TY - JOUR
T1 - Tiny-IDS
T2 - A Pruned Ensemble Distillation Pipeline for Lightweight and Explainable IoT Intrusion Detection
AU - Bahadur, Shyam
AU - Jha, Sudhanshu Kumar
AU - Rathore, Rajkumar Singh
AU - Prakash, Shiv
AU - Singh, Vishal Krishna
AU - Tripathi, Saurav
N1 - Publisher Copyright:
© 2026 The Authors.
PY - 2026/7/28
Y1 - 2026/7/28
N2 - The exponential growth of IoT (Internet of Things) devices and their deployment has raised numerous threats of botnet-based cyberattacks, making IoT networks more vulnerable than traditional IT systems. The deployment of intelligent network-based intrusion detection systems (NIDS) on these edge devices forces researchers into an impossible trilemma: accuracy, speed, or size of the model. This study presents Tiny-IDS, an intelligent, lightweight system that predicts Mirai botnet attacks on IoT devices. Tiny-IDS is a lightweight and efficient Intrusion Detection System (IDS) that jointly optimizes for four key objectives: high accuracy, low inference latency, a nominal memory footprint, and high interpretability. The core of Tiny-IDS is a three-phase pipeline applied on N-BaIoT dataset. Model performance was evaluated using accuracy, inference time, model size, and interpretability. LightGBM achieved accuracy of 0.999999 but with a inference time of 0.904 μs/sample and bigger model size of 1.74 MB. Our proposed Distilled Student Tree outperformed other models in terms of efficiency, and achieved classification accuracy of 0.999562 while reducing inference time to 0.278 μs/sample and model size to 6.25 KB. The results demonstrate the effectiveness of the proposed Tiny-IDS in accurately identifying Mirai botnet attacks on IoT devices along with a minimal memory footprint and low inference time, while also emphasizing the need for IoT-specific evaluation frameworks to support the development of robust and lightweight IDS.
AB - The exponential growth of IoT (Internet of Things) devices and their deployment has raised numerous threats of botnet-based cyberattacks, making IoT networks more vulnerable than traditional IT systems. The deployment of intelligent network-based intrusion detection systems (NIDS) on these edge devices forces researchers into an impossible trilemma: accuracy, speed, or size of the model. This study presents Tiny-IDS, an intelligent, lightweight system that predicts Mirai botnet attacks on IoT devices. Tiny-IDS is a lightweight and efficient Intrusion Detection System (IDS) that jointly optimizes for four key objectives: high accuracy, low inference latency, a nominal memory footprint, and high interpretability. The core of Tiny-IDS is a three-phase pipeline applied on N-BaIoT dataset. Model performance was evaluated using accuracy, inference time, model size, and interpretability. LightGBM achieved accuracy of 0.999999 but with a inference time of 0.904 μs/sample and bigger model size of 1.74 MB. Our proposed Distilled Student Tree outperformed other models in terms of efficiency, and achieved classification accuracy of 0.999562 while reducing inference time to 0.278 μs/sample and model size to 6.25 KB. The results demonstrate the effectiveness of the proposed Tiny-IDS in accurately identifying Mirai botnet attacks on IoT devices along with a minimal memory footprint and low inference time, while also emphasizing the need for IoT-specific evaluation frameworks to support the development of robust and lightweight IDS.
KW - Artificial Intelligence
KW - DDoS Attack
KW - Internet of Things
KW - Intrusion Detection
KW - Knowledge Distillation
KW - Mirai Botnets
UR - https://www.scopus.com/pages/publications/105046315721
U2 - 10.1109/OJCOMS.2026.3717864
DO - 10.1109/OJCOMS.2026.3717864
M3 - Article
AN - SCOPUS:105046315721
SN - 2644-125X
VL - 7
SP - 9256
EP - 9267
JO - IEEE Open Journal of the Communications Society
JF - IEEE Open Journal of the Communications Society
ER -