td>97.008</td>
<td>4.893</td>
<td>96.200</td>
<td>14.357</td>
<td>97.993</td>
<td>1.923</td>
<td>95.230</td>
<td>6.198</td>
<td>99.053</td>
<td>0.565</td>
</tr>
<tr>
<td><bold>Injection</bold></td>
<td>34.063</td>
<td>0.078</td>
<td>43.125</td>
<td>0.073</td>
<td>35.859</td>
<td>0.061</td>
<td>52.656</td>
<td>0.118</td>
<td>36.484</td>
<td>0.058</td>
<td>40.156</td>
<td>0.093</td>
</tr>
<tr>
<td><bold>MITM</bold></td>
<td>100.000</td>
<td>0.340</td>
<td>100.00</td>
<td>0.340</td>
<td>100.00</td>
<td>0.340</td>
<td>100.000</td>
<td>0.340</td>
<td>100.00</td>
<td>0.340</td>
<td>100.00</td>
<td>0.340</td>
</tr>
<tr>
<td><bold>Malware</bold></td>
<td>99.180</td>
<td>0.404</td>
<td>99.410</td>
<td>0.210</td>
<td>99.380</td>
<td>0.358</td>
<td>99.190</td>
<td>0.072</td>
<td>99.380</td>
<td>0.298</td>
<td>99.420</td>
<td>0.294</td>
</tr>
<tr>
<td><bold>Normal</bold></td>
<td>82.980</td>
<td>0.935</td>
<td>88.520</td>
<td>0.866</td>
<td>83.510</td>
<td>1.159</td>
<td>91.980</td>
<td>0.935</td>
<td>84.880</td>
<td>0.794</td>
<td>91.030</td>
<td>0.688</td>
</tr>
<tr>
<td><bold>Routing</bold></td>
<td>65.620</td>
<td>2.174</td>
<td>78.330</td>
<td>0.811</td>
<td>33.280</td>
<td>0.806</td>
<td>92.090</td>
<td>0.422</td>
<td>77.100</td>
<td>1.781</td>
<td>99.350</td>
<td>0.010</td>
</tr>
<tr>
<td><bold>Vuln_Analysis</bold></td>
<td>95.510</td>
<td>1.514</td>
<td>97.610</td>
<td>1.332</td>
<td>94.825</td>
<td>1.713</td>
<td>97.590</td>
<td>1.085</td>
<td>95.920</td>
<td>1.401</td>
<td>98.365</td>
<td>1.205</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4_3_2">
<label>4.3.2</label>
<title>Computational Efficiency and Resource Utilization</title>
<p>One of the promising features of WGAN-AE is its efficient training process, which is significantly faster than traditional GANs. The computational efficiency and resource utilization comparison are presented in <xref ref-type="table" rid="table-6">Tables 6</xref> and <xref ref-type="table" rid="table-7">7</xref> for 5G-NIDD and IDSIoT2024 datasets, respectively. On the 5G-NIDD dataset, the training time is reduced to <inline-formula id="ieqn-121"><mml:math id="mml-ieqn-121"><mml:mn>59.2</mml:mn></mml:math></inline-formula> s, compared to InfoGAN&#x2019;s <inline-formula id="ieqn-122"><mml:math id="mml-ieqn-122"><mml:mn>214.9</mml:mn></mml:math></inline-formula> s and Vanilla GAN&#x2019;s <inline-formula id="ieqn-123"><mml:math id="mml-ieqn-123"><mml:mn>208.2</mml:mn></mml:math></inline-formula> s. This efficiency stems from incorporating an autoencoder, which compresses input data before training, substantially reducing computational complexity. A similar advantage is observed in the IDSIoT2024 dataset, where the training time is just <inline-formula id="ieqn-124"><mml:math id="mml-ieqn-124"><mml:mn>10.67</mml:mn></mml:math></inline-formula> s, making WGAN-AE faster training models among its peers. Another notable advantage of WGAN-AE is its remarkably small model size. The model requires only <inline-formula id="ieqn-125"><mml:math id="mml-ieqn-125"><mml:mn>0.060</mml:mn></mml:math></inline-formula> MB for 5G-NIDD and <inline-formula id="ieqn-126"><mml:math id="mml-ieqn-126"><mml:mn>0.061</mml:mn></mml:math></inline-formula> MB for IDSIoT2024, making it an excellent choice for deployment in resource-constrained IoT environments.</p>
<table-wrap id="table-6">
<label>Table 6</label>
<caption>
<title>Comparative analysis of training cost, inferencing time, latency, throughput, and model size for 5GNIDD dataset</title>
</caption>
<table>
<colgroup>
<col/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>GAN variants</th>
<th align="center">Training cost (sec)</th>
<th align="center">Inferencing time (sec)</th>
<th align="center">Latency (ms)</th>
<th align="center">Throughput (Samples/sec)</th>
<th align="center">Model size (MBs)</th>
</tr>
</thead>
<tbody>
<tr>
<td>Vanilla GAN</td>
<td>208.23392</td>
<td>61.12484</td>
<td>0.05027</td>
<td>19891</td>
<td>0.78463</td>
</tr>
<tr>
<td>Conditional GAN</td>
<td>112.46435</td>
<td>60.25724</td>
<td>0.04956</td>
<td>20178</td>
<td>0.78463</td>
</tr>
<tr>
<td>Least squares GAN</td>
<td>155.00871</td>
<td>60.92937</td>
<td>0.05011</td>
<td>19955</td>
<td>8.65162</td>
</tr>
<tr>
<td>Info GAN</td>
<td>214.93845</td>
<td>61.21826</td>
<td>0.05035</td>
<td>19861</td>
<td>0.78463</td>
</tr>
<tr>
<td>Boundary equilibrium GAN</td>
<td>208.44314</td>
<td>71.86630</td>
