SHAP-Driven Intrusion Detection: Detecting Mirai Botnet Attacks in IoT

Yeasmin Begum Laskar, Rakesh Matam, Ferdous Ahmed Barbhuiya · 2025

IoT is expanding but faces critical security risks from Mirai, a botnet exploiting insecure devices to launch DDoS attacks (GREETH Flood, UDPPlain, GREIP Flood). To counter these threats, we propose a machine learning-based IDS using the CICIoT2023 dataset, enhanced by stratified sampling to ensure balanced data and Random Forest-based feature selection for detecting key Mirai attack signatures. This approach reduces overhead on resource-constrained IoT devices. SHAP analysis provides interpretability, revealing how network traffic features drive the model’s decisions. Among SVM, LR, DT, and LightGBM, LightGBM achieves the best results (99.79% accuracy, 98.75% F1-score). SHAP indicates that Number, Protocol Type, Weight, and Variance critically influence detection, while ack_flag_number, HTTPS, and TCP have minimal impact.

Read the paper · More papers on PaperTik