CFP last date
20 October 2026
Reseach Article

LEAF-NIDS: A Lightweight Ensemble Architecture for Feature-Efficient Network Intrusion Detection at the Edge

by Jai Mungi, Harsh Mathur
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
Volume 187 - Number 145
Year of Publication: 2026
Authors: Jai Mungi, Harsh Mathur
10.5120/ijcaca37bbb30b91

Jai Mungi, Harsh Mathur . LEAF-NIDS: A Lightweight Ensemble Architecture for Feature-Efficient Network Intrusion Detection at the Edge. International Journal of Computer Applications. 187, 145 ( Sep 2026), 31-37. DOI=10.5120/ijcaca37bbb30b91

@article{ 10.5120/ijcaca37bbb30b91,
author = { Jai Mungi, Harsh Mathur },
title = { LEAF-NIDS: A Lightweight Ensemble Architecture for Feature-Efficient Network Intrusion Detection at the Edge },
journal = { International Journal of Computer Applications },
issue_date = { Sep 2026 },
volume = { 187 },
number = { 145 },
month = { Sep },
year = { 2026 },
issn = { 0975-8887 },
pages = { 31-37 },
numpages = {9},
url = { https://ijcaonline.org/archives/volume187/number145/leaf-nids-a-lightweight-ensemble-architecture-for-feature-efficient-network-intrusion-detection-at-the-edge/ },
doi = { 10.5120/ijcaca37bbb30b91 },
publisher = {Foundation of Computer Science (FCS), NY, USA},
address = {New York, USA}
}
%0 Journal Article
%1 2026-10-01T01:00:10.836722+05:30
%A Jai Mungi, Harsh Mathur
%T LEAF-NIDS: A Lightweight Ensemble Architecture for Feature-Efficient Network Intrusion Detection at the Edge
%J International Journal of Computer Applications
%@ 0975-8887
%V 187
%N 145
%P 31-37
%D 2026
%I Foundation of Computer Science (FCS), NY, USA
Abstract

Stacking-based ensemble models with wrapper-based feature selection have proven to provide high accuracy in intrusion detection, but the models can be very computationally intensive, restricting their use in resource-constrained edge and IoT environments. This paper introduces a lightweight network intrusion detection system framework that uses adaptive feature selection (AEFSS) and has resource efficiency for use in gateway-class edge devices, called LEAF-NIDS. LEAF-NIDS takes away the need for iterative wrapper search and applies a single-pass Symmetrical Uncertainty-based redundancy-aware (SU-R) feature selection approach, using a cascaded weighted voting ensemble of a depth-bounded decision tree, Naïve Bayes, and a linear classifier. To enhance deployment efficiency, the framework also supports 8-bit quantization and branch pruning to compress the model after training, which further minimizes the model size and inference time. The suggested architecture is designed to be deployed on PoC lightweight edge devices such as NVIDIA Jetson Nano and Raspberry Pi 4. A theoretical analysis of computational complexity and resource footprints shows the efficiency of LEAF-NIDS over representative wrapper-based and stacking-based approaches. Furthermore, a comprehensive evaluation methodology with benchmark datasets, deployment platforms, performance metrics, and comparative baselines is presented, allowing for systematic evaluation. The proposed framework offers a practical compromise between detection performance, computational efficiency, and deployment feasibility and can be well adapted for real-time edge-based network intrusion detection.

