Back to results

York University

IoT network Malicious Behaviour Profiling Based on Explainable AI Using LSTM and SHAP

Abstract

dc:description.abstract

The proliferation of IoT devices has enhanced connectivity but exposed networks to new cyber threats, particularly from botnets. Detecting and identifying malicious data is critical for early threat detection, understanding botnet attack patterns, and deploying countermeasures. This research proposes an IoT Bot detection and identification profiling model using XAI. The proposed model introduces a novel feature selection techqnique with the XGBoost algorithm and a correlation-based feature selection technique to enhance efficiency. An optimized LSTM neural network enables accurate bot detection and identification, with hyperparameters selected using the Bayesian Optimization algorithm. SHAP analysis provides insightful individual and collective bot characteristic profiles. The model’s performance was evaluated using the augmented BCCC-Aposemat-Bot-IoT-24 dataset, built upon the Aposemat-Bot-IoT-23 dataset, and compared against established models assessed primarily on the same dataset in previous research. The results showed that the proposed model performed comparably to these models, with distinct advantages, including handling sequential and time-series data, managing imbalanced datasets, and providing explainable insights into botnet behavior. The model’s design also emphasizes computational efficiency, making it potentially suitable for deployment in resource-constrained environments.

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Niktabe, Sepideh
Advisor dc:contributor.advisor
  • Habibi Lashkari, Arash

Subjects

dc:subject × 1

Rights

dc:rights
Statement dc:rights
  • Author owns copyright, except where explicitly noted. Please contact the author directly with licensing requests.
Language dc:language
en

Identifiers

dc:identifier.*
Handle dc:identifier.uri
https://hdl.handle.net/10315/42467
OAI identifier oai:identifier
oai:yorkspace.library.yorku.ca:10315/42467

Chain of custody

source
Harvested from
York University
Base URL
yorkspace.library.yorku.ca/oai/request
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
related terms
citation

Niktabe, Sepideh. IoT network Malicious Behaviour Profiling Based on Explainable AI Using LSTM and SHAP. 2024. https://hdl.handle.net/10315/42467