
Research Article
PON: A Packet-Observation Spiking Neural Network for Header-Based IoT Intrusion Detection
@ARTICLE{10.4108/eetinis.133.13277, author={Phu Nguyen Phan Hai and Cam Doan Ngoc and Bao Bui Quoc and Trang Hoang}, title={PON: A Packet-Observation Spiking Neural Network for Header-Based IoT Intrusion Detection}, journal={EAI Endorsed Transactions on Industrial Networks and Intelligent Systems}, volume={13}, number={3}, publisher={EAI}, journal_a={INIS}, year={2026}, month={8}, keywords={IoT intrusion detection, packet-level features, lightweight features, 1D convolution, ternary quantization, CIC-IoT2023}, doi={10.4108/eetinis.133.13277} }- Phu Nguyen Phan Hai
Cam Doan Ngoc
Bao Bui Quoc
Trang Hoang
Year: 2026
PON: A Packet-Observation Spiking Neural Network for Header-Based IoT Intrusion Detection
INIS
EAI
DOI: 10.4108/eetinis.133.13277
Abstract
Intrusion detection in IoT environments requires real-time and lightweight systems to mitigate the computational overhead of deep packet inspection (DPI) at the network-edge. \myhl{This paper proposes PON, a packet-observation spiking neural network (SNN) for IoT intrusion detection using packet headers.} The system operates online at the individual packet-level, incorporating a behavior-adaptive redundancy filter that reduces edge processing traffic volume by over 79 percent. Header features are constructed from 64-byte normalized headers alongside a sliding-window source IP diversity ratio to capture the behaviors of diverse cyber attacks. \myhl{PON performs header-only inference using these features, while payload data are not forwarded to the classifier.} The \myhl{PON} architecture combines 1D convolution with leaky-integrate-and-fire (LIF) neurons and a Sparse Attack Detector (SAD) designed to mitigate temporal spike dilution, thereby boosting rare attack detection. Evaluated on the mixed traffic streams of the CIC-IoT2023 dataset, the proposed SNN model combined with the SAD module reaches a Macro F1 score of 92.48 percent and a detection rate of 90.23 percent, increasing the detection rate on rare attack categories by up to 21.5 percentage points compared to published reference models. Trained ternary quantization (TTQ) reduces the storage footprint from 30.69 KB in float32 format to 13.82 KB in ternary format, achieving a 2.2 fold overall model size reduction by compressing the core spiking weights 16 fold. These results demonstrate that the proposed model provides competitive detection accuracy and high memory efficiency, making it suitable for edge deployment.
Copyright © 2026 Phu Nguyen Phan Hai et al., licensed to EAI. This is an open access article distributed under the terms of the CC BY-NC-SA 4.0, which permits copying, redistributing, remixing, transformation, and building upon the material in any medium so long as the original work is properly cited.


