Aliyu Umar, Ivan Jordanov
The explosive growth of the Internet of Things (IoT) has introduced vast amounts of data and unprecedented security challenges, making effective anomaly detection in IoT environments a critical concern. This paper presents a comprehensive survey of machine learning techniques for IoT anomaly detection, with an emphasis on their applicability, performance trade-offs, and alignment with real-world requirements. We adhere to a systematic literature review methodology (PRISMA) to identify and analyse recent advances, categorising them into supervised, unsupervised, semi-supervised, and deep learning approaches, as well as emerging paradigms like federated learning. For each category, we discuss representative algorithms and architectures, ranging from isolation forests and one-class SVMs to deep autoencoders and graph neural networks, and highlight how they address issues such as data imbalance, concept drift, and limited labels in IoT data. We also review prominent IoT security datasets and evaluation metrics used in the field, and present illustrative results from experiments and simulations of the investigated techniques. Our comparative analysis underscores that while supervised and deep learning models achieve high accuracy under ample labelled data, unsupervised and hybrid methods offer robustness against novel attacks and evolving network behaviour. Finally, we identify open challenges (e.g., adaptive model updating, feature selection for high-dimensional IoT data, and privacy-preserving detection) and outline future research directions toward resilient, real-time anomaly detection in large-scale IoT networks.