PISMA: Programmable In-Switch Telemetry and Multi-Stage Adaptive Deep Learning for Threat Mitigation in SD-IoT
DOI:
https://doi.org/10.59543/comdem.v3i.18489Keywords:
Deep Learning, Machine Learning, Meta Model, Ensemble Learning, Random Forest, LightGBM, CatBoost, Logistic Regression, Iris Dataset, Infrastructure Assessment, phishing detection; machine learning; deep learning; explainable AI; binary classification; heterogeneous textAbstract
The convergence of Software-Defined Networking and the Internet of Things (SD-IoT) enhances network orchestration but exposes centralized controllers and application-layer services to sophisticated, multi-stage cyber threats such as structural web injections and stealthy application-layer floods. This study aims to develop and validate the PISMA framework, an integrated defense mechanism designed to bridge programmable data planes with intelligence-driven control layers to achieve real-time, accurate threat detection and precision mitigation without causing collateral service disruptions. The framework incorporates P4-programmable in-switch feature extraction, sliding-window behavioral aggregation, a hybrid deep learning classification engine combining convolutional representations with bidirectional recurrent neural networks, and confidence-aware policy orchestration. Comprehensive experimental evaluations were conducted across a hybrid emulation testbed using five benchmark security datasets (CICIoT2023, ToN_IoT, IoT-ID20, UNSW-NB15, and Edge-IIoTset) to assess classification performance, error rates, and operational response times. Across the benchmark evaluations, PISMA consistently outperformed alternative ensemble baselines, achieving a peak binary classification accuracy of 98.75%, an F1-score of 98.59%, a Matthews Correlation Coefficient of 0.97, and an Area Under Curve of 0.99, while keeping false positive and false negative rates below 1.5%. Furthermore, multi-class categorizations for SQL injection, cross-site scripting, command injection, and HTTP floods maintained recognition rates exceeding 96.8% with an ultra-low total mitigation response time averaging 1.12 milliseconds. The findings demonstrate that combining programmable data-plane telemetry with hybrid deep learning and confidence-aware policy enforcement successfully neutralizes application-layer intrusions, eliminates centralized processing bottlenecks, and preserves high service continuity in resource-constrained IoT networks.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Ameer El-Sayed, Mohamed Nosseir Hemdan, Ehab Rushdy, Hanaa M. Hamza

This work is licensed under a Creative Commons Attribution 4.0 International License.
COMDEM is published Open Access under a Creative Commons CC-BY 4.0 license. Authors retain full copyright, with the first publication right granted to the journal.








