Federated Learning and Data Mining based Botnet Attack Detection Framework for Internet of Things

preprint OA: closed
Full text JSON View at publisher
AI-generated deep summary by claude@2026-07, 2026-07-05 · read from full text

The paper proposes a data-mining and federated learning framework to detect individual stages of botnet attacks in Internet of Things (IoT) networks, motivated by unpatched vulnerabilities that can enable large DDoS campaigns. The authors extract advanced features from anomalous network-traffic patterns using frequent itemset mining, then train a distributed federated learning model at network gateways to obtain a centralized view of global attack-pattern distributions at a security manager while not violating user privacy. Experiments using OpenStack and a real IoT testbed show that the privacy-preserving system’s performance is comparable to existing privacy-compromising solutions. A major caveat is that the work is presented as an unreviewed preprint rather than a peer-reviewed journal study. The paper does not explicitly discuss endometriosis or adenomyosis; it was included in the corpus via a keyword match in the upstream search index.

Read from the paper's body, not the abstract. Not a substitute for reading the paper. No clinical advice. How this works

Abstract

Abstract Advancements in the Internet of Things (IoT) have resulted in numerous IoT devices, both standard and non-standard, being connected to the Internet. These devices have inherent vulnerabilities and are not patched or maintained well after deployment. This has created a wider threat surface due to the sheer number of devices present. Recently, botnet attacks exploited such weaknesses in IoT and carried out massive DDoS attacks on high profile targets. In this work, we propose a data mining and federated learning based solution to detect the individual attack stages in botnet attacks. The proposed solution extracts advanced features by mining anomalous patterns in network traffic using frequent itemset mining. Then, we use these features to train a distributed federated learning solution at gateways of networks while extracting the global distribution of attack patterns at a centralized security manager without violating user privacy. We carry out a set of experiments using OpenStack and a real IoT testbed to evaluate the performance of the proposed solution. The results demonstrate that the performance of the proposed privacy-preserving system is comparable to existing solutions that compromise user privacy.
Full text 13,565 characters · extracted from preprint-html · click to expand
Federated Learning and Data Mining based Botnet Attack Detection Framework for Internet of Things | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Federated Learning and Data Mining based Botnet Attack Detection Framework for Internet of Things Kushan Sudheera Kalupahana Liyanage, Madhuwantha Priyashan Lokuge Lehele Gedara, and 4 more This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-5365489/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract Advancements in the Internet of Things (IoT) have resulted in numerous IoT devices, both standard and non-standard, being connected to the Internet. These devices have inherent vulnerabilities and are not patched or maintained well after deployment. This has created a wider threat surface due to the sheer number of devices present. Recently, botnet attacks exploited such weaknesses in IoT and carried out massive DDoS attacks on high profile targets. In this work, we propose a data mining and federated learning based solution to detect the individual attack stages in botnet attacks. The proposed solution extracts advanced features by mining anomalous patterns in network traffic using frequent itemset mining. Then, we use these features to train a distributed federated learning solution at gateways of networks while extracting the global distribution of attack patterns at a centralized security manager without violating user privacy. We carry out a set of experiments using OpenStack and a real IoT testbed to evaluate