Ariel Justine N. Panopio, Hamza A. Abushahla, Ali Reza Sajun, Sameer Alawnah, Fadi Aloul, Imran Zualkernan
Connection and convenience come at a cost, particularly in the Internet of Things (IoT), where smart devices such as bulbs and surveillance cameras widen the attack surface for malicious actors. Intrusion Detection Systems (IDSs) are a critical line of defense, but their effectiveness must be balanced with strict resource constraints across edge, fog, and cloud layers. In this work, we propose lightweight machine learning (ML) and deep learning (DL) models for deployment across the edge–fog–cloud continuum, evaluating eight models on the RT-IoT2022 dataset. Using Optuna for hyperparameter tuning, we find that the ensemble models perform best, with LightGBM achieving the highest macro-F1 score (98.07%). However, a compact 28.8 KB Fully Connected Neural Network (FCNN) offers a favorable trade-off, attaining a macro-F1 of 94.80% with consistent sub-millisecond inference and relatively low power usage across all devices. Notably, while neural networks may not always match ensemble models in classification performance, they exhibit comparatively lower variability in inference times, making them attractive where predictability and throughput stability are crucial. Our statistical testing confirms the superiority of ensemble models while quantifying the gaps in performance. We further analyze the deployment across diverse hardware and compare ONNX runtimes against native C/C++ code generation to illustrate the convenience–performance trade-offs. We note that while quantization preserves accuracy, it can increase latency or power consumption for already-small models, cautioning against its blanket adoption. Finally, we release a reproducible end-to-end pipeline and provide practical deployment guidelines to support model and device selection under heterogeneous IoT constraints.