PISMA: Programmable In-Switch Telemetry and Multi-Stage Adaptive Deep Learning for Threat Mitigation in SD-IoT

Authors

DOI:

https://doi.org/10.59543/comdem.v3i.18489

Keywords:

Deep Learning, Machine Learning, Meta Model, Ensemble Learning, Random Forest, LightGBM, CatBoost, Logistic Regression, Iris Dataset, Infrastructure Assessment, phishing detection; machine learning; deep learning; explainable AI; binary classification; heterogeneous text

Abstract

The convergence of Software-Defined Networking and the Internet of Things (SD-IoT) enhances network orchestration but exposes centralized controllers and application-layer services to sophisticated, multi-stage cyber threats such as structural web injections and stealthy application-layer floods. This study aims to develop and validate the PISMA framework, an integrated defense mechanism designed to bridge programmable data planes with intelligence-driven control layers to achieve real-time, accurate threat detection and precision mitigation without causing collateral service disruptions. The framework incorporates P4-programmable in-switch feature extraction, sliding-window behavioral aggregation, a hybrid deep learning classification engine combining convolutional representations with bidirectional recurrent neural networks, and confidence-aware policy orchestration. Comprehensive experimental evaluations were conducted across a hybrid emulation testbed using five benchmark security datasets (CICIoT2023, ToN_IoT, IoT-ID20, UNSW-NB15, and Edge-IIoTset) to assess classification performance, error rates, and operational response times. Across the benchmark evaluations, PISMA consistently outperformed alternative ensemble baselines, achieving a peak binary classification accuracy of 98.75%, an F1-score of 98.59%, a Matthews Correlation Coefficient of 0.97, and an Area Under Curve of 0.99, while keeping false positive and false negative rates below 1.5%. Furthermore, multi-class categorizations for SQL injection, cross-site scripting, command injection, and HTTP floods maintained recognition rates exceeding 96.8% with an ultra-low total mitigation response time averaging 1.12 milliseconds. The findings demonstrate that combining programmable data-plane telemetry with hybrid deep learning and confidence-aware policy enforcement successfully neutralizes application-layer intrusions, eliminates centralized processing bottlenecks, and preserves high service continuity in resource-constrained IoT networks.

Downloads

Published

2026-08-11

How to Cite

El-Sayed, A., Nosseir Hemdan, M., Rushdy, E., & M. Hamza, H. (2026). PISMA: Programmable In-Switch Telemetry and Multi-Stage Adaptive Deep Learning for Threat Mitigation in SD-IoT. Computer and Decision Making: An International Journal, 3, 1054–1076. https://doi.org/10.59543/comdem.v3i.18489

Issue

Section

Articles