IAES
Inter
national
J
our
nal
of
Articial
Intelligence
(IJ-AI)
V
ol.
15,
No.
3,
June
2026,
pp.
2192
∼
2200
ISSN:
2252-8938,
DOI:
10.11591/ijai.v15.i3.pp2192-2200
❒
2192
A
h
ybrid
deep
lear
ning
appr
oach
f
or
BoT
-IoT
intrusion
detection
Khalid
Altarawneh
1
,
Ghayth
AlMahadin
1
,
Ibrahim
Altarawni
2
1
Department
of
Data
Science,
F
aculty
of
Information
T
echnology
,
Mutah
Uni
v
ersity
,
Al-Karak,
Jordan
2
Department
of
Articial
Intelligence,
F
aculty
of
Information
T
echnology
,
T
ala
T
echnical
Uni
v
ersity
,
T
ala,
Jordan
Article
Inf
o
Article
history:
Recei
v
ed
Feb
5,
2025
Re
vised
Apr
20,
2026
Accepted
May
11,
2026
K
eyw
ords:
Bee
colon
y
optimization
Data
augmentation
Deep
learning
Feature
selection
Internet
of
thing
ABSTRA
CT
Internet
of
things
(IoT)
de
vices
enhance
quali
ty
of
life
and
industrial
operations
b
ut
pose
signicant
security
risks,
necessitating
intelligent
intrusion
detection
systems
(IDS)
to
combat
e
v
olving
c
yber
threats.
This
paper
proposes
a
no
v
el
IDS
frame
w
ork
inte
grating
bio-inspired
heuristic
feature
selection,
a
generati
v
e
adv
ersarial
netw
ork
(GAN)-based
data
augmentation,
and
an
ensemble
classier
combining
ResNet,
Ale
xNet,
and
MobileNet.
The
methodology
,
tested
on
the
botnet
(BoT)-IoT
dataset,
follo
ws
four
stages:
preprocessing,
feature
augmentation,
feature
selection,
and
ensemble
classication.
Ev
aluated
on
benchmarks
including
CIC-IDS-2018,
NSL-KDD,
and
UNSW
-NB15,
the
model
achie
v
ed
accuracies
of
98.2%,
99.1%,
97.6%,
and
98.4%,
respecti
v
ely
,
with
consistently
high
precis
ion,
recall,
and
F1-scores,
demonstrating
rob
ust
detection
of
di
v
erse
c
yberattacks.
Be
yond
ac
curac
y
,
the
frame
w
ork
optimizes
processing
time
for
lar
ge-scale
IoT
data
,
addressing
scalability
challenges
in
real-time
threat
mitig
ation.
By
syner
gizing
feature
optimization,
synthetic
data
generation,
and
deep
learning
architectures,
the
solution
enhances
detection
rates
while
minimizing
computational
o
v
erhead.
Comparati
v
e
analysis
highlights
its
superior
performance
o
v
er
e
xisting
methods,
positioning
it
as
a
vital
tool
for
securing
IoT
ecosystems
ag
ai
nst
unauthorized
access
and
malicious
acti
vities.
The
results
underscore
its
potential
to
fortify
IoT
netw
ork
security
,
balancing
ef
cienc
y
,
adaptability
,
and
computational
feasibility
for
practic
al
deplo
yment
in
resource-constrained
en
vironments.
This
is
an
open
access
article
under
the
CC
BY
-SA
license
.
Corresponding
A
uthor:
Ghayth
AlMahadin
Department
of
Data
Science,
F
aculty
of
Information
T
echnology
,
Mutah
Uni
v
ersity
Al-Karak,
Jordan
Email:
ghayth.mahadin@mutah.edu.jo
1.
INTR
ODUCTION
Ov
er
the
signicance
of
technology
,
ne
w
and
global
threats
f
ast
gro
w
with
the
corresponding
enhancement
in
information
protection.
AI
and
more
specically
machine
learning
(ML)
are
such
adv
ancements
which
ha
v
e
recently
been
incorporated
into
the
security
realm.
The
application
of
deep
learning
methods
in
intrusion
detection
systems
(IDS)
has
been
reported
to
gi
v
e
positi
v
e
results
when
it
comes
to
detecting
and
pre
v
enting
sophisticated
c
yber
-attacks
as
sho
wn
in
Figure
1
[1]–[3].
As
for
the
other
elds
of
internet
of
things
(IoT)
security
,
ne
w
approaches
are
being
int
rodu
c
ed
to
counter
the
ne
w
threats
arising
from
the
connected
w
orld.
There
is,
for
instance,
adv
anced
deep
learning
for
intrusion
detection
for
IoT
netw
orks
where
bio-inspired
features
and
adv
anced
data
augmentation
strate
gies
pro
vide
ef
cient
features
for
impro
v
ed
accurac
y
of
the
detection
[4],
[5].
Cyber
threats
are
constantly
changing
and
gro
wing
in
comple
xity
hence
the
J
ournal
homepage:
http://ijai.iaescor
e
.com
Evaluation Warning : The document was created with Spire.PDF for Python.
Int
J
Artif
Intell
ISSN:
2252-8938
❒
2193
importance
of
solid
and
e
xible
information
security
solutions.
Therefore,
the
combination
of
AI
and
deep
learning
with
the
classical
approach
is
a
good
prospect
for
protecting
information
resources
from
ne
w
threats.
The
IoT
de
vices
present
i
n
today’
s
society
ha
v
e
impro
v
ed
the
quality
of
life
besides
industrial
and
commercial
acti
vities
and
triggered
an
increase
in
the
IoT
de
vices.
Ho
we
v
er
,
this
rapid
e
xpansion
has
also
serv
ed
as
the
primary
f
actor
in
enhancing
the
security
threat
of
IoT
netw
orks;
the
y
ha
v
e
become
primary
tar
gets
for
skirmishes.
IDS
ha
v
e
been
established
as
an
essential
solution
for
the
protection
of
such
netw
orks,
although
the
technical
approach
f
aces
great
dif
culties
when
dealing
with
contemporary
and
constantly
de
v
eloping
threat
types
as
depicted.
The
dri
v
e
in
this
study
comes
from
the
challenges
in
realizing
reliable
intrusion
detection
mechanisms
in
IoT
systems
that
are
constantly
threatened.
The
ef
fecti
v
eness
of
the
deep
learning
models
has
been
established
in
pre
vious
studies
that
aimed
at
impro
ving
the
w
ork
of
IDS
[2].
Ne
v
ertheless,
there
is
still
a
need
to
incorporate
techniques
of
data
augmentation
based
on
ML
and
bio-inspired
feature
selection
to
enhance
the
specics
of
thes
e
systems’
detection.
This
paper
presents
a
ne
w
deep-learning
method
that
combines
a
con
v
olutional
neural
netw
ork
(CNN)
and
an
autoencoder
for
intrusion
detection
in
IoT
netw
orks
using
the
botnet
(Bot)-IoT
dataset.
