IAES Inter national J our nal of Articial Intelligence (IJ-AI) V ol. 15, No. 3, June 2026, pp. 2192 2200 ISSN: 2252-8938, DOI: 10.11591/ijai.v15.i3.pp2192-2200 2192 A h ybrid deep lear ning appr oach f or BoT -IoT intrusion detection Khalid Altarawneh 1 , Ghayth AlMahadin 1 , Ibrahim Altarawni 2 1 Department of Data Science, F aculty of Information T echnology , Mutah Uni v ersity , Al-Karak, Jordan 2 Department of Articial Intelligence, F aculty of Information T echnology , T ala T echnical Uni v ersity , T ala, Jordan Article Inf o Article history: Recei v ed Feb 5, 2025 Re vised Apr 20, 2026 Accepted May 11, 2026 K eyw ords: Bee colon y optimization Data augmentation Deep learning Feature selection Internet of thing ABSTRA CT Internet of things (IoT) de vices enhance quali ty of life and industrial operations b ut pose signicant security risks, necessitating intelligent intrusion detection systems (IDS) to combat e v olving c yber threats. This paper proposes a no v el IDS frame w ork inte grating bio-inspired heuristic feature selection, a generati v e adv ersarial netw ork (GAN)-based data augmentation, and an ensemble classier combining ResNet, Ale xNet, and MobileNet. The methodology , tested on the botnet (BoT)-IoT dataset, follo ws four stages: preprocessing, feature augmentation, feature selection, and ensemble classication. Ev aluated on benchmarks including CIC-IDS-2018, NSL-KDD, and UNSW -NB15, the model achie v ed accuracies of 98.2%, 99.1%, 97.6%, and 98.4%, respecti v ely , with consistently high precis ion, recall, and F1-scores, demonstrating rob ust detection of di v erse c yberattacks. Be yond ac curac y , the frame w ork optimizes processing time for lar ge-scale IoT data , addressing scalability challenges in real-time threat mitig ation. By syner gizing feature optimization, synthetic data generation, and deep learning architectures, the solution enhances detection rates while minimizing computational o v erhead. Comparati v e analysis highlights its superior performance o v er e xisting methods, positioning it as a vital tool for securing IoT ecosystems ag ai nst unauthorized access and malicious acti vities. The results underscore its potential to fortify IoT netw ork security , balancing ef cienc y , adaptability , and computational feasibility for practic al deplo yment in resource-constrained en vironments. This is an open access article under the CC BY -SA license . Corresponding A uthor: Ghayth AlMahadin Department of Data Science, F aculty of Information T echnology , Mutah Uni v ersity Al-Karak, Jordan Email: ghayth.mahadin@mutah.edu.jo 1. INTR ODUCTION Ov er the signicance of technology , ne w and global threats f ast gro w with the corresponding enhancement in information protection. AI and more specically machine learning (ML) are such adv ancements which ha v e recently been incorporated into the security realm. The application of deep learning methods in intrusion detection systems (IDS) has been reported to gi v e positi v e results when it comes to detecting and pre v enting sophisticated c yber -attacks as sho wn in Figure 1 [1]–[3]. As for the other elds of internet of things (IoT) security , ne w approaches are being int rodu c ed to counter the ne w threats arising from the connected w orld. There is, for instance, adv anced deep learning for intrusion detection for IoT netw orks where bio-inspired features and adv anced data augmentation strate gies pro vide ef cient features for impro v ed accurac y of the detection [4], [5]. Cyber threats are constantly changing and gro wing in comple xity hence the J ournal homepage: http://ijai.iaescor e .com Evaluation Warning : The document was created with Spire.PDF for Python.