<td>0.05911</td>
<td>16918</td>
<td>0.78463</td>
</tr>
<tr>
<td>WGAN-AE</td>
<td>59.20913</td>
<td>81.51074</td>
<td>0.06704</td>
<td>14916</td>
<td>0.06024</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-7">
<label>Table 7</label>
<caption>
<title>Comparative analysis of training cost, inferencing time, latency, throughput, and model size for IDSIoT2024 dataset</title>
</caption>
<table>
<colgroup>
<col/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>GAN variants</th>
<th align="center">Training cost (sec)</th>
<th align="center">Inferencing time (sec)</th>
<th align="center">Latency (ms)</th>
<th align="center">Throughput (Samples/sec)</th>
<th align="center">Model size (MBs)</th>
</tr>
</thead>
<tbody>
<tr>
<td>Vanilla GAN</td>
<td>27.15654</td>
<td>5.66325</td>
<td>0.05882</td>
<td>17000</td>
<td>0.79781</td>
</tr>
<tr>
<td>Conditional GAN</td>
<td>19.73150</td>
<td>5.18062</td>
<td>0.05381</td>
<td>18584</td>
<td>0.79781</td>
</tr>
<tr>
<td>Least squares GAN</td>
<td>32.70655</td>
<td>5.26421</td>
<td>0.05468</td>
<td>18289</td>
<td>8.70435</td>
</tr>
<tr>
<td>Info GAN</td>
<td>26.47308</td>
<td>4.95029</td>
<td>0.05142</td>
<td>19449</td>
<td>0.79781</td>
</tr>
<tr>
<td>Boundary equilibrium GAN</td>
<td>24.77814</td>
<td>5.02102</td>
<td>0.05215</td>
<td>19175</td>
<td>0.79781</td>
</tr>
<tr>
<td>WGAN-AE</td>
<td>10.67866</td>
<td>6.43554</td>
<td>0.06684</td>
<td>14960</td>
<td>0.06184</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec id="s4_4">
<label>4.4</label>
<title>Trade-offs and Limitations: A Balanced Perspective on WGAN-AE&#x2019;s Promising Performance</title>
<p>The WGAN-AE model demonstrates remarkable performance in terms of detection accuracy and false alarm reduction, significantly outperforming state-of-the-art GAN variants across diverse attack classes. While a detailed evaluation reveals some trade-offs in inferencing time and throughput, these differences are relatively minor compared to the notable improvements WGAN-AE brings in detection performance.</p>
<sec id="s4_4_1">
<label>4.4.1</label>
<title>Latency and Inferencing Time: Minimal Trade-Offs for Superior Detection</title>
<p>A closer analysis of the inferencing time and latency highlights that although WGAN-AE incurs a slightly higher latency (<inline-formula id="ieqn-127"><mml:math id="mml-ieqn-127"><mml:mn>0.067</mml:mn></mml:math></inline-formula> ms for 5G-NIDD and <inline-formula id="ieqn-128"><mml:math id="mml-ieqn-128"><mml:mn>0.066</mml:mn></mml:math></inline-formula> ms for IDSIoT2024) compared to InfoGAN and Vanilla GAN (around <inline-formula id="ieqn-129"><mml:math id="mml-ieqn-129"><mml:mn>0.051</mml:mn></mml:math></inline-formula> ms), the difference is negligibly small in practical scenarios. This minimal latency overhead is a small price for achieving significantly higher detection rates and lower false alarm rates. In real-world intrusion detection environments, where accurate and reliable attack classification is paramount, this marginal increase in latency does not compromise the system&#x2019;s overall responsiveness.</p>
</sec>
<sec id="s4_4_2">
<label>4.4.2</label>
<title>Throughput: Prioritizing Accuracy over Speed in High-Stakes Scenarios</title>
<p>Similarly, while WGAN-AE demonstrates slightly lower throughput (around <inline-formula id="ieqn-130"><mml:math id="mml-ieqn-130"><mml:mn>14</mml:mn><mml:mo>,</mml:mo><mml:mn>916</mml:mn></mml:math></inline-formula> samples/sec for 5G-NIDD and <inline-formula id="ieqn-131"><mml:math id="mml-ieqn-131"><mml:mn>14</mml:mn><mml:mo>,</mml:mo><mml:mn>960</mml:mn></mml:math></inline-formula> samples/sec for IDSIoT 2024) compared to InfoGAN and Conditional GAN (which process over <inline-formula id="ieqn-132"><mml:math id="mml-ieqn-132"><mml:mn>19</mml:mn><mml:mo>,</mml:mo><mml:mn>000</mml:mn></mml:math></inline-formula> samples/sec), this trade-off is more than compensated for by the model&#x2019;s superior detection performance. Although important in high-speed environments, it becomes secondary in scenarios where accuracy and reliability are critical. For instance, in mission-critical IoT or 5G networks, ensuring that malicious traffic is identified with near-zero false alarms is more desirable than marginally higher processing speed.</p>
</sec>
<sec id="s4_4_3">
<label>4.4.3</label>
<title>Detection Superiority and False Alarm Reduction: WGAN-AE&#x2019;s Competitive Edge</title>
