A Hybrid Deep Autoencoders and Random Forest Framework for False Data Injection Attack Detection in Industrial Internet of Things Networks

Albarrak, Abdullah M. and Ghaleb, Fuad A. and Qasem, Sultan Noman and Saeed, Faisal (2026) A Hybrid Deep Autoencoders and Random Forest Framework for False Data Injection Attack Detection in Industrial Internet of Things Networks. Sensors, 26 (16). p. 5110. ISSN 1424-8220

[thumbnail of sensors-26-05110.pdf]
Preview
Text
sensors-26-05110.pdf - Accepted Version
Available under License Creative Commons Attribution.

Download (1MB)

Abstract

The rapid adoption of Internet of Things (IoT)-enabled applications has significantly expanded the cyberattack surface across a wide range of critical systems such as industrial IoT (IIoT), smart grids, transportation, healthcare, industrial control systems, and smart cities. False data injection attack (FDIA) has emerged as a serious security threat to these applications due to its stealthiness and adversarial nature, silently corrupting the data integrity of critical operational processes without triggering conventional detection mechanisms. Existing FDIA solutions rely on single-model architectures that are built based on classical or limited predefined attack scenarios. Such solutions often fail to achieve robust detection under adversarial and evolving attack conditions; accordingly, they lack generalisability and are insufficient to capture the broader scope of FDIAs. In this study, a hybrid detection framework is proposed that integrates a Random Forest classifier with an unsupervised anomaly detection model based on a deep autoencoder combined through a Logistic Regression metaclassifier. The proposed framework addresses the gap in single-model detectors that either rely on fixed decision boundaries that struggle with gradually evolving stealthy FDIA patterns or on anomaly detection that lacks strong discriminative power in separating subtle adversarial deviations from normal operational variability. Different types of stealthy and adversarial FDIA have been modelled and injected into the dataset samples for use in training the proposed model. The results show that the overall detection performance of the proposed architecture improved by 2.39 percentage points in terms of F1-score while maintaining a low false-positive rate of 0.49%. These findings reflect the effectiveness of feature representation learning via autoencoders and hybrid classification strategies against stealthy and adversarial FDIA patterns. Future work should include temporal modelling for further advancing robust detection against evolving adversarial threats.

Item Type: Article
Identification Number: 10.3390/s26165110
Dates:
Date
Event
10 August 2026
Accepted
12 August 2026
Published Online
Uncontrolled Keywords: false data injection, FDIA, hybrid model, Industrial Internet of Things, IIoT, adversarial attacks, stealthy attack detection
Subjects: CAH11 - computing > CAH11-01 - computing > CAH11-01-01 - computer science
Divisions: Architecture, Built Environment, Computing and Engineering > Computer Science
Depositing User: Gemma Tonks
Date Deposited: 25 Aug 2026 09:38
Last Modified: 25 Aug 2026 09:38
URI: https://www.open-access.bcu.ac.uk/id/eprint/17183

Actions (login required)

View Item View Item

Research

In this section...