Full text
! ©!The!Author(s)!2025.!Open%Access!This!article!is!licensed!under!a!Creative!Commons!Attribution!4.0!International!License,! which! permits! use,! sharing,! adaptation,! distribution! and! reproduction! in! any! medium! or! format,! as! long! as! you! give! appropriate!credit!to!the!original!author(s)!and!the!source,!provide!a!link!to!the!Creative!Commons!licence,!and!indicate!if! changes!were!made.!The!images!or!other!third!party!material!in!this!article!are!included!in!the!article’s!Creative!Commons! licence,! unless! indicated! otherwise!in!a!credit!line!to!the!material.!If!material!is!not!included!in!the!article’s!Creative! Commons!licence!and!your!intended!use!is!not!permitted!by!statutory!regulation!or!exceeds!the!permitted!use,!you!will! need! to! obtain! permission! directly! from! the! copyright! holder.! To! view! a! copy! of! this! licence,! visit! http://creativecommons.org/licenses/by/4.0/! ! 877 RESEARCH ARTICLE OPEN ACCESS Deep Learning Approach for IoT Traffic Multi-Classification in a Smart-City Scenario G Ramasubba Reddy1 . Sunil J1 . S Nareshkumar Reddy1 . L Jayasree2 . T V N Radha Parameswari1 1Department of CSM, Sai Rajeswari Institute of Technology, Proddatur, India. 4Department of CSE, Sri Padmavathi Mahila Vishwavidyalaya, Tirupati, India. DOI:!10.5281/zenodo.17376640! Received:!14!September!2025!/!Revised:!14!October!2025!/!Accepted:!17!October!2025! ©Milestone!Research!Publications,!Part!of!CLOCKSS!archiving Abstract – The recent explosive growth of Internet of Things (IoT) devices in smart cities has grown the attack surface of modern networks exponentially, calling for efficient and scalable intrusion detection means. Classical rule-based and classical machine learning (ML) approaches are typically not able to handle the heterogeneity and dynamic nature of IoT traffic. We recommend Convolutional Neural Networks (CNN) and Long Short-Term Memory (LSTM) networks combined in a hybrid deep learning (DL) model to effectively capture spatial and temporal dependencies in network flow data in this work. We preprocess ACI-IoT-2023 dataset with over 1.23 million records of benign and malware traffic through feature encoding, Min-Max normalization, and feature selection in order to present the inputs as balanced and optimized. Experimental results confirm that the suggested CNN-LSTM model performs superior with improved classification accuracy of 99.99% on average and near-perfect precision, recall, and F1-measures for every attack type. Comparison to traditional baselines including Logistic Regression (LR), Support Vector Machine (SVM), Decision Tree (DT), Random Forest (RF), CNN, and LSTM indicates the robustness and durability of the proposed method. These results indicate that hybrid CNN-LSTM is a strong contender for real-time IoT intrusion detection in the context of smart cities. Index Terms – IoT Security, Intrusion Detection System, DL, ML, CNN-LSTM, Smart City Networks, Network Traffic Classification I. INTRODUCTION In today's smart cities, the IoT is growing rapidly in energy, transportation, healthcare, and surveillance. Secure and reliable communication has become a primitive challenge due to the massive volumes of heterogeneous traffic sent by billions of networked devices [1]. Innovative city architecture
% % %! 878 mainly relies on real-time IoT traffic classification to identify malicious activity and prevent disruptions in essential services [2]. Traditional threshold-based or static rule-based approaches are insufficient for IoT systems because they are dynamic and resource-constrained, unlike conventional networks [3]. However, it is still challenging to classify IoT traffic into multiple classes for several reasons. For example, numerous protocols, data structures, and communication layers are involved in IoT traffic, resulting in intricate and interconnected patterns [4]. Then, conventional cyberattacks that imitate regular traffic, like DDoS, botnets, and spoofing, necessitate high-fidelity feature extraction that goes beyond basic heuristics [5]. Again, hand-crafted or computationally costly solutions cannot be adopted due to the scalability requirements of smart-city networks [6]. The development of computerized, intelligent models that can adapt to changing network infrastructures has been spurred by these challenges. In recent years, many researchers have used ML, and ensemble approaches to detect IoT intrusions. In earlier works, SVMs, k-Nearest Neighbors (k-NN), DTs, RFs, and boosting architectures have exhibited promise [7], [8]. Optimization-inspired strategies, such as Whale Optimization Algorithms, Particle Swarm Optimization, and