<p>The strength of WGAN-AE lies in its ability to consistently achieve higher detection rates across a wide range of attack types, including difficult-to-detect threats such as ICMPFlood, SYNFlood, TCPConnectScan, and UDPScan, while simultaneously maintaining a significantly lower false alarm rate. For example, on the 5G-NIDD dataset, WGAN-AE achieves a <inline-formula id="ieqn-133"><mml:math id="mml-ieqn-133"><mml:mn>100</mml:mn></mml:math></inline-formula>% detection rate for ICMPFlood attacks with a <inline-formula id="ieqn-134"><mml:math id="mml-ieqn-134"><mml:mn>0</mml:mn></mml:math></inline-formula>% false alarm rate, outperforming all other models. Even for complex attack types in the IDSIoT2024 dataset, WGAN-AE maintains exceptional performance, highlighting its robustness and reliability in detecting both known and emerging threats.</p>
</sec>
</sec>
<sec id="s4_5">
<label>4.5</label>
<title>Future Directions: Enhancing WGAN-AE for Greater Efficiency</title>
<p>While WGAN-AE has already set a high standard in intrusion detection, a few strategic enhancements could further refine its performance regarding inferencing time and throughput. The following two recommendations can help address these minor trade-offs:</p>
<sec id="s4_5_1">
<label>4.5.1</label>
<title>Model Pruning and Lightweight Architectures for Faster Inferencing</title>
<p>Model pruning and lightweight architectures can be employed to minimize inferencing time and latency without sacrificing detection accuracy. Pruning reduces model complexity by removing redundant connections and neurons, leading to a lighter and faster network while retaining essential feature representations. Additionally, incorporating quantization techniques can further reduce model size and computation requirements, making WGAN-AE more efficient for real-time applications. This approach can maintain the model&#x2019;s detection superiority while ensuring faster inferencing in large-scale or latency-sensitive environments.</p>
</sec>
<sec id="s4_5_2">
<label>4.5.2</label>
<title>Parallel Processing and Distributed Inference for Higher Throughput</title>
<p>Implementing parallel processing techniques and distributed inference frameworks can significantly improve performance in high-speed networks, enhancing throughput and enabling real-time intrusion detection. WGAN-AE can process a larger volume of samples concurrently by partitioning incoming network traffic across multiple computational nodes, thereby increasing overall throughput. Additionally, leveraging edge-cloud hybrid architectures can offload preliminary anomaly detection to edge devices, reducing the computational burden on central servers while maintaining accuracy and reliability.</p>
</sec>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Conclusion</title>
<p>This paper proposed a hybrid framework for an efficient IDS for IoT networks using GAN and autoencoder architectures. The proposed WGAN-AE successfully identified a range of cyberattacks with higher accuracy. The performance of the designed IDS framework was evaluated using two open source datasets, 5GNIDD and IDSIoT2024. The experimental outcomes confirm the higher attack detection accuracy in both 5-fold cross-validation scenarios and with respect to independent testing data. The microseconds attack detection time for each class and the low memory footprint makes it suitable for deployment in resource constrained IoT devices and networks.</p>
</sec>
</body>
<back>
<ack><p>The authors extend their appreciation to the Deanship of Research and Graduate Studies at King Khalid University for funding this work through Large Group Project under grant number (RGP.2/245/46). This work is funded by Princess Nourah bint Abdulrahman University Researchers Supporting Project number (PNURSP2025R760), Princess Nourah bint Abdulrahman University, Riyadh, Saudi Arabia. The research team thanks the Deanship of Graduate Studies and Scientific Research at Najran University for supporting the research project through the Nama&#x2019;a program, with the project code NU/GP/SERC/13/352-1.