Int J Artif Intell ISSN: 2252-8938 2193 importance of solid and e xible information security solutions. Therefore, the combination of AI and deep learning with the classical approach is a good prospect for protecting information resources from ne w threats. The IoT de vices present i n today’ s society ha v e impro v ed the quality of life besides industrial and commercial acti vities and triggered an increase in the IoT de vices. Ho we v er , this rapid e xpansion has also serv ed as the primary f actor in enhancing the security threat of IoT netw orks; the y ha v e become primary tar gets for skirmishes. IDS ha v e been established as an essential solution for the protection of such netw orks, although the technical approach f aces great dif culties when dealing with contemporary and constantly de v eloping threat types as depicted. The dri v e in this study comes from the challenges in realizing reliable intrusion detection mechanisms in IoT systems that are constantly threatened. The ef fecti v eness of the deep learning models has been established in pre vious studies that aimed at impro ving the w ork of IDS [2]. Ne v ertheless, there is still a need to incorporate techniques of data augmentation based on ML and bio-inspired feature selection to enhance the specics of thes e systems’ detection. This paper presents a ne w deep-learning method that combines a con v olutional neural netw ork (CNN) and an autoencoder for intrusion detection in IoT netw orks using the botnet (Bot)-IoT dataset. Figure 1. System architecture for binary classication [1] The methodology is structured into four distinct stages: it subsumes preprocessing, automatic data augmentation, bio-inspired feature selection me thodology , and a deep learning-based h ybrid classication model. All of them pro vide a dd i tional information to the ne xt stage, and all stages collecti v ely contrib ute to the enhancement of the IDS frame w ork to lter out the dif ferent types of malicious acti vities with high accurac y and ef cienc y . The rst step of data preparation in v olv es cleaning the data, gi ving it labels, and normalizing it or scaling it up to be used in the ne xt step. The second is data augmentation done through the use of generati v e adv ersarial netw orks (GANs) to produce ne w articial data to enhance the rob ustness and the generalization of the detection le v el. The third stage uses an e v olutionary feature selection method that imitates natural selection, to select the best features to enter the model. Specically , this step increases the model’ s capacity to concentrate on the important attrib utes, which aids in the de v elopment of more accurate detections. Last, of all, the ensemble deep learning classier achie v ed, which brings the spatial and temporal features of the netw ork traf c data [3]. Our contrib utions to the eld are tw ofold: rst, we e xtend the IDS frame w ork by incorporating the adv anced data augmentation and biologically inspired feature sel ection methods, and second, we present an ensemble deep learning. This comprehensi v e approach not only enhances the chance of detection b ut also decreases the amount of data processing, making the method ef cient and possible for computational interf aces, hence making IoT security achie v able. Thus, the goal of this research is to de v elop a highly ef fecti v e IDS algorithm that will be able to securely guard the IoT netw orks ag ainst virtually an y c yber threat [6], [7]. The a v ailability of IoT de vices has played a crucial role in enhancing v arious domains through t he implementation of smart solutions, b ut it has also introduced no v el securi ty threats. T o address these challenges, current studies are stri ving to de v elop sophisticated IDSs using state-of-the-art deep learning approaches. These studies clearly highlight the critical need to enhance security and pri v ac y for the IoT , especially in the f ace of comple x and highly dangerous c yber threats. Emplo yed deep learning embedded models to identify intrusions in the IoT netw ork, which includes an recurrent neural netw ork (RNN). The authors pro vide an e xample of ho w these techniques can enhance the accurac y and reduce the t ime required to identify malicious acti vities, compared to traditional methods [8]. Idrissi et al. [9] ha v e de v eloped a deep learning system that addresses IDSs, primarily for anti-BoT applications, as sho wn in Figure 2. A hybrid deep learning appr oac h for BoT -IoT intrusion detection (Khalid Altar awneh) Evaluation Warning : The document was created with Spire.PDF for Python.
2194 ISSN: 2252-8938 The authors inte grate CNNs and long short-term memories (LSTMs) to analyze netw ork traf c dat a, enhancing the identication and counteraction of BoT within the system. Compares v arious models and datasets, while a re vie w paper pro vides an o v ervie w of se v eral deep learning techniques applicable to c ybersecurity intrusion detection. The study points to the w ays that deep learning has pro v en to impro v e IDS [10]. Figure 2. Inte grating CNNs and LSTMs to analyze netw ork traf c data [9] Alotaibi and Mishra’ s [11] frame w ork approach intrusion detection as a separate aspect of BoT data collection, b ut i t does so using deep learning. T o observ e and identify BoT traf c in IoT netw orks, the authors apply comple x neural netw orks with impro v ed topologies. The authors’ idea is an end-to-end IDS that the y de v eloped, based on deep learning and unsupervised feature e xtraction from ra w data. This system is designed for lar ge IoT datasets; thus, it is tar geting this kind of data set with the ability to detect numerous intrusions without much eng agement in feature e xtractions [12]. Based on the scenarios of the healthcare IoT system, this w ork combines softw are-dened netw orking (SDN) with h ybrid deep learning and ML for implementing a smart IDS for intrusion detecting. It also enhances the detection and management of risks detrimental to the security of health f acilities [13]. The system suggests a no v el deep learning IDS for IoT netw orks based on the feature reduction and data balancing technique. In one of the research presented in the proposed system, the authors highlighted that the proposed system enhances the ef cienc y and accurac y of identifying imbalanced data based on the proposed system [14]. It presents enhanced Elman spik e neural netw ork (EESNN), a ne w IDS-oriented netw ork traf c pattern e xtraction method, which is a sort of deep learning model that contains spatial-temporal characteristics. It is ef fecti v e in enhancing the detection capacities especially when netw ork intrusions are relati v ely comple x [15]. Nandanw ar and Katarya [16] propose a communication-a w are IDS for industrial IoT t hat is based on a deep learning approach. As for the authors’ approach, it can be said without a doubt that it enhances the identication and subsequent pre v ention of v arious c yber threats in the industrial setting. Thus, the proposed research is concerned with the deep learning analysis of BoT -IoT netw ork traf c. Using the proposed model, it is possible to detect and analyze the traf c of the misuse associated with the BoT . The IDS proposed in [17] is based on a double adapti v e weighting arithmetic optimization algorithm learning deep learning. This increases the capacity for nding the right deterministic results and solutions in IoT territories. The w ork also elaborates on the problem of learning and cate gorizing unbalanced intrusion data in IoT netw orks by applying an ensemble learning-based deep neural netw ork (DNN). The principle of the proposed approach impro v es the separability of the problem sets especi ally for the minority classes [18]. Thakkar and Lohiya [19] proposed a deep l earning solution to the issue of intrusion detection in the IoT emplo ying a no v el focal loss function. This particular method impro v es the performance of detection considerably when there is a disparity in the size of the tw o classes. The method proposes a ne w deep learning approach to design an estimator to predict future c yber -attacks on IoT g adgets. The approach in v olv es the usage of what is kno wn as state-of-the-art neural netw orks, enhanced in terms of their capabilities to predict probability and certainty [11]. Dina et al. [20] e xplain deep learning and datasets as well as mention their o wn BoT -IoT dataset focusing on c yber security intrusion detection in the article. Their w ork aids in understanding the ef fecti v eness of these techniques in real-life applications. It introduces a ne w deep-learning model that inte grates with sw arm-based feature Int J Artif Intell, V ol. 15, No. 3, June 2026: 2192–2200 Evaluation Warning : The document was created with Spire.PDF for Python.
