Research Article | Open Access | Download PDF
Volume 13 | Issue 7 | Year 2026 | Article Id. IJECE-V13I7P105 | DOI : https://doi.org/10.14445/23488549/IJECE-V13I7P105An Enhanced Deep Learning Approach for IoT Botnet Attack Detection
Vinaykumar N Soni, Ashwinikumar Jha
| Received | Revised | Accepted | Published |
|---|---|---|---|
| 12 May 2026 | 11 Jun 2026 | 30 Jun 2026 | 29 Jul 2026 |
Citation :
Vinaykumar N Soni, Ashwinikumar Jha, "An Enhanced Deep Learning Approach for IoT Botnet Attack Detection," International Journal of Electronics and Communication Engineering, vol. 13, no. 7, pp. 62-76, 2026. Crossref, https://doi.org/10.14445/23488549/IJECE-V13I7P105
Abstract
The increasing development of the Internet of Things has led to several security threats and vulnerabilities associated with interconnected networks and, thus, makes them suitable targets for DDoS attacks. The increased dimensionality of traffic in the context of the Internet of Things makes IDS hard because deep learning models running independently are unable to adequately address the complexity associated with the interaction between network attributes. In this context, this research suggests a new architecture based on deep learning methods for binary classifications and featuring hybridization of multi-layer 1D-CNNs with LSTM networks. To reduce computational resources needed for training on IoT-based datasets, the ANOVA F-test is implemented to choose the key features before training. The proposed architecture includes dual convolutional layers having 64 and 128 filters, respectively, that allow to analyze the hierarchical spatial structures. Next, the data from convolutional layers is passed to the LSTM layer that analyzes high-order structural dependencies within feature maps generated at earlier stages. The proposed model was trained using the CICIoT2023 benchmark and showed superior performance compared to a standalone architecture featuring either CNNs or LSTM networks. Across five independent trials, the model achieved a mean accuracy of 98.72% ± 0.06%, with a precision of 98.91% and a recall of 98.65%. Furthermore, the proposed hybrid architecture shows high computational efficiency, achieving a remarkably low inference time of 0.15 ms per sample and a compact model footprint of 0.30 MB. These metrics confirm the model's suitability for deployment on resource-constrained IoT edge devices, providing a robust balance between high detection accuracy and low architectural complexity. These findings confirm that the constructive collaboration between spatial and structural feature modeling provides a robust, stable, and scalable solution for mitigating DDoS threats in modern IoT ecosystems.
Keywords
IoT security, Botnet detection, CNN-LSTM, CICIoT2023, ANOVA F-test.
References
- Deepa Venkataraya Premalatha, and Sukumar Ramanujam, “Ensemble-Based Intrusion Detection for IoT Networks Using the CICIoT2023 Dataset,” Journal of Information Systems Engineering and Management, vol. 10, no. 21, pp. 743-755, 2025.
[CrossRef] [Google Scholar] [Publisher Link] - Number of Internet of Things (IoT) connections worldwide from 2022 to 2023, with forecasts from 2024 to 2034, Statista, 2025. [Online]. Available: https://www.statista.com/statistics/1183457/iot-connected-devices-worldwide
- Omar Almousa, Batool Hamdallh, and Ruba Al-nu’man, “Enhancing IoT Security: A Comparative Analysis of Machine Learning and Deep Learning Techniques for Botnet Detection,” Engineering, Technology and Applied Science Research, vol. 15, no. 4, pp. 24498-24505, 2025.
[CrossRef] [Google Scholar] [Publisher Link] - Eryk Schiller et al., “Landscape of IoT Security,” Computer Science Review, vol. 44, pp. 1-18, 2022.
[CrossRef] [Google Scholar] [Publisher Link] - Samuel Kofi Erskine, “Real-Time Large-Scale Intrusion Detection and Prevention System (IDPS) CICIoT Dataset Traffic Assessment Based on Deep Learning,” Applied System Innovation, vol. 8, no. 2, pp. 1-32, 2025.
[CrossRef] [Google Scholar] [Publisher Link] - Belal Ibrahim Hairab et al., “Anomaly Detection of Zero-Day Attacks Based on CNN and Regularization Techniques,” Electronics, vol. 12, no. 3, pp. 1-18, 2023.
[CrossRef] [Google Scholar] [Publisher Link] - Bambang Susilo, Abdul Muis, and Riri Fitri Sari, “Intelligent Intrusion Detection System against Various Attacks Based on a Hybrid Deep Learning Algorithm,” Sensors, vol. 25, no. 2, pp. 1-26, 2025.
[CrossRef] [Google Scholar] [Publisher Link] - Doaa Mohsin Abd Ali Afraji, Jaime Lloret, and Lourdes Peñalver, “An Integrated Hybrid Deep Learning Framework for Intrusion Detection in IoT and IIoT Networks Using CNN-LSTM-GRU Architecture,” Computation, vol. 13, no. 9, pp. 1-28, 2025.
[CrossRef] [Google Scholar] [Publisher Link] - S.P. Jani, and M. Adam Khan, Applications of AI in Smart Technologies and Manufacturing, 1st ed., London: CRC Press, vol. 2, pp. 1-556, 2025.
[CrossRef] [Google Scholar] [Publisher Link] - Zhendong Wang et al., “A Lightweight Intrusion Detection Method for IoT Based on Deep Learning and Dynamic Quantization,” PeerJ Computer Science, vol. 9, pp. 1-29, 2023.
[CrossRef] [Google Scholar] [Publisher Link] - Abdullah Waqas et al., “Comparative Analysis of Deep Learning Models for Intrusion Detection in IoT Networks,” Computers, vol. 14, no. 7, pp. 1-18, 2025.
