Research Publications & Papers
Peer-reviewed scientific publications accepted in top ISI/Scopus journals and conferences.
Investigating the Vulnerability of Deep Neural Network to Bit-Flip Attacks in Collaborative Inference Systems
Authors: Nhu-Y Tran-Van, Hoang-Trung Le-Pham, Huy-Tan Thai, Kim-Hung Le
Abstract: The proliferation of Internet of Things devices has driven the adoption of collaborative inference (CI) for efficiently operating deep neural networks (DNNs) on resource-limited devices. However, this paradigm introduces vulnerabilities to bit-flip attacks, a form of fault injection that manipulates critical network parameters and compromises model integrity. In this paper, we design and evaluate a targeted bit-flip attack mechanism that strategically disrupts collaborative inference by flipping bits in model parameters deployed on IoT devices. We also analyze the impact of bit-flip attacks on model accuracy and reliability, providing insights into the susceptibility of different DNN layers. Experimental results reveal that flipping less than 0.02% of model parameters can cause up to a 40% accuracy degradation in DNN models, highlighting the urgent need for robust security measures in CI frameworks.
IoT Intrusion Detection: A Comprehensive Benchmark of Feature Selection and Machine Learning Models
Authors: Hong-Nhu-Y Vo, Dat-Thinh Nguyen, Xuan-Ha Nguyen, Kim-Hung Le
Abstract: Machine learning (ML) and feature selection (FS) are crucial for enhancing the accuracy and efficiency of Intrusion Detection Systems (IDS) in IoT networks. However, existing studies evaluate ML models or FS methods in isolation, lacking a holistic comparison among combinations of FS and ML across different datasets and attack types. In this study, we address this gap by conducting a comprehensive benchmark of 10 ML models and 17 FS methods with various settings on 7 IDS datasets. We first establish baseline performance of the ML models without FS, then analyze the impact of individual FS techniques on each model. Our experimental results show that (1) tree-based models consistently outperform other models in various scenarios; (2) while non-ranking-based FS methods generally show better results, ranking-based methods can be equally effective with a sufficient number of features; and (3) the combination of tree-based models and non-ranking-based FS methods consistently outperform others. These findings provide insights for security experts in developing an efficient and effective IDS in IoT networks.
MTAS: A temporal-aware multiview graph attention framework for early rumor detection on social media
Authors: Hoang-Trung Le-Pham, The-Phong Nguyen, Anh-Duy Tran, Kim-Hung Le
Abstract: The rapid growth of information dissemination on social networks such as Facebook and Twitter, along with the widespread of mobile devices, has intensified the need for early yet accurate rumor detection methods. While existing hybrid machine learning models integrating natural language processing (NLP) and graph neural networks (GNNs) show promising results but often lack effective integration of diverse features and temporal modeling. To overcome these limitations, we introduce MTAS, a novel framework designed to detect rumors effectively by generating a multiview of social data encompassing semantic, inner, global, and temporal features. Specifically, MTAS models social network data into a comprehensive graph structure representing the global relationship among all tweets, words, and users. Through this structure, the framework processes and analyzes propagation patterns, semantic content, and temporal features. Additionally, it employs a subgraph-level attention mechanism to combine the extracted representations. By explicitly modeling temporal dynamics and enhancing feature fusion, MTAS achieves superior performance. Extensive experiments on two datasets collected from Twitter, Twitter15 and Twitter16, demonstrate that MTAS outperforms state-of-the-art methods, achieving accuracies of 92.9% and 94.6%, respectively, compared to 91.1% and 93.7% for existing best-performing models. Notably, MTAS excels in early-stage rumor detection, achieving over 90% accuracy within the first 8 h of rumor propagation, a crucial step for mitigating the spread of misinformation.
Tuning-Free One-Class Discriminant Learning for Tabular Anomaly Detection
Authors: Xuan-Ha Nguyen, Vu Nguyen Thai Duong, Nguyen Van Hoi, Kim-Hung Le, Nhien-An Le-Khac
Abstract: Anomaly detection (AD) on real-world tabular data is challenged by diverse anomaly types, scarce labels, and high sensitivity to data-specific hyperparameter tuning. A central difficulty is that different anomaly types favor opposing representations: compactness - tightening the normal class to expose pointwise deviations - and structure preservation - retaining cluster and cross-feature relationships. Existing one-class detectors capture only one of these or balance them via hyperparameters, which is problematic without validation labels. We propose Discriminant Vector Machine for Anomaly Detection (DVM-AD), a closed-form one-class method derived from discriminant analysis that captures both behaviors under a single fixed configuration. From a deterministic reference point built from the training data, DVM-AD derives a bounded ratio whose two ends correspond to compressive and structure-preserving directions. This bound enables selecting directions from both ends simultaneously without dataset-specific tuning. In addition, a Moore-Penrose pseudo-inverse keeps the method well-posed under high-dimensional or rank-deficient settings, and test samples are scored by nearest-neighbor distance in the discriminant space, normalized for thresholding-ready use. Across 47 ADBench tabular datasets and 10 NLP/CV embedding benchmarks against 28 baselines, DVM-AD achieves the best average AUROC (89.65%, average rank 2.98) on tabular datasets and remains top-ranked across four anomaly types and on embedding tasks (average rank 1.60, AUROC 72.68%).
FusionNet: A latency-aware hybrid transformer architecture for efficient leaf disease detection on the IoT edge
Authors: Huy-Tan Thai, Van-Linh Truong-Dang, Kim-Hung Le
Abstract: The integration of lightweight deep learning models on edge devices for leaf disease detection offers a transformative approach for smart agriculture, enabling real-time, in-field analysis and enhanced data privacy in resource-constrained environments. However, the design of latency-aware models is hindered by the lack of layer-wise latency analysis in existing research, which is essential for on-device optimization. In this work, we first conduct a layer-wise latency investigation of popular components across both CNN and Transformer architectures. Guided by this analysis, we then introduce two novel latency-optimized blocks: ShuffleBlock and MetaFormer. These blocks are integrated into FusionNet, a hybrid CNN-Transformer architecture designed for an optimal accuracy-latency trade-off. The evaluation results demonstrate that FusionNet achieves comparable performance to recent studies and state-of-the-art deep learning models, with an F1-score of 95.04%, while providing superior inference speed with a 3.37 ms latency for on-device scenarios.
CoFANN: A collaborative framework for accelerating DNN inference in drone-based agricultural monitoring systems
Authors: Nhu-Y Tran-Van, Kim-Hung Le
Abstract: Plant leaf diseases pose a major threat to global agricultural productivity, causing substantial crop losses annually. While drone-based monitoring systems equipped with deep neural networks (DNNs) offer a promising solution for large-scale disease detection, their deployment is hindered by the computational limitations of IoT devices and the latency issues associated with cloud and edge computing. Existing collaborative inference approaches aim to mitigate end-to-end latency by offloading computation across devices. However, these methods often compromise model accuracy and add computing latency in generating inference strategies. To address these challenges, we present CoFANN, a novel collaborative framework to accelerate DNN inference in dynamic IoT environments. Our framework includes two key advances: a differentiable strategy search space with a gradient-based optimization algorithm for efficiently identify optimal partitioning strategies, and an adaptive model partitioning algorithm that effectively divides and allocates DNN components across computing devices based on their capabilities and network conditions. Experimental results in the plant disease dataset demonstrate that CoFANN reduces the total inference latency by up to 70% compared to device-only and 50% compared to edge-only approaches under varying network conditions, while maintaining comparable accuracy from 93.7% to 95.8%.
