LAFR-IoT: A Lightweight AI-Driven Network Forensic Readiness Framework for Resource-Constrained IoT–Edge Devices

Authors

  • Md Manirul Islam American International University-Bangladesh image/svg+xml , Samarkand State University named after Sharof Rashidov image/svg+xml
  • Md Mehedi Hasan Ratul American International University-Bangladesh image/svg+xml
  • Md Tahsin Tasnim Aurin American International University-Bangladesh image/svg+xml
  • Sazzad Hossain Samarkand State University named after Sharof Rashidov image/svg+xml

DOI:

https://doi.org/10.53799/8s5v6c24

Keywords:

CICIoT2023, edge AI, explainable AI, IoT forensics, lightweight machine learning, network forensic readiness, resource-constrained IoT, selective logging

Abstract

The rapid expansion of Internet of Things (IoT) deployments has increased the volume of network evidence generated at the edge, yet most IoT devices remain constrained by limited processing power, memory, energy, and storage. These limitations make conventional full-packet logging and heavyweight intrusion detection impractical for proactive forensic readiness. This study proposes LAFR-IoT, a lightweight AI-driven network forensic readiness framework for resource-constrained IoT–Edge devices. The framework integrates lightweight machine learning, edge-aware model selection, explainability-based feature analysis, and selective forensic logging to detect, triage, and preserve high-value network events before evidence is lost. Experiments were conducted using the CICIoT2023 dataset, where network traffic was mapped into eight forensic categories: Benign, Brute Force, DDoS, DoS, Mirai, Recon, Spoofing, and Web. Eight lightweight models were evaluated. Although a shallow decision tree achieved the highest validation macro-F1, a linear support vector machine achieved the best overall Edge Forensic Score because of its low latency, small model size, and deployment efficiency. On the independent test set, the linear model achieved 0.7512 accuracy, 0.5741 macro-F1, 0.7615 weighted-F1, 0.0051 ms per sample inference latency, and a 0.0077 MB model size. The proposed selective logging mechanism reduced storage usage by 74.59% while preserving 98.96% of malicious events. These results show that lightweight edge AI can support proactive IoT forensic readiness by balancing detection performance, explainability, storage efficiency, and resource-aware deployment.

References

[1]E. C. P. Neto, S. Dadkhah, R. Ferreira, A. Zohourian, R. Lu, and A. A.Ghorbani, “CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment,” Sensors, vol. 23, no. 13, Art. no. 5941, 2023, doi: 10.3390/s23135941.

[2]M. Stoyanova, Y. Nikoloudakis, S. Panagiotakis, E. Pallis, and E. K.Markakis, “A survey on the Internet of Things (IoT) forensics:Challenges, approaches, and open issues,” IEEE Commun. Surveys Tuts., vol. 22, no. 2, pp. 1191–1221, 2020, doi:10.1109/COMST.2019.2962586.

[3]H. F. Atlam, E. E.-D. Hemdan, A. Alenezi, M. O. Alassafi, and G. B.Wills, “Internet of Things forensics: A review,” Internet Things, vol. 11,Art. no. 100220, 2020, doi: 10.1016/j.iot.2020.100220.

[4]P. Lutta, M. Sedky, M. Hassan, U. Jayawickrama, and B. BakhtiariBastaki, “The complexity of Internet of Things forensics: A state-of-the-art review,” Forensic Sci. Int. Digit. Investig., vol. 38, Art. no. 301210,2021, doi: 10.1016/j.fsidi.2021.301210.

[5]A. A. Ahmed, K. Farhan, W. A. Jabbar, A. Al-Othmani, and A. G.Abdulrahman, “IoT forensics: Current perspectives and futuredirections,” Sensors, vol. 24, no. 16, Art. no. 5210, 2024, doi:10.3390/s24165210.

[6]S. Friedl and G. Pernul, “IoT forensics readiness—Influencing factors,”Forensic Sci. Int. Digit. Investig., vol. 49, Art. no. 301768, 2024, doi:10.1016/j.fsidi.2024.301768.

