Enhancing IoT Network Security: A Feature Selection and Explainable AI Approach for DDoS Attack Detection

被引:0
作者
Chaurasiya, Upendra [1 ]
Tripathi, Rakesh [1 ]
Sahu, Tirath Prasad [1 ]
机构
[1] Natl Inst Technol, Dept Informat Technol, Raipur, Chhattisgarh, India
关键词
Internet of things (IoT); Network security; Distributed denial of service (DDoS); Feature selection; Binary bat algorithm; Ensemble learning; Explainable AI; Intrusion detection system; Machine learning; SMOTE; LIME; INTRUSION DETECTION;
D O I
10.1007/s40995-025-01851-9
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
The Internet of Things (IoT) has significantly influenced areas such as healthcare, agriculture, industrial systems, and smart infrastructure. However, the rapid increase in the number of connected devices has introduced major security concerns, especially the risk of Distributed Denial of Service attacks. These attacks take advantage of the limited processing power and weak security configurations of many IoT devices, leading to network disruptions and service failures. This study presents an efficient intrusion detection approach that combines Binary Bat Algorithm (BBAT) based feature selection with an ensemble of lightweight machine learning models, including Extra Trees, Decision Trees, Random Forest, and XGBoost. The BBAT algorithm helps reduce the number of features while preserving classification accuracy, thereby lowering computational cost. To handle class imbalance, we incorporate the Synthetic Minority Over-sampling Technique, improving detection of underrepresented attack types. For interpretability, we apply Local Interpretable Model-agnostic Explanations (LIME) to identify key features that influence classification outcomes, supporting transparency and operational trust. The method is evaluated using three benchmark datasets-ToN-IoT, NSL-KDD, and UNSW-NB15 achieved high accuracy of 99.99%, 99.37%, and 99.08%, respectively. Comparative analysis with existing methods confirms the robustness, efficiency, and explainability of the proposed detection approach.
引用
收藏
页数:18
相关论文
共 59 条
[1]   A new DDoS attacks intrusion detection model based on deep learning for cybersecurity [J].
Akgun, Devrim ;
Hizal, Selman ;
Cavusoglu, Unal .
COMPUTERS & SECURITY, 2022, 118
[2]   An efficient SVM based DEHO classifier to detect DDoS attack in cloud computing environment [J].
Alam, Gowthul M. M. ;
Kumar, Jerald Nirmal S. ;
Mageswari, Uma R. ;
Raj, Michael T. F. .
COMPUTER NETWORKS, 2022, 215
[3]   An Intelligent and Explainable SaaS-Based Intrusion Detection System for Resource-Constrained IoMT [J].
Aljuhani, Ahamed ;
Alamri, Abdulelah ;
Kumar, Prabhat ;
Jolfaei, Alireza .
IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (15) :25454-25463
[4]   Enhancing IoT network security through deep learning-powered Intrusion Detection System [J].
Bakhsh, Shahid Allah ;
Khan, Muhammad Almas ;
Ahmed, Fawad ;
Alshehri, Mohammed S. ;
Ali, Hisham ;
Ahmad, Jawad .
INTERNET OF THINGS, 2023, 24
[5]   ToN_IoT: The Role of Heterogeneity and the Need for Standardization of Features and Attack Types in IoT Network Intrusion Data Sets [J].
Booij, Tim M. ;
Chiscop, Irina ;
Meeuwissen, Erik ;
Moustafa, Nour ;
den Hartog, Frank T. H. .
IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (01) :485-496
[6]   An intelligent DDoS attack detection tree-based model using Gini index feature selection method [J].
Bouke, Mohamed Aly ;
Abdullah, Azizol ;
ALshatebi, Sameer Hamoud ;
Abdullah, Mohd Taufik ;
El Atigh, Hayate .
MICROPROCESSORS AND MICROSYSTEMS, 2023, 98
[7]   A dynamic feature selection technique to detect DDoS attack [J].
Chanu, Usham Sanjota ;
Singh, Khundrakpam Johnson ;
Chanu, Yambem Jina .
JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2023, 74
[8]  
Dey AK., 2023, Decis. Anal. J, V7, P100206
[9]  
Dey SK, 2022, 2022 INT C ADV EL EL, P1
[10]   A comprehensive survey on recent metaheuristics for feature selection [J].
Dokeroglu, Tansel ;
Deniz, Ayca ;
Kiziloz, Hakan Ezgi .
NEUROCOMPUTING, 2022, 494 :269-296