SecureEdge-TDM: A Threat-to-Defense Mapping Framework for Secure Edge Computing Using Machine Learning-Based IoT Intrusion Detection
ID:59
View protection:Participant Only
Updated time:2026-07-25 18:02:53
Views:32
Online
Abstract
Edge computing enables low-latency IoT services but also increases exposure to threats such as DDoS, DoS, Mirai, spoofing, reconnaissance, brute-force, malware, and web-based attacks. Most existing intrusion detection studies focus mainly on attack classification and do not link detected threats with suitable defense actions. To address this gap, this paper proposes SecureEdge-TDM, a threat-to-defense mapping framework for secure edge computing. The framework evaluates Decision Tree, Random Forest, Extra Trees, XGBoost, and LightGBM on the CICIoT2023 dataset and maps detected threats to countermeasures such as secure offloading, rate limiting, federated threat intelligence, trusted device verification, policy-as-code enforcement, secure aggregation, and blockchain-based audit logging. Experimental results show that Random Forest achieved 99.628% accuracy and 96.098% macro-F1 for binary detection, while XGBoost achieved 99.499% accuracy and 87.819% macro-F1 for multiclass threat detection. The results show that SecureEdgeTDM supports both effective threat detection and actionable defense recommendation.
Keywords
Edge computing security,IoT intrusion detection,CICIoT2023,machine learning,federated threat intelligence,trusted device verification
Post comments