Lightweight AI-based anomaly detection in RPL-based IoT networks using temporal routing features
Azmera Chandu Naik, Lalit Kumar Awasthi, Priyanka RatheeThe Routing Protocol for Low-Power and Lossy Networks (RPL) is a common choice for Internet of Things (IoT) environments. However, it remains highly vulnerable to routing attacks, such as sinkhole, rank manipulation, and destination advertisement object (DAO) flooding attacks. Many existing detection methods depend on full-network analysis or rule-based systems, which are too heavy for resource-limited IoT devices. This research introduces a lightweight anomaly detection framework that learns temporal variations in routing behavior. It uses gated recurrent units (GRUs) to capture time-based patterns and a shallow convolutional neural network (CNN) to detect irregularities in node activity. The model analyzes local features such as parent changes, rank stability, and DODAG Information Object (DIO)/destination advertisement object (DAO) message rates, without requiring full-topology data. We tested the approach using ROUT-4-2023, IoT-RPL 2021, and UOS IOTSH 2024 datasets. The framework achieved an accuracy of 96.84%, an F1-score of 95.72%, and a false positive rate of 2.11%, while reducing computational overhead by 17.35% compared with graph-based models. Ablation testing confirmed the importance of temporal features, while complexity analysis showed an average per-sample inference time of 18.6[Formula: see text]ms in the full evaluation environment. Hardware deployment tests further validated edge feasibility, requiring only 0.85[Formula: see text]ms per sample on Cortex-A53 and 6.8[Formula: see text]ms on Cortex-M7, confirming suitability for low-power, real-time IoT inference. A comparative review against existing RPL intrusion detection systems highlighted improved efficiency and scalability. This study provides a practical, interpretable, and energy-efficient solution for securing IoT routing layers, with strong potential for deployment in real-world, edge-based smart environments, such as smart cities, healthcare monitoring, and industrial IoT systems. Our approach avoids traditional hybrid intrusion detection models that rely on reconstructing the network topology to detect anomalies. This allows for lightweight real-time anomaly detection in RPL-based IoT networks.