+7 (495) 987 43 74 ext. 3304
Join us -              
Рус   |   Eng

articles

Authors: Kotenko I., Andreev I., Lipatnikov V., Saenko I.     Published in № 2(122) 30 april 2026 year
Rubric: Data protection

A method for dynamic detection of cyber threats in distributed Internet of Things systems based on generative models

The article examines the problem of dynamic cyberthreat detection in distributed Internet of Things systems, addressing the limited adaptability of static intrusion detection systems and the vulnerability of machine learning models to adversarial influences. The aim of the work is to improve the effectiveness of cyberthreat detection in distributed IoT systems based on efficiency and timeliness criteria by using generative models capable of simulating normal and abnormal node behavior while accounting for environmental variability. A method based on generative adversarial models and contrastive learning is employed to generate anomaly estimates for IoT data time windows and make decisions based on a threshold rule. A computational experiment was conducted on the open N-BaIoT dataset for Mirai family attack scenarios, comparing statistical, linear, and autoencoder-based anomaly detection methods on windowed representations of IoT data. It was demonstrated that the selected feature description ensures high cyberthreat detection efficiency with short inference times, and the use of an autoencoder yields the best F1-score values across the scenarios considered. The obtained results confirm the potential for further implementation of the proposed generative method for analyzing IoT traffic time sequences and its application in intelligent network security monitoring tools at the edge and gateway levels of IoT systems.

Key words

generative models, intrusion detection, anomalies, Internet of Things, distributed systems, time series, cyber resilience, information security

The author:

Kotenko I.

Degree:

Professor, Honored Scientist of the Russian Federation, Chief Researcher – Head of Laboratory of Computer Security Problems, Saint Petersburg Federal Research Center of the Russian Academy of Sciences (SPС RAS)

Location:

Saint Petersburg, Russia

The author:

Andreev I.

Degree:

Scientific Company Operator, Military Academy of Communications named after Marshal of the Soviet Union S. M. Budyonny

Location:

Saint Petersburg, Russia

The author:

Lipatnikov V.

Degree:

Dr. Sci. (Eng.), Professor, Honored Scientist of the Russian Federation, Senior Researcher of Research Center, Military Academy of Communications named after Marshal of the Soviet Union S. M. Budyonny

Location:

Saint Petersburg, Russia

The author:

Saenko I.

Degree:

Professor, Chief Researcher at Laboratory of Computer Security Problems, Saint Petersburg Federal Research Center of the Russian Academy of Sciences (SPС RAS)

Location:

Saint Petersburg, Russia