PROACTIVE DEFENSE: A GENERATIVE AI-DRIVEN CYBERSECURITY FRAMEWORK FOR SECURING IOT NETWORKS AGAINST EMERGING THREATS
Keywords:
Generative Adversarial Networks (GANs), IoT Cybersecurity, Anomaly Detection, Attack Traffic Simulation, Proactive Defense, Zero-Day Attacks, AI-Driven SecurityAbstract
The IoT is growing rapidly and has brought many changes to industries, introducing new opportunities and efficiencies. But as the number of devices that are interconnected grows, securing these networks continues to be a burdensome problem. The classic forms of cybersecurity, which are mostly reactive, may not be sufficient to meet the new and advanced cyber threats that are now attacking the IoT systems, including zero-day attacks, botnets, and advanced persistent threats (APTs). This study introduces a new Generative Adversarial Network (GAN)-based cybersecurity framework that has been developed to proactively deal with these new threats. This framework uses generative AI to model realistic attack traffic specific to IoT networks and then to train powerful anomaly detection models that can identify known and unknown cyber threats. The goal of the proposed study is to create a GAN-based attack traffic generator that has the potential to model the characteristics of a wide range of IoT-specific attacks, such as zero-day threats and DDoS attacks. It also aims at training and optimizing various models of anomaly detectors, i.e. Random Forest, Long Short-Term Memory (LSTM) networks and Autoencoders, on a combined data of real and synthetic IoT traffic. The trained models are then tested in realistic IoT simulation environments (NS-3 and Cooja), where performance characteristics such as the detection rate, the false positive rate, and the computational efficiency are evaluated. The findings indicate that LSTM has the highest average performance in both detection accuracy and false positive rate, particularly with detection of time-series anomalies, whereas Autoencoders is better at detecting new threats and new attacks in general. The fast but with high false positive rate model was the Random Forest model, which was appropriate in low-latency environments. The suggested framework is also useful in the context of IoT cybersecurity, as it provides a preventative defense mechanism that can identify known and unknown threats. Also, this study offers publicly available dataset of synthetic IoT attacks and performance of multiple detection models, which can contribute to further developments of AI-based security in IoT systems. This study will establish the next generation of adaptive and resilient IoT security systems that can tackle the dearth of labeled attack data and facilitate real-time detection of cyber threats, as the fight against constantly evolving cyberspace threats continues.