Dropout Attacks on Knowledge Distillation
Authors: Duc-Tai Nguyen, Tra-My Le-Doan, Hoang-Trung Le-Pham, Kim-Hung Le
Abstract: Knowledge Distillation (KD) is crucial for deploying lightweight deep learning on IoT devices but involves a computationally demanding pre-training phase for large teacher models. This often leads to outsourcing KD on third-party platforms, therefore introducing new security vulnerabilities. This paper evaluates how dropout-based adversarial attacks affect the KD process and analyzes how corrupted teacher parameters influence student model performance. We investigate three Dropout Attack strategies, including Min Activation, Sample Dropping, and Neuron Separation, targeting the teacher model during KD, thereby affecting knowledge transfer and the resulting student model’s performance. Our experiments on the CIFAR-10 and CIFAR-100 datasets using ResNet and EfficientNet architectures reveal significant accuracy degradation under attack. These adversarial manipulations can cause major accuracy reductions, with observed drops reducing performance from nearly 70% down to approximately 10% in vulnerable configurations. Our research highlights emerging security risks in the practical KD process, emphasizing the need for verification methods and defenses against such manipulations.
ResEViT-Road: An Efficient Model for Road Quality Classification
Authors: Cao-Thi Nguyen, Tra-Bao-Ngan Nguyen, Huy-Tan Thai, Kim-Hung Le
Abstract: Nowadays, road infrastructure plays a critical role in economic development in each country. However, many roads in the world are facing bad quality due to various types of damage, including longitudinal cracks, transverse cracks, grid cracks, and potholes. This paper presents a novel model, namely ResEViT-Road, designed to accurately classify road quality based on ResNet and EfficientViT backbones. Our proposed architecture strikes a balance between convolutions and self-attention mechanisms, resulting in a simple yet efficient model. We propose an Interactive block that enhances the feature representation by transferring information while training between CNN and Transformer branches. As a result, ResEViT-Road is able to learn features more comprehensively and effectively, leading to superior classification results with F1-score reaching 86.05% for binary classification and 98.51% for multi-class classification tasks, in that order.
Undermining Trust: How Bit-Flip Attacks Compromise Anomaly-based Network Intrusion Detection Systems
Authors: Thi-Thuy-Trang Le, Hoang-Vu Le, Xuan-Ha Nguyen, Kim-Hung Le
Abstract: The rapid expansion of IoT leads to numerous security vulnerabilities, making IoT ecosystems attractive targets for cyberattacks. Anomaly-based Network Intrusion Detection Systems (aNIDS), powered by deep learning models, are widely used to enhance security in IoT environments; however, these models are inherently sensitive to physical-level attacks like bitflips, which can manipulate the model’s weights and degrade performance. While extensive research has explored deep learning security, there is a notable gap in the study of hardware-based bit-flip attacks on aNIDS in IoT. In this paper, we propose a benchmarking framework with four attack scenarios to evaluate the resilience of aNIDS against bit-flip attacks. The experimental results, using three IoT datasets, demonstrate the significant degradation of model performance under different attack schemas. The findings highlight the need for robust countermeasures to secure aNIDS models against bit-flip attacks in IoT networks.
A multimodal skin lesion classification through cross-attention fusion and collaborative edge computing
Authors: Nhu-Y Tran-Van, Kim-Hung Le
Abstract: Skin cancer is a significant global health concern requiring early and accurate diagnosis to improve patient outcomes. While deep learning-based computer-aided diagnosis (CAD) systems have emerged as effective diagnostic support tools, they often face three key limitations: low diagnostic accuracy due to reliance on single-modality data (e.g., dermoscopic images), high network latency in cloud deployments, and privacy risks from transmitting sensitive medical data to centralized servers. To overcome these limitations, we propose a unified solution that integrates a multimodal deep learning model with a collaborative inference scheme for skin lesion classification. Our model enhances diagnostic accuracy by fusing dermoscopic images with patient metadata via a novel cross-attention-based feature fusion mechanism. Meanwhile, the collaborative scheme distributes computational tasks across IoT and edge devices, reducing latency and enhancing data privacy by processing sensitive information locally. Our experiments on multiple benchmark datasets demonstrate the effectiveness of this approach and its generalizability, such as achieving a classification accuracy of 95.73% on the HAM10000 dataset, outperforming competitors. Furthermore, the collaborative inference scheme significantly improves efficiency, achieving latency speedups of up to 20% and 47% over device-only and edge-only schemes.
Bigsids: an efficient SDN-based network intrusion detection systems for big data environments
Authors: Hoang-Hai Huynh, Xuan-Ha Nguyen, Xuan-Duong Nguyen, Kim-Hung Le
Abstract: Software-defined networking (SDN) offers promising network solutions in a big data environment, but existing network intrusion detection systems (NIDS) are limited in handling the high volume of network traffic data. To address this challenge, we propose an SDN-based architecture designed for efficient big data analysis and enhanced monitoring, seamlessly integrating NIDS. The attack detector of our approach is a hybrid model leveraging the advances of both machine and deep learning paradigms with big data processing technologies; thus, it ensures a high processing rate and accuracy in detecting and classifying cyber attacks. The evaluation results on four popular NIDS datasets show that our system could detect several attacks with an accuracy rate of 99% and maintain a minimal false alarm rate of 0.35%. In addition, in a simulated distributed environment, our proposal could process over 40,000 flows per second using just five worker nodes.
A Dual-Layer Defense Mechanism for Dropout Attack in Wireless Link Estimation
Authors: Huy-Cuong Nguyen, Hoang-Trung Le-Pham, Xuan-Ha Nguyen, Khanh-Hoi Le-Minh, Kim-Hung Le
Abstract: The rapid proliferation of wireless Internet of Things devices demands reliable and secure connectivity, which can be achieved by Wireless Link Estimation (WLE) models, particularly those based on deep learning. However, these models are vulnerable to dropout attacks. This attack manipulates dropout layers to degrade model accuracy, leading to inappropriate or malicious network selections. In this paper, we introduce a dual-layer defense mechanism with real-time anomaly detection within the dropout layer. This mechanism monitors gradient variations to detect dropout attacks and rapidly reverts the compromised layers to a secure state, thereby ensuring stable training. Extensive experimental evaluation across various datasets and neural architectures highlights the severity of dropout attacks, which drop model accuracy to nearly 20%, and demonstrates the effectiveness of our solution, which restores the accuracy of WLE models to near pre-attack levels.
Beyond VirusTotal: A semantic approach to building reliable and up-to-date android malware datasets from threat reports
Authors: Ngoc-Truong Nguyen, Kim-Hung Le
Abstract: The effective development and evaluation of machine learning (ML)-based Android malware detection systems is hindered by their critical dependence on high-quality, up-to-date training datasets. Current dataset construction methods face several limitations: manual collection using threat intelligence reports ensures reliability but lacks scalability and novelty, whereas automated collection via anti-virus scanning offers scale but suffers from labelling inconsistency and unreliability. This presents a significant software engineering challenge for maintaining robust malware detection performance. This study aims to improve the software engineering practice of building security datasets by designing and implementing AMARSTR, an automated system for constructing reliable, large-scale, and continuously updated Android malware datasets. The key objectives include leveraging the reliability of expert-verified threat reports through automation and developing a novel semantic-based algorithm for accurate malware family labelling directly from the report content. We developed AMARSTR, a system that automatically gathers and parses threat intelligence reports from leading security vendors. It applies a novel semantic-based algorithm to extract Indicators of Compromise (IoCs) and reliably determines malware family labels from the report content. Subsequently, the system downloads the corresponding malicious APK samples using the identified IoCs. We deployed the AMARSTR to generate a new dataset. Our deployment yielded the PubAndMal dataset, which contains 2,894 malicious APKs from 132 families identified in 186 distinct threat reports (2013-2024). Comprehensive experiments demonstrated the effectiveness of PubAndMal for training and evaluating diverse ML-based malware detection models, thereby validating the utility of our method. AMARSTR provides an automated and scalable method for generating reliable and up-to-date Android malware datasets from threat intelligence reports. This contributes to a practical solution to the software engineering challenges of dataset construction in malware detection research and development. The PubAndMal dataset and associated codes are publicly available for further research.
