A Hybrid Intrusion Detection System for RPL-Based IoT Networks Using Decision Tree and CNN-BiLSTM Models
Mohammad Fazeli
1
(
)
Mohsen Raji
2
(
Shiraz University
)
Mohammad Mojtaba Fazeli
3
(
Islamic Azad University, Sepidan Branch
)
Keywords: Intrusion Detection, IoT Security, RPL attacks, Layered Security Architecture, Attack Classification, Decision Tree (DT), CNN-BiLSTM. ,
Abstract :
The Routing Protocol for Low-Power and Lossy Networks (RPL) is a widely adopted standard in Internet of Things (IoT) networks, enabling efficient and stable communication. However, its vulnerability to cyberattacks poses a significant threat. Traditional intrusion detection methods, although effective, are computationally complex and resource-intensive, rendering them unsuitable for resource-constrained IoT devices. This paper presents a lightweight, two-layer intrusion detection system (IDS) for RPL-based IoT networks. The first layer employs a decision tree model to detect attacks, offering accurate and rapid detection with minimal computational resources. The second layer utilizes a hybrid Convolutional Neural Network (CNN) and Bidirectional Long Short-Term Memory (BiLSTM) model to classify attack types. This combination enables automatic extraction of deep features from network traffic data and learning of temporal dependencies and complex attack patterns. Experimental results on the ROUT-4-2023 dataset, comprising four common RPL attacks (Blackhole, Flooding, Version Number, and Rank Attacks), demonstrate the proposed method's superior performance, achieving an overall accuracy of 97% and precision, recall, and F1-scores of approximately 96%. The attack detection time is significantly reduced to 0.062 seconds. These findings confirm the efficacy and high speed of the proposed system in RPL-based IoT environments, making it a suitable solution for securing resource-constrained IoT networks.
[1] A. Al-Fuqaha, M. Guizani, M. Mohammadi, M. Aledhari, and M. Ayyash, “Internet of Things: A Survey on Enabling Technologies, Protocols, and Applications,” IEEE Communications Surveys & Tutorials, vol. 17, no. 4, pp. 2347–2376, 2015.
[2] Alfriehat N., Anbar M., Aladaileh M., Hasbullah I., et al., “RPL based attack detection approaches in IoT networks: review and taxonomy,” Artificial Intelligence Review, vol. 57, art. 248, Aug. 2024
[3] T. Winter et al., RPL: IPv6 Routing Protocol for Low-Power and Lossy Networks, RFC 6550, IETF, 2012
[4] M. Emeç and M. H. Özcanhan, “ROUT-4-2023: RPL based routing attack dataset for IoT,” IEEE Dataport, doi: 10.21227/3mbe-5j70, 2023.
[5] K. O. A. Alimi, K. Ouahada, A. M. M. Abu-Mahfouz, S. Rimer, and O. A. Alimi, “Refined LSTM Based Intrusion Detection for Denial-of-Service Attack in Internet of Things,” Journal of Sensor and Actuator Networks (JSAN), vol. 11, no. 3, article 32, July 2022. DOI: 10.3390/jsan11030032
[6] Abdelouahid Derhab, Arwa Aldweesh, Ahmed Z Emam, and Farrukh Aslam Khan. 2020. Intrusion detection system for internet of things based on temporal convolution neural network and efficient feature engineering. Wireless Communications and Mobile Computing 2020 (2020), 1–16. [7] Mohamed Abdel-Basset, Hossam Hawash, Ripon K Chakrabortty, and Michael J Ryan. 2021. Semi-supervised spatiotemporal deep learning for intrusions detection in IoT networks. IEEE Internet of Things Journal 8, 15 (2021), 12251–12265.
[8] Y. Guan, M. Noferesti, and N. Ezzati-Jivan, “CNN-BiLSTM-Based Classification of RPL Attacks in IoT Smart Grid Networks (Industry Track),” in Proc. ACM/IFIP/USENIX Middleware Conf., Bologna, Italy, Dec. 2023
[9] A. Etheridge and V. Anu, RPL Attack Detection in IoT Environments: An Ensemble Approach, in Proc. IEMTRONICS 2024 – International IoT, Electronics and Mechatronics Conference, Lecture Notes in Electrical Engineering, vol. 1228, Springer, 2025, pp. 113–122
[10] M. Osman, J. He, N. Zhu, and F. M. M. Mokbal, “An ensemble learning framework for the detection of RPL attacks in IoT networks based on the genetic feature selection approach,” Ad Hoc Netw., vol. 152, 103331, Oct. 2023
[11] Mustafa Qahatan Alsudani, Salah H. Abbdal Reflish, Kohbalan Moorthy, and Myasar Mundher Adnan. 2023. A new hybrid teaching learning based Optimization -Extreme learning Machine model based Intrusion-Detection system. Materials Today: Proceedings 80 (2023),
[12] A. Chougule, R. Mane, K. Bhattacharjee, and S. Mehta, “Ensemble Learning Based Intrusion Detection System for RPL-Based IoT Networks,” in Demystifying AI and ML for Cyber-Threat Intelligence, A. Chougule and R. Mane, Eds. Cham: Springer, 2025, pp. 27–37, doi: 10.1007/978-3-031-90723-4_3.