Genetic Algorithms, have been applied to ML classifiers to assist with feature selection and convergence [6], [7]. While these approaches were more precise in controlled environments, they are still afflicted with substantial limitations: reliance on hand-engineered features, inability to be robust to cross-domain traffic, slow inference speed, and poor accuracy on multi-class attack examples [3], [2]. With hierarchical temporal and spatial features self-learned from raw or preprocessed data streams, DL has started to transform IoT traffic analysis. The temporal and spatial correlations in network traffic dependencies can be learned by Convolutional Neural Networks (CNNs), Recurrent Neural Networks (RNNs), and their hybrid CNN-LSTM models [4]. Different types of advanced techniques, such as hybrid optimization-DL models and graph neural networks (GNNs), have shown promise in simulating dynamic traffic flows and device-to-device interactions [7], [5],[6]. There is still a lot to be done, however: poor generalization in diverse IoT deployments, too many false positives for multi-class detection, and limited benchmarking in real-world smart-city settings. Motivated by the shortcomings of past work, this paper proposes a deep learning multi-classification framework for smart city IoT traffic. To capture local spatial patterns and sequential temporal behaviors of IoT traffic flows, our solution employs CNN-LSTM layers. Our framework also involves regularization and feature refinement techniques, which enhance generalization and alleviate overfitting, thereby increasing robustness. In contrast to conventional methods, the system developed here can automatically identify discriminative patterns from composite traffic without the need for feature engineering, guaranteeing adaptability and flexibility in changing attack situations. The main contributions of this work are the following: • We propose a CNN-LSTM DL architecture designed explicitly for multi-classification of IoT traffic within innovative city environments. • We compare our method against standard ML and hybrid methods on widely used IoT intrusion datasets. • We combine feature selection and regularization techniques to enhance robustness within multiclass contexts.
% % %! 879 • We evaluate computational efficiency and model interpretability to ensure the practical feasibility of our solutions within smart-city infrastructures. II. LITERATURE SURVEY Large amounts of diverse traffic have been caused by the quick expansion of IoT devices in smart cities. Appropriate traffic classification is essential for network management, anomaly detection, and cyberattack prevention. However, IoT environments pose several challenges, including dynamic traffic patterns, encrypted communications, class imbalance, and constrained device resources. As a result, researchers have investigated various ML and DL approaches, followed by more recent transformer-based models and hybrid frameworks, to achieve robust IoT traffic classification and intrusion detection. Conti et al. [9] focused on enhancing IoT security in smart cities by developing a honeypot-driven ML framework. Their methodology reaped attacker activity through decoys and employed ML classifiers to augment training data. Results were improved attack detection, but the process is limited by its dependence on honeypot deployment and inability to scale to real-time multi-class traffic classification. Xie et al. [10] attempted to minimize the computational expenses in IoT traffic classification through the application of knowledge distillation. Following compression and reduction of large teacher models, student models were trained more on benchmark IoT datasets. Although less generalized, accuracy remained constant in highly dynamic traffic. Liao and Guan [11] proposed a multi-scale convolutional feature fusion network with CBAM attention (MCF-CBAM) for classifying IoT traffic. Their approach improved accuracy by eliminating noisy features from traditional IoT datasets. However, the model's capacity to generalize to novel traffic patterns is constrained by convolutional architectures. Afifi et al. [12] addressed the issue of generalization by proposing MIND-IoT, a transformer-based tokenization model that utilizes CNNs. Their proprietary IoT-Tokenize pipeline preserved traffic semantics and was pre-trained on enormous datasets (UNSW IoT Traces and MonIoTr) with subsequent fine-tuning on IoT Sentinel and YourThings. The model's exceptional cross-dataset adaptability was demonstrated by its accuracy of over 98%. However, the approach is computationally intensive, making it impractical to