Q-Forge: An Efficient Two-Stage Framework for Noise-Aware Quantum Model Training
Authors: Ngoc-Truong Nguyen, Huy-Tan Thai
Abstract: Training quantum models on noisy devices is challenging due to the accumulation of errors from quantum noise and the high computational costs. Conventional training methods often require a large number of epochs to converge, thereby increasing the time required. In this work, we propose Q-Forge - a two-stage training framework that combines pre-training on an ideal environment (noise-free) with fine-tuning on noisy devices to address the above drawbacks. In particular, we develop the QACS algorithm to automatically determine the optimal transition point once the model has converged on the ideal environment. This point marks the transition from the training process to a noise-aware phase, where the model is adapted to the realistic error characteristics of a specific quantum device. Experimental results on three typical quantum models (SQNN,VQC1, and VQC2) show that Q-Forge reduces training time by up to 70% compared to the direct training method, while maintaining or improving accuracy (6−8% increase for VQC2). These results confirm the feasibility and “plug-and-play” capability of Q-Forge, thereby enabling an efficient approach to training quantum models on real quantum devices.
EF-CenterNet: An efficient anchor-free model for UAV-based banana leaf disease detection
Authors: Huy-Tan Thai, Kim-Hung Le, Ngan Luu-Thuy Nguyen
Abstract: UAV-based remote sensing combined with deep neural networks has recently emerged for automated leaf disease detection on large-scale farmland. This research focuses on designing a fast and high-precision model for detecting banana leaf diseases from UAV-based samples in real-field conditions, where disease-affected regions are dense with different sizes. In detail, we propose a lightweight yet efficient banana leaf disease detection model with an anchor-free design, Efficient Feature CenterNet (EF-CenterNet). To effectively handle dense scenarios, our model employs the EfficientViT block, built based on the depth-wise separable convolutional layer, incorporated with the modified ReLU-attention mechanism. Feature Pyramid Network is then involved in tackling the size variation of contaminated regions via top-down upsampling architecture to fuse the feature in multi-scale levels. The proposed model …
MobileH-Transformer: Enabling real-time leaf disease detection using hybrid deep learning approach for smart agriculture
Authors: Huy-Tan Thai, Kim-Hung Le
Abstract: Agriculture has produced the vast majority of food for the world’s population throughout human history and plays a significant role in the economies of many countries, particularly on the continents of Asia and Africa. However, the quality and quantity of crop yields are influenced by various natural factors, including leaf diseases. While recent studies leveraged advanced deep learning models to accurately detect early disease symptoms, a significant gap remains in adapting these models for resource-constrained devices with limited computational capabilities, such as drones and smartphones. In this paper, we introduce MobileH-Transformer, a novel hybrid model combining convolutional neural networks (CNN) and Transformer architectures for accurate leaf disease detection with minimal computation demands. The proposed model integrates the CNN component with a novel dual convolutional block offering the …
nNFST: A single-model approach for multiclass novelty detection in network intrusion detection systems
Authors: Xuan-Ha Nguyen, Kim-Hung Le
Abstract: The rapid evolution of cyberattack techniques necessitates advanced intrusion detection systems (IDS) capable of multiclass novelty detection (MND), accurately classifying known attacks while identifying novel ones. Despite numerous successful studies focused on multi-class attack classification or novel attack detection separately, a significant research gap remains in achieving the effective MND for IDS. In this paper, we introduce the neighbour null Foley-Sammon transformation (nNFST), a novel single-model algorithm designed to address the MND challenge in IDS. nNFST employs a novel technique based on the inverse nearest neighbour algorithm to compute within-class and between-class variation. This technique preserves both the local distribution structure within each class and the global distribution structure across classes, thereby mitigating the impact of singular points on the algorithm and …
TinyResViT: A lightweight hybrid deep learning model for on-device corn leaf disease detection
Authors: Van-Linh Truong-Dang, Huy-Tan Thai, Kim-Hung Le
Abstract: The increasing prevalence of corn leaf diseases poses a significant threat to global food security, necessitating efficient and accurate detection methods. To address this challenge, we introduce TinyResViT, a lightweight yet efficient hybrid deep learning model designed by combining Residual Network (ResNet) and Vision Transformer (ViT) for leaf disease detection. This combination leverages the strengths of ResNet in extracting local features and ViT in capturing global interactions among features. In addition, a novel downsampling block connecting ResNet and ViT is proposed to eliminate redundant model weights. The evaluation results on the PlantVillage and Bangladeshi Crops Disease datasets show TinyResViT’s superior performance, achieving F1-scores of 97.92% and 99.11%, respectively. The model also maintains a high processing speed of 83.19 Frames Per Second (FPS) and a low computational …
DetectVul: A statement-level code vulnerability detection for Python
Authors: Hoai-Chau Tran, Anh-Duy Tran, Kim-Hung Le
Abstract: Detecting vulnerabilities in source code using graph neural networks (GNN) has gained significant attention in recent years. However, the detection performance of these approaches relies highly on the graph structure, and constructing meaningful graphs is expensive. Moreover, they often operate at a coarse level of granularity (such as function-level), which limits their applicability to other scripting languages like Python and their effectiveness in identifying vulnerabilities. To address these limitations, we propose DetectVul, a new approach that accurately detects vulnerable patterns in Python source code at the statement level. DetectVul applies self-attention to directly learn patterns and interactions between statements in a raw Python function; thus, it eliminates the complicated graph extraction process without sacrificing model performance. In addition, the information about each type of statement is also …
XSShield: A novel dataset and lightweight hybrid deep learning model for XSS attack detection
Authors: Gia-Huy Luu, Minh-Khang Duong, Trong-Phuc Pham-Ngo, Thanh-Sang Ngo, Dat-Thinh Nguyen, Xuan-Ha Nguyen, Kim-Hung Le
Abstract: With the proliferation of web applications, cross-site scripting (XSS) attacks have increased significantly and now pose a significant threat to users' information security and privacy. To enhance the efficiency of XSS attack detection, the adoption of machine learning (ML) and deep learning (DL) techniques offers promising solutions, but their effectiveness is limited by the lack of comprehensive and diverse datasets. Moreover, existing approaches often prioritize detection accuracy over real-time processing capabilities, which are essential for effective defense. To address these challenges, in this paper, we propose a novel framework that automatically collects web resources, efficiently extracts informative features, and constructs an up-to-date XSS attack dataset, which is then used to train a machine learning-based XSS detection model. Using this framework, we created and published a well-structured dataset over …
DeepNIDS: A Deep Neural Network-Based Network Intrusion Detection System for IoT
Authors: Xuan-Duong Nguyen, Xuan-Ha Nguyen, Hoang-Hai Huynh, Khanh-Hoi Le-Minh, Kim-Hung Le
Abstract: Recently, the widespread use of Internet of Things (IoT) has been triggering an exponential increase in the number of smart devices lacking hardware security supports. This gives rise to various challenges in Cyber-threat protection. In this paper, we present DeepNIDS a lightweight neural networkbased network intrusion detection system (NIDS) that effectively detects abnormal traffic. The core algorithm of DeepNIDS is a novel Convolutional Neural Network (CNN) model, specifically designed for classifying network traffic patterns. To enhance the detection performance, we employ 2D reshaped features as the input of our model, which is extracted and reshaped from network traffic over a period using Damped Incremental Statistics algorithm. Our experimental results show that DeepNIDS could identify nine types of attacks, showing superior detection capabilities over existing NIDS, with an average accuracy of …
BERT-Enhanced DGA Botnet Detection: A Comparative Analysis of Machine Learning and Deep Learning Models
Authors: Qui Cao, Phuc Dao-Hoang, Dat-Thinh Nguyen, Xuan-Ha Nguyen, Kim-Hung Le
Abstract: With the proliferation of Internet of Things, detecting Domain Generation Algorithm (DGA) botnets is critical for protecting networks from evolving and sophisticated cybersecurity threats. This paper explores a novel approach combining BERT with machine learning and deep learning techniques to detect DGA botnets. We provide a comprehensive benchmark by evaluating the performance of various BERT versions and detection methods on diverse datasets. Our experimental results reveal the significant impact of BERT version selection on detection accuracy and the superior performance of deep learning models, such as CNN, MLP, and LSTM, compared to conventional machine learning models. These findings highlight the potential of BERT and deep learning in improving DGA botnet detection and offer valuable insights for future research in this area.