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>The authors extend their appreciation to the Deanship of Research and Graduate Studies at King Khalid University for funding this work through Large Group Project under grant number (RGP.2/245/46). This work is funded by Princess Nourah bint Abdulrahman University Researchers Supporting Project number (PNURSP2025R760), Princess Nourah bint Abdulrahman University, Riyadh, Saudi Arabia. The research team thanks the Deanship of Graduate Studies and Scientific Research at Najran University for supporting the research project through the Nama&#x2019;a program, with the project code NU/GP/SERC/13/352-1.</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>Mohammed S. Alshehri: Writing an original draft, Visualization, Validation, Software, Project administration, Methodology, Investigation, Formal analysis, Conceptualization. Oumaima Saidani: Writing an original draft, Visualization, Methodology, Investigation, Formal analysis, and Conceptualization. Wajdan Al Malwi: Writing, review &#x0026; editing, Writing an original draft, Visualization, Validation. Fatima Asiri: Writing, review &#x0026; editing, Visualization, Validation. Shahid Latif: Writing an original draft, Software, Methodology, Formal analysis. Aizaz Ahmad Khattak: Review &#x0026; editing, Visualization, Methodology. Jawad Ahmad: Review &#x0026; editing, Software, Project administration. All authors reviewed the results and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>We are happy to share the processed datasets and Jupyter Notebooks of the proposed scheme for research purposes upon request, subject to the approval of our research group.</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest to report regarding the present study.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Mehedi</surname> <given-names>ST</given-names></string-name>, <string-name><surname>Anwar</surname> <given-names>A</given-names></string-name>, <string-name><surname>Rahman</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Ahmed</surname> <given-names>K</given-names></string-name>, <string-name><surname>Islam</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Dependable intrusion detection system for IoT: a deep transfer learning based approach</article-title>. <source>IEEE Trans Indus Inform</source>. <year>2022</year>;<volume>19</volume>(<issue>1</issue>):<fpage>1006</fpage>&#x2013;<lpage>17</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TII.2022.3164770</pub-id>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shafiq</surname> <given-names>M</given-names></string-name>, <string-name><surname>Gu</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Cheikhrouhou</surname> <given-names>O</given-names></string-name>, <string-name><surname>Alhakami</surname> <given-names>W</given-names></string-name>, <string-name><surname>Hamam</surname> <given-names>H</given-names></string-name></person-group>. <article-title>The rise of &#x201C;Internet of Things&#x201D;: review and open research issues related to detection and prevention of IoT-based security attacks</article-title>. <source>Wirel Commun Mob Comput</source>. <year>2022</year>;<volume>2022</volume>(<issue>1</issue>):<fpage>8669348</fpage>. doi:<pub-id pub-id-type="doi">10.1155/2022/8669348</pub-id>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jarwar</surname> <given-names>MA</given-names></string-name>, <string-name><surname>FREng</surname> <given-names>JWC</given-names></string-name>, <string-name><surname>Ali</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Modelling industrial IoT security using ontologies: a systematic review</article-title>. <source>IEEE Open J Commun Soc</source>. <year>2025</year>;<volume>6</volume>(<issue>3</issue>):<fpage>2792</fpage>&#x2013;<lpage>821</lpage>. doi:<pub-id pub-id-type="doi">10.1109/OJCOMS.2025.3532224</pub-id>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Latif</surname> <given-names>S</given-names></string-name>, <string-name><surname>Huma</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Jamal</surname> <given-names>SS</given-names></string-name>, <string-name><surname>Ahmed</surname> <given-names>F</given-names></string-name>, <string-name><surname>Ahmad</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zahid</surname> <given-names>A</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Intrusion detection framework for the internet of things using a dense random neural network</article-title>. <source>IEEE Trans Indus