Muhammad Nadeem Ghouri, Ghufran Ahmed, Ahmad Sami Al-Shamayleh, Shahbaz Siddiqui, Muhammad Maaz, Adnan Akhunzada
The proliferation of Internet of Things (IoT) devices has revolutionized key domains such as agriculture, smart cities, and healthcare. However, this growth has introduced critical security challenges, particularly in low-power and lossy networks that rely on the Routing Protocol for Low-Power and Lossy Networks (RPL). While RPL ensures energy-efficient communication, it remains vulnerable to sophisticated insider attacks, specifically version number (VN) and worst parent (WP) attacks, that exploit its inherent structural weaknesses, leading to network instability, reduced energy efficiency, and compromised data integrity. This study addresses these challenges by proposing and evaluating hybrid deep learning models, including CNN-LSTM, CNN-GRU, and GRU-GRU, for early and accurate detection of RPL-based insider attacks. The models are trained and evaluated using an enhanced Routing Attack Dataset for RPL-based IoT, incorporating feature augmentation and simulated real-world scenarios. This comprehensive dataset includes both small-and large-scale network topologies, enabling robust and scalable performance assessment across diverse IoT environments. A comprehensive evaluation using standard evaluation metrics demonstrates that all models exhibit strong detection capabilities. Among them, CNN-LSTM achieves superior performance across all metrics, particularly in complex attack scenarios. CNN-GRU shows notable efficiency in small-scale networks, while GRU-GRU offers robustness and stability in larger deployments. The results show a significant effectiveness of hybrid deep learning architectures in improving the security posture of IoT networks. This work contributes to a scalable and intelligent detection framework for mitigating evolving insider threats in RPL-based environments.