implement in limited IoT edge devices. Ismail et al. [13] demonstrated lightweight ML algorithms for intrusion detection using the TON_IoT, WUSTL-IIoT-2021, and Edge-IIoT datasets. DTs, RFs, and LightGBM were compared, and ensemble approaches were found to have the best trade-off between accuracy and efficiency. However, their models were still dataset-imbalance-sensitive and did not generalize well to unseen traffic classes. Zahid and Bharati [14] proposed a hybrid CNN–BiLSTM model for detecting IoT attacks. Trained on benchmark datasets (KDDCup99, NSL-KDD, and CIC-IDS2017), the method achieved an accuracy of up to 99.9% by combining spatial and temporal feature learning. Although achieving strong outcomes, there are weak aspects, including high training complexity and reduced explainability. Miao and Liao combined CNN and Particle Swarm Optimization (PSO) [15] to intelligently predict city traffic. CNN hyperparameters were dynamically optimized using data from IoT sensors. They improved traffic flow efficiency by 25% and decreased congestion by 20%. Scalability is the main drawback for big, diverse networks. Andrysiak et al. [16] presented GC-YOLOv9, which incorporated Ghost Convolution into YOLOv9 for smart city traffic monitoring. With testing conducted on the BDD100K and Cityscapes
% % %! 880 datasets, the model increased detection accuracy in real-world traffic environments with high complexity. Limitations, however, are its lower inference rates for real-time processing with high data rates. For all such categories, traditional ML and CNN models offer lightweight and efficient solutions; however, they are not generalized across diverse traffic. Transformer models are very flexible but plagued by computational and deployment problems. Hybrid and ensemble models are accurate, but they are either too complex or non-interpretable. Domain-specific extensions in an application domain, such as GCYOLOv9, offer better detection precision but are plagued by real-time scalability challenges. These works altogether demonstrate that robust multi-class IoT traffic classification in smart cities is an open issue due to the trade-off between accuracy, efficiency, and adaptability. We offer a DL system for IoT traffic multiclassification that fills the gap by combining real-time adaptability, flexible model design, and sophisticated feature extraction, providing a comprehensive solution for creative city applications. III. METHODS & MATERIALS The methodology for analysing the paper follows a series of steps that range from data acquisition and preprocessing to feature selection, baseline model evaluation, and the development of a novel CNN+LSTM hybrid deep network architecture. Each step is chosen in order to preserve reproducibility, reliability, and peak performance in IoT traffic multi-classification in a smart-city environment. Figure 1 represents the overall research methodology. Fig. 1: Graphical representation of the overall research methodology A. Dataset Description The dataset utilized here in the study is the ACI-IoT-2023 dataset[17], consisting of 1,231,411 records of network flow traffic collected by various IoT devices located in a smart-city environment. The devices are smart cameras, sensors, thermostats, and voice assistants, and both wired and wireless traffic is emitted from them. Each network flow is labelled as benign or belonging to one of several categories of attacks, like Port Scan, ICMP Flood, DNS Flood, and other types of intrusion. The data set captures detailed flow-level statistics, such as packet counts, packet sizes, inter-arrival times, and TCP/UDP flags, and provides a detailed impression of network activity. These factors are crucial in distinguishing normal vs. malicious network traffic patterns in IoT networks. For a better overview, Table 1 shows some of the most important features selected from the data set:
% % %! 881 Table 1: Summarizing the features of the Dataset Column Name Description Src IP Source device IP address Dst IP Destination device IP address Src Port Source port number Dst Port Destination port number Protocol Network protocol used (TCP, UDP, ICMP, etc.) Flow Duration Duration of the network flow in seconds Total Fwd Packets Total number of packets sent in the forward direction Total Bwd Packets Total number of packets sent in the backward direction Fwd Packet Length Mean Average size of packets in the forward direction Bwd Packet Length Std Standard deviation of packet sizes in the backward direction B. Data Preprocessing Accurate and efficient preprocessing is crucial for multi-class IoT traffic classification. The ACIIoT-2023 dataset consists of numerical and categorical features along with different scales and potential missing values. The preprocessing pipeline was utilized for consistency, noise elimination, and preparing high-quality input for classical and DL models. 