A Hybrid Deep Autoencoders and Random Forest Framework for False Data Injection Attack Detection in Industrial Internet of Things Networks
Albarrak, Abdullah M. and Ghaleb, Fuad A. and Qasem, Sultan Noman and Saeed, Faisal (2026) A Hybrid Deep Autoencoders and Random Forest Framework for False Data Injection Attack Detection in Industrial Internet of Things Networks. Sensors, 26 (16). p. 5110. ISSN 1424-8220
Preview |
Text
sensors-26-05110.pdf - Accepted Version Available under License Creative Commons Attribution. Download (1MB) |
Abstract
The rapid adoption of Internet of Things (IoT)-enabled applications has significantly expanded the cyberattack surface across a wide range of critical systems such as industrial IoT (IIoT), smart grids, transportation, healthcare, industrial control systems, and smart cities. False data injection attack (FDIA) has emerged as a serious security threat to these applications due to its stealthiness and adversarial nature, silently corrupting the data integrity of critical operational processes without triggering conventional detection mechanisms. Existing FDIA solutions rely on single-model architectures that are built based on classical or limited predefined attack scenarios. Such solutions often fail to achieve robust detection under adversarial and evolving attack conditions; accordingly, they lack generalisability and are insufficient to capture the broader scope of FDIAs. In this study, a hybrid detection framework is proposed that integrates a Random Forest classifier with an unsupervised anomaly detection model based on a deep autoencoder combined through a Logistic Regression metaclassifier. The proposed framework addresses the gap in single-model detectors that either rely on fixed decision boundaries that struggle with gradually evolving stealthy FDIA patterns or on anomaly detection that lacks strong discriminative power in separating subtle adversarial deviations from normal operational variability. Different types of stealthy and adversarial FDIA have been modelled and injected into the dataset samples for use in training the proposed model. The results show that the overall detection performance of the proposed architecture improved by 2.39 percentage points in terms of F1-score while maintaining a low false-positive rate of 0.49%. These findings reflect the effectiveness of feature representation learning via autoencoders and hybrid classification strategies against stealthy and adversarial FDIA patterns. Future work should include temporal modelling for further advancing robust detection against evolving adversarial threats.
| Item Type: | Article |
|---|---|
| Identification Number: | 10.3390/s26165110 |
| Dates: | Date Event 10 August 2026 Accepted 12 August 2026 Published Online |
| Uncontrolled Keywords: | false data injection, FDIA, hybrid model, Industrial Internet of Things, IIoT, adversarial attacks, stealthy attack detection |
| Subjects: | CAH11 - computing > CAH11-01 - computing > CAH11-01-01 - computer science |
| Divisions: | Architecture, Built Environment, Computing and Engineering > Computer Science |
| Depositing User: | Gemma Tonks |
| Date Deposited: | 25 Aug 2026 09:38 |
| Last Modified: | 25 Aug 2026 09:38 |
| URI: | https://www.open-access.bcu.ac.uk/id/eprint/17183 |
Actions (login required)
![]() |
View Item |

Tools
Tools