Figure
1.
System
architecture
for
binary
classication
[1]
The
methodology
is
structured
into
four
distinct
stages:
it
subsumes
preprocessing,
automatic
data
augmentation,
bio-inspired
feature
selection
me
thodology
,
and
a
deep
learning-based
h
ybrid
classication
model.
All
of
them
pro
vide
a
dd
i
tional
information
to
the
ne
xt
stage,
and
all
stages
collecti
v
ely
contrib
ute
to
the
enhancement
of
the
IDS
frame
w
ork
to
lter
out
the
dif
ferent
types
of
malicious
acti
vities
with
high
accurac
y
and
ef
cienc
y
.
The
rst
step
of
data
preparation
in
v
olv
es
cleaning
the
data,
gi
ving
it
labels,
and
normalizing
it
or
scaling
it
up
to
be
used
in
the
ne
xt
step.
The
second
is
data
augmentation
done
through
the
use
of
generati
v
e
adv
ersarial
netw
orks
(GANs)
to
produce
ne
w
articial
data
to
enhance
the
rob
ustness
and
the
generalization
of
the
detection
le
v
el.
The
third
stage
uses
an
e
v
olutionary
feature
selection
method
that
imitates
natural
selection,
to
select
the
best
features
to
enter
the
model.
Specically
,
this
step
increases
the
model’
s
capacity
to
concentrate
on
the
important
attrib
utes,
which
aids
in
the
de
v
elopment
of
more
accurate
detections.
Last,
of
all,
the
ensemble
deep
learning
classier
achie
v
ed,
which
brings
the
spatial
and
temporal
features
of
the
netw
ork
traf
c
data
[3].
Our
contrib
utions
to
the
eld
are
tw
ofold:
rst,
we
e
xtend
the
IDS
frame
w
ork
by
incorporating
the
adv
anced
data
augmentation
and
biologically
inspired
feature
sel
ection
methods,
and
second,
we
present
an
ensemble
deep
learning.
This
comprehensi
v
e
approach
not
only
enhances
the
chance
of
detection
b
ut
also
decreases
the
amount
of
data
processing,
making
the
method
ef
cient
and
possible
for
computational
interf
aces,
hence
making
IoT
security
achie
v
able.
Thus,
the
goal
of
this
research
is
to
de
v
elop
a
highly
ef
fecti
v
e
IDS
algorithm
that
will
be
able
to
securely
guard
the
IoT
netw
orks
ag
ainst
virtually
an
y
c
yber
threat
[6],
[7].
The
a
v
ailability
of
IoT
de
vices
has
played
a
crucial
role
in
enhancing
v
arious
domains
through
t
he
implementation
of
smart
solutions,
b
ut
it
has
also
introduced
no
v
el
securi
ty
threats.
T
o
address
these
challenges,
current
studies
are
stri
ving
to
de
v
elop
sophisticated
IDSs
using
state-of-the-art
deep
learning
approaches.
These
studies
clearly
highlight
the
critical
need
to
enhance
security
and
pri
v
ac
y
for
the
IoT
,
especially
in
the
f
ace
of
comple
x
and
highly
dangerous
c
yber
threats.
Emplo
yed
deep
learning
embedded
models
to
identify
intrusions
in
the
IoT
netw
ork,
which
includes
an
recurrent
neural
netw
ork
(RNN).
The
authors
pro
vide
an
e
xample
of
ho
w
these
techniques
can
enhance
the
accurac
y
and
reduce
the
t
ime
required
to
identify
malicious
acti
vities,
compared
to
traditional
methods
[8].
Idrissi
et
al.
[9]
ha
v
e
de
v
eloped
a
deep
learning
system
that
addresses
IDSs,
primarily
for
anti-BoT
applications,
as
sho
wn
in
Figure
2.
A
hybrid
deep
learning
appr
oac
h
for
BoT
-IoT
intrusion
detection
(Khalid
Altar
awneh)
Evaluation Warning : The document was created with Spire.PDF for Python.
2194
❒
ISSN:
2252-8938
The
authors
inte
grate
CNNs
and
long
short-term
memories
(LSTMs)
to
analyze
netw
ork
traf
c
dat
a,
enhancing
the
identication
and
counteraction
of
BoT
within
the
system.
Compares
v
arious
models
and
datasets,
while
a
re
vie
w
paper
pro
vides
an
o
v
ervie
w
of
se
v
eral
deep
learning
techniques
applicable
to
c
ybersecurity
intrusion
detection.
The
study
points
to
the
w
ays
that
deep
learning
has
pro
v
en
to
impro
v
e
IDS
[10].
Figure
2.
Inte
grating
CNNs
and
LSTMs
to
analyze
netw
ork
traf
c
data
[9]
Alotaibi
and
Mishra’
s
[11]
frame
w
ork
approach
intrusion
detection
as
a
separate
aspect
of
BoT
data
collection,
b
ut
i
t
does
so
using
deep
learning.
T
o
observ
e
and
identify
BoT
traf
c
in
IoT
netw
orks,
the
authors
apply
comple
x
neural
netw
orks
with
impro
v
ed
topologies.
The
authors’
idea
is
an
end-to-end
IDS
that
the
y
de
v
eloped,
based
on
deep
learning
and
unsupervised
feature
e
xtraction
from
ra
w
data.
This
system
is
designed
for
lar
ge
IoT
datasets;
thus,
it
is
tar
geting
this
kind
of
data
set
with
the
ability
to
detect
numerous
intrusions
without
much
eng
agement
in
feature
e
xtractions
[12].
Based
on
the
scenarios
of
the
healthcare
IoT
system,
this
w
ork
combines
softw
are-dened
netw
orking
(SDN)
with
h
ybrid
deep
learning
and
ML
for
implementing
a
smart
IDS
for
intrusion
detecting.
It
also
enhances
the
detection
and
management
of
risks
detrimental
to
the
security
of
health
f
acilities
[13].
The
system
suggests
a
no
v
el
deep
learning
IDS
for
IoT
netw
orks
based
on
the
feature
reduction
and
data
balancing
technique.
In
one
of
the
research
presented
in
the
proposed
system,
the
authors
highlighted
that
the
proposed
system
enhances
the
ef
cienc
y
and
accurac
y
of
identifying
imbalanced
data
based
on
the
proposed
system
[14].
It
presents
enhanced
Elman
spik
e
neural
netw
ork
(EESNN),
a
ne
w
IDS-oriented
netw
ork
traf
c
pattern
e
xtraction
method,
which
is
a
sort
of
deep
learning
model
that
contains
spatial-temporal
characteristics.
It
is
ef
fecti
v
e
in
enhancing
the
detection
capacities
especially
when
netw
ork
intrusions
are
relati
v
ely
comple
x
[15].
Nandanw
ar
and
Katarya
[16]
propose
a
communication-a
w
are
IDS
for
industrial
IoT
t
hat
is
based
on
a
deep
learning
approach.
