The rapid growth of Internet of Things (IoT) devices has led to a proliferation of security risks. Botnet-mediated Distributed Denial of Service (DDoS) attacks are among the top concerns for IoT networks. Machine learning-based intrusion detection systems traditionally face challenges such as high-dimensionality, feature redundancy, and class imbalance in network traffic datasets. In this work, we introduce Hybrid Feature Extraction (HFE), a novel framework that applies statistical aggregation followed by Principal Component Analysis (PCA) and Mutual Information (MI)-based feature selection techniques to learn a low-dimensional 21-feature representation for detecting IoT botnets. The reduced set HFE pipeline consists of 8 PCA components which explain 95% of variance of data globally. They are concatenated with 13 MI-selected attributes which hold label predictive information. For experimental evaluation we chose to test our Ensemble learning classifiers, XGBoost, LightGBM, and Random Forest classifier on UNSW IoT Botnet dataset consisting of 3.6 million samples distributed among 5 attack classes. With our Hybrid approach using XGBoost classifier we attained a score of 98.33% for balanced accuracy and an F1-Macro score of 98.71%. Theft has a precision of 96% while Reconnaissance has a recall of 94%. Our method outperforms all baseline methods by atleast 1.33% and 1.21% for Balanced Accuracy and F1 Macro score respectively. HFE proves to be a lightweight, scalable method which can easily be deployed for real-time purposes in low-resource IoT devices.
Keywords
Keywords-Internet of Things SecurityBotnet DetectionDDoS Attack DetectionHybrid Feature ExtractionEnsemble Learning.
References
M. A. Ferrag, L. Maglaras, H. Janicke, Y. Meng, and E. Jorswieck, “An aggregated mutual information based feature selection approach with machine learning methods for enhancing IoT botnet attack detection,” Sensors, vol. 22, no. 1, p. 185, 2021.
N. Thockchom, M. M. Singh, and U. Nandi, “A novel hybrid feature selection and ensemble-based machine learning approach for botnet detection,” Scientific Reports, vol. 13, no. 1, p. 21207, 2023.
B. M. Kouassi, A. B. Ballo, K. J. Ayikpa, D. Mamadou, and M. Z. J. Coulibaly, “Top-K feature selection for IoT intrusion detection: Contributions of XGBoost, LightGBM, and Random Forest,” Future Internet, vol. 17, no. 11, p. 529, 2025.
A. Omar Almotairi, S. Atawneh, O. A. Khashan, and N. M. Khafajah, “Enhancing intrusion detection in IoT networks using machine learning-based feature selection and ensemble models,” Systems Science and Control Engineering, vol. 12, p. 2321381, 2024.
U. Habib, M. P. Uddin, A. Kabir, and M. R. Islam, “Feature selection-driven ensemble learning approach for accurate botnet attack detection,” Computers & Security, vol. 186, p. 104058, 2025.
E. Altulaihan, M. A. Almaiah, and A. Aljughaiman, “Anomaly detection IDS for detecting DoS attacks in IoT networks based on machine learning algorithms,” Sensors, vol. 24, no. 2, p. 713, 2024.
A. B. Musa, R. Jain, P. Varshney, and P. Pillai, “Intrusion detection framework for Internet of Things with rule induction for model explanation,” Sensors, vol. 25, no. 6, p. 1845, 2025.
S. A. Khanday, H. Fatima, and N. Rakesh, “XRFLWID: XGBoost and Random Forest-based lightweight intrusion detection model for IoT attack detection,” in Data Science and Communication (ICTDsC 2023), Springer, Singapore, 2024, pp. 1-12.
A. Hamdouchi and A. Idri, “Enhancing IoT security through boosting and feature reduction techniques for multiclass intrusion detection,” Neural Computing and Applications, vol. 37, pp. 8245-8264, 2025.
A. H. Wheeb and M. F. Khan, “A Survey of Several Machine Learning (ML) Algorithms for Security Solution in Internet of Things (IoT) Networks,” Journal of Artificial Intelligence Research & Advances, vol. 12, no. 01, pp. 1-11, 2024, [Online]. Available: https://journals.stmjournals.com/joaira/article=2024/view=191585/.
