Applying Ensemble Tree-Based Models and Explainable AI for IoT Botnet Detection in Heterogeneous Device
Parman Sukarno, Muhammad Ilham Yushronni, Aulia Arif Wardana · 2025
Botnet attacks pose significant security risks, making the Internet of Things (IoT) increasingly vulnerable. Ensuring IoT system security is crucial for detecting botnet attacks. While Machine Learning (ML) approaches have shown effectiveness, challenges related to model interpretability and transparency remain. This research aims to enhance ML model interpretability using eXplainable Artificial Intelligence (XAI) to generate more substantiated explanations. The N-BaIoT dataset is used to train an ensemble model to detect botnet attacks, learning pattern from nine IoT devices. Gradient Boost with Early Stopping, Catboost and Histogram Gradient Boost are selected to handle large and unbalanced datasets. To improve transparency, XAI methods such as SHapley Additive exPlanations (SHAP) and Local Interpretable Model-Agnostic Explanations (LIME) are identifying key features influencing predictions, enhancing model reliability. The research show that Device 7 achieves the highest accuracy among the models, with the Gradient Boosting with Early Stopping model achieving an accuracy of 99.94%, Catboost achieving 99.98% and Histogram Gradient Boosting also reaching 99.98%. Additionally, SHAP and LIME successfully identify key features affecting botnet classifications and reveal correlations between features. These findings highlight the potential the potential of ensemble models supported by XAI in understanding and trusting ML.