[7]S. Rizvi, M. Scanlon, J. McGibney, and J. W. Sheppard, “Pushingnetwork forensic readiness to the edge: A resource constrained artificialintelligence based methodology,” in Proc. 2024 Cyber Research Conf.—Ireland (Cyber-RCI), 2024, pp. 1–8, doi: 10.1109/Cyber-RCI60769.2024.10939120.

[8]S. Rizvi, M. Scanlon, J. McGibney, and J. W. Sheppard, “Application ofartificial intelligence to network forensics: Survey, challenges and future directions,” IEEE Access, vol. 10, pp. 110362–110384, 2022, doi:10.1109/ACCESS.2022.3214506.

[9]M. He, Y. Huang, X. Wang, P. Wei, and X. Wang, “A lightweight andefficient IoT intrusion detection method based on feature grouping,” IEEE Internet Things J., vol. 11, no. 2, pp. 2935–2949, 2024, doi:10.1109/JIOT.2023.3294259.

[10]M. Fatima, O. Rehman, I. M. H. Rahman, A. Ajmal, and S. J. Park,“Towards ensemble feature selection for lightweight intrusion detectionin resource-constrained IoT devices,” Future Internet, vol. 16, no. 10, Art. no. 368, 2024, doi: 10.3390/fi16100368.

[11]M. Fatima, O. Rehman, S. Ali, and M. F. Niazi, “ELIDS: Ensemblefeature selection for lightweight IDS against DDoS attacks in resource-constrained IoT environment,” Future Gener. Comput. Syst., vol. 159, pp. 172–187, 2024, doi: 10.1016/j.future.2024.05.013.

[12]J. Li, H. Chen, M. O. Shahizan, and L. M. Yusuf, “Enhancing IoTsecurity: A comparative study of feature reduction techniques forintrusion detection system,” Intell. Syst. Appl., vol. 23, Art. no. 200407,2024, doi: 10.1016/j.iswa.2024.200407.

[13]S. F. Misrak and H. M. Melaku, “Lightweight intrusion detection system for IoT with improved feature engineering and advanced dynamicquantization,” Discov. Internet Things, vol. 5, Art. no. 97, 2025, doi:10.1007/s43926-025-00203-8.

[14]X.-H. Nguyen, X.-D. Nguyen, H.-H. Huynh, and K.-H. Le, “Realguard:A lightweight network intrusion detection system for IoT gateways,”Sensors, vol. 22, no. 2, Art. no. 432, 2022, doi: 10.3390/s22020432.

[15]S. Roy, J. Li, B.-J. Choi, and Y. Bai, “A lightweight supervised intrusion detection mechanism for IoT networks,” Future Gener. Comput. Syst.,vol. 127, pp. 276–285, 2022, doi: 10.1016/j.future.2021.09.027.

[16]J. Arshad, M. A. Azad, M. M. Abdeltaif, and K. Salah, “An intrusiondetection framework for energy constrained IoT devices,” Mech. Syst.Signal Process., vol. 136, Art. no. 106436, 2020, doi:10.1016/j.ymssp.2019.106436.

[17]J. Azimjonov and T. Kim, “Stochastic gradient descent classifier-based lightweight intrusion detection systems using the efficient feature subsets

of datasets,” Expert Syst. Appl., vol. 237, Art. no. 121493, 2024, doi: 10.1016/j.eswa.2023.121493.

[18]S. Yaras and M. Dener, “IoT-based intrusion detection system using new hybrid deep learning algorithm,” Electronics, vol. 13, no. 6, Art. no. 1053, 2024, doi: 10.3390/electronics13061053.

[19]F. Ebrahimi, R. Javidan, R. Akbari, and Y. Hosseini, “Intrusion detection in the Internet of Things using convolutional neural networks: Anexplainable AI approach,” Cybersecurity, vol. 8, Art. no. 66, 2025, doi:10.1186/s42400-025-00369-2.

[20]H. Q. Gheni and W. L. Al-Yaseen, “Two-step data clustering forimproved intrusion detection system using CICIoT2023 dataset,” e-Prime—Adv. Electr. Eng. Electron. Energy, vol. 9, Art. no. 100673, 2024, doi: 10.1016/j.prime.2024.100673.

