SinoTechIntel Academic Portal
Open AccessDOI: 10.1631/FITEE_2400556Original Research

A subspace-based few-shot intrusion detection system for the Internet of Things

Zhihui LI¹,Congyuan XU¹,Kun DENG¹,Chunyuan LIU¹

School of Information Science and Engineering, Zhejiang Sci-Tech University, Hangzhou 310027, China; College of Information Science and Engineering, Jiaxing University, Jiaxing 314000, China

Read Executive PreviewQuick FAQ
A subspace-based few-shot intrusion detection system for the Internet of Things
Graphical Abstract / Figure
Published In
Frontiers of Information Technology & Electronic Engineering
Published:October 19, 2025Edition:Vol. 32, Issue 10 • pp. 677-689Citation:Zhihui LI et al. (2025), Frontiers of Information Technology & Electronic Engineering
Impact Factor2.7 (Q2 - Springer)
Sponsored Research Partner
Keywords & Index Terms:Intrusion detection systemFew-shot learningInternet of ThingsSubspace classificationNetwork traffic analysisMetric learningCICIoT2023Zero-day attack detection

Key Takeaways & Executive Findings

  • • Proposes a subspace-based few-shot learning approach for IoT intrusion detection, effectively addressing the challenge of limited training samples. • Uses metric learning with subspace classifiers to detect unknown attack categories without the need for parameter optimization. • Constructs a few-shot IoT intrusion detection dataset based on CICIoT2023 and evaluates the method across 5-way 1-shot, 5-shot, and 10-shot settings. • Achieves high detection accuracy (up to 93.65%) for unknown categories, demonstrating robust generalization in sparse data scenarios.
Sponsored Research Highlight

Abstract

Deep learning-based intrusion detection systems rely on numerous training samples to achieve satisfactory detection rates. However, in the real-world Internet of Things (IoT) environments, the diversity of IoT devices and the subsequent fragmentation of attack types result in a limited number of training samples, which urgently requires researchers to develop few-shot intrusion detection systems. In this study, we propose a subspace-based approach for few-shot IoT intrusion detection systems to cope with the dilemma of insufficient learnable samples. The method is based on the principle of classifying metrics to identify network traffic. After feature extraction of samples, a subspace is constructed for each category. Next, the distance between the query samples and the subspace is calculated by the metric module, thus detecting malicious samples. Subsequently, based on the CICIoT2023 dataset we construct a few-shot IoT intrusion detection dataset and evaluate the proposed method. For the detection of unknown categories, the detection accuracy is 93.52% in the 5-way 1-shot setting, 92.99% in the 5-way 5-shot setting, and 93.65% in the 5-way 10-shot setting.

1. Introduction

The Internet of Things (IoT) is rapidly becoming a central aspect of our daily lives and industrial operations. As an increasing number of devices connect to networks, the amount of data they generate and the range of applications they can use expand significantly. However, this connectivity poses new security challenges because the diverse and distributed nature of IoT devices makes them new targets for cyber attacks. Thus, the IoT intrusion detection system has become the key to securing the IoT. In recent years, excellent algorithms for IoT intrusion detection systems have been developed, and they are effective in detecting abnormal traffic (Lu HM et al., 2022; He et al., 2024b). These studies have one thing in common: they train models from large datasets. Traditional intrusion detection methods based on a large number of samples face the challenge of data collection and labeling owing to the diversity of IoT devices and the dynamics of the network environment. In a diverse IoT environment, a discontinuity occurs in security measures due to device diversity, differences in operating system versions, inconsistent firmware updates, and other factors. This fragmentation makes it extremely difficult to maintain a unified security policy, thereby providing opportunities for attackers to exploit. Furthermore, when faced with zero-day attacks, researchers usually fail to collect sufficient samples and therefore may be unable to build timely datasets. At this point, machine learning-based IoT intrusion detection systems can fail, which in turn can cause irreparable damage to industrial production (Yan et al., 2024).

Researchers have shifted their focus to few-shot learning in the face of very few attack samples, such as zero-day attacks. As the name implies, IoT intrusion detection systems based on few-shot learning aim to develop efficient and accurate intrusion detection models for sparse and unbalanced data. However, the development of efficient few-shot models faces challenges, such as poor generalization and overfitting (Duan RX et al., 2021; Wang ZM et al., 2021). Research on IoT intrusion detection systems based on few-shot learning is still in its infancy, and more research needs to be made available for reference. However, the feasibility of using few-shot learning to address IoT intrusion detection has already been demonstrated.

In this study, a subspace-based few-shot IoT intrusion detection system is developed to solve these problems. We apply a subspace classifier to an IoT intrusion detection system. Unlike existing parameter optimization-based methods, we use metric learning to detect network traffic, which uses prior knowledge to detect unknown categories (Simon et al., 2020). The main contributions of this study are as follows: (1) To enhance the discriminability of traffic information from different classes, we propose a few-shot classifier that uses subspaces as a metric to fully learn the common representation of each traffic flow, while designing a four-layer feature extraction network based on channel attention mechanisms to enhance the feature representation of each traffic flow.

