Industrial informatics

Machine Learning for DDoS Detection

The project investigates deep-learning approaches for intrusion detection in Internet of Things and Industrial Internet of Things environments. The growing number of connected devices, their heterogeneous hardware and communication technologies, and their often limited built-in security make IoT infrastructures especially vulnerable to attacks such as Denial of Service and Distributed Denial of Service. The project develops anomaly-based intrusion detection systems capable of learning discriminative representations directly from network traffic and identifying both known and evolving attack patterns.

A central research direction concerns the adaptation of deep models to heterogeneous datasets, different feature spaces, and binary or multi-class detection scenarios. The proposed methods combine data preprocessing, dimensionality reduction, hyperparameter optimisation, adaptive neural architectures, and transfer learning. Different fine-tuning strategies are studied to determine which layers should be updated or frozen when transferring knowledge from a large source dataset to a smaller target domain, with the aim of maintaining high detection accuracy while reducing the amount of labelled data and computational resources required.

The project also explores federated learning as a distributed and privacy-aware alternative to centralised training. Models are trained locally by multiple clients, while only model updates are shared and aggregated by a central server. Research activities address heterogeneous client resources, non-uniform data distributions, partial client participation, communication costs, client-selection strategies, and the detection of malicious or poisoned updates. The long-term goal is to create scalable, adaptive, and trustworthy intrusion detection solutions that can operate in dynamic edge and IoT environments without requiring organisations to disclose sensitive network data.

Relevant publications

M. B. Anley, A. Genovese, V. Piuri, Deep Learning for DDoS attack detection in IoT: A survey, Security and Cryptography. SECRYPT 2023/SECRYPT 2024, Communications in Computer and Information Science, vol. 2588, pp. 99-121, Springer, Cham, 2026, ISSN 978-3-032-09598-5.
M. B. Anley, P. Coscia, A. Genovese, V. Piuri, FELACS: Federated learning with adaptive client selection for IoT DDoS attack detection, Computers & Security, vol. 158, no. 104642, pp. 1-13, November 2025, ISSN 0167-4048.
M. B. Anley, A. Genovese, V. Piuri, TransferEdge: Transfer learning approach to detect evolving DDoS threats in Edge-IIoT, Proc. of the 9th Int. Forum on Research and Technologies for Society and Industry (RTSI 2025), pp. 11-16, Gammarth, Tunisia, August 2025, ISSN 979-8-3315-9788-7.
M. B. Anley, A. Genovese, D. Agostinello, V. Piuri, Robust DDoS attack detection with adaptive transfer learning, Computers & Security, vol. 144, no. 103962, pp. 1-10, September 2024, ISSN 0167-4048.
D. Agostinello, A. Genovese, V. Piuri, Anomaly-based intrusion detection system for DDoS attack with Deep Learning techniques, Proc. of the 20th Int. Conf. on Security and Cryptography (SECRYPT 2023), pp. 267-275, Rome, Italy, July 2023, ISSN 978-989-758-666-8.
D. Gümüşbaş, T. Yıldırım, A. Genovese, F. Scotti, A comprehensive survey of databases and Deep Learning methods for cybersecurity and intrusion detection systems, IEEE Systems Journal, vol. 15, no. 2, pp. 1717-1731, June 2021, ISSN 1937-9234.