[PDF]

Using ML to detect cyber attacks in IoT/ICS systems


Luke Pinson

07/05/2026

Supervised by Eirini S Anthi; Moderated by George Theodorakopoulos

This project investigates the use of machine learning techniques for detecting cyber attacks in Internet of Things (IoT) and Industrial Control System (ICS) environments. It evaluates supervised learning models, including Logistic Regression, Decision Tree and Random Forest, alongside an anomaly-based Isolation Forest approach and a simple hybrid fusion strategy. The project uses the ToN-IoT and HAI datasets to compare model performance across controlled benchmark data and more realistic ICS-style conditions. The aim is not only to assess classification accuracy, but to examine how dataset structure, class imbalance, feature separability and evaluation methodology influence the reliability of reported intrusion detection performance. The project also uses feature importance, SHAP analysis and feature-distribution plots to explore why near-perfect results may occur. It considers the practical implications of false positives, missed attacks and limited labelled attack data when applying intrusion detection systems in realistic cybersecurity settings.


Initial Plan (02/02/2026) [Zip Archive]

Final Report (07/05/2026) [Zip Archive]

Publication Form