1. Handling Missing and Irrelevant Values: Some features had missing, infinite, or undefined values due to measurement errors or division by zero, particularly Flow Bytes/s and Flow Packets/s. These columns were removed to avoid incorrect calculations. Features indirectly beneficial for traffic classification, such as Timestamp, were also removed. This avoids the model focusing on traffic behaviour rather than uninformative metadata for attack detection. 2. Categorical Encoding: Categorical features such as Protocol, Label, and Connection Type were represented as numbers by using Label Encoding, mapping each unique category to an integer of distinct value: 𝑦" #= 𝐿𝑎𝑏𝑒𝑙𝐸𝑛𝑐𝑜𝑑𝑒(𝑦") Where 𝑦"1is the original categorical value and 𝑦" #1is the encoded numerical value. This mapping helps ML and DL models handle categorical inputs efficiently. 3. Feature Normalization: IoT network traffic patterns are extremely diverse in scale, e.g., packet lengths vary from a few bytes to thousands, whereas inter-arrival times vary from milliseconds to seconds. To achieve numerical stability and better convergence of the models, all continuous features were normalized using Min-Max scaling: 𝑥" #=𝑥"− 𝑥4"5 𝑥467 − 𝑥4"5 Where 𝑥" is the original feature value, 𝑥4"511and 𝑥467 are the minimum and maximum values of the feature across the dataset, and 𝑥" # is the normalized value within the range [0, 1] bounded. This normalization process prevents the learning process from being dominated by features with large magnitudes.
% % %! 882 4. Train-Test Split: For estimating model performance, both class-balanced and stable, the data set was split stratified by class labels into training and test subsets of an 80/20 ratio. Stratified splitting preserves the original distribution of attack types in both subsets, which is essential in consideration of the highly unbalanced classes. 5. Feature Selection: Since the dataset is high-dimensional, noise or redundant features can cause higher computational cost and lower model generalizability. Two methods were applied, complementary to each other, for feature selection: Recursive Feature Elimination (RFE): Repeatedly trains a classifier and removes the least significant features according to model weights until reaching the desired number of features. Correlation Analysis: Pearson correlation coefficients are calculated between pairs of features: 𝑟"9 =𝑐𝑜𝑛𝑣(1𝑥", 𝑥9) 𝜎7=𝜎7> Where 𝑐𝑜𝑛𝑣(1𝑥", 𝑥9) is the covariance between features 1𝑥"1𝑎𝑛𝑑1𝑥9 and 𝜎7= is the standard deviation of 1𝑥". Features with |𝑟"9| > 0.9 were excluded to avoid multicollinearity. The chosen feature vector for every flow that was achieved is represented as: 𝑋 = 𝑥B, 𝑥C,……….,𝑥51𝑥"𝜖ℝ where 𝑛1is the number of chosen features. 6. Handling Imbalanced Classes: IoT traffic data sets exhibit extremely skewed class imbalance, i.e., rare attacks like ARP Spoofing vs. common Port Scan occurrence. To counter this: Stratified Sampling: Provides proportionate representation of all classes in the training and test sets. B. Methodology 1. Baseline Models: To provide a comparison baseline, several ML models were employed as baseline classifiers for the multi-classification of IoT traffic. The models were selected based on their proven suitability for intrusion detection and multi-class classification tasks. • Logistic Regression (LR): LR was employed as a linear baseline model, an interpretable and lightweight classifier. LR is utilized to predict the likelihood of a traffic flow being in a specific attack or benign class through a SoftMax function for multi-class classification. 𝑃 𝑦 = 𝑐 𝑥 = exp1(𝛽L M𝑥) (𝛽N M𝑥) O NPB where 𝑥 is the feature vector, 𝛽L is the parameter vector of class 𝑐, and 𝐾 is the number of classes. • Convolutional Neural Network (CNN): CNNs are good at learning local spatial patterns in sequential data automatically through convolutional filters. In the baseline CNN of this study, one-dimensional convolutional layers were applied to learn discriminative faultrelated features. The structure of the model consisted of convolutional layers followed by max-pooling to progressively reduce dimensionality and enhance feature abstraction. Then, densely connected layers with ReLU activation were applied before the final softmax output layer for classification. The CNN baseline was principally employed as a feature extractor to benchmark the performance of spatial pattern recognition alone [18].
