Volume 12 ,Issue 3 ,August 2026 ,Pages 205-211
1 Department of Computer Engineering, College of Engineering, Komar University of Science and Technology, Sulaimani, Kurdistan Region, Iraq
The vast expansion of IoT devices significantly expands the potential attack surface for networks; therefore, the increased complexity in detecting intrusions from these new sources is caused by the large dimensionality of the data, the severe class imbalance issue that exists when defining a normal versus abnormal behavior model based upon this data and the chaotic nature of network traffic.
This paper proposes a fully automated IoT-based Network Intrusion Detection System (NIDS), utilizing the Gotham Dataset 2025. Two AutoML approaches are used as part of the proposed system: TPOT (Tree-based Pipeline Optimization Tool) and FLAML (cost-aware lightweight AutoML framework). Both systems were evaluated using four different validation methods against approximately 5.8 million network traffic instances. FLAML achieved better results than TPOT in all evaluations, including achieving 99.98% accuracy at one evaluation. TPOT achieved comparable or slightly better performance than FLAML for precision and recall, but was less stable in its performance when dealing with class imbalance.