Comparative Evaluation of Feature Selection Strategies and Machine Learning Classifiers for IoT Botnet Detection

Authors

Fong Zi Khang

Faculty of Information and Communication Technology, Universiti Teknikal Malaysia Melaka, Melaka (Malaysia)

Mohd Faizal Abdollah

Faculty of Information and Communication Technology, Universiti Teknikal Malaysia Melaka, Melaka (Malaysia)

Warusia Yassin

Faculty of Information and Communication Technology, Universiti Teknikal Malaysia Melaka, Melaka (Malaysia)

Raihana Syahirah Abdullah

Faculty of Information and Communication Technology, Universiti Teknikal Malaysia Melaka, Melaka (Malaysia)

Nurhashikin Mohd Salleh

Faculty of Information and Communication Technology, Universiti Teknikal Malaysia Melaka, Melaka (Malaysia)

Article Information

DOI: 10.47772/IJRISS.2026.100700749

Subject Category: Security

Volume/Issue: 10/7 | Page No: 11032-11041

Publication Timeline

Submitted: 2026-07-28

Accepted: 2026-08-03

Published: 2026-08-11

Abstract

The rapid expansion of Internet of Things (IoT) devices has increased the need for accurate botnet detection methods that can operate with a compact set of network-traffic features. This study presents a controlled comparative evaluation of eight feature selection strategies and six machine learning classifiers using the N-BaIoT dataset. The feature selection strategies cover statistical, projection-based, recursive, hybrid, and ensemble approaches. Each method was evaluated at five feature-set sizes comprising 2, 3, 5, 10, and 15 features. Six classifiers—Decision Tree, Random Forest, Gradient Boosting, support vector machine with a radial basis function kernel, Logistic Regression, and K-Nearest Neighbours—were tested using fixed settings across all feature configurations. The complete design produced 240 model configurations that were assessed on the same evaluation set using accuracy, recall, precision, F1-score, training time, and inference latency. The results show that the RFE-Hybrid Lasso method produced the strongest overall feature subsets, with an average accuracy of 98.94% and an average F1-score of 98.09%. The best individual configuration combined RFE-Hybrid Lasso, 15 selected features, and Decision Tree, achieving 99.63% accuracy, 98.87% recall, 99.41% precision, and a 99.14% F1-score. Decision Tree also recorded the highest average classifier performance, reaching 99.18% accuracy with a training time of 2.1 minutes and an inference latency of 0.18 ms. The findings indicate that RFE-based hybrid selection improves detection performance over single statistical methods and that Decision Tree offers the most favourable performance–cost balance among the evaluated classifiers.

Keywords

IoT security, botnet detection, feature selection, recursive feature elimination

Downloads

References

1. A. Marzano, David Alexander and Osvaldo Fonseca. (2018). The Evolution of Bashlite and Mirai IoT Botnets. IEEE Symposium on Computers and Communications (ISCC). 813–818, doi: 10.1109/iscc.2018.8538636. [Google Scholar] [Crossref]

2. C. Kolias, G. Kambourakis, A. Stavrou, and J. Voas. (2017). DDoS in the IoT: Mirai and Other Botnets. Computer, 50(7). doi: 10.1109/mc.2017.201. [Google Scholar] [Crossref]

3. E. Bertino and N. Islam. (2017). Botnets and Internet of Things Security. Computer, 50(2). doi: 10.1109/mc.2017.62. [Google Scholar] [Crossref]

4. R. Doshi, N. Apthorpe, and N. Feamster. (2108). Machine Learning DDoS Detection for Consumer Internet of Things Devices. IEEE Symposium on Security and Privacy Workshops [Google Scholar] [Crossref]

5. Y. Dhote, S. Agrawal, and A. J. Deen. (2015). A Survey on Feature Selection Techniques for Internet Traffic Classification. International Conference on Computational Intelligence and Communication Networks. [Google Scholar] [Crossref]

6. A. Guerra-Manzanares, H. Bahşi, and S. Nõmm. (2019). Hybrid Feature Selection Models for Machine Learning Based Botnet Detection in IoT Networks. International Conference on Cyberworlds. [Google Scholar] [Crossref]

7. R. Doriguzzi-Corin, S. Millar, S. Scott-Hayward, J. Martínez-del-Rincón, and D. Siracusa. (2020). Lucid: A Practical, Lightweight Deep Learning Solution for DDoS Attack Detection,” IEEE Transactions on Network and Service Management. 17(2), 876–889. doi: 10.1109/tnsm.2020.2971776. [Google Scholar] [Crossref]

8. H. Blockeel, L. Devos, B. Frénay‬, G. Nanfack, and S. Nijssen. (2023). Decision trees: from efficient prediction to responsible AI. Frontiers in Artificial Intelligence. (6), 124553–1124553. doi: 10.3389/frai.2023.1124553. [Google Scholar] [Crossref]