% % %! 883 • Long Short-Term Memory (LSTM): LSTMs are a variant of a recurrent neural network (RNN) that can learn long-term time series data dependencies by circumventing the vanishing gradient problem using memory cells and gating mechanisms. The LSTM baseline for this study was constructed with stacked LSTM layers to understand the temporal dependencies naturally present. Hidden and cell states across time were retained by each LSTM cell such that the model had the ability to capture useful temporal information. The output step employed a dense layer with softmax activation in order to generate class probabilities[19]. • Support Vector Machine (SVM): SVM was trained with a radial basis function (RBF) kernel to deal with nonlinear class boundaries in high-dimensional space [20]. The decision function is expressed as: 𝑓 𝑥 = 𝑠𝑖𝑔𝑛 𝛼"𝑦"1𝑘(𝑥", 𝑥) 5 "PB + 𝑏 Where 𝑘 𝑥", 𝑥 1is the kernel function, 𝛼" is the learned coefficients, and 𝑦"11is the class labels. • Random Forest (RF): To prevent overfitting and model feature interactions, RF, an ensemble of DTs, was used. The predictions were made by averaging the votes from individual trees, and the final class was determined using majority voting[21]. • Decision Tree (DT): DTs were employed to evaluate the classification ability of rulebased hierarchical models [22]. Each traffic flow is classified by splitting features at decision nodes based on Gini impurity: 𝐺 = 1 −1 𝑝" C \ "PB where 𝑝"1is the probability that a sample belongs to class i. 2. Proposed CNN+LSTM Hybrid Architecture: To overcome the limitations of traditional models in learning temporal and spatial dependences of IoT traffic, a hybrid DL architecture with CNN and LSTM networks was proposed [23]. • Input Layer: Input is preprocessed feature vectors of individual IoT traffic streams. Features are scaled to [0, 1] to offer equal scaling. • CNN Block: The CNN block derives local spatial dependencies between corresponding traffic features. Various 1D convolutional filters along feature directions generate lowand high-level features. Convolutional operation in both instances, followed by ReLU activation and max pooling, is applied to reduce dimensionality. ℎ9 ^= 𝑓( 𝑤"9 ^. 5 "PB 𝑥"+1𝑏9 ^) where ℎ9 ^1is the activation of the j-th filter in layer l, 𝑤"9 ^ is the weight matrix, and f is the ReLU activation.
