An Explainable Hybrid GA–GWO Optimized Ensemble Learning Framework for IoT Botnet Attack Detection and Mitigation

  • Nidhi B. Patel
  • Dr. Swity Maniyar
Keywords: Internet of Things, Botnet Detection, Ensemble Learning, XGBoost, LightGBM, CatBoost, Genetic Algorithm, Grey Wolf Optimizer, Explainable Artificial Intelligence, SHAP.

Abstract

The rapid proliferation of Internet of Things (IoT) devices has significantly transformed modern digital ecosystems by enabling seamless communication among smart devices across healthcare, transportation, industrial automation, agriculture, and smart home environments. However, the increasing number of interconnected IoT devices has also expanded the attack surface for cyber threats, particularly botnet attacks, which exploit vulnerable devices to launch Distributed Denial of Service (DDoS), data theft, malware propagation, and command-and-control (C&C) attacks. Traditional intrusion detection systems often struggle to detect sophisticated botnet attacks because of high-dimensional network traffic, class imbalance, evolving attack patterns, and limited interpretability of machine learning models.

This research proposes an explainable hybrid ensemble learning framework for accurate IoT botnet detection and automated mitigation. The proposed framework employs hybrid feature engineering to extract statistical, behavioral, and temporal characteristics from IoT traffic. Principal Component Analysis (PCA) is applied to reduce feature dimensionality, while Synthetic Minority Oversampling Technique (SMOTE) addresses class imbalance. Three gradient boosting algorithms, namely XGBoost, LightGBM, and CatBoost, are integrated into an ensemble model to improve detection performance. Furthermore, a hybrid Genetic Algorithm–Grey Wolf Optimizer (GA–GWO) is utilized for hyperparameter optimization, enhancing convergence speed and reducing false positive predictions. Explainable Artificial Intelligence (XAI) using SHAP is incorporated to provide feature-level interpretation of detection decisions and improve transparency. Finally, automated mitigation strategies are triggered to isolate infected IoT devices and restrict malicious traffic.

Experimental evaluation on the benchmark N-BaIoT dataset demonstrates that the proposed hybrid framework achieves a classification accuracy of 98.95%, outperforming individual XGBoost (94.88%), LightGBM (94.90%), and CatBoost (95.92%) classifiers. The proposed model also achieves an interpretability score of 98.2, demonstrating its capability to deliver accurate, scalable, and explainable IoT botnet detection suitable for real-world deployment.

 

Author Biographies

Nidhi B. Patel

PhD Scholar – Swaminarayan University, Kalol, Gujarat 

Dr. Swity Maniyar

Associate Professor in GTU and PhD guide in Swaminarayan University, Kalol, Gujarat

References

[1] R. Kalakoti, S. Nomm, and H. Bahsi, “In-Depth Feature Selection for the Statistical Machine Learning-Based Botnet Detection in IoT Networks,” IEEE Access, vol. 10, pp. 94518–94535, 2022.
[2] Q. Abu Al-Haija and M. Al-Dala’ien, “ELBA-IoT: An Ensemble Learning Model for Botnet Attack Detection in IoT Networks,” Journal of Sensor and Actuator Networks, vol. 11, no. 1, p. 18, 2022.
[3] M. Almseidin and M. Alkasassbeh, “An Accurate Detection Approach for IoT Botnet Attacks Using Interpolation Reasoning Method,” Information, vol. 13, no. 6, p. 300, 2022.
[4] X. Liu and Y. Du, “Towards Effective Feature Selection for IoT Botnet Attack Detection Using a Genetic Algorithm,” Electronics, vol. 12, no. 5, p. 1260, 2023.
[5] D. C. Muñoz and A. del-Corte Valiente, “A Novel Botnet Attack Detection for IoT Networks Based on Communication Graphs,” Cybersecurity, vol. 6, no. 1, p. 33, 2023.
[6] A. Arafa, N. El-Fishawy, M. Badawy, and M. Radad, “RN-SMOTE: Reduced Noise SMOTE Based on DBSCAN for Enhancing Imbalanced Data Classification,” Journal of King Saud University – Computer and Information Sciences, vol. 34, no. 8, pp. 5059–5074, 2022.
[7] A. Burrello, A. Marchioni, D. Brunelli, and L. Benini, “Embedding Principal Component Analysis for Data Reduction in Structural Health Monitoring on Low-Cost IoT Gateways,” in Proceedings of the 16th ACM International Conference on Computing Frontiers, pp. 235–239, 2019.
[8] X. Wang et al., “Predicting the Prognosis of Patients in the Coronary Care Unit: A Novel Multi-Category Machine Learning Model Using XGBoost,” Frontiers in Cardiovascular Medicine, vol. 9, 2022.
[9] J. Zhou, X. Tong, S. Bai, and J. Zhou, “A LightGBM-Based Power Grid Frequency Prediction Method with Dynamic Significance–Correlation Feature Weighting,” Energies, vol. 18, no. 13.
[10] İ. Mert, “Prediction of Wind Speed Using Tree-Based Ensemble Algorithms: CatBoost, HistGBM, and XGBoost,” International Journal of Multidisciplinary Studies and Innovative Technologies, vol. 9, no. 1, pp. 145–150.
[11] R. Natras, B. Soja, and M. Schmidt, “Ensemble Machine Learning of Random Forest, AdaBoost and XGBoost for Vertical Total Electron Content Forecasting,” Remote Sensing, vol. 14, no. 15, 2022.
[12] A. M. Salih et al., “A Perspective on Explainable Artificial Intelligence Methods: SHAP and LIME,” Advanced Intelligent Systems, vol. 7, no. 1.
[13] “N-BaIoT Dataset,” Kaggle. Available: https://www.kaggle.com/datasets/mkashifn/nbaiot-dataset
[14] “Applying Ensemble Tree-Based Models and Explainable AI for IoT Botnet Detection in Heterogeneous Device,” International Conference on Advancement in Data Science, E-learning and Information System (ICADEIS), IEEE.
Published
2024-01-20
How to Cite
Nidhi B. Patel, & Dr. Swity Maniyar. (2024). An Explainable Hybrid GA–GWO Optimized Ensemble Learning Framework for IoT Botnet Attack Detection and Mitigation. Revista Electronica De Veterinaria, 25(1), 4706 - 4714. https://doi.org/10.69980/redvet.v25i1.2486
Section
Articles