As
for
the
authors’
approach,
it
can
be
said
without
a
doubt
that
it
enhances
the
identication
and
subsequent
pre
v
ention
of
v
arious
c
yber
threats
in
the
industrial
setting.
Thus,
the
proposed
research
is
concerned
with
the
deep
learning
analysis
of
BoT
-IoT
netw
ork
traf
c.
Using
the
proposed
model,
it
is
possible
to
detect
and
analyze
the
traf
c
of
the
misuse
associated
with
the
BoT
.
The
IDS
proposed
in
[17]
is
based
on
a
double
adapti
v
e
weighting
arithmetic
optimization
algorithm
learning
deep
learning.
This
increases
the
capacity
for
nding
the
right
deterministic
results
and
solutions
in
IoT
territories.
The
w
ork
also
elaborates
on
the
problem
of
learning
and
cate
gorizing
unbalanced
intrusion
data
in
IoT
netw
orks
by
applying
an
ensemble
learning-based
deep
neural
netw
ork
(DNN).
The
principle
of
the
proposed
approach
impro
v
es
the
separability
of
the
problem
sets
especi
ally
for
the
minority
classes
[18].
Thakkar
and
Lohiya
[19]
proposed
a
deep
l
earning
solution
to
the
issue
of
intrusion
detection
in
the
IoT
emplo
ying
a
no
v
el
focal
loss
function.
This
particular
method
impro
v
es
the
performance
of
detection
considerably
when
there
is
a
disparity
in
the
size
of
the
tw
o
classes.
The
method
proposes
a
ne
w
deep
learning
approach
to
design
an
estimator
to
predict
future
c
yber
-attacks
on
IoT
g
adgets.
The
approach
in
v
olv
es
the
usage
of
what
is
kno
wn
as
state-of-the-art
neural
netw
orks,
enhanced
in
terms
of
their
capabilities
to
predict
probability
and
certainty
[11].
Dina
et
al.
[20]
e
xplain
deep
learning
and
datasets
as
well
as
mention
their
o
wn
BoT
-IoT
dataset
focusing
on
c
yber
security
intrusion
detection
in
the
article.
Their
w
ork
aids
in
understanding
the
ef
fecti
v
eness
of
these
techniques
in
real-life
applications.
It
introduces
a
ne
w
deep-learning
model
that
inte
grates
with
sw
arm-based
feature
Int
J
Artif
Intell,
V
ol.
15,
No.
3,
June
2026:
2192–2200
Evaluation Warning : The document was created with Spire.PDF for Python.
Int
J
Artif
Intell
ISSN:
2252-8938
❒
2195
selection
for
intelligent
intrusion
detection
in
the
IoT
.
It
indicates
the
possibility
of
an
increase
in
the
detection
rate
of
the
suspicious
object,
as
well
as
the
time
tak
en
to
complete
the
process
[21].
Using
deep
learning
methods,
propose
an
abnormality-based
netw
ork
IDS
for
IoT
attacks.
According
to
their
model,
the
y
are
highly
ef
fecti
v
e
at
detecting
atypical
beha
viours
[22].
Anushiya
and
La
v
an
ya
[23]
introduce
an
intrusion
detection
technique
designed
for
the
cloud
and
the
IoT
,
utilizing
deep
learning
and
the
capuchin
search
algorithm.
The
approach
impro
v
es
attack
detection
accurac
y
and
reduces
the
number
of
f
alse
alarms.
De
v
elop
a
ne
w
deep
learning-based
approach
to
identify
BoT
-IoT
attacks.
This
method
uses
a
neural
netw
ork
that
gro
ws
detection
capacities
and
lessens
threats
[24].
This
method
proposes
an
intrusion
detecti
on
model
to
counter
distrib
uted
denial
of
service
(DDoS)
attacks
in
lightweight
IoT
netw
orks.
The
model
empl
o
ys
deep
learning
to
enhance
the
identication
ability
and
the
time
tak
en
to
respond
[25].
2.
METHOD
This
paper
presented
a
detailed
and
inte
grated
frame
w
ork
to
impro
v
e
the
intrusion
detection
in
IoT
netw
orks;
moreo
v
er
,
the
proposed
approach
in
v
olv
es
multiple
stages
of
preprocessing,
automatic
data
augmentation,
bi
o-inspired
feature
selection,
and
a
set
of
deep
learning
classiers.
The
presented
inte
grated
solution
plan
w
as
designed
to
respond
to
the
increasing
number
of
numerous
and
di
v
erse
c
yber
threats
to
w
ards
IoT
de
vi
ces.
Thus,
the
usage
of
the
BoT
-IoT
dataset
in
the
architectural
methodology
guarantees
the
high
accurac
y
and
rob
ustness
of
the
IDS.
The
proposed
frame
w
ork
consists
of
four
main
stages:
i)
preprocessing:
the
rst
of
these
is
preprocessing,
which
entails
such
preprocessing
as
cleaning
the
data,
naming
the
features,
and
normalizing
or
scaling
the
data
v
alues.
Preprocessing
can
be
look
ed
at
as
one
of
the
most
critical
steps
in
the
data
analysis
process
that
directly
impacts
the
quality
of
the
data
and
the
ne
xt
steps
of
the
data
analysis
process;
ii)
automatic
data
augmentation:
in
this
phase,
the
data-GANs
is
used
to
produce
articial
data
to
impro
v
e
the
training
dataset.
This
increases
the
model’
s
stability
and
ability
to
reect
real-life
scenarios
thus
challenging
v
arious
attacks
on
it;
iii)
bio-inspired
feature
select
ion:
this
stage
applies
e
v
olutionary
optimization
algorithms
in
the
selection
process
of
rele
v
ant
features
to
enhance
the
capaci
ty
of
the
model
for
discrimination
of
attrib
utes;
thereby
enhancing
t
he
intended
detection.
This
e
xplains
wh
y
the
ensemble
feature
selection
technique
ensures
that
features
selected
for
the
model
are
reliable
and
enhance
the
model’
s
performance;
and
i
v)
ensemble
deep
learning
classier:
the
last
le
v
el
in
v
olv
es
the
use
of
ResNet,
Ale
xNet,
and
MobileNet,
which
are
deep
learning
architectures
to
create
an
ensemble
model.
This
inte
gration
mak
es
use
of
the
strong
features
of
each
architecture
to
capture
multiple
characteristics
of
the
netw
ork
traf
c
data
and
i
ncrease
the
o
v
erall
detection
rate
of
comple
x
intrusion
patterns.
The
procedure
of
the
proposed
model
stages
is
as
follo
ws.
i)
Stage
1.
preprocessing:
−
Cleansing
objecti
v
e:
that
is,
when
construct
ing
the
f
actual
information
base,
it
is
necessary
to
reject
such
options
as
the
remo
v
al
of
the
data
irrele
v
ant
or
its
redundanc
y
.
