Detecting IoT Botnet Attacks Using Explainable Artificial Intelligence (XAI) with Decision Tree and Random Forest

Ary Mazharuddin Shiddiqi, Rahel Cecilia Purba, Baskoro Adi Pratomo · 2025

Advancements in technology, particularly in the Internet of Things (IoT), bring significant challenges related to data security that demand immediate attention. Among these challenges, the threat posed by botnets stands out as a critical concern. The term botnet, derived from “robot” and “network,” reflects their automated operation within a network and their adherence to instructions from an attacker (botmaster). Developing detection approaches that are both effective and efficient is imperative to mitigate these threats. Combining DT and RF models with Explainable Artificial Intelligence (XAI) methods offers a robust foundation for IoT attack classification. This approach not only effectively identifies botnet attacks but also provides clear explanations for the predictions made. Decision Tree and Random Forest models excel at classifying complex data, i.e. malicious and benign. Performance evaluation was conducted using the F1-score provides valuable insights into their classification capabilities. Experiment results indicate that our proposed approach is effective in detecting botnets, as evidenced by achieving an F1-score of$\mathbf{9 9 \%}$, demonstrating high accuracy, precision, and recall in distinguishing between benign and malicious traffic.

Read the paper · More papers on PaperTik