% % %! 884 • LSTM Block (Temporal Dependency Modeling): The output of the CNN block is passed to stacked LSTM layers for capturing sequential dependencies from traffic flows. The LSTM updates are regulated by the forget, input, and output gates: 𝑓 `= 𝜎 𝑊 b. ℎ`cB, 𝑥`+ 𝑏b 𝑖`= 𝜎 𝑊". ℎ`cB, 𝑥`+ 𝑏" 𝑜`= 𝜎 𝑊 d. ℎ`cB, 𝑥`+ 𝑏d 𝑐`= 𝑓 `1⨀1𝑐`cB + 𝑖`1⨀1𝑡𝑎𝑛ℎ1 𝑊 L. ℎ`cB, 𝑥`+ 𝑏L ℎ`= 𝑜`1⨀1tanh1(𝑐`) where 𝑓 `, 𝑖`, 𝑜` are the forget, input, and output gates, respectively; 𝑐` is the cell state; and ℎ` is the hidden state. • Fully Connected Layer: After the hierarchical spatial–temporal features are learnt using the CNN and LSTM layers, the resulting feature map is flattened into a one-dimensional vector for dense connectivity purposes. The flat structure preserves both the local discriminative patterns learnt by the CNN and the long-range dependencies learnt by the LSTM. The vector is then sent to a single or multiple dense, fully connected layers, in which every neuron learns a weighted sum of the features in order to supply intricate non-linear decision boundaries. Dropout regularization is employed to prevent overfitting by randomly turning off a specified percentage of the neurons during training, such that the network becomes independent of specific feature paths. Batch normalization is also introduced to stabilize and accelerate convergence by normalizing the layer activations, improving the generalization performance across different classes of IoT traffic. • Output Layer: The final dense layer is linked to the output layer, having the same number of neurons as traffic classes (kinds of attacks and benign). In this place, a SoftMax activation is applied, which maps raw outputs (logits) to a normalized probability for each class. This ensures that the probabilities sum up to 1, and the maximum probability is the outputted traffic class. Mathematically, for any class j, probability equals: 𝑃 𝑦 = 𝑗 𝑥 = 𝑒l> 𝑒lm O NPB where 𝑧91represents the class j, and C denotes the number of classes. The probabilistic interpretation enables multi-class classification in the smart-city IoT scenario so that the model can accurately classify between normal traffic and different types of malicious attacks. The softmax output is then used for categorical cross-entropy loss computation, which guides the network parameter updates during training.
% % %! 885 Fig. 2: Overview of the CNN+LSTM architecture • Loss Function and Optimization: Class-Weighted Loss: While training DL, a weighted categorical cross-entropy loss was employed: ℒpq"rs`qt = − 𝑤". 𝑦"1log1(𝑦x) \ "PB Where: 𝑤"= 1 𝑁 𝐶. 𝑁" Here, C is the number of classes, N is the total number of samples, 𝑁" is the number of samples in class i, 𝑦" is the ground truth label (one-hot encoded), 𝑦x1is the predicted probability for class i. • Model weights are updated using the Adam optimizer, a variant of stochastic gradient descent that combines adaptive learning rate with momentum: 𝜃`|B 1=1𝜃`1− 1𝜂1. 𝑚` 𝑣`1+1∈1 Where,𝑚` and 𝑣` are bias-corrected first and second moment estimates, and η is the learning rate (set to 0.001). Table 2: Proposed Model Configuration and Training Strategy Component Specification Input Layer Preprocessed IoT traffic features (normalized) Convolutional Layers Two 1D CNN layers with 64 and 128 filters, kernel size = 3, stride = 1, ReLU activation Pooling Layers MaxPooling1D after each convolution (pool size = 2) LSTM Layers Two stacked LSTM layers with 128 and 64 hidden units, tanh activation Flattening Layer Converts multidimensional feature maps to 1D representation Fully Connected Layer Dense layer with 128 neurons, ReLU activation, Dropout rate = 0.5 Output Layer Dense layer with softmax activation for multi-class classification
