MARATTO

article · Scientific Reports

RNN-based detection of IoT malware using diverse feature engineering methods

2026Open accessZagazig University

Abstract

The Internet of Things (IoT) has rapidly expanded, introducing critical security vulnerabilities due to increasingly sophisticated malware that traditional detection methods struggle to identify. To enhance malware detection in IoT environments, we developed a framework leveraging recurrent neural networks (RNNs) integrated with advanced preprocessing and multilevel feature engineering techniques, including label encoding, MinMax scaling, TF-IDF, bag-of-words, word2vec, and principal component analysis. We evaluated three distinct RNN architectures on the UNSW-NB15 dataset via stratified fivefold cross-validation, and the final performance was assessed on the independent official test set, achieving progressively improved performance, with the final model demonstrating near-optimal classification results across accuracy, precision, recall, F1 score, specificity, and AUC. The results highlight the potential of combining deep learning techniques with diverse feature engineering strategies for improving malware detection in IoT environments. The proposed framework provides a scalable and experimentally validated approach for enhancing IoT malware detection against evolving threats.

Research topics

  • Advanced Malware Detection Techniques
  • Network Security and Intrusion Detection
  • Spam and Phishing Detection

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1038/s41598-026-51074-0

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.