A. H. Wheeb, F. Shaik, and S. Karimullah, “Two Purpose-Oriented RIS-Aided Schemes to Enhance and Evaluate the Performance of Wireless Communication,” COJ Electronics & Communications, vol. 3, no. 1, pp. 1-13, Oct. 2024, [Online]. Available: https://crimsonpublishers.com/cojec/fulltext/COJEC.000555.php.
S. Khatun, G. Nyoman Ciptaningtyas, M. P. Uddin, and M. A. Hossain, “Robust machine learning based intrusion detection system using simple statistical techniques in feature selection,” Scientific Reports, vol. 15, no. 1, p. 2779, 2025.
C. Vargas-Rosales, H. Anaya-Sánchez, F. Villarreal-Vasquez, and C. Garza-Salazar, “Time series feature selection method based on mutual information and hybrid PCA-kernel regression,” Applied Sciences, vol. 14, no. 5, p. 1960, 2024.
I. Guyon and A. Elisseeff, “An introduction to variable and feature selection,” Journal of Machine Learning Research, vol. 3, pp. 1157-1182, 2003.
S. Akgun, A. Mehmet Duran, and S. Kurnaz, “A comparative analysis of machine learning techniques for IoT intrusion detection,” in 2023 International Conference on Data-Driven Machine Intelligence and Cybersecurity, Springer, 2024, pp. 1-15.
T. Chen and C. Guestrin, “XGBoost: A scalable tree boosting system,” in Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 2016, pp. 785-794.
G. Ke, Q. Meng, T. Finley, et al., “LightGBM: A highly efficient gradient boosting decision tree,” in Advances in Neural Information Processing Systems (NIPS), 2017, pp. 3146-3154.
L. Breiman, “Random forests,” Machine Learning, vol. 45, no. 1, pp. 5-32, 2001.
Y. K. Saheed, O. H. Abdulganiyu, and T. A. Tchakoucht, “A novel hybrid ensemble learning for anomaly detection in industrial sensor networks and SCADA systems for smart city infrastructures,” Journal of King Saud University - Computer and Information Sciences, vol. 35, no. 5, p. 101532, 2023.
D. Kshirsagar and S. Kumar, “Toward an intrusion detection system for detecting web attacks based on an ensemble of filter feature selection techniques,” Cyber-Physical Systems, vol. 9, no. 3, pp. 244-259, 2023.
M. Saied and S. Guirguis, “Explainable artificial intelligence for botnet detection in internet of things,” Sci. Rep., vol. 15, Art. no. 7632, Mar. 2025, [Online]. Available: https://doi.org/10.1038/s41598-025-90420-6.
S. Ullah, J. Wu, Z. Lin, M. M. Kamal, H. Mostafa, M. Sheraz, and T. C. Chuah, “Comparative analysis of deep learning and traditional methods for IoT botnet detection using a multi-model framework across diverse datasets,” Sci. Rep., vol. 15, Art. no. 31072, Aug. 2025, [Online]. Available: https://doi.org/10.1038/s41598-025-16553-w.
M. Ali, M. F. Mushtaq, U. Akram, M. Junaid, A. Haider, F. Safdar, and I. Ashraf, “Botnet detection in internet of things using stacked ensemble learning model,” Sci. Rep., vol. 15, Art. no. 21012, Jul. 2025, [Online]. Available: https://doi.org/10.1038/s41598-025-02008-9.
M. Nawaz, S. Tahira, D. Shah, A. Alshammari, M. Alshammari, M. S. Arshad, and O. M. Elkomy, “Lightweight machine learning framework for efficient DDoS attack detection in IoT networks,” Sci. Rep., vol. 15, Art. no. 24961, Jul. 2025, [Online]. Available: https://doi.org/10.1038/s41598-025-10092-0.
F. Firgiawan, D. P. Hostiadi, and R. R. Huizen, “Classification Model for Bot-IoT Attack Detection Using Correlation and Analysis of Variance,” Jurnal RESTI, vol. 9, no. 2, pp. 425-434, 2025, [Online]. Available: https://doi.org/10.29207/resti.v9i2.6332.