About | Contact Us | Register | Login
ProceedingsSeriesJournalsSearchEAI
inis 26(3):

Research Article

PON: A Packet-Observation Spiking Neural Network for Header-Based IoT Intrusion Detection

Download19 downloads
Cite
BibTeX Plain Text
  • @ARTICLE{10.4108/eetinis.133.13277,
        author={Phu Nguyen Phan Hai and Cam Doan Ngoc and Bao Bui Quoc and Trang Hoang},
        title={PON: A Packet-Observation Spiking Neural Network for Header-Based IoT Intrusion Detection},
        journal={EAI Endorsed Transactions on Industrial Networks and Intelligent Systems},
        volume={13},
        number={3},
        publisher={EAI},
        journal_a={INIS},
        year={2026},
        month={8},
        keywords={IoT intrusion detection, packet-level features, lightweight features, 1D convolution, ternary quantization, CIC-IoT2023},
        doi={10.4108/eetinis.133.13277}
    }
    
  • Phu Nguyen Phan Hai
    Cam Doan Ngoc
    Bao Bui Quoc
    Trang Hoang
    Year: 2026
    PON: A Packet-Observation Spiking Neural Network for Header-Based IoT Intrusion Detection
    INIS
    EAI
    DOI: 10.4108/eetinis.133.13277
Phu Nguyen Phan Hai1,2, Cam Doan Ngoc1,2, Bao Bui Quoc1,2, Trang Hoang1,2,*
  • 1: Ho Chi Minh City University of Technology
  • 2: Vietnam National University Ho Chi Minh City
*Contact email: hoangtrang@hcmut.edu.vn

Abstract

Intrusion detection in IoT environments requires real-time and lightweight systems to mitigate the computational overhead of deep packet inspection (DPI) at the network-edge. \myhl{This paper proposes PON, a packet-observation spiking neural network (SNN) for IoT intrusion detection using packet headers.} The system operates online at the individual packet-level, incorporating a behavior-adaptive redundancy filter that reduces edge processing traffic volume by over 79 percent. Header features are constructed from 64-byte normalized headers alongside a sliding-window source IP diversity ratio to capture the behaviors of diverse cyber attacks. \myhl{PON performs header-only inference using these features, while payload data are not forwarded to the classifier.} The \myhl{PON} architecture combines 1D convolution with leaky-integrate-and-fire (LIF) neurons and a Sparse Attack Detector (SAD) designed to mitigate temporal spike dilution, thereby boosting rare attack detection. Evaluated on the mixed traffic streams of the CIC-IoT2023 dataset, the proposed SNN model combined with the SAD module reaches a Macro F1 score of 92.48 percent and a detection rate of 90.23 percent, increasing the detection rate on rare attack categories by up to 21.5 percentage points compared to published reference models. Trained ternary quantization (TTQ) reduces the storage footprint from 30.69 KB in float32 format to 13.82 KB in ternary format, achieving a 2.2 fold overall model size reduction by compressing the core spiking weights 16 fold. These results demonstrate that the proposed model provides competitive detection accuracy and high memory efficiency, making it suitable for edge deployment.

Keywords
IoT intrusion detection, packet-level features, lightweight features, 1D convolution, ternary quantization, CIC-IoT2023
Received
2026-06-01
Accepted
2026-08-04
Published
2026-08-19
Publisher
EAI
http://dx.doi.org/10.4108/eetinis.133.13277

Copyright © 2026 Phu Nguyen Phan Hai et al., licensed to EAI. This is an open access article distributed under the terms of the CC BY-NC-SA 4.0, which permits copying, redistributing, remixing, transformation, and building upon the material in any medium so long as the original work is properly cited.

EBSCOProQuestDBLPDOAJPortico
EAI Logo

About EAI

  • Who We Are
  • Leadership
  • Research Areas
  • Partners
  • Media Center
  • Cookie Preferences

Community

  • Membership
  • Conference
  • Recognition
  • Sponsor Us

Publish with EAI

  • Publishing
  • Journals
  • Proceedings
  • Books
  • EUDL