LAFR-IoT: A Lightweight AI-Driven Network Forensic Readiness Framework for Resource-Constrained IoT–Edge Devices
Annotatsiya
The rapid expansion of Internet of Things (IoT) deployments has increased the volume of network evidence generated at the edge, yet most IoT devices remain constrained by limited processing power, memory, energy, and storage. These limitations make conventional full-packet logging and heavyweight intrusion detection impractical for proactive forensic readiness. This study proposes LAFR-IoT, a lightweight AI-driven network forensic readiness framework for resource-constrained IoT–Edge devices. The framework integrates lightweight machine learning, edge-aware model selection, explainability-based feature analysis, and selective forensic logging to detect, triage, and preserve high-value network events before evidence is lost. Experiments were conducted using the CICIoT2023 dataset, where network traffic was mapped into eight forensic categories: Benign, Brute Force, DDoS, DoS, Mirai, Recon, Spoofing, and Web. Eight lightweight models were evaluated. Although a shallow decision tree achieved the highest validation macro-F1, a linear support vector machine achieved the best overall Edge Forensic Score because of its low latency, small model size, and deployment efficiency. On the independent test set, the linear model achieved 0.7512 accuracy, 0.5741 macro-F1, 0.7615 weighted-F1, 0.0051 ms per sample inference latency, and a 0.0077 MB model size. The proposed selective logging mechanism reduced storage usage by 74.59% while preserving 98.96% of malicious events. These results show that lightweight edge AI can support proactive IoT forensic readiness by balancing detection performance, explainability, storage efficiency, and resource-aware deployment.
Hali tarjima qilinmagan