2025/11/20 by Kamran Asgarov · 1 voice
Computer Science · Engineering · #Anomaly Detection Techniques and Applications #Network Security and Intrusion Detection #Smart Grid Security and Resilience
paper · doi:10.70389/pjs.100175
openalex publication_date 2025/11/20 · openalex created_date 2025/12/01 · openalex updated_date 2026/05/21
BACKGROUND The primary goal of the research was to determine whether high detection accuracy could be achieved without significant computational overhead, using only publicly available data and modest simulation infrastructure. MATERIALS AND METHODS The research was conducted using the open-access TONIoT dataset, which contains over one million time-stamped records collected from various types of IoT devices. The study applied a hybrid machine learning architecture combining convolutional and recurrent layers with gating mechanisms. A five-fold cross-validation procedure was used to ensure the statistical reliability of the obtained results. RESULTS This article presents the results of a study aimed at evaluating the effectiveness of machine learning methods for detecting anomalies in Internet of Things (IoT) telemetry streams under realistic conditions. The anomaly detection model demonstrated an average detection rate of 92.1%, a false positive rate of 3.7%, and a mean F1-score of 92.4%. In 85% of test cases, the detection latency remained below 1 s. The use of lightweight pre-processing, statistical filters, and synthetic data augmentation helped ensure robustness under conditions of class imbalance. The model retained high performance when applied to unseen data from different simulated regions, with only minimal fine-tuning required to restore accuracy. CONCLUSION The practical significance of the findings lies in the demonstrated feasibility of deploying anomaly detection systems for industrial IoT environments using only publicly available datasets and limited computational resources. The proposed approach can be implemented in monitoring platforms for early threat detection, predictive maintenance, and autonomous security control, particularly in sectors lacking access to high-end computing infrastructure or proprietary data.