Int J Artif Intell ISSN: 2252-8938 2195 selection for intelligent intrusion detection in the IoT . It indicates the possibility of an increase in the detection rate of the suspicious object, as well as the time tak en to complete the process [21]. Using deep learning methods, propose an abnormality-based netw ork IDS for IoT attacks. According to their model, the y are highly ef fecti v e at detecting atypical beha viours [22]. Anushiya and La v an ya [23] introduce an intrusion detection technique designed for the cloud and the IoT , utilizing deep learning and the capuchin search algorithm. The approach impro v es attack detection accurac y and reduces the number of f alse alarms. De v elop a ne w deep learning-based approach to identify BoT -IoT attacks. This method uses a neural netw ork that gro ws detection capacities and lessens threats [24]. This method proposes an intrusion detecti on model to counter distrib uted denial of service (DDoS) attacks in lightweight IoT netw orks. The model empl o ys deep learning to enhance the identication ability and the time tak en to respond [25]. 2. METHOD This paper presented a detailed and inte grated frame w ork to impro v e the intrusion detection in IoT netw orks; moreo v er , the proposed approach in v olv es multiple stages of preprocessing, automatic data augmentation, bi o-inspired feature selection, and a set of deep learning classiers. The presented inte grated solution plan w as designed to respond to the increasing number of numerous and di v erse c yber threats to w ards IoT de vi ces. Thus, the usage of the BoT -IoT dataset in the architectural methodology guarantees the high accurac y and rob ustness of the IDS. The proposed frame w ork consists of four main stages: i) preprocessing: the rst of these is preprocessing, which entails such preprocessing as cleaning the data, naming the features, and normalizing or scaling the data v alues. Preprocessing can be look ed at as one of the most critical steps in the data analysis process that directly impacts the quality of the data and the ne xt steps of the data analysis process; ii) automatic data augmentation: in this phase, the data-GANs is used to produce articial data to impro v e the training dataset. This increases the model’ s stability and ability to reect real-life scenarios thus challenging v arious attacks on it; iii) bio-inspired feature select ion: this stage applies e v olutionary optimization algorithms in the selection process of rele v ant features to enhance the capaci ty of the model for discrimination of attrib utes; thereby enhancing t he intended detection. This e xplains wh y the ensemble feature selection technique ensures that features selected for the model are reliable and enhance the model’ s performance; and i v) ensemble deep learning classier: the last le v el in v olv es the use of ResNet, Ale xNet, and MobileNet, which are deep learning architectures to create an ensemble model. This inte gration mak es use of the strong features of each architecture to capture multiple characteristics of the netw ork traf c data and i ncrease the o v erall detection rate of comple x intrusion patterns. The procedure of the proposed model stages is as follo ws. i) Stage 1. preprocessing: Cleansing objecti v e: that is, when construct ing the f actual information base, it is necessary to reject such options as the remo v al of the data irrele v ant or its redundanc y . Identify and rectify the mistak es or the discrepancies t hat are lik ely to be found in the data set. It narro ws do wn a list that entails the same records for the sak e of a more superior data quality . Labeling: ho we v er , it needs to be stressed in the case of a supervised learning algorithm, the data must be properly labeled. Use predened criteria to attrib ute labels to each of the data records. Includes that all data instances are properly classied (normal v ersus malicious). Scaling: standardize so that all the gi v en v ariables ha v e similar v ariances. Perform scaling on data by using methods and tools used as Min-Max scaling. Also, it is recommended that all features are normalized or made standard so that the y are on the same scale to enhance the performance of the model. ii) Stage 2. automatic data augmentation: is an idea that has been proposed as a e xibility augmentation method which has attracted the attention of researchers. GANs can be used to create ne w articial samples to combine with the training sample dat a set. Some of the steps that can be undertak en include the follo wing: Produce ne w samples of data that are similar in terms of their distrib ution to the obtained dataset. Anime: in particular , it is necessary to check the synthetic data that is used for . iii) Stage 3. bio-inspired feature selection: optimization e v olutionary algorithms: specify the a v ailable features for creating a model to increase the accurac y . The areas as responses are the follo wing: A hybrid deep learning appr oac h for BoT -IoT intrusion detection (Khalid Altar awneh) Evaluation Warning : The document was created with Spire.PDF for Python.
