Analysis of machine learning models for IoT malware detection in network traffic
Maram Aljasim, Abdelhameed F. Ibrahim · IET conference proceedings. · 2025
The rapid increase of attacks on IoT devices has intensified the security challenge, making it necessary for effective IoT malware detection methods. This paper presents a comparative analysis of regression models for IoT malware detection using the IoT-23 dataset. Unlike traditional classification models, the use of regression models is employed, specifically Random Forest Regressor (RFR), Decision Tree Regressor (DTR), K-Nearest Neighbors (KNN) Regressor, and Multi-Layer Perceptron (MLP) Regressor. After preprocessing the dataset, a selected number of files are used to create a balanced dataset for training and testing. The models are then assessed on both multiclass detection and binary detection using metrics such as Mean Squared Error (MSE), Mean Absolute Error (MAE), R-squared (R²), and fitted time. In multiclass detection, RFR achieved the best performance with the best metrics. DTR showed competitive results, while KNN and MLP demonstrated higher error values and lower accuracy and efficiency. For binary detection, RFR again had the best metrics. KNN was computationally efficient but less accurate, and DTR and MLP were the least effective overall. The findings showcase that RFR is the most efficient and reliable model for IoT malware detection.