MARATTO

article · Computer and decision making.

PISMA: Programmable In-Switch Telemetry and Multi-Stage Adaptive Deep Learning for Threat Mitigation in SD-IoT

2026Open accessZagazig University

Abstract

The convergence of Software-Defined Networking and the Internet of Things (SD-IoT) enhances network orchestration but exposes centralized controllers and application-layer services to sophisticated, multi-stage cyber threats such as structural web injections and stealthy application-layer floods. This study aims to develop and validate the PISMA framework, an integrated defense mechanism designed to bridge programmable data planes with intelligence-driven control layers to achieve real-time, accurate threat detection and precision mitigation without causing collateral service disruptions. The framework incorporates P4-programmable in-switch feature extraction, sliding-window behavioral aggregation, a hybrid deep learning classification engine combining convolutional representations with bidirectional recurrent neural networks, and confidence-aware policy orchestration. Comprehensive experimental evaluations were conducted across a hybrid emulation testbed using five benchmark security datasets (CICIoT2023, ToN_IoT, IoT-ID20, UNSW-NB15, and Edge-IIoTset) to assess classification performance, error rates, and operational response times. Across the benchmark evaluations, PISMA consistently outperformed alternative ensemble baselines, achieving a peak binary classification accuracy of 98.75%, an F1-score of 98.59%, a Matthews Correlation Coefficient of 0.97, and an Area Under Curve of 0.99, while keeping false positive and false negative rates below 1.5%. Furthermore, multi-class categorizations for SQL injection, cross-site scripting, command injection, and HTTP floods maintained recognition rates exceeding 96.8% with an ultra-low total mitigation response time averaging 1.12 milliseconds. The findings demonstrate that combining programmable data-plane telemetry with hybrid deep learning and confidence-aware policy enforcement successfully neutralizes application-layer intrusions, eliminates centralized processing bottlenecks, and preserves high service continuity in resource-constrained IoT networks.

Research topics

  • Software-Defined Networks and 5G
  • Network Security and Intrusion Detection
  • Security and Verification in Computing

Sustainable Development Goals

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.59543/comdem.v3i.18489

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.