Inform</source>. <year>2021</year>;<volume>18</volume>(<issue>9</issue>):<fpage>6435</fpage>&#x2013;<lpage>44</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TII.2021.3130248</pub-id>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Alwaisi</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Soderi</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Towards robust IoT defense: comparative statistics of attack detection in resource-constrained scenarios</article-title>. In: <conf-name>EAI International Conference on Body Area Networks</conf-name>; <year>2024 Feb 4&#x2013;5</year>; <publisher-loc>Milan, Italy</publisher-loc>. p. <fpage>272</fpage>&#x2013;<lpage>91</lpage>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Rahman</surname> <given-names>S</given-names></string-name>, <string-name><surname>Pal</surname> <given-names>S</given-names></string-name>, <string-name><surname>Mittal</surname> <given-names>S</given-names></string-name>, <string-name><surname>Chawla</surname> <given-names>T</given-names></string-name>, <string-name><surname>Karmakar</surname> <given-names>C</given-names></string-name></person-group>. <article-title>SYN-GAN: a robust intrusion detection system using GAN-based synthetic data for IoT security</article-title>. <source>Internet of Things</source>. <year>2024</year>;<volume>26</volume>(<issue>7</issue>):<fpage>101212</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.iot.2024.101212</pub-id>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lin</surname> <given-names>R</given-names></string-name>, <string-name><surname>Qiu</surname> <given-names>H</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>L</given-names></string-name>, <string-name><surname>Shu</surname> <given-names>F</given-names></string-name></person-group>. <article-title>Physical layer security enhancement in energy harvesting-based cognitive internet of things: a GAN-powered deep reinforcement learning approach</article-title>. <source>IEEE Internet of Things J</source>. <year>2024</year>;<volume>11</volume>(<issue>3</issue>):<fpage>4899</fpage>&#x2013;<lpage>913</lpage>. doi:<pub-id pub-id-type="doi">10.1109/JIOT.2023.3300770</pub-id>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Karthika</surname> <given-names>S</given-names></string-name>, <string-name><surname>Durgadevi</surname> <given-names>M</given-names></string-name></person-group>. <chapter-title>Generative Adversarial Network (GAN): a general review on different variants of GAN and applications</chapter-title>. In: <source>2021 6th International Conference on Communication and Electronics Systems (ICCES)</source>. <publisher-loc>Coimbatre, India</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2021</year>. p. <fpage>1</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Fetaya</surname> <given-names>E</given-names></string-name>, <string-name><surname>Jacobsen</surname> <given-names>JH</given-names></string-name>, <string-name><surname>Grathwohl</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zemel</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Understanding the limitations of conditional generative models</article-title>. <comment>arXiv:190601171. 2019</comment>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Cabezon Pedroso</surname> <given-names>T</given-names></string-name>, <string-name><surname>Ser</surname> <given-names>JD</given-names></string-name>, <string-name><surname>D&#x00ED;az-Rodr&#x00ED;guez</surname> <given-names>N</given-names></string-name></person-group>. <article-title>Capabilities, limitations and challenges of style transfer with CycleGANs: a study on automatic ring design generation</article-title>. In: <conf-name>International Cross-Domain Conference for Machine Learning and Knowledge Extraction</conf-name>; <year>2022 Aug 23&#x2013;26</year>; <publisher-loc>Vienna, Austria</publisher-loc>: <publisher-name>Springer</publisher-name>. p. <fpage>168</fpage>&#x2013;<lpage>87</lpage>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hasan</surname> <given-names>MN</given-names></string-name>, <string-name><surname>Jan</surname> <given-names>SU</given-names></string-name>, <string-name><surname>Koo</surname> <given-names>I</given-names></string-name></person-group>. <article-title>Wasserstein GAN-based digital twin-inspired model for early drift fault detection in wireless sensor networks</article-title>. <source>IEEE Sens J</source>. <year>2023</year>;<volume>23</volume>(<issue>12</issue>):<fpage>13327</fpage>&#x2013;<lpage>39</lpage>. doi:<pub-id