{"id":"https://openalex.org/W3185153723","doi":"https://doi.org/10.1109/jiot.2021.3100755","title":"Federated Deep Learning for Zero-Day Botnet Attack Detection in IoT-Edge Devices","display_name":"Federated Deep Learning for Zero-Day Botnet Attack Detection in IoT-Edge Devices","publication_year":2021,"publication_date":"2021-07-28","ids":{"openalex":"https://openalex.org/W3185153723","doi":"https://doi.org/10.1109/jiot.2021.3100755","mag":"3185153723"},"language":"en","primary_location":{"id":"doi:10.1109/jiot.2021.3100755","is_oa":false,"landing_page_url":"https://doi.org/10.1109/jiot.2021.3100755","pdf_url":null,"source":{"id":"https://openalex.org/S2480266640","display_name":"IEEE Internet of Things Journal","issn_l":"2327-4662","issn":["2327-4662","2372-2541"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Internet of Things Journal","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://e-space.mmu.ac.uk/628278/7/FDL_for_Botnet_Attack_Detection_in_IoT_Edge_Devices%20e.pdf","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5057364146","display_name":"Segun I. Popoola","orcid":"https://orcid.org/0000-0002-3941-5903"},"institutions":[{"id":"https://openalex.org/I11983389","display_name":"Manchester Metropolitan University","ror":"https://ror.org/02hstj355","country_code":"GB","type":"education","lineage":["https://openalex.org/I11983389"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"Segun I. Popoola","raw_affiliation_strings":["Department of Engineering, Faculty of Science and Engineering, Manchester Metropolitan University, Manchester, U.K","[Department of Engineering, Faculty of Science and Engineering, Manchester Metropolitan University, Manchester M1 5GD, United Kingdom. (e-mail: segun.i.popoola@stu.mmu.ac.uk)]"],"affiliations":[{"raw_affiliation_string":"Department of Engineering, Faculty of Science and Engineering, Manchester Metropolitan University, Manchester, U.K","institution_ids":["https://openalex.org/I11983389"]},{"raw_affiliation_string":"[Department of Engineering, Faculty of Science and Engineering, Manchester Metropolitan University, Manchester M1 5GD, United Kingdom. (e-mail: segun.i.popoola@stu.mmu.ac.uk)]","institution_ids":["https://openalex.org/I11983389"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069757184","display_name":"Ruth Ande","orcid":"https://orcid.org/0000-0003-1632-8484"},"institutions":[{"id":"https://openalex.org/I4210164862","display_name":"Artificial Intelligence in Medicine (Canada)","ror":"https://ror.org/05p590m36","country_code":"CA","type":"company","lineage":["https://openalex.org/I4210164862"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Ruth Ande","raw_affiliation_strings":["Artificial Intelligence for Cybersecurity Research Team, Cyraatek Ltd., Manchester, U.K","[Artificial Intelligence for Cybersecurity Research Team, Cyraatek Ltd., Manchester M5 3EZ, United Kingdom.]"],"affiliations":[{"raw_affiliation_string":"Artificial Intelligence for Cybersecurity Research Team, Cyraatek Ltd., Manchester, U.K","institution_ids":["https://openalex.org/I4210164862"]},{"raw_affiliation_string":"[Artificial Intelligence for Cybersecurity Research Team, Cyraatek Ltd., Manchester M5 3EZ, United Kingdom.]","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5031253024","display_name":"Bamidele Adebisi","orcid":"https://orcid.org/0000-0001-9071-9120"},"institutions":[{"id":"https://openalex.org/I11983389","display_name":"Manchester Metropolitan University","ror":"https://ror.org/02hstj355","country_code":"GB","type":"education","lineage":["https://openalex.org/I11983389"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Bamidele Adebisi","raw_affiliation_strings":["Department of Engineering, Faculty of Science and Engineering, Manchester Metropolitan University, Manchester, U.K","[Department of Engineering, Faculty of Science and Engineering, Manchester Metropolitan University, Manchester M1 5GD, United Kingdom.]"],"affiliations":[{"raw_affiliation_string":"Department of Engineering, Faculty of Science and Engineering, Manchester Metropolitan University, Manchester, U.K","institution_ids":["https://openalex.org/I11983389"]},{"raw_affiliation_string":"[Department of Engineering, Faculty of Science and Engineering, Manchester Metropolitan University, Manchester M1 5GD, United Kingdom.]","institution_ids":["https://openalex.org/I11983389"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5027367677","display_name":"Guan Gui","orcid":"https://orcid.org/0000-0003-3888-2881"},"institutions":[{"id":"https://openalex.org/I41198531","display_name":"Nanjing University of Posts and Telecommunications","ror":"https://ror.org/043bpky34","country_code":"CN","type":"education","lineage":["https://openalex.org/I41198531"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Guan