Deep Q learning algorithm for detecting DDoS attacks on IoT devices
Abstract
The rapid expansion of internet of things (IoT) networks has heightened security risks, particularly regarding distributed denial of service (DDoS) attacks against devices with limited computing capacity. High detection accuracy is crucial for these resource-constrained environments, where false positives can disrupt legitimate traffic and false negatives allow attacks to persist. However, modern reinforcement learning (RL) and machine learning (ML) intrusion detection solutions often exhibit poor generalization due to static state representations. To address this, this paper proposes a deep Q-learning (DQL) framework that integrates K-means clustering directly into the RL action space. Unlike prior RL-based IDS models, our approach dynamically integrates clustering into the learning process, enabling adaptive state representation and improved generalization to unseen traffic patterns. The system is formulated as a Markov decision process where the agent optimizes a composite reward function based on accuracy, precision, recall, and F1-score. Evaluated on the N-BaIoT dataset using 10-fold cross-validation, the proposed method achieves a classification accuracy of 98.95% and a weighted F1-score of 98.73%, significantly outperforming traditional ML and RL baselines. These results demonstrate the framework's effectiveness as a scalable, adaptive solution for intelligent IoT DDoS detection.
Keywords
Deep Q-learning; Distributed denial of service; Internet of things security; Q learning; Reinforcement learning
Full Text:
PDFDOI: http://doi.org/10.11591/ijeecs.v43.i1.pp299-313
Refbacks
- There are currently no refbacks.

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Indonesian Journal of Electrical Engineering and Computer Science (IJEECS)
p-ISSN: 2502-4752, e-ISSN: 2502-4760
This journal is published by the Institute of Advanced Engineering and Science (IAES).