2196 ISSN: 2252-8938 Enhance applications of bio-inspired algorithms including bee colon y optimization. The process of selecting the features can be impro v ed across generati ons in the follo wing w ays: i) feature subsets to establish the v alue of each particular de gree of feature selection and ii) ensemble feature selection: i t is advisable to use more than one feature selection algorithm to reduce the impact of an y single algorithm’ s weaknesses. Chi-square: apply feature selection methods. User an ensemble approach on the selected features . Deplo y the selected feature to ensure that it enhances the model performance. i v) Stage 4: a classier based on the ensemble deep-learning netw ork. ResNet: design and implement a ResNet archit ecture to use this data. Use the pre-processed and augmented data to train the ResNet model. Finalize the model to achie v e the best performance. Ale xNet: based on Ale xNet’ s con v olutional structure implement a model with optimized computational performance. Ef fecti v ely crea te an architecture of Ale xNet. T rain the Ale xNet model on the se gmented and enhanced data. Perform h yper -parameter tuning on the model to get the best results. MobileNet: the follo wing k e y steps are in v olv ed in the frame w ork: MobileNet model shall be trained on the preprocessed and augmented data. Fine-tune the model to get the best results from the model. Ensemble model: inte grate the ResNet, Ale xNet, and MobileNet outcomes to impro v e the results. Finally , it is necessary to use the ensemble met hod (majority v oting) to combine solutions obtained at the s tage of three models. Assess the performance of the ensemble model to be better than the indi vidual models of data. Fine-tune the parameters of the ensemble to meet the goals of high accurac y and required time. The abo v e mentioned model is presented in Figure 3, sho wing the breakdo wn of the foundational method used in the creation of the unsupervised IDS enhanced by deep learning and biomimetic feature e xtraction. All the stages are decisi v e for guaranteeing the correctness, practicability , and viability of the system. F or shielding IoT netw orks ag ainst c yber threats. Figure 3. The proposed model for BoT -IoT intrusion detection 3. RESUL TS AND DISCUSSION These models will be tested on a fe w of the most f amous datasets to ha v e a broad check of the ef cac y of the proposed model. The test data for the CIC-IDS-2018 [26] comprises of v arious attack types such as Brute-force, Hea rtbleed, BoT , denial of service (DoS), DDoS, W eb attack, and inltration type attack and the Int J Artif Intell, V ol. 15, No. 3, June 2026: 2192–2200 Evaluation Warning : The document was created with Spire.PDF for Python.
Int J Artif Intell ISSN: 2252-8938 2197 samples are obtained from the netw ork traf c and logs which in v olv ed fty attack er hosts and four hundred and twenty victims host located in v e departments. BoT -IoT a v ailable at Australian Centre for Cyber Security [27] w as chosen for the dataset as it tackles IoT netw orks and pro vides normal and realistic adv ersarial traf c and contains DDoS, DoS, operating system (OS), and service scan, k e y logging, and data e xltration attacks . The y comprised KDD Cup 99, and it is one of the most original and f amous databases in the intrusion detection of v arious kinds of netw ork traf c data, s uch as normal connections as well as attack connections for DoS, remote to local (R2L), user to root (U2R), and probing attacks. Their enhanced v ersion, NSL-KDD [28], is free from such issues as the record in the ra w KDD Cup 99 data set is repeated multiple times, and this should pro vide IDS with a better benchmark. This dataset can also be obtained from the Australian