[CrossRef] [Google Scholar] [Publisher Link] - Maher Alharby, “Evaluating Machine Learning Approaches for Multiple Attack Classification with Improved Computational Efficiency in IoT Networks,” Scientific Reports, vol. 15, no. 1, pp. 1-18, 2025.
[CrossRef] [Google Scholar] [Publisher Link] - Md. Alamgir Hossain, “Deep Learning-Based Intrusion Detection for IoT Networks: A Scalable and Efficient Approach,” EURASIP Journal on Information Security, vol. 2025, pp. 1-23, 2025.
[CrossRef] [Google Scholar] [Publisher Link] - Enock Mudau, Topside E. Mathonsi, and Tshimangadzo Tshilongamulenzhe, “A Deep Learning Algorithm to Minimize Cyber-Security Attacks for Small Enterprises,” 2024 International Conference on Electrical, Computer and Energy Technologies ICECET, Sydney, Australia, pp. 1-7, 2024.
[CrossRef] [Google Scholar] [Publisher Link] - Nik Muhammad Danial Bin Nik Ram Zaedi, Amy Lim Hui Lan, and Goh Hui-Ngo, “Developing Deep Learning Models to Predict Benign and Malicious Attacks in IoT Networks,” 2024 IEEE International Conference on Computing (ICOCO), Kuala Lumpur, Malaysia, pp. 90-95, 2024.
[CrossRef] [Google Scholar] [Publisher Link] - Afrah Gueriani, Hamza Kheddar, and Ahmed Cherif Mazari, “Enhancing IoT Security with CNN and LSTM-Based Intrusion Detection Systems,” 2024 6th International Conference on Pattern Analysis and Intelligent Systems (PAIS), EL OUED, Algeria, pp. 1-7, 2024.
[CrossRef] [Google Scholar] [Publisher Link] - Abdullah Mujawib Alashjaee, “Deep Learning for Network Security: An Attention-CNN-LSTM Model for Accurate Intrusion Detection,” Scientific Reports, vol. 15, no. 1, pp. 1-12, 2025.
[CrossRef] [Google Scholar] [Publisher Link] - Amna Naeem et al., “Efficient IoT Intrusion Detection with an Improved Attention-Based CNN-BiLSTM Architecture,” 2026 International Conference on Integrated Intelligence and Cognitive Engineering (ICIICE), Dubai, United Arab Emirates, pp. 1-6, 2026.
[CrossRef] [Google Scholar] [Publisher Link] - Jaydeep R.Tadhani et al., “Securing Web Applications against XSS and SQLi Attacks using a Novel Deep Learning Approach,” Scientific Reports, vol. 14, no. 1, pp. 1-17, 2024.
[CrossRef] [Google Scholar] [Publisher Link] - Preeti Kailas Suryawanshi, and Sonal Kirankumar Jagtap, “Mitigating Iot Botnets with CNN-LSTM and Anomaly Detection,” International Journal of Environmental Sciences, vol. 11, no. 16, pp. 1216-1223, 2025.
[CrossRef] [Publisher Link] - Selman Hizal, Unal Cavusoglu, and Devrim Akgun, “A Novel Deep Learning-Based Intrusion Detection System for IoT DDoS Security,” Internet of Things, vol. 28, 2024.
[CrossRef] [Google Scholar] [Publisher Link] - Akinul Islam Jony, and Arjun Kumar Bose Arnob, “A Long Short-Term Memory based Approach for Detecting Cyber-Attacks in IoT using CIC-IoT2023 Dataset,” Journal of Edge Computing, vol. 3, no. 1, pp. 28-42, 2024.
[CrossRef] [Google Scholar] [Publisher Link] - Noor Ul Ain et al., “Securing IoT Networks Against DDoS Attacks: A Hybrid Deep Learning Approach,” Sensors, vol. 25, no. 5, pp. 1-23, 2025.
[CrossRef] [Google Scholar] [Publisher Link] - Sami Yaras, and Murat Dener, “IoT-Based Intrusion Detection System Using New Hybrid Deep Learning Algorithm,” Electronics, vol. 13, no. 6, pp. 1-28, 2024.
[CrossRef] [Google Scholar] [Publisher Link] - Euclides Carlos Pinto Neto et al., “CICIoT2023: A Real-Time Dataset and Benchmark for Large-Scale Attacks in IoT Environment,” Sensors, vol. 23, no. 13, pp. 1-26, 2023.
[CrossRef] [Google Scholar] [Publisher Link] - Burak Aydin, Hakan Aydin, and Sedat Gormus, “Intrusion Detection Systems in IoT: A Detailed Review of Threat Categories, Detection Strategies, and Future Technologies,” Journal of Information Security and Applications, vol. 95, 2025.
[CrossRef] [Google Scholar] [Publisher Link] - Thorir Mar Ingolfsson, Insights into LSTM Architecture. 2021. [Online]. Available: https://thorirmar.com/post/insight_into_lstm/
- Miracle Udurume, Vladimir Shakhov, and Insoo Koo, “Comparative Analysis of Deep Convolutional Neural Network—Bidirectional Long Short-Term Memory and Machine Learning Methods in Intrusion Detection Systems,” Applied Sciences, vol. 14, no. 16, pp. 1-1 6, 2024.
[CrossRef] [Google Scholar] [Publisher Link] - Sidra Abbas et al., Evaluating Deep Learning Variants for Cyber-Attacks Detection and Multi-Class Classification in IoT Networks,” PeerJ Computer Science, vol. 10, pp. 1-23, 2024.
[CrossRef] [Google Scholar] [Publisher Link]