Gui","raw_affiliation_strings":["College of Telecommunications and Information Engineering, Nanjing University of Posts and Telecommunications, Nanjing, China","[College of Telecommunications and Information Engineering, Nanjing University of Posts and Telecommunications (NJUPT), Nanjing, 210003 China.]"],"affiliations":[{"raw_affiliation_string":"College of Telecommunications and Information Engineering, Nanjing University of Posts and Telecommunications, Nanjing, China","institution_ids":["https://openalex.org/I41198531"]},{"raw_affiliation_string":"[College of Telecommunications and Information Engineering, Nanjing University of Posts and Telecommunications (NJUPT), Nanjing, 210003 China.]","institution_ids":["https://openalex.org/I41198531"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5089637331","display_name":"Mohammad Hammoudeh","orcid":"https://orcid.org/0000-0003-1058-0996"},"institutions":[{"id":"https://openalex.org/I11983389","display_name":"Manchester Metropolitan University","ror":"https://ror.org/02hstj355","country_code":"GB","type":"education","lineage":["https://openalex.org/I11983389"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Mohammad Hammoudeh","raw_affiliation_strings":["Department of Computing and Mathematics, Manchester Metropolitan University, Manchester, U.K","Department of Computing and Mathematics, Manchester Metropolitan University, Manchester, M1 5GD, United Kingdom"],"affiliations":[{"raw_affiliation_string":"Department of Computing and Mathematics, Manchester Metropolitan University, Manchester, U.K","institution_ids":["https://openalex.org/I11983389"]},{"raw_affiliation_string":"Department of Computing and Mathematics, Manchester Metropolitan University, Manchester, M1 5GD, United Kingdom","institution_ids":["https://openalex.org/I11983389"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5084989172","display_name":"Olamide Jogunola","orcid":"https://orcid.org/0000-0002-2701-9524"},"institutions":[{"id":"https://openalex.org/I11983389","display_name":"Manchester Metropolitan University","ror":"https://ror.org/02hstj355","country_code":"GB","type":"education","lineage":["https://openalex.org/I11983389"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Olamide Jogunola","raw_affiliation_strings":["Department of Engineering, Faculty of Science and Engineering, Manchester Metropolitan University, Manchester, U.K","[Department of Engineering, Faculty of Science and Engineering, Manchester Metropolitan University, Manchester M1 5GD, United Kingdom.]"],"affiliations":[{"raw_affiliation_string":"Department of Engineering, Faculty of Science and Engineering, Manchester Metropolitan University, Manchester, U.K","institution_ids":["https://openalex.org/I11983389"]},{"raw_affiliation_string":"[Department of Engineering, Faculty of Science and Engineering, Manchester Metropolitan University, Manchester M1 5GD, United Kingdom.]","institution_ids":["https://openalex.org/I11983389"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5057364146"],"corresponding_institution_ids":["https://openalex.org/I11983389"],"apc_list":null,"apc_paid":null,"fwci":35.3549,"has_fulltext":false,"cited_by_count":312,"citation_normalized_percentile":{"value":0.9992295,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":100},"biblio":{"volume":"9","issue":"5","first_page":"3930","last_page":"3944"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10917","display_name":"Smart Grid Security and Resilience","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/2207","display_name":"Control and Systems Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.8721579909324646},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7713569402694702},{"id":"https://openalex.org/keywords/internet-of-things","display_name":"Internet of Things","score":0.6483387351036072},{"id":"https://openalex.org/keywords/enhanced-data-rates-for-gsm-evolution","display_name":"Enhanced Data Rates for GSM Evolution","score":0.5620316863059998},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5160081386566162},{"id":"https://openalex.org/keywords/edge-computing","display_name":"Edge computing","score":0.5100849270820618},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.49294185638427734},{"id":"https://openalex.org/keywords/edge-device","display_name":"Edge