LLM-Enhanced Security Framework for IoT Network: Anomaly Detection and Malicious Devices Identification

8Citations
Citations of this article
28Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Due to resource constraints, Internet of Things (IoT) devices often lack built-in security systems, making them vulnerable to zero-day attacks. Consequently, there is a growing need for anomaly-based intrusion detection systems for IoT networks. However, traditional anomaly systems suffer from a high number of false positives, which wastes analysts’ time. Besides this, there is a semantic gap between the system outputs and the network operators. In this paper, we propose a machine learning-based framework with large language model (LLM) integration to address those challenges we face in traditional systems. The model not only detects potential threats but also bridges the semantic gap. The framework employs isolation forest for anomaly detection and random forest for device integrity assessment. To enhance anomaly evaluation and improve interpretability, the system’s insights are further processed by GPT-4o mini, an LLM. The LLM elucidates statistical summaries of IoT traffic, assigns risk scores, and provides human-readable explanations and thereby enhancing decision-making. This approach reduces the reliance on expert network operators. As a result, non-technical users can understand and act upon the system’s outputs.

Cite

CITATION STYLE

APA

Arif Iftakher Mahmood, M., Ashab, F., Saifuzzaman Sohan, M., Hedayetul Islam Chy, M., & Kader, M. F. (2025). LLM-Enhanced Security Framework for IoT Network: Anomaly Detection and Malicious Devices Identification. IEEE Access, 13, 168405–168419. https://doi.org/10.1109/ACCESS.2025.3613588

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free