Skip to content

Leveraging Cyber-Physical Security Solutions Blended With Machine Learning for Advanced IoT Botnet Detection

Sep 2026 · IEEE Communications Standards Magazine · Vol 10, pp. 83-93 · 1 citation · 15 references

Abstract

The proliferation of Internet of Things (IoT) ecosystems has significantly increased the attack surface of cyber-physical systems, leading to the emergence of large-scale botnets that exploit device vulnerabilities for distributed and persistent attacks. This survey comprehensively reviews state-of-the-art techniques that integrate cyber-physical security solutions with machine learning (ML) for advanced detection and mitigation of IoT botnets. It categorizes existing methods into networkcentric, host-based, and hybrid cyber-physical detection frameworks, emphasizing their detection granularity, scalability, and computational feasibility in resource-constrained environments. The paper systematically analyzes supervised, unsupervised, and deep learning approaches, ranging from Random Forests and Support Vector Machines to Autoencoders, LSTMs, and Graph Neural Networks, highlighting their adaptability to evolving botnet behaviours and zero-day threats. Furthermore, the survey explores the integration of federated learning, edge computing, and software-defined networking (SDN) to enable distributed, privacy-preserving, and realtime detection architectures. Key challenges, including data imbalance, adversarial resilience, explainability, and cross-domain generalization, are critically discussed. Finally, this work outlines a taxonomy of cyber-physical and ML-based IoT botnet detection models and identifies future research directions toward autonomous, adaptive, and explainable cyber-physical defense systems.

View source

Similar papers

Review Open access Aug 2026

AI-ENHANCED INFORMATION SECURITY FRAMEWORKS FOR CLOUD-ENABLED IOT NETWORKS: A COMPREHENSIVE REVIEW

This review paper critically examines the integration of Artificial Intelligence (AI) and Machine Learning (ML) techniques to enhance information security within Cloud-IoT networks, focusing on hybrid Deep Learning models (CNN-LSTM), predictive analytics, and automated threat response mechanisms.

R. Saravanakumar, V.Anuratha, M.Elamparithi · 0 citations
Open access Aug 2026

HybridML CyberShield for explainable proactive intrusion detection in enterprise and IoT networks

The framework introduces CNN–BiLSTM deep learning networks to represent traffic in a spatiotemporal manner and adopts ensemble machine learning classifiers to enhance the robustness of traffic detection and its interpretability, to enhance the robustness of traffic detection and its interpretability.

Ramesh N. S. V. S. C. Sripada, A. Bhavani, Kiran B. Malagi et al. · 0 citations
Open access Aug 2026

Adaptive Machine Learning Framework for Real-Time Cyber-Attack Detection and Prevention in IoT Networks

This paper introduces an innovative ML-based security paradigm that improves the attack detection accuracy by combining adaptive feature extraction techniques with a context-attentive hybrid mechanism and maximizes detection accuracy and computational efficiency.

P. P. Bairagi, Ashish Bagwari, Sailen Dutta Kalita et al. · 0 citations
Review Open access Sep 2026

Deep Learning-Based Intrusion Detection in IoT: A Comprehensive Review of Architectures, Attacks, Challenges, and Future Directions

The rapid proliferation of Internet of Things (IoT) devices across critical domains including healthcare, smart cities, industrial control systems, and intelligent transportation has fundamentally transformed the cybersecurity threat landscape. The inherent characteristics of IoT environments, namely resource-constrain...

Mohammed Gharkan, Mustafa I. Hussien Al-Janabi, Obaid Salim · 0 citations
Open access Aug 2026

Detecting and Preventing Cyberattacks in Internet of Things (IoT) Systems

This study proposes a hybrid machine learning-based intrusion detection and prevention framework for securing IoT networks that integrates Isolation Forest, Autoencoder, Extreme Gradient Boosting, and Bidirectional Long Short-Term Memory models within a stacked ensemble architecture to improve attack detection while re...

Ruthwik Palem, Likhith Reddy Peketi, Vanathi M et al. · 0 citations

Related blog posts

Microsoft Research Blog Jul 13, 2026

Verifying Rust cryptography in SymCrypt, from standards to code

Cryptographic code supports vital protections in modern computing systems. Learn how a new method helps verify code as developers write it while preserving speed and adaptability as it gets implemented and evolves. The post Verifying Rust cryptography in SymCrypt, from standards to code appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.