An Effective Unsupervised Cyber Attack Detection on Web Applications Using Gaussian Mixture Model
Authors: KH. Tran-Thi, MH., Ngo, TK., Le, XH., Nguyen, DT., Nguyen, XH., Le
Abstract: Due to the popularity of web applications, web attacks have become more prevalent and sophisticated, which poses a threat to cyber security. Many works have proposed training a supervised learning model to detect these attacks, which has also been demonstrated to deliver a high detection rate. However, this methodology is challenging to deploy in the real world. Firstly, it demands a sufficiently annotated dataset, which is often difficult and costly to collect. Secondly, a supervised learning-based detection system could only detect new variants of known attacks while unable to detect novel attack types. Recognizing these challenges, this paper introduces an unsupervised approach that employs a Gaussian Mixture Model (GMM) for web attack detection. This approach not only eliminates the need for annotated datasets but also improves the ability to detect zero-day attacks, as it only requires training on normal …
Advancing Phishing Attack Detection with a Novel Dataset and Deep Learning Solution
Authors: KH. Le, QK., Nguyen, QA., Nguyen, DT., Nguyen, XH., Le
Abstract: Phishing attacks, increasingly complex and accessible due to low cost and technical requirements, demand advanced detection methods. While recent machine learning-based approaches show promising results in preventing these threats, they still face limitations in terms of outdated training datasets and the number of extracted features. Therefore, in this paper, we introduce a novel phishing attack dataset with a high number of samples and dimensionality. We also propose a transformer-based deep learning model to detect phishing attacks accurately. Our experimental results on our dataset show a significant performance gain, achieving 98.13% accuracy, surpassing popular machine learning models and SAINT, a state-of-the-art deep learning model for tabular data.
Deep learning models for UAV-assisted bridge inspection: A YOLO benchmark analysis
Authors: Trong-Nhan Phan, Hoang-Hai Nguyen, Huy-Tan Thai, Kim-Hung Le
Abstract: Visual inspections of bridges are critical to ensure their safety and identify potential failures early. This inspection process can be rapidly and accurately automated by using unmanned aerial vehicles (UAVs) integrated with deep learning models. However, choosing an appropriate model that is lightweight enough to integrate into the UAV and fulfills the strict requirements for inference time and accuracy is challenging. Therefore, our work contributes to the advancement of this model selection process by conducting a benchmark of 23 models belonging to the four newest YOLO variants (YOLOv5, YOLOv6, YOLOv7, YOLOv8) on COCO-Bridge-2021+, a dataset for bridge details detection. Through comprehensive bench-marking, we identify YOLOv8n, YOLOv7tiny, YOLOv6m, and YOLOv6m6 as the models offering an optimal balance between accuracy and processing speed, with mAP@50 scores of 0.803, 0.837, 0 …
An automated benchmarking framework for anomaly-based intrusion detection systems
Authors: Xuan-Ha Nguyen, Kim-Hung Le
Abstract: The rapid evolution of cyber threats has set an urgent requirement for cyber security solutions. In response to this, anomaly-based IDSs, powered by artificial intelligence, have emerged as a promising solution for detecting novel threats. However, the development of these systems is hindered by the time-consuming data preparation process and the absence of standardized evaluation frameworks. To address these challenges, this paper introduces a comprehensive benchmark framework designed to automate the evaluation of anomaly-based IDS solutions. The framework streamlines data preparation by incorporating multiple datasets and preprocessing steps, enabling researchers to more focus on model development. Additionally, we present baseline results for integrating machine learning models into IDSs by evaluating six models on five popular datasets CIC-IoT2023, CIC-DDoS2019, UNSWNB15 …
A Multi-Input Bi-LSTM Autoencoder Model with Wavelet Transform for Air Quality Prediction
Authors: Minh-Hao Ho, Nhu-Y Tran-Van, Kim-Hung Le
Abstract: Air pollution is a serious global issue that affects the health of millions of people worldwide. Machine learning models have shown promise in accurate prediction of the air quality index (AQI), which plays a crucial role in controlling and mitigating their impact. However, existing approaches have limitations in capturing temporal dependencies and analyzing frequency domain relationships among pollutants. In this study, we propose a novel multi-input model based on Bidirectional Long Short-Term Memory (Bi-LSTM) architecture, incorporating wavelet transformation for enhanced air quality prediction. The model first decomposes air quality data from neighboring regions into frequency components using wavelet transform, then extract valuable characteristic information and relationships using the Bi-LSTM module. This make our model effectively captures features across both temporal and frequency domains …
The Impact of Rotational Invariance on Tree-and Deep Learning-Based Network Intrusion Detection System
Authors: Dat-Thinh Nguyen, Xuan-Ha Nguyen, Kim-Hung Le
Abstract: In light of the achievements of deep learning in computer vision, natural language processing, and audio processing, recent research endeavors have been made to introduce novel deep learning models for tabular data. However, recent evaluations on small and medium-sized tabular datasets have shown that tree-based models still deliver better results than deep learning. One compelling rationale for this performance superiority lies in the non-rotational invariance property of tree-based models. However, in the context of intrusion detection with relatively large, the relationship between rotational invariance and the performance of these models remains unexplored. Therefore, this paper attempts to analyze the intrusion detection capabilities of tree-based and deep-learning models under rotations, shedding light on the relationship between the rotational invariance property and their detection performance. From …
Benchmarking svm variants for unsupervised intrusion detection system
Authors: Xuan-Ha Nguyen, Dat-Thinh Nguyen, Kim-Hung Le
Abstract: With the growing complexity of the computer network, novel cyber-attacks have been emerging rapidly, increasing the demand for unsupervised learning-based intrusion detection systems (IDS). While SVM-based algorithms are a popular solutions for anomaly IDSs, it is lacking studies that comprehensively evaluating the performance of these algorithms. Therefore, this paper aims to address the gap by quantitatively benchmarking 11 variants of SVM algorithms within four popular network intrusion datasets, including BoT-IoT, N-BaIoT, CIC-IDS-2017, and CIC-DDoS-2019. Our comprehensive analysis, involving over 400 model-attack pairs with thousands of experiment trials, provides invaluable insights into the capabilities and limitations of these algorithms. The findings offer guidance for the practical application of SVM-based techniques in IDS, enhance cybersecurity, and foster more secure, resilient network …
The robust scheme for intrusion detection system in internet of things
Authors: Dat-Thinh Nguyen, Kim-Hung Le
Abstract: Machine learning and deep learning-based anomaly intrusion detection systems (IDSs) have become prevalent in securing IoT networks due to their ability to monitor traffic and detect zero-day attacks. However, recent studies highlight the high vulnerability of these models to adversarial attacks, in which minor input perturbations can significantly decrease the detection accuracy. Although many studies have focused on adversarial attack and defense techniques for deep learning, machine learning, particularly decision trees, has received limited attention. In this study, we aim to assess the efficacy of the robust decision tree in adversarial IoT environments. Our first experiments reveal the robust decision tree’s sensitivity to the offset parameter. We thus propose a statistical approach to auto-select the offset value, enhancing model stability across varying attack offsets. Then, we present a robust scheme for IDSs in IoT …
Towards real-time outdoor air quality prediction using a hybrid model based on internet of things devices
Authors: Nhu-Y Tran-Van, Huy-Tan Thai, Khanh-Hoi Le-Minh, Kim-Hung Le
Abstract: Monitoring Air Quality Index (AQI) provides comprehensive air quality and valuable information about health risks and environmental impacts. The proliferation of IoT devices has enabled real-time AQI prediction by allowing individuals to locally collect and analyze air quality. However, deploying these AQI prediction models on resource-constrained IoT devices poses significant challenges, including computational limitations, model optimization, and data synchronization. In this paper, we propose a hybrid model combining convolutional neural networks and long short-term memory networks to predict the hourly air quality index. Our proposed model achieved a high accuracy of 95% while maintaining a lightweight model size. These results demonstrate that the proposed model can operate effectively on resource-constrained devices, such as the Raspberry Pi 3, without impacting other tasks.