% % %! 892 layers to learn features and LSTM layers to learn sequences. When the model was tested on the ACI-IoT2023 dataset, it performed significantly better than a large repository of baseline methods with almost perfect accuracy. These results show that there is a lucrative future for IoT network security through the integration of spatial and temporal learning. All the same, the work is not perfect. The model also misidentified some attacks sometimes, for example, confusing UDP Flood with ARP Spoofing, showing that high-level traffic similarities may also be difficult to catch. Much more importantly, the experiment only used a single dataset. Real-world IoT deployments are significantly more heterogeneous, and crossvalidation across multiple datasets must be conducted before conclusions can be reached more definitively. Future work will focus on minimizing the overhead of architecture and deployment on resource-constrained IoT devices, exploring online learning methodologies for real-time adaptation to shifting attack patterns, and the incorporation of explainable AI in an effort to provide network administrators with effective and actionable intelligence. These steps will help to evolve the proposed model to a reliable and viable intrusion detection system. REFERENCES 1. Raza, M. S., Nowsin, M., Sheikh, A., & Hwang, I.-S. (2025). Ensemble learning-based DDoS attack recognition in IoT networks. Computer Networks and Communications, 73–83. https://doi.org/10.37256/CNC.3220256755 2. Al Dawi, A., Tezel, N. S., Rahebi, J., & Akbas, A. (2025). An approach to botnet attacks in the fog computing layer and Apache Spark for smart cities. Journal of Supercomputing, 81(4), 1–30. https://doi.org/10.1007/s11227-024-06915-y 3. Chennupati, N., Gottam, J., Marrelli, R., & Panda, A. (2025). Enhancing IoT intrusion detection with Greylag Goose Optimization and Extreme Learning Machine: A data-driven study on IoT23. ResearchGate. https://www.researchgate.net/publication/394046831_Enhancing_IoT_Intrusion_Detection_with_Greylag_Goose_Opti mization_and_Extreme_Learning_Machine_A_Data-Driven_Study_on_IoT23 4. Aloqaily, A., Abdallah, E. E., AbuZaid, H., Abdallah, A. E., & Al-Hassan, M. (2025). Supervised machine learning for real-time intrusion attack detection in connected and autonomous vehicles: A security paradigm shift. Informatics, 12(1), 4. https://doi.org/10.3390/informatics12010004 5. Shan, L. (2025). IoT network intrusion detection system using optimization algorithms. Scientific Reports, 15(1), 1–19. https://doi.org/10.1038/s41598-025-04638-5 6. Rahmani, A. M., et al. (2022). A particle swarm optimization and deep learning approach for intrusion detection system in Internet of Medical Things. Sustainability, 14(19), 12828. https://doi.org/10.3390/su141912828 7. Lazrek, G., Chetioui, K., Balboul, Y., Mazer, S., & El Bekkali, M. (2024). An RFE/Ridge-ML/DL based anomaly intrusion detection approach for securing IoMT system. Results in Engineering, 23, 102659. https://doi.org/10.1016/j.rineng.2024.102659 8. Urs, P. M., Reddy, A. T. N., Mallikarjunaswamy, S., & Lakshminarayan, U. M. (2025). An innovative IoT framework using machine learning for predicting information loss at the data link layer in smart networks. Engineering, Technology & Applied Science Research, 15(2), 20904–20911. https://doi.org/10.48084/ETASR.9597 9. Ahmed, Y., Beyioku, K., & Yousefi, M. (2024). Securing smart cities through machine learning: A honeypot-driven approach to attack detection in Internet of Things ecosystems. IET Smart Cities, 6(3), 180–198. https://doi.org/10.1049/smc2.12084 10. Abbasi, M., Shahraki, A., Prieto, J., Arrieta, A. G., & Corchado, J. M. (2024). Unleashing the potential of knowledge distillation for IoT traffic classification. IEEE Transactions on Machine Learning in Communications and Networking, 2, 