ML and Blockchain Framework for Secure IoT Anomaly Detection — ISAISS 2026 | TechShield Publications
ISAISS 2026 · Conference Article

ML and Blockchain Framework for Secure IoT Anomaly Detection

Authors: Shan Rasool, Abdul Basit, Aoun Muhammad, Umar Fayyaz, Sehrish Raza

Abstract

The Internet of Things (IoT) has become part of modern life, linking many devices across homes, industries, cities and healthcare systems. While this connectivity improves efficiency and convenience, it also exposes networks to a growing range of cyber threats. Many IoT devices are lightweight, inexpensive and limited in processing capability, meaning they cannot support complex security software. This makes them winning targets for attackers who begin Distributed Denial of Service (DDoS) attacks, manipulate data or attempt to disrupt critical services. Traditional centrally managed security systems struggle under this scale and are themselves vulnerable as single points of failure. In addition, the integrity of logs and training data used by automated detection systems can be compromised, which may mislead machine-learning models during operation. This paper presents a hybrid security framework that combines machine learning for anomaly detection with blockchain technology for secure logging of security events. Machine-learning algorithms are used to classify network activity as normal or malicious, while blockchain stores the corresponding detection records in an immutable ledger to prevent later alteration. Three machine-learning models—Random Forest, Support Vector Machine (SVM) and XGBoost—are determined using an IoT-Blockchain dataset. The results show that SVM delivers the best performance, achieving 80.00% accuracy and 100% recall, meaning that all attack instances in the test set were detected. Random Forest performs competitively, whereas XGBoost records lower accuracy on this relatively small and lightweight dataset. The main contribution of this work lies in demonstrating that combining anomaly detection with blockchain-based integrity protection offers a practical pathway to more trustworthy IoT security. The approach not only identifies malicious behavior but also preserves reliable proof of detected threats. This framework can support future large-scale IoT deployments and motivates further research on optimizing blockchain overhead and expanding datasets with emerging attack types.

IoT Security Anomaly Detection Blockchain Machine Learning SVM Cybersecurity

Cite This Paper

S. Rasool, A. Basit, A. Muhammad, U. Fayyaz, and S. Raza, “ML and Blockchain Framework for Secure IoT Anomaly Detection,” Proc. Int. Symp. on AI and Secure Systems (ISAISS 2026), University of Central Punjab, Bahawalpur, Jan. 2026, doi: 10.67535/tsp.000002.010.