An Edge-based Fire Detection System for Real-Time IoT Applications
Authors: Huy-Tan Thai, Nhu-Y Tran-Van, Khanh-Hoi Le-Minh, Kim-Hung Le
Abstract: Fire detection is a crucial research topic that has recently attracted many works. However, most of these existing methods tend to achieve high accuracy based on large deep neural networks without concern for real-time processing. Therefore, this paper proposes FireNet Lite, a lightweight CNN model optimized for real-time fire pattern recognition through efficient network design and pruning techniques. Experimental results show FireNet Lite achieves 96% accuracy on fire detection benchmarks while running at 36 fps on a Raspberry Pi 4, outperforming baseline deep neural networks. In addition, we also introduce a system that broadens the fire detection range by connecting all IoT devices with ThingsBoard.
Towards sustainable agriculture: A lightweight hybrid model and cloud-based collection of datasets for efficient leaf disease detection
Authors: Huy-Tan Thai, Kim-Hung Le, Ngan Luu-Thuy Nguyen
Abstract: Agricultural sustainability is a crucial component of the global economy and faces several challenges, including plant diseases. However, the application of deep learning models in unmanned aerial vehicles (UAVs) to detect plant diseases is hindered by their computational complexity and the lack of public datasets and information in this field. In this paper, we have two objectives. Firstly, we present a cloud-based collection by compiling and analyzing 38 available public datasets, which simplifies the work of researchers by reducing the time spent searching for suitable datasets. Secondly, we propose a lightweight model named Tiny-LeViT based on the transformer architecture for efficient leaf disease classification in edge network contexts. Our experiments on five popular datasets show that the proposed model outperforms its competitors, achieving at least 9% higher frame rate while retaining comparable F1 …
Robust detection of unknown DoS/DDoS attacks in IoT networks using a hybrid learning model
Authors: Xuan-Ha Nguyen, Kim-Hung Le
Abstract: The fourth industrial revolution is marked by the rapid growth of Internet of Things (IoT) technology, leading to an increase in the number of IoT devices. Unfortunately, this also makes these devices more susceptible to cyber threats, especially DoS/DDoS attacks. While supervised learning models have been adopted to detect and mitigate these threats, they have limitations in detecting unknown attacks that can cause severe consequences. This research aims to address those limitations and provide better protection for IoT networks against DoS/DDoS attacks. We propose a new approach that combines a soft-ordering convolutional neural network (SOCNN) model with local outlier factor (LOF) and isolation-based anomaly detection using nearest-neighbor ensembles (iNNE) models that use both supervised and unsupervised learning methods. We evaluated our approach on three benchmark datasets with varying …
Brainyedge: An ai-enabled framework for iot edge computing
Authors: Kim-Hung Le, Khanh-Hoi Le-Minh, Huy-Tan Thai
Abstract: Along with the proliferation of the Internet of Things (IoT) and the surge in the use of artificial intelligence (AI), Edge Computing has proved considerable success in reducing latency, network traffic consumption, and security risks. The convergence of AI and Edge Computing, emerging a brand-new paradigm called edge intelligence, has been expected to unleash the full potential of intelligent IoT services. Unfortunately, integrating AI and Edge Computing into IoT is highly challenging due to the concerns over IoT device performance, energy efficiency, and privacy. In this paper, we present brainyEdge, an AI-enabled framework for edge devices able to jointly satisfy the Quality of Experience (QoE) criteria of IoT applications. We enhanced the intelligence of AI models operating at edges by designing a learning procedure consisting of transfer learning and incremental learning to dynamically retrain the models with …
Towards generating semi-synthetic datasets for network intrusion detection system
Authors: Ngoc-Truong Nguyen, Ton-Nhan Le, Khanh-Hoi Le-Minh, Kim-Hung Le
Abstract: We have witnessed the proliferation of machine learning and its applications, especially in network-based intrusion detection systems (NIDS). With the ability to learn complex informative systems from data, machine learning models play a crucial role in identifying and preventing network attacks. However, training these models requires a massive volume of labeled data, which is nontrivial to obtain. Moreover, public datasets are often unbalanced, outdated, and different with network traffic from the networks that need to be protected. Therefore, in this paper, we introduce a framework, namely DGIDS, for generating semi-synthetic datasets for NIDS, which combines synthetic data and regular network traffic collected from the local network. Our proposed framework is capable of producing both benign and attack network data with characteristics similar to those in real scenarios. In practical experiments, we show that …
FormerLeaf: An efficient vision transformer for Cassava Leaf Disease detection
Authors: Huy-Tan Thai, Kim-Hung Le, Ngan Luu-Thuy Nguyen
Abstract: Leaf diseases have become more prevalent in recent years due to climate change, increased growth of outdoor air pollutants, and global warming. They may severely damage crop yield, leading to detrimental effects on global food security. The timely and precise detection of leaf diseases is thus crucial for preventing their spread and ensuring the sustainability of agricultural production. In this paper, we introduce a transformer-based leaf disease detection model, namely FormerLeaf along with two optimization methods to enhance the model performance. In more detail, we propose the Least Important Attention Pruning (LeIAP) algorithm to select the most important attention heads of each layer in the Transformer model. It could reduce the model size up to 28% and accelerate the evaluation speed by 15% with about 3% accuracy enhancement. In addition, we employ the sparse matrix-matrix multiplication (SPMM …
Enhancing explainability of machine learning-based intrusion detection systems
Authors: Thuy-Linh Nguyen, Xuan-Ha Nguyen, Kim-Hung Le
Abstract: Over the past decade, the anomaly-based Intrusion Detection System (IDS) has established itself with many studies proving its effectiveness, especially with deep learning models. However, these models have become more complex, thus making them difficult for humans to explain the system's decisions. Meanwhile, research to increase the transparency of IDSs receives insufficient attention from the research community. Therefore, this study proposes an Explainable NIDS capable of accurately detecting attacks and providing explicit explanations for its decisions. Our proposed IDS employs the Shapley Additive exPlanations (SHAP) framework to account for IDS decisions. It assists our IDS in self-explain its decisions at both the local and global levels. The local explanation explains the IDS decisions for each specific sample, while the global level provides the feature's importance and shows the attacks' …
A Real-time Border Surveillance System using Deep Learning and Edge Computing
Authors: Dang-Khoa Luong-Huu, Tan-An Ngo, Huy-Tan Thai, Kim-Hung Le
Abstract: Border security has always been one of the top priority obligations and responsibilities in protecting the peace of nations. Most nations have thousands of kilometers of long borders, where illegal activities occur frequently. To ensure safety, robust and timely border surveillance systems are in high demand. However, current border surveillance systems using cloud architecture have faced several problems with high latency, bandwidth consumption, and security risks. In this paper, we introduce a real-time border surveillance system based on edge computing that shifts computation tasks from cloud to edge, resulting in alleviating existing problems. In detail, we produce a lightweight human detection model based on the MobileNet architecture, namely BorderEdge, to operate on resource-constrained devices effectively. Our experiment results on Raspberry Pi 4 show that our system could achieve high accuracy with …
Towards an attention-based threat detection system for iot networks
Authors: Thanh-Nhan Nguyen, Khanh-Mai Dang, Anh-Duy Tran, Kim-Hung Le
Abstract: The proliferation of the Internet of Things (IoT) serves demands in our life ranging from smart homes and smart cities to manufacturing and many other industries. As a result of the massive deployment of IoT devices, the risk of cyber-attacks on these devices also increases. The limitation in computing resources of IoT devices stops people from directly operating antivirus software on them. Therefore, these devices are vulnerable to cyber-attacks. In this research, we present our novel approach that could be applied to construct a lightweight Network Intrusion Detection System (NIDS) on IoT gateways. We utilize TabNet-the Google’s recently developed model for tabular data-as our detection model. The evaluation results on BOT-IoT and UNSW-NB15 datasets prove the ability of our proposal in intrusion detection tasks with the accuracy of 98,53% and 99,43%. Finally, we experiment with our approach on the …
Preventing Adversarial Attacks Against Deep Learning-Based Intrusion Detection System
Authors: Xuan-Ha Nguyen, Xuan-Duong Nguyen, Kim-Hung Le
Abstract: Deep learning (DL) applications in network intrusion detection systems (NIDS) are increasingly popular in protecting IoT networks against cyber threats. However, these systems are threatened by adversarial attacks that can evade detection and disrupt the network. Preventing such attacks is highly challenging due to their variation and the resource-constrained nature of IoT devices. Therefore, in this paper, we first evaluate the impact of adversarial attacks on a novel DL-based NIDS designed for IoT networks. Then, we propose an adversarial detector powered by a light gradient boosted algorithm against adversarial attacks. The superiority of our proposal is to detect several types of adversarial attacks with high accuracy while ensuring low additional latency. The evaluation results on practical datasets show that our model effectively detects adversarial attacks, with an overall F-score of 99.66% and much higher …
Deep feature selection for machine learning based attack detection systems
Authors: Minh-Tri Huynh, Hoang-Trung Le, Xuan-Ha Nguyen, Kim-Hung Le
Abstract: The typical intrusion detection system (IDS) based on machine learning classifies normal and attack network traffic by extracting and analyzing network features. However, several extracted features are irrelevant and may degrade the classification accuracy. In addition, they also increase the training time and model size. Therefore, feature selection is an essential process in building an IDS system. In this paper, we propose a feature selection method for IDS by employing a Deep Neural Network model to search for and select the most crucial features. The proposal is evaluated with two datasets UNSW-NB15 and CIC-IDS2017, and archives superior results compared with other feature selection algorithms with accuracy up to 99.96% for UNSW-NB15, 99.88% for CIC-IDS2017 while combining with LSTM-based IDS. It also reduces significant data size and time for training.
