Bi-GRU Based Botnet Attack Detection: Performance Comparison Between Centralized and Federated Learning
I. Nyoman Putra Maharddhika, Jiann-Liang Chen · 2024
The number of connected IoT devices is increasing every year. This leads to concerns due to their potential exploitation in Botnet attacks. Botnet attack itself uses contaminated IoT devices to launch cyber-attacks. Deep learning is commonly used in cyber-attack detection, especially in botnet attack detection. However, some deep learning models still do not detect a class that has a small amount of data in the dataset (imbalanced dataset), This causes the model accuracy to be less effective in certain classes. To address the problem we introduced the Fed-Bi-GRU and Cen-Bi-GRU models to detect botnet attacks. In this study to evaluate and analyze our models we used the BoT-IoT dataset. We calculated the precision, recall, f1-score, and accuracy of each model. The goal of this paper was to recognize the most effective model for detecting botnet attacks and prove that the federated learning approach could be used to produce a robust model that competes effectively with centralized learning. In this paper, our models successfully got a good performance in detecting the theft class, we got 100% in precision, recall, and f1-score. Where the theft data had the smallest amount of data in the BoT-IoT dataset. Moreover, our model got 99.98% accuracy for Cen-Bi-GRU and 99.97% for Fed-Bi-GRU. Both models successfully got high score of accuracy. It means our model is efficient to be used for botnet attack detection especially it can adapt to imbalanced data.