Skip to content
Open access

SHAP-Guided Feature Selection for IoT Botnet Detection: A Comparative Study with Conventional Methods

Sep 2026 · Applied Sciences · Vol 16, pp. 8840 · 0 citations

TL;DR

An explainability-guided feature selection framework that employs SHAP values derived from an XGBoost model to rank features and systematically compares its effectiveness with Mutual Information, Analysis of Variance (ANOVA), and Principal Component Analysis (PCA) across nine machine learning classifiers using the N-BaIoT dataset is presented.

Abstract

The widespread deployment of Internet of Things (IoT) devices has expanded the attack surface of modern networks, making IoT botnets a persistent cybersecurity threat. Although machine learning-based intrusion detection systems (IDSs) have demonstrated promising detection capability, their performance is often hindered by redundant high-dimensional features and limited model interpretability. This study presents an explainability-guided feature selection framework that employs SHAP values derived from an XGBoost model to rank features and systematically compares its effectiveness with Mutual Information (MI), Analysis of Variance (ANOVA), and Principal Component Analysis (PCA) across nine machine learning classifiers using the N-BaIoT dataset. Experimental results indicate that LightGBM with SHAP-selected features achieves an accuracy of 0.9994 using only the top 10 features. Among the evaluated feature selection methods, SHAP achieves the highest classification performance on seven of the nine classifiers, while Wilcoxon signed-rank tests indicate a statistically significant difference between SHAP and ANOVA (p = 3.03 × 10−5); the difference between SHAP and MI is significant at the conventional threshold (p = 2.86 × 10−2) but does not remain significant after Bonferroni correction for multiple comparisons. Furthermore, SHAP-based analysis reveals distinct traffic statistical signatures between the Mirai and Gafgyt botnet families, offering actionable insights for explainability-aware IoT intrusion detection. The proposed framework provides a practical solution for balancing detection performance and model interpretability in IoT botnet detection.

Read PDF

Similar papers

Open access 2026

Comparative Evaluation of Feature Selection Strategies and Machine Learning Classifiers for IoT Botnet Detection

The rapid expansion of Internet of Things (IoT) devices has increased the need for accurate botnet detection methods that can operate with a compact set of network-traffic features. This study presents a controlled comparative evaluation of eight feature selection strategies and six machine learning classifiers using t...

Fong Zi Khang, M. F. Abdollah, W. Yassin et al. · 0 citations
Open access Aug 2026

A Correlation-Based Feature Selection and Weighted XGBoost Framework for Minority IoT Attack Detection

This study proposes a Correlation-Based Feature Selection (CFS)–Weighted XGBoost framework that combines redundancy-aware feature selection with an embedded class-weighted learning classifier to improve minority-attack detection.

M. Alnagdawi, Tariq Bishtawi, Ayman Ghaben · 0 citations
Open access 2026

An Explainable Ensemble Feature Selection Framework for Enhanced IoT Edge Attack Detection

An explainable hybrid feature-selection framework (X-EFS) that combines multiple feature reduction techniques via a multi-expert system module, then uses the MDA metric to select the most important features, ensuring high performance and explainability.

Minh Trọng Hoàng, Le Thi Trang Linh, Hoang Minh Nguyen et al. · 0 citations
Review Open access Aug 2026

An Empirical Comparative Review of Classifiers for Real-Time IoT Cyber Attack Detection

The rapid growth of the Internet of Things (IoT) has significantly expanded the attack surface of modern networks, generating an urgent need for robust and efficient intrusion detection mechanisms. Machine learning (ML) is a promising approach to detect cyber attacks in IoT environments by automatically learning discri...

Youssef Boulkhiout, Samir Balbal, Khaled Nasri et al. · 0 citations
Open access Aug 2026

Enhancing IoT botnet detection with explainable ensemble learning

Introduction Internet of Things (IoT) botnet detection faces significant challenges due to the growing intricacy and decreased transparency of Machine Learning (ML) models. Methods In this work, we provide an ensemble-based detection system that makes use of a voting classifier made up of a Boosted Decision Tree and a...

Linda Joseph, S. M., V. M · 0 citations
Open access Sep 2026

Machine Learning-Based Anomaly Detection for Traffic in IoT-Enabled Transportation Networks

The rapid proliferation of Internet of Things (IoT) devices and their integration into increasingly interconnected applications have substantially expanded the attack surface of modern networked systems. The heterogeneous nature and high volume of IoT traffic make timely and reliable identification of malicious activit...

Connor Gladish, Molly Corgan, J. Moss et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.