LAPIS: Layered anomaly detection system for IoT security

Conference paper


Wang, C., Aung, Y., Dong, Y., Limbasiya, T. and Zhou, J. 2025. LAPIS: Layered anomaly detection system for IoT security. 7th International Workshop on 
Artificial Intelligence and IoT Security (AIoTS). Munich, Germany 23 - 26 Jun 2025 Springer.
AuthorsWang, C., Aung, Y., Dong, Y., Limbasiya, T. and Zhou, J.
TypeConference paper
Abstract

Internet of Things (IoT) is a rapidly growing technology that significantly benefits and impacts our daily lives. However, with the rise of IoT, new challenges in security have emerged. A formidable challenge to tackle new threats arises as a result of the constantly evolving nature of malware. In this paper, we present an anomaly detection system that has been integrated with a honeypot infrastructure to facilitate real-time data capture and anomaly detection. The two-layer anomaly detection system, named LAPIS, is capable of detecting malicious network traffic and identifying novel attacks. This integration aims to enhance security measures by providing a sophisticated mechanism for monitoring and analyzing network flows with precision and efficiency. We evaluated LAPIS using realistic network traffic collected by the honeypot during 12 months of operation. The experimental results show that the overall F1 score of LAPIS reaches 0.91 and 0.84 for detecting malicious network flows and zero-day attacks, respectively outperforming the closest state-of-the-art work. Compared to VirusTotal, which analyzes suspicious files and URLs to detect malware and malicious content, 61% of novel attacks are detected earlier by our system or yet to be available in VirusTotal.

KeywordsAnomaly Detection; IoT Honeypot; Machine Learning; Cyber Security
Year2025
Conference7th International Workshop on 
Artificial Intelligence and IoT Security (AIoTS)
PublisherSpringer
Web address (URL)https://aiotsweb.github.io/aiots2025/
Accepted author manuscript
File Access Level
Restricted
Publication process dates
Deposited31 Oct 2025
Permalink -

https://repository.derby.ac.uk/item/qy732/lapis-layered-anomaly-detection-system-for-iot-security

  • 10
    total views
  • 3
    total downloads
  • 10
    views this month
  • 0
    downloads this month

Export as

Related outputs

HoneyWin: high-interaction windows honeypot in enterprise environment
Aung, Y., Khoo, Y., Zheng, D., Duo, B., Chattopadhyay, S., Zhou, J., Lu, L. and Goh, W. 2025. HoneyWin: high-interaction windows honeypot in enterprise environment. The 2025 8th IEEE Conference on Dependable and Secure Computing. Taipei, Taiwan 18 - 20 Oct 2025 IEEE.
CANDIDS: CAN/CAN-FD deep learning-based intrusion detection systems
Aung, Y., Cahyadi, W. and Zhou, J. 2025. CANDIDS: CAN/CAN-FD deep learning-based intrusion detection systems. 11th ACM Cyber-Physical System Security Workshop (CPSS 2025). Hanoi, Vietnam 26 - 26 Aug 2025 ACM. https://doi.org/10.1145/3709017.3737713