Method for detection and classification of information security threats during multivector attacks on agents in a decentralized Internet of Things environment
- Authors: Tebueva F.B.1, Petrenko V.I.1, Satybaldina D.Z.2, Ryabtsev S.S.1
-
Affiliations:
- FSAEI HE "North-Caucasus Federal University"
- Research Institute of Information Security and Cryptology of L. N. Gumilyov Eurasian National University
- Issue: Vol 32, No 8 (2026)
- Pages: 437-448
- Section: Information security
- Published: 21.08.2026
- URL: https://journals.eco-vector.com/1684-6400/article/view/717426
- DOI: https://doi.org/10.17587/it.32.437-448
- ID: 717426
Cite item
Abstract
The article presents an innovative method for detecting and classifying multivector attacks in decentralized Internet of Things (IoT) networks, significantly enhancing information security. The proposed approach combines Generative Adversarial Networks (GAN) to create realistic synthetic anomalous data and Reinforcement Learning (RL) algorithms for adaptive real-time updating of the attack detection model. This integration effectively addresses the shortage of high-quality, balanced data on rare and emerging attack types, as well as the dynamic nature of threats in IoT environments, which traditional methods struggle to handle adequately.
The method comprises two key interconnected components: a synthetic anomaly generator that expands the training dataset, and an RL classifier capable of continuous learning on hybrid data that includes both real and generated events. To improve decision-making reliability, a weighted voting mechanism is employed among agents, taking into account the trust levels of each network node. The article provides a detailed description of the RL agent’s neural network architecture, featuring three hidden layers with Batch Normalization and Dropout, along with its training algorithm using Deep Q-Network (DQN) and double Q-learning.
Experimental evaluation was conducted on a synthetic dataset simulating real IoT scenarios with various multivector attacks such as trust undermining, behavior manipulation, data leakage, and cooperation disruption. The results demonstrate significant improvements in recall and F1-score metrics compared to classical machine learning methods, including Random Forest and Support Vector Machine, especially when trained on the extended dataset with GAN-generated synthetic data. The method offers high attack detection accuracy while reducing false positives and maintains adaptability to novel, previously unknown threats. This makes the proposed approach a promising solution for next-generation IoT security systems, capable of effectively operating under resource-constrained devices and dynamically changing environments.
Full Text
About the authors
F. B. Tebueva
FSAEI HE "North-Caucasus Federal University"
Author for correspondence.
Email: ftebueva@ncfu.ru
Dr. of Phys.-Math. Sc., Professor
Russian Federation, StavropolV. I. Petrenko
FSAEI HE "North-Caucasus Federal University"
Email: vipetrenko@ncfu.ru
Cand. of Tech. Sci., Head of Department
Russian Federation, StavropolD. Z. Satybaldina
Research Institute of Information Security and Cryptology of L. N. Gumilyov Eurasian National University
Email: satybaldina_dzh@enu.kz
Cand. of Phys.-Math. Sc., Director
Kazakhstan, AstanaS. S. Ryabtsev
FSAEI HE "North-Caucasus Federal University"
Email: nalfartorn@yandex.ru
Senior Lecturer
Russian Federation, StavropolReferences
- Alfahaid A., Alalwany E., Almars A. M., Alharbi F., Atlam E., Mahgoub I. Machine Learning-Based Security Solutions for IoT Networks: А Comprehensive Survey, Sensors, 2025, vol. 25 (11), article 3341, doi: 10.3390/s25113341.
- Petrenko V. I., Tebueva F. B., Ogur M. G., Linets G. I., Mochalov V. P. Methodology for Detection and Counteraction of Multivector Threats to Information Security in Decentralized IoT Systems, International Journal of Open Information Technologies, 2025, vol. 13, no. 1, pp. 14—24 (in Russian).
- Tebueva F. B., Ryabtsev S. S., Ogur M. G., Andreev I. A., Goryainov S. A. Information Security Threat Model for Agents in Decentralized Internet of Things Environment, Formalizing Attack Scenarios on Trusted Interaction Information Security, Kuznechno-shtampovochnoe proizvodstvo. Obrabotka materialov davleniem, 2024, no.11, pp. 220—232 (in Russian)
- Buja A., Pacolli M., Bajrami D., Polstra P., Mutoh А. Enhancing IoT Security: Development and Evaluation of a Predictive Machine Learning Model for Attack Detection, Advances in Artificial Intelligence and Machine Learning, 2024, vol. 4 (3), pp. 2490—2498, doi: 10.54364/AAIML.2024.43145.
- Gueriani A., Kheddar H., Mazari А. C. Deep Reinforcement Learning for Intrusion Detection in IoT, Proceedings of the 2nd International Conference on Electronics, Energy and Measurement (IC2EM 2023). El Oued, Algeria, 2023, pp. 1—6, doi: 10.1109/IC2EM59981.2023.10410425.
- Alam M. M., Jahan I., Wang W. IoTWarden: А Deep Reinforcement Learning Based Real-time Defense System to Mitigate Trigger-action IoT Attacks, IEEE Wireless Communications and Networking Conference (WCNC). Dubai, United Arab Emirates, 2024, pp. 1—6, doi: 10.1109/WCNC60032.2024.10510657.
