Automated IoT Fingerprinting with LLMs: Harnessing Explainable AI and Artificial Bee Colony Optimization
Yaman Shrestha, Khursaid Ansari, Ahmet Aksoy · 2025
Identifying malicious IoT devices significantly impacts the security of hosts within a network. Many automated systems have been introduced using machine learning and deep-learning techniques. However, these approaches often lack explainability, adaptability, and the ability to incorporate contextual and domain-specific knowledge seamlessly. This study investigates an automated approach for classifying IoT devices using LLMs by analyzing network packets. Another issue with current implementations utilizing traditional or LLM-based techniques is that they usually need to process vast amounts of data to be trained. A rigorous feature selection before classification can immensely increase efficiency without sacrificing accuracy. Therefore, we integrate Explainable AI (XAI) techniques, such as SHAP, and optimization algorithms, like Artificial Bee Colony (ABC), to reduce the features obtained from network packets and utilize an LLM for classification. Our method achieves substantial feature reduction-up to 75%-while maintaining high classification accuracy, up to 98.9%. With the help of SHAP and ABC, we can automatically and successfully detect the most relevant features that help distinguish IoT devices efficiently and accurately. This helps our models adapt to changes in device behavior and generalize to diverse network environments.