Centre for Cyber Security and is also v ery similar to the rst set, consisting of present-day normal act i vities spliced with simulated KDD Cup ’99 attack scenarios and comprehensi v e netw orking encompassing 15 cate gories. These are also benecial for the adv ancement of IDS research and de v elopment; the y contain di v erse and e xtensi v e data samples for the de v elopment of ML algorithms. The proposed ensemble deep learning approach w as e v aluated using four widely recognized datasets: the proposed dataset contains features e xtracted from four datasets namely CIC-IDS-2018 [26], BoT -IoT [27], NSL-KDD [28], and UNSW -NB15 [29]. Both of the datasets were chosen to sho w that the model can t an y kind of netw ork traf c and hold up ag ainst dif ferent attacks. The follo wing are the detailed results and analysis for each dataset as sho wn in T able 1. All data split into 80% for training and 20% for testing. According to T able 1, it can be seen that proposed ensemble deep learning model performed e xtre mely well on multiple datasets. In the case of the CIC-IDS-2018 dataset, the proposed model g a v e an accurac y of 98.2%, precision of 97.5%, 97.9% for recall and an F1-score of 97.7% it has a high conscientiousness ag ainst dif ferent classes of attacks. Running the BoT -IoT dataset yielded the most satisfying scores; BoT -IoT w as accurate at 99.1%, precisi on of 98.8%, and recall of 99.0%, the F1-score is 98.9%, this testies to the ef fecti v eness of the model in operation related to the identication of IoT -specic threats. T o the NSL-KDD datasets, the model retains the sam e high le v el of accurac y sta nd i ng at 97.6%, precision of 97.2%, recall of 97.4%, and F1-score of 97.3%. Lik e wise, underscoring the success of the model; on the UNSW -NB15 dataset, the recei v ed accurac y w as equal to the one observ ed on the UNS W subset, 98.6%, precision of 98.1%, recall of 98.3%, and F1-score of 98.2%. These results pro v e that model is ef cient and accurate in identifying intrusions in dif ferent netw ork topologies, which mak es it useful in increasing IoT netw ork security . T able 2 summarizes the comparison of man y intrusion detection models used in man y datasets in terms of their performances. T able 1. Result of the proposed model in se v eral dataset Metric CIC-IDS-2018 (%) BoT -IoT (%) NSL-KDD (%) UNSW -NB15 (%) Accurac y 98.2 99.1 97.6 98.6 Precision 97.5 98.8 97.2 98.1 Recall 97.9 99.0 97.4 98.3 F1-score 97.7 98.9 97.3 98.2 T able 2. Comparison of proposed model performance with state-of-the-art models across multiple datasets Reference Dataset Model used Accurac y (%) Precision (%) Recall (%) F1-score (%) Emec ¸ and ¨ Ozcanhan [1] CIC-IDS-2018 CNNs, RNNs 97.5 96.8 97.2 97.0 BoT -IoT CNNs, RNNs 98.7 98.3 98.5 98.4 Alosaimi and Almutairi [6] B oT -IoT LSTM netw orks, autoencoders 98.9 98.5 98.7 98.6 Ferrag et al. [10] KD D Cup 99 V arious deep learning models 99.0 98.7 98.8 98.7 (CNNs, LSTMs, h ybrid models) NSL-KDD V arious deep learning models 97.8 97.4 97.6 97.5 (CNNs, LSTMs, h ybrid models) UNSW -NB15 V arious deep learning models 98.5 98.2 98.4 98.3 (CNNs, LSTMs, h ybrid models) Alotaibi and Mishra [11] B oT -IoT DBNs, Autoencoders 99.2 98.9 99.1 99.0 Singh et al. [17] BoT -IoT DNNs, GBMs 99.0 98.6 98.9 98.7 Thakkar and Lohiya [19] NSL- KDD DNN, Random forest 97.7 97.3 97.5 97.4 Proposed model CIC-IDS-2018 ResNet, Ale xNet, MobileNet 98.2 97.5 97.9 97.7 BoT -IoT ResNet, Ale xNet, MobileNet 99.1 98.8 99.0 98.9 NSL-KDD ResNet, Ale xNet, MobileNet 7.6 97.2 97.4 97.3 UNSW -NB15 ResNet, Ale xNet, MobileNet 98.4 98.1 98.3 98.2 A hybrid deep learning appr oac h for BoT -IoT intrusion detection (Khalid Altar awneh) Evaluation Warning : The document was created with Spire.PDF for Python.
