Table 1.
Acronyms employed in the document.
| Acronyms | Meaning |
|---|---|
| 6LoWPAN | IPv6 over Low-power Wireless Personal Area Networks |
| CBOR | Concise Binary Object Representation |
| CCRL | Compressed Certificate Revocation List |
| CNN | Convolutional Neural Network |
| CoAP | Constrained Application Protocol |
| DAG | Directed Acyclic Graph |
| DAO | Destination Advertisement Object |
| DAO-ACK | Destination Advertisement Object Acknowledgment |
| DDAO | Dropped Destination Advertisement Object |
| DDoS | Distributed Denial-of-Service |
| DIO | DODAG Information Object |
| DIS | DODAG Information Solicitation |
| DODAG | Destination-Oriented Directed Acyclic Graph |
| DoS | Denial of Service |
| DNM | Detection based on Node pruning and Model fusion |
| DTF | Dynamic Trust Factor |
| HMM | Hidden Markov Model |
| ICMPv6 | Internet Control Message Protocol version 6 |
| IDS | Intrusion Detection System |
| IETF | Internet Engineering Task Force |
| IoT | Internet of Things |
| IPT | Inter-Packet Time |
| IPv6 | Internet Protocol version 6 |
| LLNs | Low-power and Lossy Networks |
| LSTM | Long Short-Term Memory |
| NDNoT | Named Data Networking of Things |
| OCSP | Online Certificate Status Protocol |
| OF | Objective Function |
| PDR | Packet Delivery Ratio |
| PSCM | Prime Sequence Code Matrix |
| QoS | Quality of Service |
| RAD | Rank Attack Detection |
| RPL | Routing Protocol for Low-power and Lossy Networks |
| SECaaS | Security-as-a-Service |
| UDGM | Unit Disk Graph Medium |
| UDP | User Datagram Protocol |

Figure 1.
Architecture of IoT Network with Adaptation Layer.

Figure 2.
A single-instance RPL network with a single DODAG.

Figure 3.
Attacks targeting RPL in 6LoWPAN.

Figure 4.
Sinkhole attack through the combination of Decreased rank and Blackhole attacks.
Table 2:
Overview of RPL-based IoT security mechanisms under different attacks.
| Ref. | Year | Mechanism | Description | Mobility | Limitations |
|---|---|---|---|---|---|
| [22] | 2026 | ML-based adaptive routing | Detects sinkhole and blackhole. | Yes | Training overhead |
| [23] | 2026 | TH-DCNN + optimization | DL-based attack detection with clustering. | Yes | High computation |
| [24] | 2026 | MDNN + optimization | Detects HELLO flood attacks using DL. | Yes | High complexity |
| [17] | 2025 | FL-based IDS | Improves intrusion detection in RPL. | No | High overhead |
| [18] | 2025 | Collaborative detection | Detects blackhole attacks. | No | Limited scope |
| [19] | 2025 | Trust-aware routing | Enhances secure routing. | No | Ignores inactive attacks |
| [20] | 2025 | FL-based IDS | Improves detection accuracy. | No | Limited evaluation |
| [25] | 2025 | ML-based clustering | Detects sinkhole attacks efficiently. | Yes | Dataset dependency |
| [26] | 2025 | Mathematical model | Models sinkhole impact on PDR, delay, throughput. | No | No mitigation |
| [27] | 2024 | Multi-tier approach | Detects Sybil attacks. | No | No privacy analysis |
| [28] | 2024 | Blacklisting | Mitigates DAO insider attacks. | No | Weak in mobility |
| [29] | 2024 | SECaaS IDS | Detects multiple RPL attacks. | No | Static defense |
| [30] | 2024 | Logic-based encoder | Prevents multiple attacks. | No | No 100% mobility |
| [31] | 2024 | PIT-based defense | Mitigates flooding attacks. | No | Interoperability issues |
| [32] | 2024 | Ensemble IDS | Detects rank and flooding attacks. | No | No 100% mobility |
| [33] | 2024 | HMM-based IDS | Detects sinkhole attacks. | No | No 100% mobility |
| [4] | 2024 | Performance analysis | Evaluates rank attacks. | Yes | No IDS |
| [34] | 2023 | Provenance model | Detects jamming and sync attacks. | No | No 100% mobility |
| [35] | 2023 | Challenge-response | Mitigates DDAO attacks. | No | Limited scope |
| [36] | 2023 | ML-based detection | Detects DDoS attacks. | No | Dataset limits |
| [37] | 2023 | Key management | Secures communication. | No | Single point failure |
| [38] | 2023 | ML + pruning | Detects delay attacks. | No | Weak for hybrid attacks |
| [39] | 2023 | Q-learning | Detects version attacks. | No | No 100% mobility |
| [40] | 2023 | ML-based IDS | Detects multiple attacks. | No | No 100% mobility |
| [41] | 2023 | OCSP-based | Prevents replay and DoS. | No | Scalability issues |
| [42] | 2023 | Federated DL | Detects wormhole attacks. | No | No ensemble |
| [5] | 2023 | Performance analysis | Evaluates version attacks. | Yes | No IDS |
| [43] | 2023 | PSCM-based authentication | Mitigates DDAO attacks. | No | Limited scope |
| Our Work | 2026 | Simulation-based analysis | Evaluates sinkhole attack. | Yes | No IDS |
Table 3.
Simulation parameters.
| Parameters | Value |
|---|---|
| Simulator | Cooja (Contiki OS) |
| Mote type | Z1 |
| Radio medium | UDGM |
| Transport layer protocol | UDP |
| PHY and MAC layer | IEEE 802.15.4 |
| Scenario dimension | 200 m * 200 m |
| Transmission range | 50 m |
| DODAG root rank | 1 |
| Gateway nodes | 1 |
| Number of sensor nodes | 10, 20, 30, 40, 50 |
| Number of mobiles nodes | 0%, 50%, 100% |
| Number of attacker node | 0%, 10%, 20%, 30% |
| Speed of node | 1 to 2 mps |
| Data packet size | 30 bytes |
| Simulation time | 30 minutes |

Figure 5.
Number of isolated nodes.

Figure 6.
Average packet delivery ratio.

Figure 7.
Average inter-packet time.

Figure 8.
Average power consumption.

Figure 9.
Memory requirement.