Identify
and
rectify
the
mistak
es
or
the
discrepancies
t
hat
are
lik
ely
to
be
found
in
the
data
set.
It
narro
ws
do
wn
a
list
that
entails
the
same
records
for
the
sak
e
of
a
more
superior
data
quality
.
−
Labeling:
ho
we
v
er
,
it
needs
to
be
stressed
in
the
case
of
a
supervised
learning
algorithm,
the
data
must
be
properly
labeled.
Use
predened
criteria
to
attrib
ute
labels
to
each
of
the
data
records.
Includes
that
all
data
instances
are
properly
classied
(normal
v
ersus
malicious).
−
Scaling:
standardize
so
that
all
the
gi
v
en
v
ariables
ha
v
e
similar
v
ariances.
Perform
scaling
on
data
by
using
methods
and
tools
used
as
Min-Max
scaling.
Also,
it
is
recommended
that
all
features
are
normalized
or
made
standard
so
that
the
y
are
on
the
same
scale
to
enhance
the
performance
of
the
model.
ii)
Stage
2.
automatic
data
augmentation:
is
an
idea
that
has
been
proposed
as
a
e
xibility
augmentation
method
which
has
attracted
the
attention
of
researchers.
GANs
can
be
used
to
create
ne
w
articial
samples
to
combine
with
the
training
sample
dat
a
set.
Some
of
the
steps
that
can
be
undertak
en
include
the
follo
wing:
−
Produce
ne
w
samples
of
data
that
are
similar
in
terms
of
their
distrib
ution
to
the
obtained
dataset.
−
Anime:
in
particular
,
it
is
necessary
to
check
the
synthetic
data
that
is
used
for
.
iii)
Stage
3.
bio-inspired
feature
selection:
optimization
e
v
olutionary
algorithms:
specify
the
a
v
ailable
features
for
creating
a
model
to
increase
the
accurac
y
.
The
areas
as
responses
are
the
follo
wing:
A
hybrid
deep
learning
appr
oac
h
for
BoT
-IoT
intrusion
detection
(Khalid
Altar
awneh)
Evaluation Warning : The document was created with Spire.PDF for Python.
2196
❒
ISSN:
2252-8938
−
Enhance
applications
of
bio-inspired
algorithms
including
bee
colon
y
optimization.
−
The
process
of
selecting
the
features
can
be
impro
v
ed
across
generati
ons
in
the
follo
wing
w
ays:
i)
feature
subsets
to
establish
the
v
alue
of
each
particular
de
gree
of
feature
selection
and
ii)
ensemble
feature
selection:
i
t
is
advisable
to
use
more
than
one
feature
selection
algorithm
to
reduce
the
impact
of
an
y
single
algorithm’
s
weaknesses.
Chi-square:
apply
feature
selection
methods.
User
an
ensemble
approach
on
the
selected
features
.
Deplo
y
the
selected
feature
to
ensure
that
it
enhances
the
model
performance.
i
v)
Stage
4:
a
classier
based
on
the
ensemble
deep-learning
netw
ork.
−
ResNet:
design
and
implement
a
ResNet
archit
ecture
to
use
this
data.
Use
the
pre-processed
and
augmented
data
to
train
the
ResNet
model.
Finalize
the
model
to
achie
v
e
the
best
performance.
−
Ale
xNet:
based
on
Ale
xNet’
s
con
v
olutional
structure
implement
a
model
with
optimized
computational
performance.
Ef
fecti
v
ely
crea
te
an
architecture
of
Ale
xNet.
T
rain
the
Ale
xNet
model
on
the
se
gmented
and
enhanced
data.
Perform
h
yper
-parameter
tuning
on
the
model
to
get
the
best
results.
−
MobileNet:
the
follo
wing
k
e
y
steps
are
in
v
olv
ed
in
the
frame
w
ork:
MobileNet
model
shall
be
trained
on
the
preprocessed
and
augmented
data.
Fine-tune
the
model
to
get
the
best
results
from
the
model.
−
Ensemble
model:
inte
grate
the
ResNet,
Ale
xNet,
and
MobileNet
outcomes
to
impro
v
e
the
results.
Finally
,
it
is
necessary
to
use
the
ensemble
met
hod
(majority
v
oting)
to
combine
solutions
obtained
at
the
s
tage
of
three
models.
Assess
the
performance
of
the
ensemble
model
to
be
better
than
the
indi
vidual
models
of
data.
Fine-tune
the
parameters
of
the
ensemble
to
meet
the
goals
of
high
accurac
y
and
required
time.
The
abo
v
e
mentioned
model
is
presented
in
Figure
3,
sho
wing
the
breakdo
wn
of
the
foundational
method
used
in
the
creation
of
the
unsupervised
IDS
enhanced
by
deep
learning
and
biomimetic
feature
e
xtraction.
All
the
stages
are
decisi
v
e
for
guaranteeing
the
correctness,
practicability
,
and
viability
of
the
system.
F
or
shielding
IoT
netw
orks
ag
ainst
c
yber
threats.
Figure
3.
The
proposed
model
for
BoT
-IoT
intrusion
detection
3.
RESUL
TS
AND
DISCUSSION
These
models
will
be
tested
on
a
fe
w
of
the
most
f
amous
datasets
to
ha
v
e
a
broad
check
of
the
ef
cac
y
of
the
proposed
model.
The
test
data
for
the
CIC-IDS-2018
[26]
comprises
of
v
arious
attack
types
such
as
Brute-force,
Hea
rtbleed,
BoT
,
denial
of
service
(DoS),
DDoS,
W
eb
attack,
and
inltration
type
attack
and
the
Int
J
Artif
Intell,
V
ol.
15,
No.
3,
June
2026:
2192–2200
Evaluation Warning : The document was created with Spire.PDF for Python.
Int
J
Artif
Intell
ISSN:
2252-8938
❒
2197
samples
are
obtained
from
the
netw
ork
traf
c
and
logs
which
in
v
olv
ed
fty
attack
er
hosts
and
four
hundred
and
twenty
victims
host
located
in
v
e
departments.
BoT
-IoT
a
v
ailable
at
Australian
Centre
for
Cyber
Security
[27]
w
as
chosen
for
the
dataset
as
it
tackles
IoT
netw
orks
and
pro
vides
normal
and
realistic
adv
ersarial
traf
c
and
contains
DDoS,
DoS,
operating
system
(OS),
and
service
scan,
k
e
y
logging,
and
data
e
xltration
attacks
.
The
y
comprised
KDD
Cup
99,
and
it
is
one
of
the
most
original
and
f
amous
databases
in
the
intrusion
detection
of
v
arious
kinds
of
netw
ork
traf
c
data,
s
uch
as
normal
connections
as
well
as
attack
connections
for
DoS,
remote
to
local
(R2L),
user
to
root
(U2R),
and
probing
attacks.
