Latent space alignment for robust detection of IoT botnet attacks in non-stationary environments
Hassan Wasswa, Hussein A. Abbass, Timothy Lynar · Knowledge-Based Systems · 2025
• Proposed an approach for IoT botnet attack detection under non-stationarity. • Deployed latent space alignment to mitigate frequent classifier retraining. • Demonstrated the impact of non-stationarity on detection performance. • Improved attack detection under non-stationary IoT traffic. • Prevents catastrophic forgetting by preserving historical information. Although earlier research has demonstrated that AI-driven models can attain exceptionally high accuracy in identifying IoT-based threats, their practical integration into enterprise environments for real-world attack detection and classification remains limited. This is primarily due to their reliance on stationary datasets for training and evaluation, which fail to capture the dynamic nature of real-world IoT NetFlow traffic, characterized by frequent concept drifts. A common solution is to retrain and update the classifier whenever a concept drift is detected. However, the rapid evolution of IoT attacks translates into frequent drifts, leading to high retraining costs and the risk of the model forgetting historical patterns, making it vulnerable to previously seen attack types. To address these challenges and facilitate real-world adoption, this study proposes a method for detecting novel attacks in non-stationary environments without requiring constant model retraining. The approach involves training a Variational Auto-encoder (VAE) on historical data, followed by training a classifier on the VAE’s latent space representations. Through latent space alignment, new instances are mapped to the established latent space learned from historical data, enabling the classifier to effectively detect attacks without retraining while preserving knowledge of past attack patterns. Our evaluation, using both synthetic and real-world IoT attack traffic, demonstrates the robustness of this approach, achieving improved detection performance under concept drift while significantly reducing false alarms and missed detections on unseen traffic.