AdvBiTrans: an efficient botnet detection method based on adversarial BiLSTM-Transformer in IIoT.

Saved in:
Bibliographic Details
Title: AdvBiTrans: an efficient botnet detection method based on adversarial BiLSTM-Transformer in IIoT.
Authors: Wang, Yong1 (AUTHOR), Yan, Zhenyang1 (AUTHOR), Zhang, Kai1 (AUTHOR), Wen, Mi1 (AUTHOR)
Source: Computer Journal. Apr2026, Vol. 69 Issue 4, p703-717. 15p.
Subjects: Botnets, Transformer models, Deep learning, Adversarial machine learning, Long short-term memory, Feature selection, Internet security, Cyber physical systems
Abstract: In the Industrial Internet of Things (IIoT), the stealthiness and extensiveness of botnet attacks pose major security challenges, leading to potential data breaches and system outages. While deep learning techniques effectively detect botnets, their increasing complexity often necessitates adding more features. This not only elevates computational costs, but also hinders the timely detection of botnets. Therefore, there is a need for more effective strategies to enhance the security of IIoT systems. We propose an efficient IIoT botnet detection method, AdvBiTrans, that utilizes Pearson Correlation Coefficients Multi-stage Clustering Feature Selection (PMSFCS) and BiLSTM-Transformer framework (BiTrans) with PGD adversarial training, aiming to enhance detection accuracy and reduce feature dependency. The N-BaIoT and CIC-DDoS2019 datasets are analyzed, using data sampling methods to ensure balanced data. Experimental results showed that on the N-BaIoT dataset, the detection accuracy of the most prevalent malware families Mirai and Gafgyt reaches 99.94%, surpassing prior work by 0.44%, with an F1-score of 99.91%. On the CIC-DDoS2019 dataset, the detection accuracy reaches 97.79% after applying data balancing techniques, representing an improvement of 1.89%, with an F1-score of 99.88%. [ABSTRACT FROM AUTHOR]
Copyright of Computer Journal is the property of Oxford University Press / USA and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
Description
Abstract:In the Industrial Internet of Things (IIoT), the stealthiness and extensiveness of botnet attacks pose major security challenges, leading to potential data breaches and system outages. While deep learning techniques effectively detect botnets, their increasing complexity often necessitates adding more features. This not only elevates computational costs, but also hinders the timely detection of botnets. Therefore, there is a need for more effective strategies to enhance the security of IIoT systems. We propose an efficient IIoT botnet detection method, AdvBiTrans, that utilizes Pearson Correlation Coefficients Multi-stage Clustering Feature Selection (PMSFCS) and BiLSTM-Transformer framework (BiTrans) with PGD adversarial training, aiming to enhance detection accuracy and reduce feature dependency. The N-BaIoT and CIC-DDoS2019 datasets are analyzed, using data sampling methods to ensure balanced data. Experimental results showed that on the N-BaIoT dataset, the detection accuracy of the most prevalent malware families Mirai and Gafgyt reaches 99.94%, surpassing prior work by 0.44%, with an F1-score of 99.91%. On the CIC-DDoS2019 dataset, the detection accuracy reaches 97.79% after applying data balancing techniques, representing an improvement of 1.89%, with an F1-score of 99.88%. [ABSTRACT FROM AUTHOR]
ISSN:00104620
DOI:10.1093/comjnl/bxaf140