Their
enhanced
v
ersion,
NSL-KDD
[28],
is
free
from
such
issues
as
the
record
in
the
ra
w
KDD
Cup
99
data
set
is
repeated
multiple
times,
and
this
should
pro
vide
IDS
with
a
better
benchmark.
This
dataset
can
also
be
obtained
from
the
Australian
Centre
for
Cyber
Security
and
is
also
v
ery
similar
to
the
rst
set,
consisting
of
present-day
normal
act
i
vities
spliced
with
simulated
KDD
Cup
’99
attack
scenarios
and
comprehensi
v
e
netw
orking
encompassing
15
cate
gories.
These
are
also
benecial
for
the
adv
ancement
of
IDS
research
and
de
v
elopment;
the
y
contain
di
v
erse
and
e
xtensi
v
e
data
samples
for
the
de
v
elopment
of
ML
algorithms.
The
proposed
ensemble
deep
learning
approach
w
as
e
v
aluated
using
four
widely
recognized
datasets:
the
proposed
dataset
contains
features
e
xtracted
from
four
datasets
namely
CIC-IDS-2018
[26],
BoT
-IoT
[27],
NSL-KDD
[28],
and
UNSW
-NB15
[29].
Both
of
the
datasets
were
chosen
to
sho
w
that
the
model
can
t
an
y
kind
of
netw
ork
traf
c
and
hold
up
ag
ainst
dif
ferent
attacks.
The
follo
wing
are
the
detailed
results
and
analysis
for
each
dataset
as
sho
wn
in
T
able
1.
All
data
split
into
80%
for
training
and
20%
for
testing.
According
to
T
able
1,
it
can
be
seen
that
proposed
ensemble
deep
learning
model
performed
e
xtre
mely
well
on
multiple
datasets.
In
the
case
of
the
CIC-IDS-2018
dataset,
the
proposed
model
g
a
v
e
an
accurac
y
of
98.2%,
precision
of
97.5%,
97.9%
for
recall
and
an
F1-score
of
97.7%
it
has
a
high
conscientiousness
ag
ainst
dif
ferent
classes
of
attacks.
Running
the
BoT
-IoT
dataset
yielded
the
most
satisfying
scores;
BoT
-IoT
w
as
accurate
at
99.1%,
precisi
on
of
98.8%,
and
recall
of
99.0%,
the
F1-score
is
98.9%,
this
testies
to
the
ef
fecti
v
eness
of
the
model
in
operation
related
to
the
identication
of
IoT
-specic
threats.
T
o
the
NSL-KDD
datasets,
the
model
retains
the
sam
e
high
le
v
el
of
accurac
y
sta
nd
i
ng
at
97.6%,
precision
of
97.2%,
recall
of
97.4%,
and
F1-score
of
97.3%.
Lik
e
wise,
underscoring
the
success
of
the
model;
on
the
UNSW
-NB15
dataset,
the
recei
v
ed
accurac
y
w
as
equal
to
the
one
observ
ed
on
the
UNS
W
subset,
98.6%,
precision
of
98.1%,
recall
of
98.3%,
and
F1-score
of
98.2%.
These
results
pro
v
e
that
model
is
ef
cient
and
accurate
in
identifying
intrusions
in
dif
ferent
netw
ork
topologies,
which
mak
es
it
useful
in
increasing
IoT
netw
ork
security
.
T
able
2
summarizes
the
comparison
of
man
y
intrusion
detection
models
used
in
man
y
datasets
in
terms
of
their
performances.
T
able
1.
Result
of
the
proposed
model
in
se
v
eral
dataset
Metric
CIC-IDS-2018
(%)
BoT
-IoT
(%)
NSL-KDD
(%)
UNSW
-NB15
(%)
Accurac
y
98.2
99.1
97.6
98.6
Precision
97.5
98.8
97.2
98.1
Recall
97.9
99.0
97.4
98.3
F1-score
97.7
98.9
97.3
98.2
T
able
2.
Comparison
of
proposed
model
performance
with
state-of-the-art
models
across
multiple
datasets
Reference
Dataset
Model
used
Accurac
y
(%)
Precision
(%)
Recall
(%)
F1-score
(%)
Emec
¸
and
¨
Ozcanhan
[1]
CIC-IDS-2018
CNNs,
RNNs
97.5
96.8
97.2
97.0
BoT
-IoT
CNNs,
RNNs
98.7
98.3
98.5
98.4
Alosaimi
and
Almutairi
[6]
B
oT
-IoT
LSTM
netw
orks,
autoencoders
98.9
98.5
98.7
98.6
Ferrag
et
al.
[10]
KD
D
Cup
99
V
arious
deep
learning
models
99.0
98.7
98.8
98.7
(CNNs,
LSTMs,
h
ybrid
models)
NSL-KDD
V
arious
deep
learning
models
97.8
97.4
97.6
97.5
(CNNs,
LSTMs,
h
ybrid
models)
UNSW
-NB15
V
arious
deep
learning
models
98.5
98.2
98.4
98.3
(CNNs,
LSTMs,
h
ybrid
models)
Alotaibi
and
Mishra
[11]
B
oT
-IoT
DBNs,
Autoencoders
99.2
98.9
99.1
99.0
Singh
et
al.
[17]
BoT
-IoT
DNNs,
GBMs
99.0
98.6
98.9
98.7
Thakkar
and
Lohiya
[19]
NSL-
KDD
DNN,
Random
forest
97.7
97.3
97.5
97.4
Proposed
model
CIC-IDS-2018
ResNet,
Ale
xNet,
MobileNet
98.2
97.5
97.9
97.7
BoT
-IoT
ResNet,
Ale
xNet,
MobileNet
99.1
98.8
99.0
98.9
NSL-KDD
ResNet,
Ale
xNet,
MobileNet
7.6
97.2
97.4
97.3
UNSW
-NB15
ResNet,
Ale
xNet,
MobileNet
98.4
98.1
98.3
98.2
A
hybrid
deep
learning
appr
oac
h
for
BoT
-IoT
intrusion
detection
(Khalid
Altar
awneh)
Evaluation Warning : The document was created with Spire.PDF for Python.
2198
❒
ISSN:
2252-8938
Emec
¸
and
¨
Ozcanhan
[1]
emplo
yed
CIC-IDS-2018
and
BoT
-IoT
databases
with
CNNs
and
RNNs
ha
ving
accurac
y
equal
to
97.5%
and
98.7%,
respecti
v
ely
.
Alosaimi
and
Almutairi
[6]
also
used
LSTM
netw
orks
and
autoencoders
on
the
BoT
-IoT
dat
aset
with
an
accurac
y
of
98.9%
accurac
y
.
Ferrag
et
al.
[10]
o
v
er
se
v
eral
models
based
on
comparati
v
ely
on
KDD
Cup
99,
NSLKDD,
and
UNSW
-NB15,
and
got
the
maximum
of
99.0%
accurac
y
.