- Kotenko I. V., Saenko I. B., Lauta O. S., Vasiliev N. A., Sadovnikov V. E. Attacks and Protection Methods in Machine Learning Systems: Analysis of Recent Studies, Voprosy kiberbezopasnosti, 2024, no. 1 (59), doi: 10.21681/2311-2024-1-24-37 (in Russian).
- Henda N. B., Msolli A., Haggui I., Helali A., Maaref Н. Attack Detection in IoT Network Using Support Vector Machine and Improved Feature Selection Technique, Journal of Network and Systems Management, 2024, vol. 32 (4), pp. 1—20, doi: 10.1007/s10922-024-09871-3.
- Geetha C., Johnson S. D., Oliver A. S., Lekha D. Adaptive Weighted Kernel Support Vector Machine-Based Circle Search Approach for Intrusion Detection in IoT Environments, Signal, Image and Video Processing, 2024, vol. 18 (5), pp. 4479—4490, doi: 10.1007/s11760-024-03088-2.
- Zidan R.A., Karraz G. Towards an Efficient Internet of Things Intrusion Detection by Using Support Vector Machine, Baghdad Science Journal, 2025, vol. 22 (5), article 29, pp. 1714—1724, DOI: https://doi.org/10.21123/bsj.2024.11067.
- Azimjonov J., Kim T. Designing accurate lightweight intrusion detection systems for IoT networks using fine-tuned linear SVM and feature selectors, Computers & Security, 2023, vol. 137, article 103598, doi: 10.1016/j.cose.2023.103598
- Amine M. S., Nada F. A., Hosny K. M. Improved model for intrusion detection in the Internet of Things, Scientific Reports, 2025, vol. 15, article 21547, doi: 10.1038/s41598-025-92852-6.
- Abid M. N., Beggas M., Laouid А. Reinforcement Learning Approach for IoT Security using CyberBattleSim: А Simulation-based Study, 6th International Conference on Pattern Analysis and Intelligent Systems (PAIS), EL OUED, Algeria, 2024, pp. 1—7, doi: 10.1109/PAIS62114.2024.10541295.
- Benaddi H., Jouhari M., Ibrahimi K., Othman J. B., Amhoud E. M. Anomaly Detection in Industrial IoT Using Distributional Reinforcement Learning and Generative Adversarial Networks, Sensors, 2022, vol. 22 (21), article 8085, doi: 10.3390/s22218085.
- Khayat M., Barka E., Serhani M. A., Sallabi F., Shuaib K., Khater Н. M. Reinforcement Learning with Deep Features: А Dynamic Approach for Intrusion Detection in IOT Networks, IEEE Access, 2025, vol. 13, pp. 92319—92337, doi: 10.1109/ACCESS.2025.3569312.
- Al-Ajlan M., Ykhlef M. А Review of Generative Adversarial Networks for Intrusion Detection Systems: Advances, Challenges, and Future Directions, Computers, Materials & Continua, 2024, vol. 8, no. 2, pp. 2053—2076, doi: 10.32604/cmc.2024.055891.
- Cheng Q. C., Tang W., Wang Y. RGAnomaly: Data reconstruction-based generative adversarial networks for multivariate time series anomaly detection in the Internet of Things, Future Generation Computer Systems, 2025, vol. 167, article 107751, doi: 10.1016/j.future.2025.107751.
- Lin Z., Shi Y., Xue Z. IDSGAN: Generative Adversarial Networks for Attack Generation against Intrusion Detection, Advances in Knowledge Discovery and Data Mining. PAKDD 2022. LNCS, 2022, vol. 13282, pp. 79—91, doi: 10.1007/978-3-031-05981-0_7.
- Mubarakali А. Novel GAN-based privacy-enhanced intrusion detection system for cyberattack classification, Intelligent Data Analysis: An International Journal, october 2025, doi: 10.1177/1088467X251372743.
- Ma C., Cui S., Xu M., Ma Z., Li Y., Ding Z. KiNETGAN: Enabling Distributed Network Intrusion Detection through Knowledge-Infused Synthetic Data Generation, arXiv preprint arXiv:2405.16476, 2024, available at: https://arxiv.org/abs/2405.16476.
- Holubenko V., Gaspar D., Leal R., Silva P. Autonomous intrusion detection for IoT: a decentralized and privacy preserving approach, International Journal of Information Security, 2025, vol. 24, no. 7, doi: 10.1007/s10207-024-00926-9.
- Strickland C., Zakar M., Saha C., Nejad S. S., Tasnim N., Lizotte D. J., Haque A. DRL-GAN: А Hybrid Approach for Binary and Multiclass Network Intrusion Detection, Sensors, 2024, vol. 24, no. 9, p. 2746, doi: 10.3390/s24092746.
- Deng Z., Torim A., Yahia S. B., Bahsi Н. Generative AI in Intrusion Detection Systems for Internet of Things: А Systematic Literature Review, IEEE Open Journal of the Computer Society, 2025, vol. 6, pp. 4689—4717, doi: 10.1109/OJCOMS.2025.3573194.
Supplementary files






