Cuckoo Search-Based Compact Feature Optimization for IoT Intrusion Detection: An Experimental Study on the IoT-23 Dataset
DOI:
https://doi.org/10.51483/IJAIML.6.9s.2026.2084-2099Keywords:
IoT intrusion detection; IoT-23; Cuckoo Search; binary feature selection; RFE; PCA; SMOTE; Random Under-Sampling; KNN; machine learning; few-shot learning.Abstract
The increasing scale and complexity of IoT traffic poses a challenge to accurate and computationally efficient intrusion detection, especially in the presence of redundant features and class imbalance. In this study, a machine learning framework for the IoT-23 dataset is presented which includes preprocessing of data, Synthetic Minority Oversampling Technique (SMOTE)/Random Under-Sampling, recursive feature elimination (RFE)–principal component analysis (PCA) dimensionality reduction, and binary Cuckoo Search (CS) feature selection. CS enables to optimize the feature selection by using a fitness function which balances the classification accuracy and feature compactness. The method chooses always the first and second principal components (PC1 and PC2) as the compressed representation. The K-nearest neighbors (KNN) classifier had the highest test accuracy, achieving 99.35%, followed by Random Forest (99.78%) and Decision Tree (99.76%) while bootstrap validation reports KNN accuracy of 99.35 ± 0.03%, leave-one-attack-out (LOAO) evaluation yields 0% accuracy for unseen attacks, thus illustrating the limitation of conventional supervised learning. A Prototypical Network reaches a mean validation accuracy of 90.37 ±10.48%. Finally, the results show the efficacy of CS in compact known-attack classification and the need for few-shot, open-set or zero-shot methods for emerging threats.