References
  1. R. Bace and P. Mell, “NIST Special Publication on Intrusion Detection Systems,” NIST, Gaithersburg, MD, USA, Tech. Rep. 800-31, 2001.
  2. S. Axelsson, “Intrusion detection systems: A survey and taxonomy,” Chalmers Univ. of Technology, Goteborg, Sweden, Tech. Rep. 99-15, 2000.
  3. R. S. Tiwari, D. Lakshmi, T. K. Das, A. K. Tripathy, and K.-C. Li, “A lightweight optimized intrusion detection system using machine learning for edge-based IIoT security,” Telecommun. Syst., vol. 87, pp. 605–624, 2024, doi: 10.1007/s11235-024-01200-y.
  4. S. A. Abdulkareem, C. H. Foh, F. Carrez, and K. Moessner, “A lightweight SEL for attack detection in IoT/IIoT networks,” J. Netw. Comput. Appl., vol. 230, Art. no. 103980, 2024, doi: 10.1016/j.jnca.2024.103980.
  5. T. Hasan, A. Hossain, M. Q. Ansari, and T. H. Syed, “Enhanced intrusion detection in IIoT networks: A lightweight approach with autoencoder-based feature learning,” in Proc. Int. Conf. Internet of Things, Big Data and Security, 2025, arXiv:2501.15266, doi: 10.48550/arXiv.2501.15266.
  6. H. G. A. Umar et al., “Energy-efficient deep learning-based intrusion detection system for edge computing: a novel DNN-KDQ model,” J. Cloud Comput., vol. 14, Art. no. 32, 2025, doi: 10.1186/s13677-025-00762-9.
  7. W. Gao, M. Wang, Y. Pei, F. Li, and C. Wang, “A lightweight multiclassification intrusion detection model for edge IoT networks,” Electronics, vol. 15, no. 5, Art. no. 938, 2026, doi: 10.3390/electronics15050938.
  8. J. Lundqvist, A. Hadzic, T. M. Kirkeluten, and M. P. N. Halkjelsvik, “Lightweight machine learning models for intrusion detection on IoT devices,” Norsk IKT-konferanse for forskning og utdanning (NIKT), vol. 37, no. 3, 2025, doi: 10.5324/jrxdjb92.
  9. S. F. Misrak and H. M. Melaku, “Lightweight intrusion detection system for IoT with improved feature engineering and advanced dynamic quantization,” Discover Internet of Things, vol. 5, Art. no. 97, 2025, doi: 10.1007/s43926-025-00203-8.
  10. A. Aldaej, I. Ullah, and M. Atiquzzaman, “Ensemble technique of intrusion detection for IoT-edge platform,” Sci. Rep., vol. 14, Art. no. 11703, 2024, doi: 10.1038/s41598-024-62435-y.
  11. F. Ullah, S. Ullah, G. Srivastava, and J. C.-W. Lin, “IDSInt: Intrusion detection system using transformer-based transfer learning for imbalanced network traffic,” Digit. Commun. Netw., vol. 10, no. 1, pp. 190–204, 2024, doi: 10.1016/j.dcan.2023.03.008.
  12. H. Benaddi, M. Jouhari, N. Laamech, A. Motii, and K. Ibrahimi, “Lightweight intrusion detection in IoT via SHAP-guided feature pruning and knowledge-distilled Kronecker networks,” arXiv:2512.19488, 2025.
  13. T. Wisanwanichthan and M. Thammawichai, “A lightweight intrusion detection system for IoT and UAV using deep neural networks with knowledge distillation,” Computers, vol. 14, no. 7, Art. no. 291, 2025, doi: 10.3390/computers14070291.
  14. S. Yang, X. Zheng, Z. Xu, and X. Wang, “A lightweight approach for network intrusion detection based on self-knowledge distillation,” arXiv:2307.10191, 2023.
  15. G. Hinton, O. Vinyals, and J. Dean, “Distilling the knowledge in a neural network,” arXiv:1503.02531, 2015.
  16. L. Breiman, “Random forests,” Mach. Learn., vol. 45, no. 1, pp. 5–32, 2001.
  17. M. A. Hall, “Correlation-based feature selection for machine learning,” Ph.D. dissertation, Dept. Comput. Sci., Univ. Waikato, Hamilton, New Zealand, 1999.
  18. N. Moustafa and J. Slay, “UNSW-NB15: A comprehensive data set for network intrusion detection systems,” in Proc. Military Communications and Information Systems Conf. (MilCIS), Canberra, Australia, 2015, pp. 1–6.
  19. M. Tavallaee, E. Bagheri, W. Lu, and A. A. Ghorbani, “A detailed analysis of the KDD CUP 99 data set,” in Proc. IEEE Symp. Computational Intelligence for Security and Defense Applications (CISDA), Ottawa, Canada, 2009, pp. 1–6.
  20. D. Chicco and G. Jurman, “The advantages of the Matthews correlation coefficient (MCC) over F1 score and accuracy in binary classification evaluation,” BMC Genomics, vol. 21, Art. no. 6, 2020.
  21. H. Yao, P. Gao, P. Zhang, J. Wang, C. Jiang, and L. Lu, “Hybrid intrusion detection system for edge-based IIoT relying on machine-learning-aided detection,” IEEE Netw., vol. 33, no. 5, pp. 75–81, 2019, doi: 10.1109/MNET.001.1800479.
Index Terms

Computer Science
Information Sciences

Keywords

Intrusion Detection System Lightweight Machine Learning Ensemble Learning Edge Computing Knowledge Distillation IoT Security