A Hybrid Deep Spatio-Temporal and Ensemble Learning Framework for Accurate IoT Malware Detection
Abstract
With the rapid development of Internet of Things (IoT) devices, more and more malware are emerging and spreading, which seriously threaten the IoT security. To address this challenge, a hybrid deep spatio-temporal ensemble learning framework is proposed in this paper for highly accurate IoT malware detection. In this architecture, the CNN module is adopted to capture the spatial information of network behavior, the BILSTM module is exploited to find out the temporal dependencies, the Attention Mechanism is applied to selectively sharpen subspaces, and the stacking ensemble method is employed with classifiers such as LightGBM, XGBoost, and RF. Compared to traditional frameworks, it depicts network behaviors in the two dimensions simultaneously. The optimal experimental results on the CicIoT2023 achieve an accuracy of 99.20%, a precision of 99.10%, a recall of 99.00%, and an F1 score of 99.10%. Ablation experiments demonstrate the effectiveness of our method. Meanwhile, the single-family and cross-family testing experiments show that our framework has a good generalization ability for malware of various categories. With spatio-temporal features representing network traffic, the deep autonomous extracting ability, the selective sharpening ability, and the robust ensemble learning method, our framework can be used as one of the effective network-wide-deploying malware detection solutions.