Alotaibi
and
Mishra
[11]
applied
the
deep
belief
netw
orks
(DBNs)
and
autoencoders
on
BoT
-IoT
,
and
obtained
99.2%
accurac
y
.
Similarly
,
Singh
et
al.
[17]
us
ed
the
BoT
-IoT
with
DNN
and
gradient
boosting
machines
(GBMs)
and
achie
v
ed
99.0%
accurac
y
.
Thakkar
and
Lohiya
[19]
used
an
ensemble
of
DNN
and
random
forest
on
NSL-KDD,
where
accurac
y
got:
97.7%
accurac
y
.
This
tim
e,
the
model
based
on
ResNet,
Ale
xNet,
and
MobileNet
achie
v
ed
e
xcellent
performance
in
all
the
gi
v
en
datasets
with
an
accurac
y
of
98.2%
on
CIC-IDS-2018,
99.1%
on
BoT
-IoT
,
97.6%
on
the
KDD
cup
set
where
the
mean
accurac
y
gi
v
en
by
the
base
classier
w
as
98.6%
on
UNSW
-NB15
which
further
testies
to
its
resistance
and
ef
cienc
y
i
n
notifying
of
c
yber
threats.
4.
CONCLUSION
The
suggested
strate
gy
for
the
impro
v
ement
of
intrusion
dete
ction
in
IoT
netw
orks
is
b
uilt
on
the
utilization
of
a
detailed,
multi-step
approach
that
includes
preprocessing,
GAN-based
data
augmentation,
bio-inspired
feature
selection,
and
a
h
ybrid
deep-learning
classier
.
In
this
w
ay
,
this
inte
grated
frame
w
ork
enables
to
adequately
meet
the
challenges
created
by
a
steady
augmentation
both
in
the
comple
xity
and
in
the
v
ariety
of
the
c
yber
threats
acting
on
IoT
de
vices,
as
well
as
to
pro
vide
high
accurac
y
and
almost
limitless
rob
ustness
of
the
IDS.
The
methodology
w
as
rigorously
tested
on
four
widely
recognized
datasets:
CIC-IDS-2018
e
v
aluates
the
model’
s
performance
in
detecting
netw
ork
traf
c
and
attacks,
as
does
BoT
-IoT
,
NSL-KDD,
and
UNSW
-NB15,
to
sho
wcase
the
model’
s
e
xibility
to
w
ork
under
dif
ferent
scenarios.
The
ndings
re
v
eal
equal
superior
performance
with
accuracies
of
between
97.6%
to
99.1%.
From
the
abo
v
e
result,
it
is
clear
that
the
proposed
multi-vie
w
clustering
model
achie
v
es
almost
stable
accurac
y
with
the
increase
of
sample
size
across
the
datasets,
and
the
highest
accurac
y
is
abo
v
e
90%
for
most
of
the
datasets
with
less
than
1%
standard
de
viation
mainly
achie
ving
higher
precision,
recall,
and
F1-scores.
This
e
xplains
wh
y
the
model
is
ef
cient
and
reliable
in
identifying
infringements,
making
the
enhancement
of
IoT
netw
ork
security
critical.
A
comparati
v
e
analysis
that
will
pro
v
e
the
ef
fecti
v
eness
of
the
proposed
model
needs
to
be
carried
out
as
compared
to
the
other
state-of-the-art
methods,
which
will
depict
the
ef
fecti
v
eness
of
the
proposed
model
in
handling
c
yber
threats
on
dif
ferent
netw
orks.
FUNDING
INFORMA
TION
Authors
state
no
funding
in
v
olv
ed.
A
UTHOR
CONTRIB
UTIONS
ST
A
TEMENT
This
journal
uses
the
Contrib
utor
Roles
T
axonomy
(CRediT)
to
recognize
indi
vidual
author
contrib
utions,
reduce
authorship
disputes,
and
f
acilitate
collaboration.
Name
of
A
uthor
C
M
So
V
a
F
o
I
R
D
O
E
V
i
Su
P
Fu
Khalid
Altara
wneh
✓
✓
✓
✓
✓
✓
✓
✓
✓
✓
✓
✓
✓
Ghayth
AlMahadin
✓
✓
✓
✓
✓
✓
✓
✓
✓
Ibrahim
Altara
wni
✓
✓
✓
✓
✓
✓
✓
C
:
C
onceptualization
I
:
I
n
v
estig
ation
V
i
:
V
i
sualization
M
:
M
ethodology
R
:
R
esources
Su
:
Su
pervision
So
:
So
ftw
are
D
:
D
ata
Curation
P
:
P
roject
Administration
V
a
:
V
a
lidation
O
:
Writing
-
O
riginal
Draft
Fu
:
Fu
nding
Acquisition
F
o
:
F
o
rmal
Analysis
E
:
Writing
-
Re
vie
w
&
E
diting
CONFLICT
OF
INTEREST
ST
A
TEMENT
Authors
state
no
conict
of
interest.
Int
J
Artif
Intell,
V
ol.
15,
No.
3,
June
2026:
2192–2200
Evaluation Warning : The document was created with Spire.PDF for Python.
Int
J
Artif
Intell
ISSN:
2252-8938
❒
2199
D
A
T
A
A
V
AILABILITY
The
supporting
data
of
this
study
are
openly
a
v
ailable
in:
–
CIC-IDS-2018
a
v
ailable
in
Mendele
y
Data
at
http://doi.or
g/10.17632/29hdbdzx2r
.1
and
on
A
WS
at
https://re
gistry
.opendata.a
ws/cse-cic-ids2018/.
The
primary
source
is
hosted
by
the
Canadian
Institute
for
Cybersecurity
at
https://www
.unb
.ca/cic/datasets/ids-2018.html.
–
BoT
-IoT
a
v
ailable
on
IEEE
DataPort
at
http://doi.or
g/10.21227/r7v2-x988.
The
dataset
includes
netw
ork
traf
c
in
pcap
format
(69.3
GB)
and
e
xtracted
o
w
traf
c
in
CSV
format
(16.7
GB).
Also
inde
x
ed
on
the
IMP
A
CT
repository
at
http://doi.or
g/10.23721/100/1504338.
–
NSL-KDD
a
v
ailable
on
IEEE
DataPort
at
http://doi.or
g/10.21227/425a-3e55.
Alternati
v
e
repositories
include
Zenodo
at
http://doi.or
g/10.5281/zenodo.17424143
and
the
original
source
at
https://www
.unb
.ca/cic/datasets/nsl.html.
–
UNSW
-NB15
a
v
ailable
on
Research
Data
Australia
at
http://doi.or
g/10.26190/5d7ac5b1e8485
and
on
IEEE
DataPort
at
http://doi.or
g/10.21227/8vf7-s525.
The
primary
source
is
a
v
ailable
at
https://research.unsw
.edu.au/projects/unsw-nb15-dataset.