LS-TFP: A LSTM-Based Traffic Flow Prediction Method in Intelligent Internet of Things
Authors: Nhu-Y Tran-Van, Nhat-Tuan Pham, Kim-Hung Le
Abstract: Intelligent transport system has been emerging as a crucial component of the smart city context, and traffic flow prediction plays an essential role in ITS. Recently, many studies have used algorithms based on time prediction and deep learning. However, their prediction accuracy is insufficient for the significant growth in IoT applications. To overcome this issue, we proposed a novel prediction model, namely the LSTM-based traffic flow prediction (LS-TFP), using the combination of the long short-term memory and recurrent neural network (LSTM-RNN). In our proposal, we stack two LSTM layers to produce a more in-depth model. In addition, as a consequence of the remembering ability of LSTM, the predicted value could achieve high accuracy. Our practical experiments on real datasets show that the LS-TFP accuracy is reached up to 98.1% and outperforms our competitors.
Towards smart traffic lights based on deep learning and traffic flow information
Authors: Nhu-Y Tran-Van, Xuan-Ha Nguyerr, Kim-Hung Le
Abstract: Traffic congestion is a significant cause hindering development and adversely affecting socio-economic life; mean-while, traditional traffic light systems have become obsolete. Therefore, the application of machine learning to enhance the effectiveness of these systems has received much attention from the research community. However, their practical application is limited because of the lack of training datasets and high computational requirements. In this paper, we propose a lightweight approach that can dynamically control traffic lights at intersections based on current traffic situation. To do this, we design a deep learning model based on the Bidirectional LSTM architecture to estimate the appropriate duration of traffic lights by learning traffic flow information. Our model achieves high accuracy and is lightweight enough to deploy resource-constrained IoT devices. In addition, we introduce an algorithm to generate …
Towards a Robust and Scalable Information Retrieval Framework in Big Data Context
Authors: Hoang-Long Nguyen, Trong-Nhan Trinh-Huynh, Kim-Hung Le
Abstract: The proliferation of information in cyberspace is increasing exponentially, leading to challenges for information retrieval systems to satisfy demands for performance and accuracy. How-ever, most existing works concentrate more on designing natural language processing (NLP) models than building such systems, which require massive efforts. In this study, we propose a modular framework for an information retrieval system consisting of several large-scale components capable of processing massive data. In addition, the proposed framework provides a high level of customization by assisting end-users in quickly replacing the NLP models to suit different contexts. This shortens the deployment from research to production of novel NLP models. The evaluation results of our prototype integrated with Vietnamese retrieval models show that the proposed framework is highly robust and scalable in big data contexts.
Toward a predictive smart parking system in IoT-enabled cities
Authors: Huy-Tan Thai, Tuyen-Lam Nguyen-Tran, Kim-Hung Le
Abstract: One of the main traffic problems that need to be taken care of is traffic congestion, which causes many harmful consequences such as air pollution and waste of fuel. The ineffectiveness of parking vehicles is the main reason for traffic congestion due to the shortage of parking spaces and the lack of guidance information leading to spending considerable time searching for parking spaces, which causes traffic delays. In this paper, we proposed a smart parking system that can predict parking availability based on long short-term memory (LSTM) network. The system then notifies the drivers about forecast information that help drivers save time in choosing parking lots. Subsequently, we deploy a license plate recognition (LPR) mechanism on the Jetson nano developer kit that automatically recognizes the vehicle's plate at the parking lot entrance. Experimental results show that LSTM can outperform the popular time …
Towards a high-performance threat-aware system for software-defined networks
Authors: Van-Tai Nguyen, Van-Chuc Hoang, Xuan-Ha Nguyen, Kim-Hung Le
Abstract: With the rapid development of intelligent devices and high-speed networks, the popularity of Internet services and the Internet of Things (IoT) has been increasing significantly in the last decade. This leads to the explosion of data exchanged over the Internet, also known as the Big Data era, which has posed several challenges in preventing security threats, especially for intrusion detection systems (IDS) due to high data velocity. In this paper, we propose a Distributed Network Intrusion Detection System (DisIDS) that accurately detects security threats by gathering statistical information about flows from software-defined network (SDN) switches in real-time and identifying abnormal traffic patterns using a distributed machine learning model. Evaluation results on a simulated system show that our proposal could identify several security threats with high accuracy (94.7% f1-score) and a relatively low false alarm rate …
A lightweight machine-learning based wireless link estimation for iot devices
Authors: Khanh-Hoi Le-Minh, Kim-Hung Le, Quan Le-Trung
Abstract: Robust wireless communication between devices is crucial to ensuring the reliability of IoT systems. However, it is strictly relied on estimating the link quality of these devices, which is usually interfered with by environmental factors. In such a scenario, intelligent algorithms based on machine learning to select resistant communication links are promising solutions, but they demand sophisticated computation, limiting their deployment on resource-constrained IoT devices. Therefore, this paper introduces a lightweight link quality estimation algorithm, namely LLQE, built from the gradient boosting decision tree. The superiority of our proposal not only precisely assesses several levels of link quality but also is lightweight enough for resource-constraint devices. The evaluation results on publicly available datasets show that LLQE accurately estimates various link quality indicators with 97% accuracy.
