Browsing by Author "IJEH, Adaora Princess"
Now showing 1 - 1 of 1
- Results Per Page
- Sort Options
Item DEVELOPMENT OF A LIGHTWEIGHT EXPLAINABLE ADAPTIVE FRAMEWORK FOR UNSUPERVISED ANOMALY DETECTION IN ENCRYPTED INTERNET OF THINGS NETWORKS(Covenant University, Ota, 2026-09) IJEH, Adaora Princess; Covenant University, DissertationThe rapid growth of encrypted Internet of Things (IoT) networks has increased the need for lightweight and adaptive anomaly detection methods that can operate without inspecting packet payloads. This study proposes a lightweight, adaptive, and explainable framework for unsupervised anomaly detection in encrypted IoT traffic using a unidirectional GRU autoencoder, Page-Hinkley-based drift and evasion detection, LoRA-based continual adaptation, and a surrogate decision tree for explanations. Experiments on the CIC IoT-DIAD 2024 dataset achieved an F1-score of 0.9415, ROC-AUC of 0.9469, PR-AUC of 0.9673, and false-positive rate of 1.59% for the static baseline. The proposed PH-UP mechanism detected simulated concept drift after 13,127 sequences, while PH-DOWN detected an inserted BruteForce evasion window within 11 sequences. LoRA adaptation required only 768 trainable parameters (0.8% of the model) and achieved an F1-score of 0.9445, while introducing only 0.78% computational overhead. The explainability surrogate produced explanations in 0.240 ms per instance. INT8 quantization reduced the model size by approximately 71.5%, from 384.2 KB to 109.6 KB, with post-recalibration F1-score of 0.9431 and false-positive rate of 1.15%. These results demonstrate that the framework can provide accurate, adaptive, computationally efficient, and explainable anomaly detection for resource-constrained encrypted IoT environments.