9. C. Cortes and V. Vapnik. (1995). Support-vector networks. Machine Learning, 20(3), 273–297. doi: 10.1007/bf00994018. [Google Scholar] [Crossref]

10. G.-X. Yuan, C.-H. Ho, and C. Lin. (2012). Recent Advances of Large-Scale Linear Classification. Proceedings of the IEEE. 100(9), 2584–2603. doi: 10.1109/jproc.2012.2188013. [Google Scholar] [Crossref]

11. I. H. Sarker, A. S. M. Kayes, and P. Watters. (2019). Effectiveness Analysis of Machine Learning Classification Models for Predicting Personalized Context-aware Smartphone Usage. Journal Of Big Data. 6(1). doi: 10.1186/s40537-019-0219-y. [Google Scholar] [Crossref]

12. M. Injadat, A. Moubayed, and A. Shami. (2020). Detecting Botnet Attacks in IoT environments: An Optimized Machine Learning Approach,” in Proc. 32nd International Conference on Microelectronics. [Google Scholar] [Crossref]

13. M. Alqahtani, H. Mathkour, and M. M. B. Ismail. (2020). IoT Botnet Attack Detection Based on Optimized Extreme Gradient Boosting and Feature Selection. Sensors. 20(21), 6336–6336, . [Google Scholar] [Crossref]

14. S. Susanto, D. Stiawan, M. A. S. Arifin, Mohd. Y. Idris, and R. Budiarto. (2020). IoT Botnet Malware Classification Using Weka Tool and Scikit-learn Machine Learning. 7th International Conference on Electrical Engineering, Computer Sciences and Informatics. [Google Scholar] [Crossref]

15. F. Abbasi, M. Naderan, and S. E. Alavi. (2021). Anomaly Detection In Internet Of Things Using Feature Selection And Classification Based On Logistic Regression And Artificial Neural Network On N-Baiot Dataset. 5th International Conference on Internet of Things and Applications (IoT) [Google Scholar] [Crossref]

16. H. Bahşi, S. Nõmm, and F. B. L. Torre. (2018). Dimensionality Reduction for Machine Learning Based IoT Botnet Detection. International Conference on Control, Automation, Robotics and Vision [Google Scholar] [Crossref]

17. S. Susanto, D. Stiawan, M. A. S. Arifin, J. Rejito, Mohd. Y. Idris, and R. Budiarto. (2021). A Dimensionality Reduction Approach for Machine Learning Based IoT Botnet Detection. 8th International Conference on Electrical Engineering, Computer Science and Informatics. [Google Scholar] [Crossref]

18. M. G. Desai, Y. Shi, and K. Suo, “A Hybrid Approach for IoT Botnet Attack Detection. (2021). 2021 IEEE 12th Annual Information Technology, Electronics and Mobile Communication Conference (IEMCON) [Google Scholar] [Crossref]

19. S. Rabhi, T. Abbes, and F. Zarai. (2023). Transfer learning-based Mirai botnet detection in IoT networks. International Conference on Innovations in Intelligent Systems and Applications (INISTA). [Google Scholar] [Crossref]

20. R. Muthukrishnan and R. Rohini. (2016). LASSO as a feature selection method for weather forecasting. International Conference on Communication and Electronics Systems. [Google Scholar] [Crossref]

21. H. L. And, H. Liu, and R. Setiono. (1995). Chi2: Feature Selection and Discretization of Numeric Attributes. 7th IEEE International Conference on Tools with Artificial Intelligence [Google Scholar] [Crossref]

22. W. B. Johnson and J. Lindenstrauss. (1984). Extensions of Lipschitz mappings into a Hilbert Space. Contemporary mathematics - American Mathematical Society. American Mathematical Society, pp. 189–206, [Google Scholar] [Crossref]

23. H. Wang, B. Gu, and S. Qu. (2019). A novel hybrid feature selection method for improved high-dimensional data classification. Neurocomputing, vol. 338. [Google Scholar] [Crossref]

24. PedregosaFabian, Gaël Varoquaux, Alexandre Gramfort, Vincent Michel and Bertrand Thirion,(2012). Scikit-learn: Machine Learning in Python. Journal of Machine Learning Research. [Google Scholar] [Crossref]

25. Alghamdi, A., & Keshta, I. (2026). Blockchain consensus mechanisms and enhancement techniques for federated learning-based intrusion detection systems in IoT smart homes. Journal of Reliable and Secure Computing, 2(1), 1–26. [Google Scholar] [Crossref]

26. Punitha, P., Dinesh Kumar, V. K., & Lakshmana Kumar, R. (2025). Advancing IoT security with an innovative machine learning paradigm for botnet attack detection. EAI Endorsed Transactions on Internet of Things, 11(1). [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles