Library
PubMed
research article
Professional

Interpretable intrusion detection for IoT: a CNN-BiLSTM permutation importance framework for deep feature selection.

Source: PubMed, NCBI / U.S. National Library of Medicine

Frontiers in big dataAl-Shibly Ibrahim, Burgas Llorenç, Massana JoaquimPublished 1/1/2026Last synced 6/9/2026Status: syncedPMID: 42257188DOI: 10.3389/fdata.2026.1813265

Industrial intrusion detection systems (IDS) in Industrial Internet of Things (IIoT) environments have to address the problem of handling multi-feature temporally correlated network traffic and dynamic changes in attack patterns. Traditional filter-based feature selection methods, like Mutual Information (MI), only consider individual feature performance and may not be effective in dealing with non-linear feature dependencies. This may degrade detection performance, especially in class-imbalanced problems. To mitigate such challenges, this paper proposes a deep feature selection (DFS) framework that utilizes a hybrid Convolutional Neural Network (CNN) and Bidirectional Long Short-Term Memory (BiLSTM) model. The proposed framework assesses the importance of native features using permutation importance. In the proposed framework, the CNN model detects local features in the data, whereas the BiLSTM model detects bidirectional temporal features in the data. The importance of features is computed by assessing the performance degradation of the model using time-aware perturbations on individual features. These identified features that are most relevant are then used to train lightweight traditional machine learning models like decision tree, K-nearest neighbor (KNN), logistic regression, naïve Bayes, and random forest. This makes it easy to deploy in resource-constrained IIoT environments. The approach is tested on the CIC IIoT 2025 dataset. From the experimental results, it i

Abstract

Industrial intrusion detection systems (IDS) in Industrial Internet of Things (IIoT) environments have to address the problem of handling multi-feature temporally correlated network traffic and dynamic changes in attack patterns. Traditional filter-based feature selection methods, like Mutual Information (MI), only consider individual feature performance and may not be effective in dealing with non-linear feature dependencies. This may degrade detection performance, especially in class-imbalanced problems. To mitigate such challenges, this paper proposes a deep feature selection (DFS) framework that utilizes a hybrid Convolutional Neural Network (CNN) and Bidirectional Long Short-Term Memory (BiLSTM) model. The proposed framework assesses the importance of native features using permutation importance. In the proposed framework, the CNN model detects local features in the data, whereas the BiLSTM model detects bidirectional temporal features in the data. The importance of features is computed by assessing the performance degradation of the model using time-aware perturbations on individual features. These identified features that are most relevant are then used to train lightweight traditional machine learning models like decision tree, K-nearest neighbor (KNN), logistic regression, naïve Bayes, and random forest. This makes it easy to deploy in resource-constrained IIoT environments. The approach is tested on the CIC IIoT 2025 dataset. From the experimental results, it is clear that the CNN-BiLSTM DFS framework improves recall and F1-score compared to other feature selection approaches like MI. This is especially true in imbalanced settings. The decoupling of feature selection from offline and edge-side inference provides a balance between detection accuracy, robustness, and deployability in real-world IIoT settings.

Educational only
This information is for general education and is not medical advice. Always talk to a licensed U.S. clinician about your situation, medications, or treatment decisions.