Exploring the Effectiveness of Traditional Machine Learning Models in IoT Malicious Traffic Detection
Chong Wang, Chang Gao, Famei He, Songheng He, Runshi Liu, Qianli Li, Wen Chen, Xuren Wang · 2025
As the Internet of Things (IoT) rapidly evolves, security concerns have become increasingly prominent. Machine learning-based network intrusion detection systems can identify and respond to malicious traffic with minimal latency. However, building an effective IoT malicious traffic detection system requires specialized knowledge, and the limited computational resources of IoT devices pose a trade-off between utility and security. Addressing these challenges, this study presents research on an IoT malicious traffic detection model based on traditional machine learning techniques. Compared to other methods, traditional machine learning models have fewer parameters and lower storage requirements. This study optimized the construction process of traditional machine learning models, using feature reduction and recursive feature elimination to minimize the number of features, thereby further reducing model parameters. Bayesian optimization was employed to mitigate performance errors from manual tuning, leading to the selection of the most optimal model. This research focuses on flow-level data classification, specifically selecting flow-level statistical features as model inputs. These features enable the model to conduct detailed analysis of data flows, accurately classifying them into different categories, such as benign traffic, DDoS attacks, and botnets. In experimental evaluations, the model demonstrated high accuracy, with an F1 score exceeding 0.75, validating its effectiveness and reliability in real-world applications.