AdvBiTrans: an efficient botnet detection method based on adversarial BiLSTM-Transformer in IIoT.

Saved in:
Bibliographic Details
Title: AdvBiTrans: an efficient botnet detection method based on adversarial BiLSTM-Transformer in IIoT.
Authors: Wang, Yong1 (AUTHOR), Yan, Zhenyang1 (AUTHOR), Zhang, Kai1 (AUTHOR), Wen, Mi1 (AUTHOR)
Source: Computer Journal. Apr2026, Vol. 69 Issue 4, p703-717. 15p.
Subjects: Botnets, Transformer models, Deep learning, Adversarial machine learning, Long short-term memory, Feature selection, Internet security, Cyber physical systems
Abstract: In the Industrial Internet of Things (IIoT), the stealthiness and extensiveness of botnet attacks pose major security challenges, leading to potential data breaches and system outages. While deep learning techniques effectively detect botnets, their increasing complexity often necessitates adding more features. This not only elevates computational costs, but also hinders the timely detection of botnets. Therefore, there is a need for more effective strategies to enhance the security of IIoT systems. We propose an efficient IIoT botnet detection method, AdvBiTrans, that utilizes Pearson Correlation Coefficients Multi-stage Clustering Feature Selection (PMSFCS) and BiLSTM-Transformer framework (BiTrans) with PGD adversarial training, aiming to enhance detection accuracy and reduce feature dependency. The N-BaIoT and CIC-DDoS2019 datasets are analyzed, using data sampling methods to ensure balanced data. Experimental results showed that on the N-BaIoT dataset, the detection accuracy of the most prevalent malware families Mirai and Gafgyt reaches 99.94%, surpassing prior work by 0.44%, with an F1-score of 99.91%. On the CIC-DDoS2019 dataset, the detection accuracy reaches 97.79% after applying data balancing techniques, representing an improvement of 1.89%, with an F1-score of 99.88%. [ABSTRACT FROM AUTHOR]
Copyright of Computer Journal is the property of Oxford University Press / USA and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 193140938
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: AdvBiTrans: an efficient botnet detection method based on adversarial BiLSTM-Transformer in IIoT.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Wang%2C+Yong%22">Wang, Yong</searchLink><relatesTo>1</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Yan%2C+Zhenyang%22">Yan, Zhenyang</searchLink><relatesTo>1</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Zhang%2C+Kai%22">Zhang, Kai</searchLink><relatesTo>1</relatesTo> (AUTHOR)<br /><searchLink fieldCode="AR" term="%22Wen%2C+Mi%22">Wen, Mi</searchLink><relatesTo>1</relatesTo> (AUTHOR)
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Computer+Journal%22">Computer Journal</searchLink>. Apr2026, Vol. 69 Issue 4, p703-717. 15p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Botnets%22">Botnets</searchLink><br /><searchLink fieldCode="DE" term="%22Transformer+models%22">Transformer models</searchLink><br /><searchLink fieldCode="DE" term="%22Deep+learning%22">Deep learning</searchLink><br /><searchLink fieldCode="DE" term="%22Adversarial+machine+learning%22">Adversarial machine learning</searchLink><br /><searchLink fieldCode="DE" term="%22Long+short-term+memory%22">Long short-term memory</searchLink><br /><searchLink fieldCode="DE" term="%22Feature+selection%22">Feature selection</searchLink><br /><searchLink fieldCode="DE" term="%22Internet+security%22">Internet security</searchLink><br /><searchLink fieldCode="DE" term="%22Cyber+physical+systems%22">Cyber physical systems</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: In the Industrial Internet of Things (IIoT), the stealthiness and extensiveness of botnet attacks pose major security challenges, leading to potential data breaches and system outages. While deep learning techniques effectively detect botnets, their increasing complexity often necessitates adding more features. This not only elevates computational costs, but also hinders the timely detection of botnets. Therefore, there is a need for more effective strategies to enhance the security of IIoT systems. We propose an efficient IIoT botnet detection method, AdvBiTrans, that utilizes Pearson Correlation Coefficients Multi-stage Clustering Feature Selection (PMSFCS) and BiLSTM-Transformer framework (BiTrans) with PGD adversarial training, aiming to enhance detection accuracy and reduce feature dependency. The N-BaIoT and CIC-DDoS2019 datasets are analyzed, using data sampling methods to ensure balanced data. Experimental results showed that on the N-BaIoT dataset, the detection accuracy of the most prevalent malware families Mirai and Gafgyt reaches 99.94%, surpassing prior work by 0.44%, with an F1-score of 99.91%. On the CIC-DDoS2019 dataset, the detection accuracy reaches 97.79% after applying data balancing techniques, representing an improvement of 1.89%, with an F1-score of 99.88%. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Computer Journal is the property of Oxford University Press / USA and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=193140938
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1093/comjnl/bxaf140
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 15
        StartPage: 703
    Subjects:
      – SubjectFull: Botnets
        Type: general
      – SubjectFull: Transformer models
        Type: general
      – SubjectFull: Deep learning
        Type: general
      – SubjectFull: Adversarial machine learning
        Type: general
      – SubjectFull: Long short-term memory
        Type: general
      – SubjectFull: Feature selection
        Type: general
      – SubjectFull: Internet security
        Type: general
      – SubjectFull: Cyber physical systems
        Type: general
    Titles:
      – TitleFull: AdvBiTrans: an efficient botnet detection method based on adversarial BiLSTM-Transformer in IIoT.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Wang, Yong
      – PersonEntity:
          Name:
            NameFull: Yan, Zhenyang
      – PersonEntity:
          Name:
            NameFull: Zhang, Kai
      – PersonEntity:
          Name:
            NameFull: Wen, Mi
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 04
              Text: Apr2026
              Type: published
              Y: 2026
          Identifiers:
            – Type: issn-print
              Value: 00104620
          Numbering:
            – Type: volume
              Value: 69
            – Type: issue
              Value: 4
          Titles:
            – TitleFull: Computer Journal
              Type: main
ResultId 1