RNN-based detection of IoT malware using diverse feature engineering methods

M Mahmoud Khaled Abd-Ellah N Nayera A. Alsayed O Osama M. Elkomy W Walaa M. EL-Hady

Abstract

Abstract The Internet of Things (IoT) has rapidly expanded, introducing critical security vulnerabilities due to increasingly sophisticated malware that traditional detection methods struggle to identify. To enhance malware detection in IoT environments, we developed a framework leveraging recurrent neural networks (RNNs) integrated with advanced preprocessing and multilevel feature engineering techniques, including label encoding, MinMax scaling, TF-IDF, bag-of-words, word2vec, and principal component analysis. We evaluated three distinct RNN architectures on the UNSW-NB15 dataset via stratified fivefold cross-validation, and the final performance was assessed on the independent official test set, achieving progressively improved performance, with the final model demonstrating near-optimal classification results across accuracy, precision, recall, F1 score, specificity, and AUC. The results highlight the potential of combining deep learning techniques with diverse feature engineering strategies for improving malware detection in IoT environments. The proposed framework provides a scalable and experimentally validated approach for enhancing IoT malware detection against evolving threats.

Article Details

Volume / Issue Vol. 16, Issue 1
Published May 11, 2026
ISSN 2045-2322
Publisher Nature Portfolio

Journal Info

Scientific Reports

Nature Portfolio

ISSN: 2045-2322 Open Access Life Sciences

Authors (4)

M

Mahmoud Khaled Abd-Ellah

N

Nayera A. Alsayed

O

Osama M. Elkomy

W

Walaa M. EL-Hady