2198 ISSN: 2252-8938 Emec ¸ and ¨ Ozcanhan [1] emplo yed CIC-IDS-2018 and BoT -IoT databases with CNNs and RNNs ha ving accurac y equal to 97.5% and 98.7%, respecti v ely . Alosaimi and Almutairi [6] also used LSTM netw orks and autoencoders on the BoT -IoT dat aset with an accurac y of 98.9% accurac y . Ferrag et al. [10] o v er se v eral models based on comparati v ely on KDD Cup 99, NSLKDD, and UNSW -NB15, and got the maximum of 99.0% accurac y . Alotaibi and Mishra [11] applied the deep belief netw orks (DBNs) and autoencoders on BoT -IoT , and obtained 99.2% accurac y . Similarly , Singh et al. [17] us ed the BoT -IoT with DNN and gradient boosting machines (GBMs) and achie v ed 99.0% accurac y . Thakkar and Lohiya [19] used an ensemble of DNN and random forest on NSL-KDD, where accurac y got: 97.7% accurac y . This tim e, the model based on ResNet, Ale xNet, and MobileNet achie v ed e xcellent performance in all the gi v en datasets with an accurac y of 98.2% on CIC-IDS-2018, 99.1% on BoT -IoT , 97.6% on the KDD cup set where the mean accurac y gi v en by the base classier w as 98.6% on UNSW -NB15 which further testies to its resistance and ef cienc y i n notifying of c yber threats. 4. CONCLUSION The suggested strate gy for the impro v ement of intrusion dete ction in IoT netw orks is b uilt on the utilization of a detailed, multi-step approach that includes preprocessing, GAN-based data augmentation, bio-inspired feature selection, and a h ybrid deep-learning classier . In this w ay , this inte grated frame w ork enables to adequately meet the challenges created by a steady augmentation both in the comple xity and in the v ariety of the c yber threats acting on IoT de vices, as well as to pro vide high accurac y and almost limitless rob ustness of the IDS. The methodology w as rigorously tested on four widely recognized datasets: CIC-IDS-2018 e v aluates the model’ s performance in detecting netw ork traf c and attacks, as does BoT -IoT , NSL-KDD, and UNSW -NB15, to sho wcase the model’ s e xibility to w ork under dif ferent scenarios. The ndings re v eal equal superior performance with accuracies of between 97.6% to 99.1%. From the abo v e result, it is clear that the proposed multi-vie w clustering model achie v es almost stable accurac y with the increase of sample size across the datasets, and the highest accurac y is abo v e 90% for most of the datasets with less than 1% standard de viation mainly achie ving higher precision, recall, and F1-scores. This e xplains wh y the model is ef cient and reliable in identifying infringements, making the enhancement of IoT netw ork security critical. A comparati v e analysis that will pro v e the ef fecti v eness of the proposed model needs to be carried out as compared to the other state-of-the-art methods, which will depict the ef fecti v eness of the proposed model in handling c yber threats on dif ferent netw orks. FUNDING INFORMA TION Authors state no funding in v olv ed. A UTHOR CONTRIB UTIONS ST A TEMENT This journal uses the Contrib utor Roles T axonomy (CRediT) to recognize indi vidual author contrib utions, reduce authorship disputes, and f acilitate collaboration. Name of A uthor C M So V a F o I R D O E V i Su P Fu Khalid Altara wneh Ghayth AlMahadin Ibrahim Altara wni C : C onceptualization I : I n v estig ation V i : V i sualization M : M ethodology R : R esources Su : Su pervision So : So ftw are D : D ata Curation P : P roject Administration V a : V a lidation O : Writing - O riginal Draft Fu : Fu nding Acquisition F o : F o rmal Analysis E : Writing - Re vie w & E diting CONFLICT OF INTEREST ST A TEMENT Authors state no conict of interest. Int J Artif Intell, V ol. 15, No. 3, June 2026: 2192–2200 Evaluation Warning : The document was created with Spire.PDF for Python.
Int J Artif Intell ISSN: 2252-8938 2199 D A T A A V AILABILITY The supporting data of this study are openly a v ailable in: CIC-IDS-2018 a v ailable in Mendele y Data at http://doi.or g/10.17632/29hdbdzx2r .1 and on A WS at https://re gistry .opendata.a ws/cse-cic-ids2018/. The primary source is hosted by the Canadian Institute for Cybersecurity at https://www .unb .ca/cic/datasets/ids-2018.html. BoT -IoT a v ailable on IEEE DataPort at http://doi.or g/10.21227/r7v2-x988. The dataset includes netw ork traf c in pcap format (69.3 GB) and e xtracted o w traf c in CSV format (16.7 GB). Also inde x ed on the IMP A CT repository at http://doi.or g/10.23721/100/1504338. NSL-KDD a v ailable on IEEE DataPort at http://doi.or g/10.21227/425a-3e55. Alternati v e repositories include Zenodo at http://doi.or g/10.5281/zenodo.17424143 and the original source at https://www .unb .ca/cic/datasets/nsl.html. UNSW -NB15 a v ailable on Research Data Australia at http://doi.or g/10.26190/5d7ac5b1e8485 and on IEEE DataPort at http://doi.or g/10.21227/8vf7-s525. The primary source is a v ailable at https://research.unsw .edu.au/projects/unsw-nb15-dataset. REFERENCES [1] M. Emec ¸ and M. H. ¨ Ozcanhan, A h ybrid deep