the performance of the proposed solution. The results demonstrate that the performance of the proposed privacy-preserving system is comparable to existing solutions that compromise user privacy. Botnet Attack Cyber-Security Data Mining Federated Learning IoT Machine Learning Full Text Additional Declarations No competing interests reported. Author Contributions : Conceptualization: [Kalupahana Liyanage Kushan Sudheera], [Wijethunga Gamage Chatum Aloj Sankalpa], [Gammana Guruge Nadeesha Sandamali]; Methodology: [Kalupahana Liyanage Kushan Sudheera], [Lokuge Lehele Gedara Madhuwantha Priyashan], [Oruthota Arachchige Sanduni Pavithra], [Malwaththe Widanalage Tharindu Aththanayake]; Formal analysis and investigation: [Lokuge Lehele Gedara Madhuwantha Priyashan], [Oruthota Arachchige Sanduni Pavithra], [Malwaththe Widanalage Tharindu Aththanayake]; Writing - original draft preparation: [Kalupahana Liyanage Kushan Sudheera], [Lokuge Lehele Gedara Madhuwantha Priyashan], [Oruthota Arachchige Sanduni Pavithra]; Writing - review and editing: [Kalupahana Liyanage Kushan Sudheera], [Wijethunga Gamage Chatum Aloj Sankalpa], [Gammana Guruge Nadeesha Sandamali]; Resources: [Kalupahana Liyanage Kushan Sudheera], [Wijethunga Gamage Chatum Aloj Sankalpa]; Supervision: [Kalupahana Liyanage Kushan Sudheera], [Wijethunga Gamage Chatum Aloj Sankalpa], [Gammana Guruge Nadeesha Sandamali] Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-5365489","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":373668642,"identity":"07d8ffde-502c-4816-83d3-1dd4de7509d7","order_by":0,"name":"Kushan Sudheera Kalupahana Liyanage","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA4ElEQVRIiWNgGAWjYBACCQYGNiBlAyYZGBtAJHMzMVrSkLUwEqXlMIRHlBbJGenPHvzccV6Oj72B7TPvDgZ5/gbGZgN8WqQlcswNe8/cNmbjOcA8m/cMg+GMA4zNCfi0yEnksEnwtt1ObJNIYGbmbWNg3AB02AH8WtKfSf5tO1ffJv8ArMWeoBZpiQQzad62AwlsEgxgLYkgLXgdJtnzxkxati3ZsI0nsZlxbptE8ozDBLwvcRzosLdtdvLy7YcPM7xts7Htb28+LIFPCxIARwpQMTOR6kfBKBgFo2AU4AYAAxE9xwgATXkAAAAASUVORK5CYII=","orcid":"","institution":"University of Ruhuna","correspondingAuthor":true,"prefix":"","firstName":"Kushan","middleName":"Sudheera Kalupahana","lastName":"Liyanage","suffix":""},{"id":373668643,"identity":"416bc565-25df-4749-a609-fa7cfcad55e1","order_by":1,"name":"Madhuwantha Priyashan Lokuge Lehele Gedara","email":"","orcid":"","institution":"University of Ruhuna","correspondingAuthor":false,"prefix":"","firstName":"Madhuwantha","middleName":"Priyashan Lokuge Lehele","lastName":"Gedara","suffix":""},{"id":373668644,"identity":"63076201-740d-4f46-8926-f0b698083390","order_by":2,"name":"Sanduni Pavithra Oruthota Arachchige","email":"","orcid":"","institution":"University of Ruhuna","correspondingAuthor":false,"prefix":"","firstName":"Sanduni","middleName":"Pavithra Oruthota","lastName":"Arachchige","suffix":""},{"id":373668645,"identity":"46851e20-98f6-4a7a-9ff5-10df610eb448","order_by":3,"name":"Tharindu Aththanayake Malwaththe Widanalage","email":"","orcid":"","institution":"University of Ruhuna","correspondingAuthor":false,"prefix":"","firstName":"Tharindu","middleName":"Aththanayake Malwaththe","lastName":"Widanalage","suffix":""},{"id":373668646,"identity":"6332335e-6266-442a-a0c8-ed6b774b7076","order_by":4,"name":"Chatum Aloj Sankalpa Wijethunga Gamage","email":"","orcid":"","institution":"University of Ruhuna","correspondingAuthor":false,"prefix":"","firstName":"Chatum","middleName":"Aloj Sankalpa Wijethunga","lastName":"Gamage","suffix":""},{"id":373668647,"identity":"b3e442c6-2d3c-4ef3-963a-f7c340e60202","order_by":5,"name":"Nadeesha Sandamali Gammana Guruge","email":"","orcid":"","institution":"University of Ruhuna","correspondingAuthor":false,"prefix":"","firstName":"Nadeesha","middleName":"Sandamali Gammana","lastName":"Guruge","suffix":""}],"badges":[],"createdAt":"2024-10-31 07:23:11","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-5365489/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-5365489/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":72636210,"identity":"60ff3892-0f38-4582-944f-36be7289bc28","added_by":"auto","created_at":"2024-12-30 15:16:58","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":985983,"visible":true,"origin":"","legend":"","description":"","filename":"BotnetAttackPaperSpringer.pdf","url":"https://assets-eu.researchsquare.com/files/rs-5365489/v1_covered_dba066e8-b26f-40d6-a975-3bf81507f6f5.pdf"}],"financialInterests":"\u003cp\u003eNo competing interests reported.