Deep Reinforcement Learning-Based Intrusion Detection System: Defending Edge Gateways Against Mirai and Gafgyt

preprint OA: closed
View at publisher

Abstract

The rapid growth of the Internet of Things (IoT) has transformed industries, resulting in unprecedented opportunities alongside significant cybersecurity challenges. Malware, for example, Mirai and Gafgyt, exploits IoT vulnerabilities, leading to large-scale attacks. Traditional Intrusion Detection Systems (IDS) struggle to detect these evolving threats due to their reliance on static rule-based or classic Machine Learning (ML) models, which lack adaptability to zero-day attacks and dynamic traffic patterns. This paper presents EdgeShield-DRL, a novel Deep Reinforcement Learning (DRL)-based IDS designed for IoT edge gateways. EdgeShield-DRL dynamically detects and mitigates evolving threats in real-time while ensuring efficient operation on resource-constrained edge devices. We evaluated EdgeShield-DRL on the N-BaIoT dataset, achieving a high detection accuracy of 97% during training phases and 96% in real-time detection scenarios. Moreover, the system demonstrates robust resource efficiency, maintaining minimal energy consumption and carbon emissions even under attack conditions. Experiments on a realworld testbed further validate EdgeShield-DRL's effectiveness, showcasing resilience against diverse attack scenarios, including large-scale botnet activity. Furthermore, EdgeShield-DRL effectively balances robust security with resource constraints, making it particularly suitable for critical IoT systems, e.g., smart cities, healthcare, and industrial automation.

My notes (saved in your browser only)

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2025) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00