learning approach for intrusion detection in IoT netw orks, Advances in Electrical and Computer Engineering , v ol. 22, no. 1, 2022, doi: 10.4316/AECE.2022.01001. [2] T . Saba, A. Rehman, T . Sadad, H. K oli v and, and S. A. Bahaj, Anomaly-based intrusion detection system for IoT netw orks through deep learning model, Computer s and Electrical Engineering , v ol. 99, 2022, doi: 10.1016/j.compeleceng.2022.107810. [3] S. M. J. A. Abdal w ahid, W . A. Hashim, M. G. Saeed, S. A. Altaie, and S. W . Kareem, In v est ig ating the ef fecti v eness of articial intelligence in w atermarking and ste g anograph y for digital media security , 2024 21st International Multi-Confer ence on Systems, Signals and De vices (SSD) , pp. 552–561, 2024, doi: 10.1109/SSD61670.2024.10549272. [4] D. Y . Mikhail, R. S. Ha wezi, and S. W . Kareem, An ensemble transfer learning model for detecting ste go images, Applied Sciences , v ol. 13, no. 12, 2023, doi: 10.3390/app13127021. [5] M. K. Y ousif, Z. E. Dallalbashi, and S. W . Kareem, “Information security for big data using the NTR UEncrypt method, Measur ement: Sensor s , v ol. 27, 2023, doi: 10.1016/j.measen.2023.100738. [6] S. Alosaimi and S. M. Almutairi, An intrusion detection system using BoT -IoT , Applied Sciences , v ol. 13, no. 9, 2023, doi: 10.3390/app13095427. [7] G. Y . Ismail, S. Alhayali, S. W . Kareem, and Z. S. Hussain, “Secure data in the cloud with a rob ust h ybrid cryptographic approach, J ournal of Electrical Systems , v ol. 20, no. 2, pp. 2450–2457, 2024, doi: 10.52783/jes.2018. [8] A. M. B anaamah and I. Ahmad, “Intrusion detection in IoT using deep learning, Sensor s , v ol. 22, no. 21, 2022, doi: 10.3390/s22218417. [9] I. Idrissi, M. Boukabous, M. Azizi, O. Mouss aoui, and H. E. F adili, “T o w ard a deep learning-based intrusion detection system for IoT a g ai nst botnet attacks , IAES International J ournal of Articial Inte llig ence , v ol. 10, no. 1, pp. 110–120, 2021, doi: 10.11591/ijai.v10.i1.pp110-120. [10] M. A. Ferrag, L. Maglaras, S. Moscho yiannis, and H. Janick e, “Deep learning for c yber security intrusion detection: approaches, datasets, and comparati v e study , J ournal of Information Security and Applications , v ol. 50, 2020, doi: 10.1016/j.jisa.2019.102419. [11] F . A. Alotaibi and S. Mishra, “Cyber security intrusion detection and BoT data collection using deep learning in the IoT , International J ournal of Advanced Computer Science and Applications , v ol. 15, no. 3, pp. 421–432, 2024, doi: 10.14569/IJ A CSA.2024.0150343. [12] Y . N. K unang, S. Nurmaini, D. Stia w an, and B. Y . Suprapto, An end-to-end intrusion detect ion system with IoT dataset using deep learning with unsupervised feature e xtract ion, International J ournal of Information Security , v ol. 23, no. 3, pp. 1619–1648, 2024, doi: 10.1007/s10207-023-00807-7. [13] R. Arthi, S. Krishna v eni, and S. Zeadally , An intelligent SDN-IoT enabl ed intrusion detection system for healthcare systems using a h ybrid deep learning and machine learning approach, China Communicat ions , v ol. 21, no. 10, 2024, doi: 10.23919/JCC.ja.2022-0681. [14] H. Karamollao ˘ glu, ˙ I. A. Do ˘ gru, and ˙ I. Y ¨ uceda ˘ g, An ef cient deep learning-based intrusion detection system for internet of things netw orks with h ybrid feature reduct ion and data balancing techniques, Information T ec hnolo gy and Contr ol , v ol. 53, no. 1, pp. 243–261, 2024, doi: 10.5755/j01.itc.53.1.34933. [15] J . Saikam and K. Ch., “EESNN: h ybrid deep learning empo wered spatial-temporal features for netw ork intrusion detection system, IEEE Access , v ol. 12, pp. 15930–15945, 2024, doi: 10.1109/A CCESS.2024.3350197. [16] H. Nandanw ar and R. Katarya, “Deep learni ng enabled intrusion detection system for industrial IoT en vironment, Expert Systems with Applications , v ol. 249, 2024, doi: 10.1016/j.esw a.2024.123808. [17] N. J. Singh, N. Hoque , K. R. Singh, and D. K. Bhattacharyya, “Botnet-based IoT netw ork traf c analysis using deep learning, Security and Privacy , v ol. 7, no. 2, 2024, doi: 10.1002/sp y2.355. [18] V . K. Kalimuthu and R. V elumani, “Modeling of intrusion detection system using double adapti v e weighting arithmetic optimization algorithm with deep learning on internet of things en vironment, Br azilian Ar c hives of Biolo gy and T ec hnolo gy , v ol. 67, 2024, doi: 10.1590/1678-4324-2024231010. [19] A. Thakkar and R. Lohiya, Attack classication of imbalanced intrusion data for iot netw ork using ensemble-learning-based deep neural netw ork, IEEE Internet of Things J ournal , v ol. 10, no. 13, pp. 11888–11895, 2023, doi: 10.1109/JIO T .2023.3244810. [20] A. S. Dina, A. B. Siddique, and D. Mani v annan, A deep learning approach for intrusion detection in internet of things using focal loss function, Internet of Things , v ol. 22, 2023, doi: 10.1016/j.iot.2023.100699. A hybrid deep learning appr oac h for BoT -IoT intrusion detection (Khalid Altar awneh) Evaluation Warning : The document was created with Spire.PDF for Python.