pub-id-type="doi">10.1109/JSEN.2023.3272908</pub-id>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cai</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Du</surname> <given-names>H</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Si</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Li</surname> <given-names>P</given-names></string-name></person-group>. <article-title>One-dimensional convolutional wasserstein generative adversarial network based intrusion detection method for industrial control systems</article-title>. <source>Electronics</source>. <year>2023</year>;<volume>12</volume>(<issue>22</issue>):<fpage>4653</fpage>. doi:<pub-id pub-id-type="doi">10.3390/electronics12224653</pub-id>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Alrayes</surname> <given-names>FS</given-names></string-name>, <string-name><surname>Zakariah</surname> <given-names>M</given-names></string-name>, <string-name><surname>Amin</surname> <given-names>SU</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>ZI</given-names></string-name>, <string-name><surname>Helal</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Intrusion detection in IoT systems using denoising autoencoder</article-title>. <source>IEEE Access</source>. <year>2024</year>;<volume>12</volume>:<fpage>122401</fpage>&#x2013;<lpage>25</lpage>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Boppana</surname> <given-names>TK</given-names></string-name>, <string-name><surname>Bagade</surname> <given-names>P</given-names></string-name></person-group>. <article-title>GAN-AE: an unsupervised intrusion detection system for MQTT networks</article-title>. <source>Eng Appl Artif Intell</source>. <year>2023</year>;<volume>119</volume>(<issue>11</issue>):<fpage>105805</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.engappai.2022.105805</pub-id>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>S</given-names></string-name>, <string-name><surname>Cao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>S</given-names></string-name>, <string-name><surname>Lai</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Zhu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Ahmad</surname> <given-names>N</given-names></string-name></person-group>. <article-title>HDA-IDS: a hybrid DoS attacks intrusion detection system for IoT by using semi-supervised CL-GAN</article-title>. <source>Expert Syst Appl</source>. <year>2024</year>;<volume>238</volume>(<issue>15</issue>):<fpage>122198</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.eswa.2023.122198</pub-id>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>de Araujo-Filho</surname> <given-names>PF</given-names></string-name>, <string-name><surname>Kaddoum</surname> <given-names>G</given-names></string-name>, <string-name><surname>Campelo</surname> <given-names>DR</given-names></string-name>, <string-name><surname>Santos</surname> <given-names>AG</given-names></string-name>, <string-name><surname>Mac&#x00EA;do</surname> <given-names>D</given-names></string-name>, <string-name><surname>Zanchettin</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Intrusion detection for cyber-physical systems using generative adversarial networks in fog environment</article-title>. <source>IEEE Internet of Things J</source>. <year>2020</year>;<volume>8</volume>(<issue>8</issue>):<fpage>6247</fpage>&#x2013;<lpage>56</lpage>. doi:<pub-id pub-id-type="doi">10.1109/JIOT.2020.3024800</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zeghida</surname> <given-names>H</given-names></string-name>, <string-name><surname>Boulaiche</surname> <given-names>M</given-names></string-name>, <string-name><surname>Chikh</surname> <given-names>R</given-names></string-name>, <string-name><surname>Bamhdi</surname> <given-names>AM</given-names></string-name>, <string-name><surname>Barros</surname> <given-names>ALB</given-names></string-name>, <string-name><surname>Zeghida</surname> <given-names>D</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Enhancing IoT cyber attacks intrusion detection through GAN-based data augmentation and hybrid deep learning models for MQTT network protocol cyber attacks</article-title>. <source>Cluster Comput</source>. <year>2025</year>;<volume>28</volume>(<issue>1</issue>):<fpage>58</fpage>. doi:<pub-id