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eAuthor Contributions\u003c/strong\u003e: Conceptualization: [Kalupahana Liyanage Kushan Sudheera], [Wijethunga Gamage Chatum Aloj Sankalpa], [Gammana Guruge Nadeesha Sandamali];\u003c/p\u003e\n\u003cp\u003eMethodology: [Kalupahana Liyanage Kushan Sudheera], [Lokuge Lehele Gedara Madhuwantha Priyashan], [Oruthota Arachchige Sanduni Pavithra], [Malwaththe Widanalage Tharindu Aththanayake];\u003c/p\u003e\n\u003cp\u003eFormal analysis and investigation: [Lokuge Lehele Gedara Madhuwantha Priyashan], [Oruthota Arachchige Sanduni Pavithra], [Malwaththe Widanalage Tharindu Aththanayake];\u003c/p\u003e\n\u003cp\u003eWriting - original draft preparation: [Kalupahana Liyanage Kushan Sudheera], [Lokuge Lehele Gedara Madhuwantha Priyashan], [Oruthota Arachchige Sanduni Pavithra];\u003c/p\u003e\n\u003cp\u003eWriting - review and editing: [Kalupahana Liyanage Kushan Sudheera], [Wijethunga Gamage Chatum Aloj Sankalpa], [Gammana Guruge Nadeesha Sandamali];\u003c/p\u003e\n\u003cp\u003eResources: [Kalupahana Liyanage Kushan Sudheera], [Wijethunga Gamage Chatum Aloj Sankalpa];\u003c/p\u003e\n\u003cp\u003eSupervision: [Kalupahana Liyanage Kushan Sudheera], [Wijethunga Gamage Chatum Aloj Sankalpa], [Gammana Guruge Nadeesha Sandamali]\u003c/p\u003e","formattedTitle":"Federated Learning and Data Mining based Botnet Attack Detection Framework for Internet of Things","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"Botnet Attack, Cyber-Security, Data Mining, Federated Learning, IoT, Machine Learning","lastPublishedDoi":"10.21203/rs.3.rs-5365489/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-5365489/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"Advancements in the Internet of Things (IoT) have resulted in numerous IoT devices, both standard and non-standard, being connected to the Internet. These devices have inherent vulnerabilities and are not patched or maintained well after deployment. This has created a wider threat surface due to the sheer number of devices present. Recently, botnet attacks exploited such weaknesses in IoT and carried out massive DDoS attacks on high profile targets. In this work, we propose a data mining and federated learning based solution to detect the individual attack stages in botnet attacks. The proposed solution extracts advanced features by mining anomalous patterns in network traffic using frequent itemset mining. Then, we use these features to train a distributed federated learning solution at gateways of networks while extracting the global distribution of attack patterns at a centralized security manager without violating user privacy. We carry out a set of experiments using OpenStack and a real IoT testbed to evaluate the performance of the proposed solution. The results demonstrate that the performance of the proposed privacy-preserving system is comparable to existing solutions that compromise user privacy. ","manuscriptTitle":"Federated Learning and Data Mining based Botnet Attack Detection Framework for Internet of Things","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2024-11-14 05:28:57","doi":"10.21203/rs.3.rs-5365489/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"c8288e9b-1ae1-449c-85be-9b381f6bb495","owner":[],"postedDate":"November 14th, 2024","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2024-12-30T15:08:47+00:00","versionOfRecord":[],"versionCreatedAt":"2024-11-14 05:28:57","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-5365489","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-5365489","identity":"rs-5365489","version":["v1"]},"buildId":"qtupq5eGEP_6zYnWcrvyt","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2024) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00