Empirical performance evaluation of machine learning based DDoS attack detections
Authors: Bao-Sam Tran, Thi-Huyen Ho, Thanh-Xuan Do, Kim-Hung Le
Abstract: A distributed denial-of-service attack (DDoS) is a critical attack-type that strongly damages the Quality of Service (QoE). Although various novel security technologies have been continually developing, completely preventing DDoS threats is still unreached. Hence, applying deep learning to detect DDoS attacks effectively is high interest. However, comprehensively analyzing these techniques remains unobservant. In this paper, we present a solid architecture supporting evaluating machine-learning-based DDoS detection techniques from both public and self-generated datasets. A high-accuracy ensemble DDoS detection method is proposed from the evaluation results. Furthermore, we expect that these results could be essential resources for later DDoS researches. Furthermore, the study also provides an overview of the features, labels from which there is a basis for creating a complete dataset used for DDoS …
A real-time evaluation framework for machine learning-based ids
Authors: Anh-Hao Vu, Minh-Quan Nguyen-Khac, Xuan-Thanh Do, Kim-Hung Le
Abstract: With the rapid evolution of internal and external cyber threats, building a reliable security management system has become an urgent demand to mitigate system risks. In such systems, the Intrusion Detection System (IDSs) and Intrusion Prevention Systems (IPSs) are central components widely deployed to prevent malicious traffic from attackers. Most of the research target to enhance the performance of IDSs and IPSs. One problem that affects the performance is training datasets, and the solution to resolve this problem use benchmark datasets. However, there are many problems with that solution. Firstly, many valuable datasets used for evaluating the IDS model are internal and cannot be shared due to privacy issues. Secondly, open-source datasets such as DEFCON, KDD, CAIDA have its limitation and do not reflect the current world trends. In this paper, we introduce a framework used for practically evaluating …
IMIDS: An intelligent intrusion detection system against cyber threats in IoT
Authors: Kim-Hung Le, Minh-Huy Nguyen, Trong-Dat Tran, Ngoc-Duan Tran
Abstract: The increasing popularity of the Internet of Things (IoT) has significantly impacted our daily lives in the past few years. On one hand, it brings convenience, simplicity, and efficiency for us; on the other hand, the devices are susceptible to various cyber-attacks due to the lack of solid security mechanisms and hardware security support. In this paper, we present IMIDS, an intelligent intrusion detection system (IDS) to protect IoT devices. IMIDS’s core is a lightweight convolutional neural network model to classify multiple cyber threats. To mitigate the training data shortage issue, we also propose an attack data generator powered by a conditional generative adversarial network. In the experiment, we demonstrate that IMIDS could detect nine cyber-attack types (e.g., backdoors, shellcode, worms) with an average F-measure of 97.22% and outperforms its competitors. Furthermore, IMIDS’s detection performance is notably improved after being further trained by the data generated by our attack data generator. These results demonstrate that IMIDS can be a practical IDS for the IoT scenario.
Realguard: A lightweight network intrusion detection system for IoT gateways
Authors: Xuan-Ha Nguyen, Xuan-Duong Nguyen, Hoang-Hai Huynh, Kim-Hung Le
Abstract: Cyber security has become increasingly challenging due to the proliferation of the Internet of things (IoT), where a massive number of tiny, smart devices push trillion bytes of data to the Internet. However, these devices possess various security flaws resulting from the lack of defense mechanisms and hardware security support, therefore making them vulnerable to cyber attacks. In addition, IoT gateways provide very limited security features to detect such threats, especially the absence of intrusion detection methods powered by deep learning. Indeed, deep learning models require high computational power that exceeds the capacity of these gateways. In this paper, we introduce Realguard, an DNN-based network intrusion detection system (NIDS) directly operated on local gateways to protect IoT devices within the network. The superiority of our proposal is that it can accurately detect multiple cyber attacks in real time with a small computational footprint. This is achieved by a lightweight feature extraction mechanism and an efficient attack detection model powered by deep neural networks. Our evaluations on practical datasets indicate that Realguard could detect ten types of attacks (e.g., port scan, Botnet, and FTP-Patator) in real time with an average accuracy of 99.57%, whereas the best of our competitors is 98.85%. Furthermore, our proposal effectively operates on resource-constraint gateways (Raspberry PI) at a high packet processing rate reported about 10.600 packets per second.
Towards Remote Deployment for Intrusion Detection System to IoT Edge Devices
Authors: Xuan-Thanh Do, Kim-Hung Le
Abstract: Recently, low latency in data transmission has become one of the most critical requirements in developing the Internet of Things (IoT) applications. It triggers a novel network architecture, namely edge computing, that aims to move computing units close to data sources. This transformation emerges several security issues about designing and implementing security applications. An intrusion detection system (IDS), a well-designed system for detecting abnormal behaviors, needs to be transformed into modern system architectures. This article presents an edge-based architecture to quickly deploy a deep learning-based IDS to edge network devices regardless of the heterogeneity in hardware and deep learning model configurations. To demonstrate the effectiveness of our proposal, we also analyze various performance indicators of the architecture, deployment process, and deep-learning models.
MidSiot: A multistage intrusion detection system for internet of things
Authors: Nguyen Dat-Thinh, Ho Xuan-Ninh, Le Kim-Hung
Abstract: Internet of Things (IoT) has been thriving in recent years, playing an important role in a multitude of various domains, including industry 4.0, smart transportation, home automation, and healthcare. As a result, a massive number of IoT devices are deployed to collect data from our surrounding environment and transfer these data to other systems over the Internet. This may lead to cybersecurity threats, such as denial of service attacks, brute‐force attacks, and unauthorized accesses. Unfortunately, many IoT devices lack solid security mechanisms and hardware security supports because of their limitations in computational capability. In addition, the heterogeneity of devices in IoT networks causes nontrivial challenges in detecting security threats. In this article, we present a collaborative intrusion detection system (IDS), namely, MidSiot, deployed at both Internet gateways and IoT local gateways. Our proposed IDS …
Odlie: On-demand deep learning framework for edge intelligence in industrial internet of things
Authors: Khanh-Hoi Le Minh, Kim-Hung Le
Abstract: Recently, we have witnessed the evolution of Edge Computing (EC) and Deep Learning (DL) serving Industrial Internet of Things (IIoT) applications, in which executing DL models is shifted from cloud servers to edge devices to reduce latency. However, achieving low latency for IoT applications is still a critical challenge because of the massive time consumption to deploy and operate complex DL models on constrained edge devices. In addition, the heterogeneity of IoT data and device types raises edge-cloud collaboration issues. To address these challenges, in this paper, we first introduce ODLIE, an on-demand deep learning framework for IoT edge devices. ODLIE employs DL right-selecting and DL right-sharing features to reduce inference time while maintaining high accuracy and edge collaboration. In detail, DL right-selecting chooses the appropriate DL model adapting to various deployment contexts and …
LS-SPP: A LSTM-Based Solar Power Prediction Method from Weather Forecast Information
Authors: Nhat-Tuan Pham, Nhu-Y Tran-Van, Kim-Hung Le
Abstract: Solar radiation is an unlimited source of clean energy with huge exploitation potential. To effectively exploit this valuable resource, the arrival of the solar forecast has shown an improvement in incorporating renewable energy into the grid system. Having accurate solar prediction would yield useful information to ensure the power grid’s stability, gain the advantage of renewable energy, and minimize mineral resource consumption. In this paper, we introduce a novel deep learning model, namely LSTM-Based Solar Power Prediction (LS-SPP), combining long short-term memory and a recurring neural network (LSTM-RNN). The proposed model is stacked with two LSTM layers to produce a high prediction accuracy based on historical meteorological time series. Our practical experiment on real datasets shows that the LS-SSP model achieves up to 96.78% accuracy in performance, higher than the best of competitors …
An ensemble feature selection algorithm for machine learning based intrusion detection system
Authors: Phuoc-Cuong Nguyen, Quoc-Trung Nguyen, Kim-Hung Le
Abstract: In recent years, we have witnessed the significant growth of the Internet along with emerging security threats. A machine learning-based Intrusion Detection System (IDS) is widely employed to detect cyber attacks by continuously monitoring network traffic. However, the diversity of network features considerably affected the accuracy and training time of the IDS model. In this paper, a lightweight and effective feature selection algorithm for IDS is proposed. This algorithm combines the advantages of both Random Forest and AdaBoost algorithms. The evaluation results on popular datasets (NSL- KDD, UNSW-NB15, and CICIDS-2017) show that our proposal outperforms existing feature selection algorithms regarding the detection accuracy and the number of selected features.