REFERENCES
[1]
M.
Emec
¸
and
M.
H.
¨
Ozcanhan,
“
A
h
ybrid
deep
learning
approach
for
intrusion
detection
in
IoT
netw
orks,
”
Advances
in
Electrical
and
Computer
Engineering
,
v
ol.
22,
no.
1,
2022,
doi:
10.4316/AECE.2022.01001.
[2]
T
.
Saba,
A.
Rehman,
T
.
Sadad,
H.
K
oli
v
and,
and
S.
A.
Bahaj,
“
Anomaly-based
intrusion
detection
system
for
IoT
netw
orks
through
deep
learning
model,
”
Computer
s
and
Electrical
Engineering
,
v
ol.
99,
2022,
doi:
10.1016/j.compeleceng.2022.107810.
[3]
S.
M.
J.
A.
Abdal
w
ahid,
W
.
A.
Hashim,
M.
G.
Saeed,
S.
A.
Altaie,
and
S.
W
.
Kareem,
“
In
v
est
ig
ating
the
ef
fecti
v
eness
of
articial
intelligence
in
w
atermarking
and
ste
g
anograph
y
for
digital
media
security
,
”
2024
21st
International
Multi-Confer
ence
on
Systems,
Signals
and
De
vices
(SSD)
,
pp.
552–561,
2024,
doi:
10.1109/SSD61670.2024.10549272.
[4]
D.
Y
.
Mikhail,
R.
S.
Ha
wezi,
and
S.
W
.
Kareem,
“
An
ensemble
transfer
learning
model
for
detecting
ste
go
images,
”
Applied
Sciences
,
v
ol.
13,
no.
12,
2023,
doi:
10.3390/app13127021.
[5]
M.
K.
Y
ousif,
Z.
E.
Dallalbashi,
and
S.
W
.
Kareem,
“Information
security
for
big
data
using
the
NTR
UEncrypt
method,
”
Measur
ement:
Sensor
s
,
v
ol.
27,
2023,
doi:
10.1016/j.measen.2023.100738.
[6]
S.
Alosaimi
and
S.
M.
Almutairi,
“
An
intrusion
detection
system
using
BoT
-IoT
,
”
Applied
Sciences
,
v
ol.
13,
no.
9,
2023,
doi:
10.3390/app13095427.
[7]
G.
Y
.
Ismail,
S.
Alhayali,
S.
W
.
Kareem,
and
Z.
S.
Hussain,
“Secure
data
in
the
cloud
with
a
rob
ust
h
ybrid
cryptographic
approach,
”
J
ournal
of
Electrical
Systems
,
v
ol.
20,
no.
2,
pp.
2450–2457,
2024,
doi:
10.52783/jes.2018.
[8]
A.
M.
B
anaamah
and
I.
Ahmad,
“Intrusion
detection
in
IoT
using
deep
learning,
”
Sensor
s
,
v
ol.
22,
no.
21,
2022,
doi:
10.3390/s22218417.
[9]
I.
Idrissi,
M.
Boukabous,
M.
Azizi,
O.
Mouss
aoui,
and
H.
E.
F
adili,
“T
o
w
ard
a
deep
learning-based
intrusion
detection
system
for
IoT
a
g
ai
nst
botnet
attacks
,
”
IAES
International
J
ournal
of
Articial
Inte
llig
ence
,
v
ol.
10,
no.
1,
pp.
110–120,
2021,
doi:
10.11591/ijai.v10.i1.pp110-120.
[10]
M.
A.
Ferrag,
L.
Maglaras,
S.
Moscho
yiannis,
and
H.
Janick
e,
“Deep
learning
for
c
yber
security
intrusion
detection:
approaches,
datasets,
and
comparati
v
e
study
,
”
J
ournal
of
Information
Security
and
Applications
,
v
ol.
50,
2020,
doi:
10.1016/j.jisa.2019.102419.
[11]
F
.
A.
Alotaibi
and
S.
Mishra,
“Cyber
security
intrusion
detection
and
BoT
data
collection
using
deep
learning
in
the
IoT
,
”
International
J
ournal
of
Advanced
Computer
Science
and
Applications
,
v
ol.
15,
no.
3,
pp.
421–432,
2024,
doi:
10.14569/IJ
A
CSA.2024.0150343.
[12]
Y
.
N.
K
unang,
S.
Nurmaini,
D.
Stia
w
an,
and
B.
Y
.
Suprapto,
“
An
end-to-end
intrusion
detect
ion
system
with
IoT
dataset
using
deep
learning
with
unsupervised
feature
e
xtract
ion,
”
International
J
ournal
of
Information
Security
,
v
ol.
23,
no.
3,
pp.
1619–1648,
2024,
doi:
10.1007/s10207-023-00807-7.
[13]
R.
Arthi,
S.
Krishna
v
eni,
and
S.
Zeadally
,
“
An
intelligent
SDN-IoT
enabl
ed
intrusion
detection
system
for
healthcare
systems
using
a
h
ybrid
deep
learning
and
machine
learning
approach,
”
China
Communicat
ions
,
v
ol.
21,
no.
10,
2024,
doi:
10.23919/JCC.ja.2022-0681.
[14]
H.
Karamollao
˘
glu,
˙
I.
A.
Do
˘
gru,
and
˙
I.
Y
¨
uceda
˘
g,
“
An
ef
cient
deep
learning-based
intrusion
detection
system
for
internet
of
things
netw
orks
with
h
ybrid
feature
reduct
ion
and
data
balancing
techniques,
”
Information
T
ec
hnolo
gy
and
Contr
ol
,
v
ol.
53,
no.
1,
pp.
243–261,
2024,
doi:
10.5755/j01.itc.53.1.34933.
[15]
J
.
Saikam
and
K.
Ch.,
“EESNN:
h
ybrid
deep
learning
empo
wered
spatial-temporal
features
for
netw
ork
intrusion
detection
system,
”
IEEE
Access
,
v
ol.
12,
pp.
15930–15945,
2024,
doi:
10.1109/A
CCESS.2024.3350197.
[16]
H.
Nandanw
ar
and
R.
Katarya,
“Deep
learni
ng
enabled
intrusion
detection
system
for
industrial
IoT
en
vironment,
”
Expert
Systems
with
Applications
,
v
ol.
249,
2024,
doi:
10.1016/j.esw
a.2024.123808.
[17]
N.
J.
Singh,
N.
Hoque
,
K.
R.
Singh,
and
D.
K.
Bhattacharyya,
“Botnet-based
IoT
netw
ork
traf
c
analysis
using
deep
learning,
”
Security
and
Privacy
,
v
ol.
7,
no.
2,
2024,
doi:
10.1002/sp
y2.355.
[18]
V
.
K.
Kalimuthu
and
R.
