Varshani, Varshani, Huang, Yuxiang, Li, Haoxiang, Wang, Yichao, Brierley, Calvin, Arief, Budi, Oikonomou, George, Pope, James (2026) Unsupervised Machine Learning for Anomaly Detection in Thread IoT Networks. In: 2026 22nd International Conference on Distributed Computing in Smart Systems and the Internet of Things (DCOSS-IoT). IEEE Computer Society (doi:10.1109/DCOSS-IoT69657.2026.00106) (KAR id:116433)
|
PDF
Author's Accepted Manuscript
Language: English |
|
|
Download this file (PDF/1MB) |
Preview |
| Request a format suitable for use with assistive technology e.g. a screenreader | |
| Official URL: https://doi.ieeecomputersociety.org/10.1109/DCOSS-... |
|
Abstract
Thread is a low-power, IPv6-based mesh networking protocol increasingly deployed in smart home and industrial Internet of Things (IoT) environments. However, security monitoring is largely designed for traditional IP or Wi-Fi traffic and unexplored for Thread networks. Existing intrusion detection systems are ill-suited to the protocol’s constrained, fragmented, and protocol-specific communication patterns. In this paper, we address this gap by formulating anomaly detection in Thread networks as an unsupervised machine learning problem, where models are trained exclusively on normal traffic. We present an anomaly detection pipeline tailored to low-power Thread networks, incorporating packet-level annotation, session-based segmentation, and the extraction of 33 statistical and protocol-aware features. Using this representation, we design a deep autoencoder to detect anomalies by learning normal behaviour. To determine the autoencoder efficacy, we compare against the classical One-Class Support Vector Machine (OCSVM). We conduct experiments using Carnegie Mellon University’s (CMU) Thread dataset. In addition to normal behaviour, the dataset provides energy-depletion, session jamming, spoofing, and password guessing attacks. Our results show that the autoencoder consistently outperforms the OCSVM, achieving an overall F1-score of 87% compared to 60%. However, we show that the model has limitations detecting the spoofing and password guessing attacks. These results highlight the effectiveness of unsupervised approaches for modelling complex traffic patterns in low-power IoT networks and underscores the need for more adaptive detection strategies.
| Item Type: | Conference proceeding |
|---|---|
| DOI/Identification number: | 10.1109/DCOSS-IoT69657.2026.00106 |
| Uncontrolled keywords: | Internet of Things, Anomaly Detection, Intrusion Detection Systems, Unsupervised Learning, Autoencoder |
| Subjects: | Q Science > QA Mathematics (inc Computing science) |
| Institutional Unit: |
Schools > School of Computing Institutes > Institute of Cyber Security for Society |
| Former Institutional Unit: |
There are no former institutional units.
|
| Funders: | Engineering and Physical Sciences Research Council (https://ror.org/0439y7842) |
| Depositing User: | Budi Arief |
| Date Deposited: | 25 Sep 2026 14:44 UTC |
| Last Modified: | 25 Sep 2026 14:48 UTC |
| Resource URI: | https://kar.kent.ac.uk/id/eprint/116433 (The current URI for this page, for reference purposes) |
- Link to SensusAccess
- Export to:
- RefWorks
- EPrints3 XML
- BibTeX
- CSV
- Depositors only (login required):

https://orcid.org/0000-0002-4633-3690
Altmetric
Altmetric