Game-Theoretic Analysis of Adaptive Behavior Between Attacker and Intrusion Detection System in IoT Gateways

Authors

  • Mojtaba Sandoughi Sandoughi * Department of Computer Engineering, Faculty of Electrical and Computer Engineering, University of Birjand, Birjand, Iran. https://orcid.org/0009-0008-2485-0639
  • Mohammad Malek Raeisi Department of Computer Engineering, Faculty of Electrical and Computer Engineering, University of Birjand, Birjand, Iran.
  • Hamid Saadatfar Department of Computer Engineering, Faculty of Electrical and Computer Engineering, University of Birjand, Birjand, Iran.

https://doi.org/10.48314/ijorai.v2i1.86

Abstract

With the rapid expansion of the Internet of Things (IoT) and the increasing dependence of smart infrastructures on communication gateways, securing these gateways against adaptive attacks has become a fundamental challenge in computer engineering. In many existing methods, the behavior of either the attacker or the Intrusion Detection System (IDS) is modeled statically or independently of the opponent's actions. However, in real-world scenarios, both sides continuously learn and adapt. In this study, a game-theoretic framework is proposed to analyze the adaptive behavior of an attacker and an IDS in IoT gateways. The interaction between the attacker and the IDS is modeled as a repeated game with memory-one strategies, and the mutual learning process is implemented using incremental optimization of each agent's long-term payoff. Furthermore, to adapt the model to the practical constraints of the IoT, the cost of processing resources and energy consumption of the IDS system is incorporated into its utility function. Numerical simulation results show that asymmetry in the learning speeds of the attacker and the IDS plays a decisive role in the stability of IoT gateway security. Specifically, when the IDS adapts at a faster rate than the attacker, the attacker's behavior is significantly suppressed, and the probability of successful attacks decreases, although the operational costs of the IDS increase. Conversely, for intermediate learning speeds, an adaptive competitive dynamic is observed in which neither party achieves a sustainable advantage. The results of this study can be utilized as an analytical tool for designing and tuning lightweight IDSs in IoT gateways.    

Keywords:

Internet of things, Intrusion detection system, Game theory, Adaptive learning, Network security

References

  1. [1] Wang, S., Yan, C., & Yong, S. (2023). A review of road traffic accident prediction methods. American journal of management science and engineering, 8(3), 73–77. https://doi.org/10.11648/j.ajmse.20230803.12

  2. [2] Marcillo, P., Valdivieso Caraguay, Á. L., & Hernández-Álvarez, M. (2022). A systematic literature review of learning-based traffic accident prediction models based on heterogeneous sources. Applied sciences, 12(9), 4529. https://doi.org/10.3390/app12094529

  3. [3] Sajadi, P., Qorbani, M., Moosavi, S., & Hassannayebi, E. (2025). Accident impact prediction based on a deep convolutional and recurrent neural network model. Urban Science, 9(8), 299. https://doi.org/10.3390/urbansci9080299

  4. [4] Behboudi, N., Moosavi, S., & Ramnath, R. (2024). Recent advances in traffic accident analysis and prediction: A comprehensive review of machine learning techniques. https://doi.org/10.48550/arXiv.2406.13968

  5. [5] Yeole, M., Jain, R. K., & Menon, R. (2023). Road traffic accident prediction for mixed traffic flow using artificial neural network. Materials Today: Proceedings, 72, 832–837. https://doi.org/10.1016/j.matpr.2022.11.490

  6. [6] Babanezhad, M., Khorsha, H., Mohajervatan, A., & Choori, A. (2025). Estimating the demand for ambulances in traffic accidents. Health in emergencies and disasters quarterly, 10(4), 247–258. https://doi.org/10.32598/hdq.10.4.149.8

  7. [7] Moslehi, S., Gholami, A., Haghdoust, Z., Abed, H., Mohammadpour, S., & Moslehi, M. A. (2021). Prediction of traffic accidents based on weather conditions in Gilan province using artificial neural network. Journal of health administration, 24(2), 67–78. https://doi.org/10.52547/JHA.24.3.67

  8. [8] Agyemang, E. F., Mensah, J. A., Ocran, E., Opoku, E., & Nortey, E. N. N. (2024). Time series based road traffic accidents forecasting via SARIMA and facebook prophet model with potential changepoints. Heliyon, 10(4), e26051. https://doi.org/10.1016/j.heliyon.2024.e26051

  9. [9] Lim, B., & Zohren, S. (2021). Time-series forecasting with deep learning: A survey. Philosophical transactions of the royal society A, 379(2194), 20200209. https://doi.org/10.1098/rsta.2020.0209

  10. [10] Panicker, N. K. K. (2024). Hybrid SARIMA-LSTM approach for improved time series prediction of aerosol optical depth across Delhi, India. Journal of theoretical and applied information technology, 102(11), 4836–4853. https://www.jatit.org/volumes/Vol102No11/14Vol102No11

  11. [11] Sherstinsky, A. (2020). Fundamentals of recurrent neural network (RNN) and long short-term memory (LSTM) network. Physica D: Nonlinear phenomena, 404, 132306. https://doi.org/10.1016/j.physd.2019.132306

  12. [12] He, L., Zhang, Z., Liu, Y., & Wang, X. (2021). Using SARIMA–CNN–LSTM approach to forecast daily tourism demand. International journal of hospitality management, 94, 102862. https://doi.org/10.1016/j.ijhm.2021.102862

  13. [13] Li, G., & Yang, N. (2023). A hybrid SARIMA-LSTM model for air temperature forecasting. Advanced Theory and Simulations, 6(1), 2200502. https://doi.org/10.1002/adts.202200502

  14. [14] Suryanarayana, S. V., Chand, T. S., Mahesh, D. B., Gurrala, R. R., & Appana, K. K. (2025). Hybrid CNN-LSTM model for accurate time series forecasting: A deep learning approach. In 2025 international conference on sustainable communication networks and application (ICSCN) (pp. 1034–1039). Theni, India: IEEE. https://doi.org/10.1109/ICSCN67106.2025.11308601

  15. [15] Feng, T., Zheng, Z., Xu, J., Liu, M., Li, M., Jia, H., & Yu, X. (2024). The comparative analysis of SARIMA, Facebook Prophet, and LSTM for road traffic injury prediction in Northeast China. Frontiers in public health, 12, 1418350. https://doi.org/10.3389/fpubh.2024.1418350

Published

2026-03-18

How to Cite

Sandoughi, M. S., Malek Raeisi, M. ., & Saadatfar, H. . (2026). Game-Theoretic Analysis of Adaptive Behavior Between Attacker and Intrusion Detection System in IoT Gateways. International Journal of Operations Research and Artificial Intelligence , 2(1), 31-41. https://doi.org/10.48314/ijorai.v2i1.86

Similar Articles

1-10 of 12

You may also start an advanced similarity search for this article.