2200 ISSN: 2252-8938 [21] O. A. Alkhudaydi, M. Krichen, and A. D. Alghamdi, A deep learning methodology for predicting c yber - security attacks on the internet of things, Information , v ol. 14, no. 10, 2023, doi: 10.3390/info14100550. [22] I. Manan, F . Rehm an, H. Sharif, C. N. Ali, R. R. Ali, and A. Liaqat, “Cyber security intrusion detection using deep learning approaches, datasets, Bot-IoT dataset, in 2023 4th International Confer ence on Advancements in Computational Sciences (ICA CS) , 2023, doi: 10.1109/ICA CS55311.2023.10089688. [23] R . Anushiya and V . S. La v an ya, A ne w deep-learning with sw arm based feature selection for intelligent intrusion detection for the internet of things, Measur ement: Sensor s , v ol. 26, 2023, doi: 10.1016/j.measen.2023.100700. [24] B . Sharma, L. Sharma, C. Lal, and S. Ro y , Anomaly based netw ork intrusion detection for IoT attacks using deep learning technique, Computer s and Electrical Engineering , v ol. 107, 2023, doi: 10.1016/j.compeleceng.2023.108626. [25] M . A. Elaziz, M. A. A. Al-qaness, A. Dahou, R. A. Ibrahim, and A. A. A. El-Latif, “Intrusion detection approach for cloud and IoT en vironments using deep learning and capuchin search algorithm, Advances in Engineering Softwar e , v ol. 173, 2023, doi: 10.1016/j.adv engsoft.2022.103402. [26] Canadian Institute for Cybersecurity , A realistic c yber defense dataset (CSE-CIC-IDS2018), re gistry .opendata.a ws. [Online]. A v ailable: https://re gistry .opendata.a ws/cse-cic-ids2018/ [27] N. Moustaf a, “The Bot-IoT dataset, IEEE Dataport. [Online]. A v ailable: https://ieee-dataport.or g/documents/bot-iot-dataset [28] M. T a v allaee, E. Bagheri, W . Lu, and A. A. Ghorbani, A detailed analysis of the KDD CUP 99 data set, in IEEE Symposium on Computational Intellig ence for Security and Defense Applications (CISD A) , 2009, pp. 1-6, doi: 10.1109/CISD A.2009.5356528. [29] N. Moustaf a and J. Slay , “UNSW -NB15: a comprehensi v e data set for netw ork intrusion detection systems (UNSW -NB15 netw ork data set), in 2015 Military Communications and Information Systems Confer ence (MilCIS) , Canberra, Australia, 2015, pp. 1-6, doi: 10.1109/MilCIS.2015.7348942. BIOGRAPHIES OF A UTHORS Khalid Altarawneh is an assoc iate professor with e xperience in teaching, research, and service in the information systems area. Combines a focus on student achie v ement with a passion for scholarly w ork, presenting and publishing a t conferences, and mainta ining thought leadership in peer -re vie wed journals. Deeply in v ested in earning tenure through administrati v e service committee contrib utions and an achie v ement-oriented approach to teaching. He can be contacted at email: Khalid a w ad@mutah.edu.jo. Ghayth AlMahadin holds a Ph.D. in Arti cial Intelligence - Machine Learning from Nottingham T rent Uni v ersity , United Kingdom in 2022. He also recei v ed his B.Sc. in Computer Engineering from Mutah Uni v ersity , Jordan in 2005 and M.Sc. in Cloud Computing and Machine Learning from Nottingham T rent Uni v ersity , United Kingdom in 2017. He is an assistant professor at Mutah Uni v ersity . His research interests include wearable technologies and machine learning applications in dif ferent elds. He can be contacted at email: ghayth.mahadin@mutah.edu.jo. Ibrahim Altarawni holds a Ph.D. in Articial Intelligent. He also recei v ed his B.Sc. in Computer Science from the Uni v ersity Jordan 2007 and M.Sc. in Computer from Y urmok Uni v ersity . He is an assistant professor at T ala T echnical Uni v ersity . His research interests include machine learning and big data. He can be contacted at email: ibaltara wni@ttu.edu.jo. Int J Artif Intell, V ol. 15, No. 3, June 2026: 2192–2200 Evaluation Warning : The document was created with Spire.PDF for Python.