pub-id-type="doi">10.1007/s10586-024-04752-5</pub-id>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Das</surname> <given-names>S</given-names></string-name>, <string-name><surname>Majumder</surname> <given-names>A</given-names></string-name>, <string-name><surname>Namasudra</surname> <given-names>S</given-names></string-name>, <string-name><surname>Singh</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Intrusion detection using CTGAN and lightweight neural network for Internet of Things</article-title>. <source>Expert Syst</source>. <year>2025</year>;<volume>42</volume>(<issue>2</issue>):<fpage>e13793</fpage>. doi:<pub-id pub-id-type="doi">10.1111/exsy.13793</pub-id>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Kandah</surname> <given-names>F</given-names></string-name>, <string-name><surname>Mendis</surname> <given-names>T</given-names></string-name>, <string-name><surname>Medury</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Clustering-based intrusion detection system meets multi-critics generative adversarial networks</article-title>. <source>IEEE Internet Things J</source>. <year>2025</year>. doi:<ext-link ext-link-type="uri" xlink:href="https://10.1109/JIOT.2025.3533918">10.1109/JIOT.2025.3533918</ext-link>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Dong</surname> <given-names>B</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>H</given-names></string-name>, <string-name><surname>Luo</surname> <given-names>R</given-names></string-name></person-group>. <article-title>MasqueradeGAN-GP: a generative adversarial network framework for evading black-box intrusion detection systems</article-title>. <source>Internet Technol Lett</source>. <year>2025</year>;<volume>16</volume>(<issue>8</issue>):<fpage>e640</fpage>. doi:<pub-id pub-id-type="doi">10.1002/itl2.640</pub-id>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Brabin</surname> <given-names>DD</given-names></string-name>, <string-name><surname>Kumar</surname> <given-names>KK</given-names></string-name>, <string-name><surname>Sunitha</surname> <given-names>T</given-names></string-name></person-group>. <article-title>Strengthening security in IoT-based smart cities utilizing cycle-consistent generative adversarial networks for attack detection and secure data transmission</article-title>. <source>Peer Peer Netw Appl</source>. <year>2025</year>;<volume>18</volume>(<issue>2</issue>):<fpage>79</fpage>. doi:<pub-id pub-id-type="doi">10.1007/s12083-024-01838-0</pub-id>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Samarakoon</surname> <given-names>S</given-names></string-name>, <string-name><surname>Siriwardhana</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Porambage</surname> <given-names>P</given-names></string-name>, <string-name><surname>Liyanage</surname> <given-names>M</given-names></string-name>, <string-name><surname>Chang</surname> <given-names>SY</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>J</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>5G-NIDD: a comprehensive network intrusion detection dataset generated over 5G wireless network</article-title>. <source>IEEE Dataport</source>. <year>2022</year>. doi:<pub-id pub-id-type="doi">10.21227/xtep-hv36</pub-id>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Manasa</surname> <given-names>K</given-names></string-name>, <string-name><surname>Leo Joseph</surname> <given-names>LMI</given-names></string-name></person-group>. <article-title>A real time dataset &#x201C;IDSIoT2024&#x201D; for machine learning/deep learning based cyber attack detection system for IoT architecture</article-title>. In: <conf-name>2025 3rd International Conference on Intelligent Data Communication Technologies and Internet of Things (IDCIoT)</conf-name>. <publisher-loc>Bengaluru, India</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. doi:<pub-id pub-id-type="doi">10.21227/gfaz-t124</pub-id>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Arjovsky</surname> <given-names>M</given-names></string-name>, <string-name><surname>Chintala</surname> <given-names>S</given-names></string-name>, <string-name><surname>Bottou</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Wasserstein generative adversarial networks</article-title>. In: <conf-name>International Conference on Machine Learning</conf-name>. <publisher-name>Sydney, Australia</publisher-name>: <publisher-name>PMLR</publisher-name>; <year>2017</year>. p. <fpage>214</fpage>&#x2013;<lpage>23</lpage>. </mixed-citation></ref>
</ref-list>
</back></article>