221–239. https://doi.org/10.1109/TMLCN.2024.3360915 11. Liao, N., & Guan, J. (2024). Multi-scale convolutional feature fusion network based on attention mechanism for IoT traffic classification. International Journal of Computational Intelligence Systems, 17(1), 1–25. https://doi.org/10.1007/s44196-024-00421-y 12. Afifi, F., Zaki, F., Hanif, H., Aqil, N., & Anuar, N. B. (2025). Transformer-based tokenization for IoT traffic classification across diverse network environments. PeerJ Computer Science, 11, e3126. https://doi.org/10.7717/peerj-cs.3126 13. Ismail, S., Dandan, S., & Qushou, A. (2025). Intrusion detection in IoT and IIoT: Comparing lightweight machine learning techniques using TON_IoT, WUSTL-IIoT-2021, and EdgeIIoTset datasets. IEEE Access, 13, 73468–73485. https://doi.org/10.1109/ACCESS.2025.3554083 14. Zahid, M., & Bharati, T. S. (2025). Enhancing cybersecurity in IoT systems: A hybrid deep learning approach for realtime attack detection. Discover Internet of Things, 5(1), 1–31. https://doi.org/10.1007/s43926-025-00156-y 15. Miao, Z., & Liao, Q. (2025). IoT-based traffic prediction for smart cities. IEEE Access, 13, 52369–52384. https://doi.org/10.1109/ACCESS.2025.3552276
% % %! 893 16. An, R., Zhang, X., Sun, M., & Wang, G. (2024). GC-YOLOv9: Innovative smart city traffic monitoring solution. Alexandria Engineering Journal, 106, 277–287. https://doi.org/10.1016/j.aej.2024.07.004 17. Nack, E. A., McKenzie, M. C., & Bastian, N. D. (2024). ACI-IoT-2023: A robust dataset for Internet of Things network security analysis. In Proceedings of the IEEE Military Communications Conference (MILCOM). https://doi.org/10.1109/MILCOM61039.2024.10773916 18. Yang, J., et al. (2025). BrainCNN: Automated brain tumor grading from magnetic resonance images using a convolutional neural network-based customized model. SLAS Technology, 34, 100334. https://doi.org/10.1016/j.slast.2025.100334 19. Ali, M., et al. (2025). Improving daily reference evapotranspiration forecasts: Designing AI-enabled recurrent neural networks based long short-term memory. Ecological Informatics, 85, 102995. https://doi.org/10.1016/j.ecoinf.2025.102995 20. Zhang, J., Lai, Z., Kong, H., & Yang, J. (2025). Learning the optimal discriminant SVM with feature extraction. IEEE Transactions on Pattern Analysis and Machine Intelligence, 47(4), 2897–2911. https://doi.org/10.1109/TPAMI.2025.3529711 21. Wu, W. (2025). Research on customer traffic value recognition model based on improved random forest algorithm. International Journal of Business, Management and Economics Technology. https://doi.org/10.38007/IJBMET.2025.060109 22. Achari, A. P. S. K., & Sugumar, R. (2025). Performance analysis and determination of accuracy using machine learning techniques for decision tree and RNN. AIP Conference Proceedings, 3252(1). https://doi.org/10.1063/5.0258588 23. Sinha, P., Sahu, D., Prakash, S., Yang, T., Rathore, R. S., & Pandey, V. K. (2025). A high performance hybrid LSTMCNN secure architecture for IoT environments using deep learning. Scientific Reports, 15(1), 1–26. https://doi.org/10.1038/s41598-025-94500-5 24. Pasha, A., Ahmed, S. T., Painam, R. K., Mathivanan, S. K., Mallik, S., & Qin, H. (2024). Leveraging ANFIS with Adam and PSO optimizers for Parkinson's disease. Heliyon, 10(9). 25. Ahmed, S. T., Priyanka, H. K., Attar, S., & Patted, A. (2017, June). Cataract density ratio analysis under color image processing approach. In 2017 International Conference on Intelligent Computing and Control Systems (ICICCS) (pp. 178180). IEEE 26. Ahmed, S. T., Kumar, V. V., & Jeong, J. (2024). Heterogeneous workload-based consumer resource recommendation model for smart cities: EHealth edge–cloud connectivity using federated split learning. IEEE Transactions on Consumer Electronics, 70(1), 4187-4196.