AdvBiTrans: an efficient botnet detection method based on adversarial BiLSTM-Transformer in IIoT

Yong Wang, Zhenyang Yan, Kai Zhang, Mi Wen · The Computer Journal · 2025

Abstract In the Industrial Internet of Things (IIoT), the stealthiness and extensiveness of botnet attacks pose major security challenges, leading to potential data breaches and system outages. While deep learning techniques effectively detect botnets, their increasing complexity often necessitates adding more features. This not only elevates computational costs, but also hinders the timely detection of botnets. Therefore, there is a need for more effective strategies to enhance the security of IIoT systems. We propose an efficient IIoT botnet detection method, AdvBiTrans, that utilizes Pearson Correlation Coefficients Multi-stage Clustering Feature Selection (PMSFCS) and BiLSTM-Transformer framework (BiTrans) with PGD adversarial training, aiming to enhance detection accuracy and reduce feature dependency. The N-BaIoT and CIC-DDoS2019 datasets are analyzed, using data sampling methods to ensure balanced data. Experimental results showed that on the N-BaIoT dataset, the detection accuracy of the most prevalent malware families Mirai and Gafgyt reaches 99.94%, surpassing prior work by 0.44%, with an F1-score of 99.91%. On the CIC-DDoS2019 dataset, the detection accuracy reaches 97.79% after applying data balancing techniques, representing an improvement of 1.89%, with an F1-score of 99.88%.

Read the paper · More papers on PaperTik