Artificial cognition for early leaf disease detection using vision transformers
Authors: Huy-Tan Thai, Nhu-Y Tran-Van, Kim-Hung Le
Abstract: There are many kinds of cassava leaf diseases firmly harm cassava yield, including four main types as followings Cassava Bacterial Blight (CBB), Cassava Brown Streak Disease (CBSD), Cassava Green Mottle (CGM), and Cassava Mosaic Disease (CMD). In a traditional way, leaf diseases were diagnosed intuitively by farmers. This process is inefficient and unreliable. Several studies have recently relied on deep neural networks for identifying leaf diseases. In this research, we exploit the novel model named Vision Transformer (ViT) in place of a convolution neural network (CNN) for classifying cassava leaf diseases. Experimental results show that this model can obtain competitive accuracy at least 1% higher than popular CNN models (EfficientNet, Resnet50d) on Cassava Leaf Disease Dataset. These results also indicate the potential superiority of the ViT over established methods in analyzing leaf diseases …
AirGen: GAN-based synthetic data generator for air monitoring in Smart City
Authors: Khanh-Hoi Le Minh, Kim-Hung Le
Abstract: The past decade has seen a notable increase in air pollution that directly damages health, animals, and plants worldwide. To mitigate such negative effects, several research groups have been working on predicting air quality using deep learning. However, the lack of high-quality air quality datasets is a major obstacle encountered to achieve high accuracy prediction. In this paper, we introduce an air monitoring data generator powered by learning distributed real sequences using the generative adversarial network (GAN), namely AirGen. An unsupervised adversarial loss is also employed in the network to minimize the difference between generated synthetic and original data in the training process. Experiments on real datasets indicate that the data generated by Airgen could significantly increase the prediction accuracy performed by deep learning models. The mean square error (MSE) is remarkably reduced …
Towards AI‐based traffic counting system with edge computing
Authors: Duc-Liem Dinh, Hong-Nam Nguyen, Huy-Tan Thai, Kim-Hung Le
Abstract: The recent years have witnessed a considerable rise in the number of vehicles, which has placed transportation infrastructure and traffic control under tremendous pressure. Yielding timely and accurate traffic flow information is essential in the development of traffic control strategies. Despite the continual advances and the wealth of literature available in intelligent transportation system (ITS), there is a lack of practical traffic counting system, which is readily deployable on edge devices. In this study, we introduce a low‐cost and effective edge‐based system integrating object detection models to perform vehicle detecting, tracking, and counting. First, a vehicle detection dataset (VDD) representing traffic conditions in Vietnam was created. Several deep learning models for VDD were then examined on two different edge device types. Using this detection, we presented a lightweight counting method seamlessly …
Thesis-supervised students
Authors: Khanh-An Le-Minh
Abstract: students supervised for their theses
Dlase: A light-weight framework supporting deep learning for edge devices
Authors: Khanh-Hoi Le Minh, Kim-Hung Le, Quan Le-Trung
Abstract: With the rapid growth of the Internet of Things (IoT), there is a massive number of constrained devices connected to the internet, resulting in the generation of large data volume. The deep learning (DL) has become a promised solution to extract more valuable knowledge from collected data but struggle to execute DL algorithms due to limited computing resources of IoT devices. Leveraging the computation power of cloud computing, we could offload the data to cloud servers for processing and response results to the devices. But, this paradigm leads to a significant increase in latency and security risks. Therefore, there have been many efforts to perform DL algorithms on edge devices, which are close to the data sources. Deploying various DL systems to such edge devices a complex process due to the diversity of DL models and running environment configuration. In this paper, we propose a light-weight framework …
User-driven adaptive sampling for massive internet of things
Authors: Le Kim-Hung, Quan Le-Trung
Abstract: Energy conservation techniques are crucial to achieving high reliability in the Internet of Things (IoT) services, especially in the Massive IoT (MIoT), which stringently requires cost-effective and low-energy consumption for battery-powered devices. Most of the proposed techniques generally assume that data acquiring and processing consume significantly lower than that of communication. Unfortunately, this assumption is incorrect in the MIoT scenario, which mostly involves the low-power wide-area network (LPWAN) and complex data sensing operations (e.g., biological and seismic sensing) using “power-hungry” sensors (e.g., gas sensors, seismometers). Thus, sensing actions may consume even more energy than transmission. In addition, none of them support end-users in controlling the trade-off between energy conservation and data precision. To deal with these issues, we propose an adaptive sampling …
User-driven error detection for time series with events
Authors: Kim-Hung Le, Paolo Papotti
Abstract: Anomalies are pervasive in time series data, such as sensor readings. Existing methods for anomaly detection cannot distinguish between anomalies that represent data errors, such as incorrect sensor readings, and notable events, such as the watering action in soil monitoring. In addition, the quality performance of such detection methods highly depends on the configuration parameters, which are dataset specific. In this work, we exploit active learning to detect both errors and events in a single solution that aims at minimizing user interaction. For this joint detection, we introduce an algorithm that accurately detects and labels anomalies with a non-parametric concept of neighborhood and probabilistic classification. Given a desired quality, the confidence of the classification is then used as termination condition for the active learning algorithm. Experiments on real and synthetic datasets demonstrate that our …
WoT-AD: A descriptive language for group of things in massive IoT
Authors: Kim-Hung Le, Soumya Kanti Datta, Christian Bonnet, Francois Hamon
Abstract: Recently, the Massive Internet of Things (IoT) and Web of Things (WoT) are remarkable research fields aiming to facilitate the connectivity, accessibility, and control of the Things by Web standards and technologies for large-scale deployment. In such context, the end-user is capable of simply creating, mashing-up, and presenting the multiple Things to gain high-level information. However, current research approaches much more pay attention to describe a single Thing. The modeling and building the application for the compound objects consisting of groups of Things namely "Asset" are still limited due to the lack of description and seamless integration mechanism. Moreover, the traditional IoT Device Description Language directly installed on device is highly restricted in Massive IoT scenario because of stringent requirements for power consumption and operation cost. In this paper, we introduce the WoT based …
A scalable IoT framework to design logical data flow using virtual sensor
Authors: Le Kim-Hung, Soumya Kanti Datta, Christian Bonnet, François Hamon, Alexandre Boudonne
Abstract: During recent years, we have witnessed an explosion in the Internet of Thing (IoT) in terms of the number and types of physical devices. However, there are many limitations of these devices regarding their computing power, storage, and connection capabilities. They affect on-device processing of sensed data significantly. Centralized treatment of IoT data has proven challenging for many use cases demanding real time response. This paper aims at augmenting sensor data processing using the concept of virtual sensors. We propose a scalable virtual sensor framework that supports building a logical dataflow (LDF) by visualizing either physical sensors or custom virtual sensors. The process produces high-level information from the sensed data that can be easily perceived by machines and humans. A web-based virtual sensor editor (VSE) is also implemented on the top of the framework to simplify creation and …
An industrial IoT framework to simplify connection process using system-generated connector
Authors: Le Kim-Hung, Soumya Kanti Datta, Christian Bonnet, Francois Hamon, Alexandre Boudonne
Abstract: Industrial Internet of Thing (IIoT) promises a lot of positive impacts on manufacturing, process transformation and digital value acceleration. IIoT is considered to have the potential to launch fourth industrial revolution and related economies. However, since IIoT is at its early stage, its benefits are limited to connected devices and open data sources to enrich the measurements and analysis. In this paper, we propose an innovative IIoT framework that could automate the process of creating cloud-based middleware connector for things used in industrial settings. The framework significantly accelerates the configuration process for heterogeneous connections by using a light-weight and convenient connector template and supports the common set of protocols. Interoperability with other such implementations is preserved using ongoing IoT standardization.
