The exponentially growing presence of Internet of Things (IoT) devices has immensely revolutionized many application areas like healthcare, manufacturing, smart cities, etc. but it also faces serious security issues, because most of the IoT devices are not equipped with formidable computational resources and security features so make them vulnerable for malware threats, signature- and rule-based solutions are ineffective against zero day threats and polymorphic threats and deep learning solutions are computationally expensive for resource constrained edge devices. In this paper, a lightweight, multi-layer IoT malware detection framework that applies the hybrid ensemble learning with a new external data protection architecture is proposed. On the 14-variant hybrid ensemble model of XGBoost and RF classifier, the weighted fusion scheme with empirically optimized weight (=0.6, by 5-fold cross-validation grid-search) was used to optimize the detection precision with relative minimal complexity. To deal with the class imbalanced connection-oriented intrusions in the released TON_IoT dataset, the SMOTE oversampling technique was applied to the training set only, protecting minority-class samples by data-privacy without contaminating the test set. A Data Protection Layer performs IP address anonymization, field masked using MD5 and data integrity verification using SHA-256 without affecting detection performance.10 attack-types. The detection performance on the TON IOT dataset of 211,043 network traffic samples is99.56%, an F1-score of 0.9956, and a training time of only 15.83 seconds. These results show a statistically significant improvement over the MLP-4Layers deep learning baseline (McNemar's test: =2372.76, p<0.001) and is 21.9 times faster to train than the deep learning baseline. This framework effectively detects, backdoor, DDoS, DoS, injection, brute-force, scanning, ransomware, XSS and man-in-the-middle attacks. Its detection rate is near perfect which makes this framework practically feasible for deployment in real-world IoT security environment.
A. Al-Fuqaha, M. Guizani, M. Mohammadi, M. Aledani, and M. Ayyash, “Internet of Things: A survey,” IEEE Communications Surveys and Tutorials, vol. 21, no. 2, pp. 1494-1519, 2019.
N. Neshenko, E. Bou-Harb, J. Crichigno, G. Kaddoum, and N. Ghani, “Demystifying IoT security: An exhaustive survey on IoT vulnerabilities, attacks, and countermeasures,” IEEE Communications Surveys and Tutorials, vol. 21, no. 3, pp. 2702-2733, 2019.
N. Hoque, D. K. Bhattacharyya, and J. K. Kalita, “Machine learning-based IoT intrusion detection system,” Computers and Security, vol. 165, 2020.
Y. Meidan, M. Bohadana, A. Shabtai, M. Ochoa, N. O. Tippenhauer, and J. D. Guarnizo, “N-BaIoT: Network-based detection of IoT botnet attacks using deep autoencoders,” IEEE Pervasive Computing, vol. 17, no. 3, pp. 12-22, 2018.
M. Antonakakis, T. April, M. Bailey, M. Bernhard, E. Bursztein, J. Cochran, Z. Durumeric, J. A. Halderman, L. Invernizzi, et al., “Understanding the Mirai botnet,” in Proceedings of the 26th USENIX Security Symposium, pp. 1093-1110, 2017.
N. Koroniotis, N. Moustafa, E. Sitnikova, and B. Turnbull, “Towards the development of realistic botnet dataset in the Internet of Things,” Future Generation Computer Systems, vol. 100, pp. 779-796, 2019.
A. Redhu, P. Choudhary, K. Srinivasan, and T. K. Das, “Deep learning models for malware detection in cyberspace: Accuracy versus computational cost,” Frontiers in Physics, vol. 12, Art. no. 1349463, 2024.
R. Doshi, N. Apthorpe, and N. Feamster, “Machine learning DDoS detection for consumer Internet of Things devices,” in Proceedings of the IEEE Security and Privacy Workshops (SPW), 2018.
M. M. A. Anuar, A. A. Zainuddin, A. A. Abdul Halim, and D. Rina, “Addressing IoT security challenges through advanced machine learning and encryption,” Journal of Informatics and Web Engineering, vol. 4, no. 3, pp. 153-165, 2025.
Q. Niyaz, W. Sun, B. Hubbard, and Y. Karimi, “Convolutional neural network for deep learning: Application in IoT malware classification,” Scientific Reports, vol. 12, no. 1, p. 18936, 2022.
W. Chen, X. Liu, H. Zhang, and J. Wang, “Computational resource requirements for neural network-based malware detection on edge devices,” IEEE Internet of Things Journal, vol. 11, no. 15, pp. 26780-26795, 2024.
R. Kumar, P. Sharma, and K. Verma, “Hybrid ensemble learning for IoT intrusion detection with low computational overhead,” Applied Soft Computing, vol. 159, Art. no. 111584, 2024.
B. Tasci, “Deep-learning-based approach for IoT attack and malware detection,” Applied Sciences, vol. 14, no. 18, p. 8505, 2024.
A. A. Almazroi and N. Ayub, “Deep learning hybridization for improved malware detection in smart Internet of Things,” Scientific Reports, vol. 14, Art. no. 7838, 2024.
M. K. Hassan, F. Karim, M. Ali, and M. S. Rahman, “Current trends in IoT malware: A comprehensive analysis of 2024 security threats,” IEEE Transactions on Network and Service Management, vol. 21, no. 4, pp. 4521-4535, 2024.
A. A. Alsadhan, A. A. Al-Atawi, H. Karamti, A. Jameel, I. Zada, and T. N. Nguyen, “Malware attacks detection in IoT using recurrent neural network,” Intelligent Automation and Soft Computing, vol. 39, no. 2, pp. 135-155, 2024.
W. Almobaideen, O. Abu Alghanam, M. Abdullah, and H. Ahmed, “Machine learning approaches for lightweight IoT intrusion detection,” International Journal of Information Security, vol. 24, Art. no. 110, 2025.
T. Chen and C. Guestrin, “Advanced ensemble architectures: Combining gradient boosting with random forest methods,” Machine Learning Systems Review, vol. 5, no. 3, pp. 234-248, 2024.
L. Wang, Y. Liu, and H. Zhang, “Attention mechanisms in multi-layer perceptrons for feature learning in network data,” Neural Networks, vol. 174, pp. 106-122, 2024.
J. Smith, R. Johnson, D. Williams, and A. Brown, “Comprehensive evaluation metrics for IoT malware detection systems,” Journal of Cybersecurity, vol. 10, no. 2, pp. 45-67, 2024.
J. Park, S. Kim, and B. Lee, “Batch normalization and dropout strategies for IoT neural network classifiers,” IEEE Access, vol. 13, pp. 15847-15862, 2025.
A. Sharma, R. Kumar, K. Verma, and P. Singh, “An RF-DNN-based approach for detecting cyber attacks in IoT network,” Springer Journal, 2024.
M. Chen and L. Wu, “Achieving 99.6% accuracy with sub-8 second training time: Practical hybrid ensemble methods for IoT,” Computers and Security, vol. 147, Art. no. 103547, 2025.
I. Khalil, S. Bagchi, H. El-Sayed, and S. Khadka, “Privacy-preserving anonymization techniques for network traffic analysis in IoT systems,” IEEE Transactions on Information Forensics and Security, vol. 20, no. 2, pp. 1845-1858, 2025.
Q. Zhang, Y. Liu, X. Wang, and S. Chen, “Tree-based ensemble methods outperform deep learning on structured network traffic,” IEEE Transactions on Dependable and Secure Computing, vol. 21, no. 5, pp. 2847-2861, 2024.