Combined Deep Learning Framework With Selective Features for Botnet Attack Detection in Internet of Things

V. Ashok Kumar, G. R. Kanagachidambaresan · Computational Intelligence · 2025

ABSTRACT Botnet attacks pose a substantial risk to Internet of Things (IoT) settings by using interconnected nodes for malicious intentions, including infiltrating networks or initiating Distributed Denial of Service (DDoS) attacks. To overwhelm systems and cause service interruptions and security breaches, these attacks take advantage of compromised IoT devices. Given the growing prevalence of IoT devices and their associated vulnerabilities, an effective botnet attack detection model is crucial for safeguarding network integrity. To address this critical issue, a new botnet attack detection approach based on the Improved Bi‐LSTM‐LinkNet model (IBLLNet) is proposed, which is specifically implemented for IoT settings. Preprocessing, feature extraction, feature selection, and detection are the four main stages of this methodology. To solve class imbalance, the preprocessing phase makes use of the Enhanced Synthetic Minority Over‐sampling Technique (ESMOTE) method, which produces more representative synthetic data than the traditional SMOTE algorithm. During feature extraction, the proposed approach captures diverse network behaviors through raw, statistical, and entropy‐based features. This hybrid approach utilizes Correlation‐based Feature Selection (CFS), Recursive Feature Elimination (RFE), and Ridge (L2 regularization) methods, and incorporates an improved selection process where feature weights are assigned based on their predicted significance. In the detection phase, the IBLLNet model integrates an Improved Bidirectional Long Short‐Term Memory (IBi‐LSTM) and LinkNet models. Here, the IBi‐LSTM model incorporates advanced layers like Bi‐LSTM, Attentive Context Normalization (ACN), and Artificial Neural Network (ANN) layers to increase detection efficiency and accuracy. The effectiveness of this strategy is confirmed by thorough tests against a number of performance metrics and comparisons with current strategies, indicating its resilience in addressing security risks associated with botnet assaults in Internet of Things environments.

Read the paper · More papers on PaperTik