| International Journal of Computer Applications |
| Foundation of Computer Science (FCS), NY, USA |
| Volume 187 - Number 145 |
| Year of Publication: 2026 |
| Authors: Jai Mungi, Harsh Mathur |
10.5120/ijcaca37bbb30b91
|
Jai Mungi, Harsh Mathur . LEAF-NIDS: A Lightweight Ensemble Architecture for Feature-Efficient Network Intrusion Detection at the Edge. International Journal of Computer Applications. 187, 145 ( Sep 2026), 31-37. DOI=10.5120/ijcaca37bbb30b91
Stacking-based ensemble models with wrapper-based feature selection have proven to provide high accuracy in intrusion detection, but the models can be very computationally intensive, restricting their use in resource-constrained edge and IoT environments. This paper introduces a lightweight network intrusion detection system framework that uses adaptive feature selection (AEFSS) and has resource efficiency for use in gateway-class edge devices, called LEAF-NIDS. LEAF-NIDS takes away the need for iterative wrapper search and applies a single-pass Symmetrical Uncertainty-based redundancy-aware (SU-R) feature selection approach, using a cascaded weighted voting ensemble of a depth-bounded decision tree, Naïve Bayes, and a linear classifier. To enhance deployment efficiency, the framework also supports 8-bit quantization and branch pruning to compress the model after training, which further minimizes the model size and inference time. The suggested architecture is designed to be deployed on PoC lightweight edge devices such as NVIDIA Jetson Nano and Raspberry Pi 4. A theoretical analysis of computational complexity and resource footprints shows the efficiency of LEAF-NIDS over representative wrapper-based and stacking-based approaches. Furthermore, a comprehensive evaluation methodology with benchmark datasets, deployment platforms, performance metrics, and comparative baselines is presented, allowing for systematic evaluation. The proposed framework offers a practical compromise between detection performance, computational efficiency, and deployment feasibility and can be well adapted for real-time edge-based network intrusion detection.