Integrating Side-Channel Power Signals and Network Traffic for Machine Learning-Based Intrusion Detection in IoT
Felipe Lemus-Prieto, Alejandro Domínguez Campos, José-Luis González-Sánchez, Andrés Caro Lindo
The Internet of Things (IoT) is rapidly being integrated into critical infrastructure sectors, such as energy, transportation, healthcare, and industry. This surge of interconnected devices dramatically expands the attack surface and increases the risk of cascading system failures and data breaches. To address these emerging threats, this work proposes an intrusion detection system (IDS) for IoT networks that incorporates machine learning techniques, considering side-channel (power) and network traffic features. We collected power consumption traces and network metrics from IoT devices during normal operation and under diverse cyberattacks (e.g., cryptomining, flooding, port scanning). Time-series machine learning classifiers are trained on this hybrid dataset to differentiate benign versus malicious behavior. The experimental results show that the combined-feature model significantly outperforms models using only one data type, achieving high detection accuracy (F1≈0.89) and correctly identifying the attack type. The resulting IDS generalizes to previously unseen attacks, demonstrating robust, adaptive defense capabilities. The novelty of our approach lies in integrating physical side-channel signals into an automated ML framework, enhancing robustness and resilience. This smart, data-driven solution operates in near real time and helps build autonomous, constantly evolving defenses against cyber threats. Overall, our study delivers a state-of-the-art ML-based tool that learns and evolves to counter modern IoT cyberattacks.