V
elumani,
“Modeling
of
intrusion
detection
system
using
double
adapti
v
e
weighting
arithmetic
optimization
algorithm
with
deep
learning
on
internet
of
things
en
vironment,
”
Br
azilian
Ar
c
hives
of
Biolo
gy
and
T
ec
hnolo
gy
,
v
ol.
67,
2024,
doi:
10.1590/1678-4324-2024231010.
[19]
A.
Thakkar
and
R.
Lohiya,
“
Attack
classication
of
imbalanced
intrusion
data
for
iot
netw
ork
using
ensemble-learning-based
deep
neural
netw
ork,
”
IEEE
Internet
of
Things
J
ournal
,
v
ol.
10,
no.
13,
pp.
11888–11895,
2023,
doi:
10.1109/JIO
T
.2023.3244810.
[20]
A.
S.
Dina,
A.
B.
Siddique,
and
D.
Mani
v
annan,
“
A
deep
learning
approach
for
intrusion
detection
in
internet
of
things
using
focal
loss
function,
”
Internet
of
Things
,
v
ol.
22,
2023,
doi:
10.1016/j.iot.2023.100699.
A
hybrid
deep
learning
appr
oac
h
for
BoT
-IoT
intrusion
detection
(Khalid
Altar
awneh)
Evaluation Warning : The document was created with Spire.PDF for Python.
2200
❒
ISSN:
2252-8938
[21]
O.
A.
Alkhudaydi,
M.
Krichen,
and
A.
D.
Alghamdi,
“
A
deep
learning
methodology
for
predicting
c
yber
-
security
attacks
on
the
internet
of
things,
”
Information
,
v
ol.
14,
no.
10,
2023,
doi:
10.3390/info14100550.
[22]
I.
Manan,
F
.
Rehm
an,
H.
Sharif,
C.
N.
Ali,
R.
R.
Ali,
and
A.
Liaqat,
“Cyber
security
intrusion
detection
using
deep
learning
approaches,
datasets,
Bot-IoT
dataset,
”
in
2023
4th
International
Confer
ence
on
Advancements
in
Computational
Sciences
(ICA
CS)
,
2023,
doi:
10.1109/ICA
CS55311.2023.10089688.
[23]
R
.
Anushiya
and
V
.
S.
La
v
an
ya,
“
A
ne
w
deep-learning
with
sw
arm
based
feature
selection
for
intelligent
intrusion
detection
for
the
internet
of
things,
”
Measur
ement:
Sensor
s
,
v
ol.
26,
2023,
doi:
10.1016/j.measen.2023.100700.
[24]
B
.
Sharma,
L.
Sharma,
C.
Lal,
and
S.
Ro
y
,
“
Anomaly
based
netw
ork
intrusion
detection
for
IoT
attacks
using
deep
learning
technique,
”
Computer
s
and
Electrical
Engineering
,
v
ol.
107,
2023,
doi:
10.1016/j.compeleceng.2023.108626.
[25]
M
.
A.
Elaziz,
M.
A.
A.
Al-qaness,
A.
Dahou,
R.
A.
Ibrahim,
and
A.
A.
A.
El-Latif,
“Intrusion
detection
approach
for
cloud
and
IoT
en
vironments
using
deep
learning
and
capuchin
search
algorithm,
”
Advances
in
Engineering
Softwar
e
,
v
ol.
173,
2023,
doi:
10.1016/j.adv
engsoft.2022.103402.
[26]
Canadian
Institute
for
Cybersecurity
,
“
A
realistic
c
yber
defense
dataset
(CSE-CIC-IDS2018),
”
re
gistry
.opendata.a
ws.
[Online].
A
v
ailable:
https://re
gistry
.opendata.a
ws/cse-cic-ids2018/
[27]
N.
Moustaf
a,
“The
Bot-IoT
dataset,
”
IEEE
Dataport.
[Online].
A
v
ailable:
https://ieee-dataport.or
g/documents/bot-iot-dataset
[28]
M.
T
a
v
allaee,
E.
Bagheri,
W
.
Lu,
and
A.
A.
Ghorbani,
“
A
detailed
analysis
of
the
KDD
CUP
99
data
set,
”
in
IEEE
Symposium
on
Computational
Intellig
ence
for
Security
and
Defense
Applications
(CISD
A)
,
2009,
pp.
1-6,
doi:
10.1109/CISD
A.2009.5356528.
[29]
N.
Moustaf
a
and
J.
Slay
,
“UNSW
-NB15:
a
comprehensi
v
e
data
set
for
netw
ork
intrusion
detection
systems
(UNSW
-NB15
netw
ork
data
set),
”
in
2015
Military
Communications
and
Information
Systems
Confer
ence
(MilCIS)
,
Canberra,
Australia,
2015,
pp.
1-6,
doi:
10.1109/MilCIS.2015.7348942.
BIOGRAPHIES
OF
A
UTHORS
Khalid
Altarawneh
is
an
assoc
iate
professor
with
e
xperience
in
teaching,
research,
and
service
in
the
information
systems
area.
Combines
a
focus
on
student
achie
v
ement
with
a
passion
for
scholarly
w
ork,
presenting
and
publishing
a
t
conferences,
and
mainta
ining
thought
leadership
in
peer
-re
vie
wed
journals.
Deeply
in
v
ested
in
earning
tenure
through
administrati
v
e
service
committee
contrib
utions
and
an
achie
v
ement-oriented
approach
to
teaching.
He
can
be
contacted
at
email:
Khalid
a
w
ad@mutah.edu.jo.
Ghayth
AlMahadin
holds
a
Ph.D.
in
Arti
cial
Intelligence
-
Machine
Learning
from
Nottingham
T
rent
Uni
v
ersity
,
United
Kingdom
in
2022.
He
also
recei
v
ed
his
B.Sc.
in
Computer
Engineering
from
Mutah
Uni
v
ersity
,
Jordan
in
2005
and
M.Sc.
in
Cloud
Computing
and
Machine
Learning
from
Nottingham
T
rent
Uni
v
ersity
,
United
Kingdom
in
2017.
He
is
an
assistant
professor
at
Mutah
Uni
v
ersity
.
His
research
interests
include
wearable
technologies
and
machine
learning
applications
in
dif
ferent
elds.
He
can
be
contacted
at
email:
ghayth.mahadin@mutah.edu.jo.
Ibrahim
Altarawni
holds
a
Ph.D.
in
Articial
Intelligent.
He
also
recei
v
ed
his
B.Sc.
in
Computer
Science
from
the
Uni
v
ersity
Jordan
2007
and
M.Sc.
in
Computer
from
Y
urmok
Uni
v
ersity
.
He
is
an
assistant
professor
at
T
ala
T
echnical
Uni
v
ersity
.
His
research
interests
include
machine
learning
and
big
data.
He
can
be
contacted
at
email:
ibaltara
wni@ttu.edu.jo.
Int
J
Artif
Intell,
V
ol.
15,
No.
3,
June
2026:
2192–2200
Evaluation Warning : The document was created with Spire.PDF for Python.