SinoTechIntel Interactive Document Reader
Page 1–5 of Preview
100%
Download Full PDF

Loading authentic research manuscript (Pages 1–5)...

Sponsored Research Partner
Cite This Research Paper
Zhihui LI, Congyuan XU, Kun DENG, Chunyuan LIU (2025). A subspace-based few-shot intrusion detection system for the Internet of Things. Frontiers of Information Technology & Electronic Engineering. https://doi.org/10.1631/FITEE_2400556
SinoTechIntel Academic & Legal Disclaimer

Research & Educational Purpose Only:The translations, structured abstracts, analytical annotations, and data reports provided by SinoTechIntel are intended exclusively for academic research, internal corporate R&D, and educational benchmarking. They do not constitute formal engineering, chemical safety, legal, or professional advice.

Copyright & Intellectual Property Notice: Original copyright of the underlying source articles and experimental data remains with the respective authors, institutions, and original publishing journals. SinoTechIntel claims intellectual property only over its proprietary translations, analytical syntheses, and AEO structured enhancements in accordance with international fair use and academic citation principles.

Frequently Asked Questions

What is the main contribution of this paper?

The paper proposes a subspace-based few-shot intrusion detection system for IoT that uses metric learning and subspace classifiers to detect unknown attack categories with limited samples, achieving over 93% accuracy on the CICIoT2023 dataset.

How does the proposed method work?

The method extracts features using a four-layer network with channel attention, constructs a subspace for each traffic category, and computes distances between query samples and subspaces to identify malicious traffic.

What dataset is used for evaluation?

The authors constructed a few-shot IoT intrusion detection dataset based on CICIoT2023 and evaluated the method in 5-way 1-shot, 5-shot, and 10-shot settings.

What are the detection accuracies reported?

The detection accuracies for unknown categories are 93.52% in the 5-way 1-shot setting, 92.99% in the 5-way 5-shot setting, and 93.65% in the 5-way 10-shot setting.

Why is few-shot learning important for IoT intrusion detection?

Because IoT environments generate diverse and fragmented attack types, and zero-day attacks often provide insufficient samples for training, making traditional deep learning methods fail; few-shot learning aims to develop efficient models from sparse data.

Recommended Scientific Literature & Research Partners

Related Technical Papers & Translations

Research Paper
Design and optimization of a high-efficiency distillation process for cellulosic fuel ethanol integrated with thermal coupling and molecular sieve adsorption

Design and optimization of a high-efficiency distillation process for cellulosic fuel ethanol integrated with thermal coupling and molecular sieve adsorption

To address the challenges of high energy consumption and prominent costs in the traditional three-columns distillation process for cellulosic fuel ethanol, a distillation—molecular sieve coupling separation process is proposed. This process integrates a three-column (crude distillation column, first distillation column, second distillation column) system with a 3A molecular sieve adsorption deep dehydration unit. A thermal coupling network is constructed via differential pressure design (steam from medium/high-pressure columns as mutual heat sources, reboiler liquid waste heat for feed preheating), and molecular sieve adsorption conditions are optimized. The study first performs a thermodynamic consistency test on the ethanol—water system, determines optimal non-random two-liquid (NRTL) model binary interaction parameters via experimental data regression for Aspen Plus simulation. Aiming at minimum total annual cost (TAC), Aspen Plus is used to optimize process parameters (theoretical tray number, feed location, reflux ratio, side-draw position, etc.). Economic analysis shows this process reduces CO2 emission costs by 27.56%, TAC by 15.58% (to 5.123 × 106 USD·a-1), and increases ethanol purity to >99.6%, providing an effective solution for green, efficient separation.

Read Abstract & PDF
Research Paper
A cohesion loss model for determining residual strength of deep bedded sandstone

A cohesion loss model for determining residual strength of deep bedded sandstone

Rock residual strength, as an important input parameter, plays an indispensable role in proposing the reasonable and scientific scheme about stope design, underground tunnel excavation and stability evaluation of deep chambers. Therefore, previous residual strength models of rocks established were reviewed. And corresponding related problems were stated. Subsequently, starting from the effects of bedding and whole life-cycle evolution process, series of triaxial mechanical tests of deep bedded s

Read Abstract & PDF
Research Paper
Federated model with contrastive learning and adaptive control variates for human activity recognition

Federated model with contrastive learning and adaptive control variates for human activity recognition

Recent attention to privacy issues demands a communication-safe method for training human activity recognition (HAR) models on client activity data. Federated learning (FL) has become a compelling technique to facilitate model training between the server and clients while preserving data privacy. However, classical FL methods often assume independent and identically distributed (IID) data among clients. This assumption does not hold true in practical scenarios. Human activity in real-world scena

Read Abstract & PDF