[21]P. Mahadevappa, R. K. Murugesan, R. Al-amri, R. Thabit, A. H. Al-Ghushami, and G. Alkawsi, “A secure edge computing model usingmachine learning and IDS to detect and isolate intruders,” MethodsX, vol. 12, Art. no. 102597, 2024, doi: 10.1016/j.mex.2024.102597.

[22]Y. Meidan, M. Bohadana, Y. Mathov, Y. Mirsky, D. Breitenbacher, A.Shabtai, and Y. Elovici, “N-BaIoT—Network-based detection of IoTbotnet attacks using deep autoencoders,” IEEE Pervasive Comput., vol.17, no. 3, pp. 12–22, 2018, doi: 10.1109/MPRV.2018.03367731.

[23]A. A. Diro and N. Chilamkurti, “Distributed attack detection schemeusing deep learning approach for Internet of Things,” Future Gener.Comput. Syst., vol. 82, pp. 761–768, 2018, doi:10.1016/j.future.2017.08.043.

[24]T. Saba, A. Rehman, T. Sadad, H. Kolivand, and S. A. Bahaj, “Anomaly-based intrusion detection system for IoT networks through deep learning model,” Comput. Electr. Eng., vol. 99, Art. no. 107810, 2022, doi:10.1016/j.compeleceng.2022.107810.

[25]B. Sharma, L. Sharma, C. Lal, and S. Roy, “Explainable artificialintelligence for intrusion detection in IoT networks: A deep-learning-based approach,” Expert Syst. Appl., vol. 238, Art. no. 121751, 2024, doi: 10.1016/j.eswa.2023.121751.

[26]A. Alabbadi and F. Bajaber, “An intrusion detection system over the IoTdata streams using explainable artificial intelligence (XAI),” Sensors, vol. 25, no. 3, Art. no. 847, 2025, doi: 10.3390/s25030847.

[27]S. Bin Hulayyil, S. Li, and N. Saxena, “Explainable AI-based intrusiondetection in IoT systems,” Internet Things, vol. 31, Art. no. 101589, 2025, doi: 10.1016/j.iot.2025.101589.

[28]O. Arreche, T. Guntur, and M. Abdallah, “XAI-IDS: Toward proposingan explainable artificial intelligence framework for enhancing networkintrusion detection systems,” Appl. Sci., vol. 14, no. 10, Art. no. 4170,2024, doi: 10.3390/app14104170.

[29]M. T. Ribeiro, S. Singh, and C. Guestrin, “‘Why should I trust you?’:Explaining the predictions of any classifier,” in Proc. 22nd ACMSIGKDD Int. Conf. Knowl. Discovery Data Mining, 2016, pp. 1135–1144, doi: 10.1145/2939672.2939778.

[30]S. M. Lundberg, G. Erion, H. Chen, et al., “From local explanations toglobal understanding with explainable AI for trees,” Nat. Mach. Intell.,vol. 2, no. 1, pp. 56–67, 2020, doi: 10.1038/s42256-019-0138-9.

[31]N. Koroniotis, N. Moustafa, E. Sitnikova, and B. Turnbull, “Towards the development of realistic botnet dataset in the Internet of Things fornetwork forensic analytics: Bot-IoT dataset,” Future Gener. Comput.Syst., vol. 100, pp. 779–796, 2019, doi: 10.1016/j.future.2019.05.041.

[32]N. Moustafa, “A new distributed architecture for evaluating AI-based security systems at the edge: Network TON_IoT datasets,” Sustain. Cities Soc., vol. 72, Art. no. 102994, 2021, doi: 10.1016/j.scs.2021.102994.

[33]M. A. Ferrag, O. Friha, D. Hamouda, L. Maglaras, and H. Janicke, “Edge-IIoTset: A new comprehensive realistic cyber security dataset of IoT andIIoT applications for centralized and federated learning,” IEEE Access,vol. 10, pp. 40281–40306, 2022, doi: 10.1109/ACCESS.2022.3165809.

Downloads

Published

31-08-2026

How to Cite

[1]
“LAFR-IoT: A Lightweight AI-Driven Network Forensic Readiness Framework for Resource-Constrained IoT–Edge Devices”, AJSE, vol. 25, no. 1, pp. 112–122, Aug. 2026, doi: 10.53799/8s5v6c24.