device","score":0.47371596097946167},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.4276581406593323},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.2970191240310669},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.19233497977256775},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.18505212664604187},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.1551554799079895},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.13263779878616333}],"concepts":[{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.8721579909324646},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7713569402694702},{"id":"https://openalex.org/C81860439","wikidata":"https://www.wikidata.org/wiki/Q251212","display_name":"Internet of Things","level":2,"score":0.6483387351036072},{"id":"https://openalex.org/C162307627","wikidata":"https://www.wikidata.org/wiki/Q204833","display_name":"Enhanced Data Rates for GSM Evolution","level":2,"score":0.5620316863059998},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5160081386566162},{"id":"https://openalex.org/C2778456923","wikidata":"https://www.wikidata.org/wiki/Q5337692","display_name":"Edge computing","level":3,"score":0.5100849270820618},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.49294185638427734},{"id":"https://openalex.org/C138236772","wikidata":"https://www.wikidata.org/wiki/Q25098575","display_name":"Edge device","level":3,"score":0.47371596097946167},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.4276581406593323},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.2970191240310669},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.19233497977256775},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.18505212664604187},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.1551554799079895},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.13263779878616333}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/jiot.2021.3100755","is_oa":false,"landing_page_url":"https://doi.org/10.1109/jiot.2021.3100755","pdf_url":null,"source":{"id":"https://openalex.org/S2480266640","display_name":"IEEE Internet of Things Journal","issn_l":"2327-4662","issn":["2327-4662","2372-2541"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Internet of Things Journal","raw_type":"journal-article"},{"id":"pmh:oai:e-space.mmu.ac.uk:628278","is_oa":true,"landing_page_url":"https://e-space.mmu.ac.uk/view/authors/c8a0550b6d0833d32b050bfeb864a412.html>","pdf_url":"https://e-space.mmu.ac.uk/628278/7/FDL_for_Botnet_Attack_Detection_in_IoT_Edge_Devices%20e.pdf","source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"PeerReviewed"}],"best_oa_location":{"id":"pmh:oai:e-space.mmu.ac.uk:628278","is_oa":true,"landing_page_url":"https://e-space.mmu.ac.uk/view/authors/c8a0550b6d0833d32b050bfeb864a412.html>","pdf_url":"https://e-space.mmu.ac.uk/628278/7/FDL_for_Botnet_Attack_Detection_in_IoT_Edge_Devices%20e.pdf","source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"PeerReviewed"},"sustainable_development_goals":[{"score":0.6299999952316284,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G1642956914","display_name":null,"funder_award_id":"7454460","funder_id":"https://openalex.org/F4320312933","funder_display_name":"Department for Business, Energy and Industrial Strategy, UK Government"}],"funders":[{"id":"https://openalex.org/F4320311699","display_name":"Manchester Metropolitan University","ror":"https://ror.org/02hstj355"},{"id":"https://openalex.org/F4320312933","display_name":"Department for Business, Energy and Industrial Strategy, UK Government","ror":"https://ror.org/019ya6433"}],"has_content":{"grobid_xml":false,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3185153723.pdf"},"referenced_works_count":56,"referenced_works":["https://openalex.org/W1522301498","https://openalex.org/W1677182931","https://openalex.org/W2290944024","https://openalex.org/W2541884796","https://openalex.org/W2586432806","https://openalex.org/W2733765803","https://openalex.org/W2752533296","https://openalex.org/W2799758613","https://openalex.org/W2945566856","https://openalex.org/W2962621836","https://openalex.org/W2962814013","https://openalex.org/W2963748489","https://openalex.org/W2982426954","https://openalex.org/W2991507433","https://openalex.org/W3008631145","https://openalex.org/W3014810737","https://openalex.org/W3016980352","https://openalex.org/W3027095011","https://openalex.org/W3030742901","https://openalex.org/W3036078548","https://openalex.org/W3045398511","https://openalex.org/W3082551002","https://openalex.org/W3083130672","https://openalex.org/W3086579950","https://openalex.org/W3090327961","https://openalex.org/W3092144916","https://openalex.org/W3092448674","https://openalex.org/W3094151218","https://openalex.org/W3094254938","https://openalex.org/W3095460055","https://openalex.org/W3095531713","https://openalex.org/W3098486933","https://openalex.org/W3100144320","https://openalex.org/W3107566242","https://openalex.org/W3108027302","https://openalex.org/W3111563271","https://openalex.org/W3112006757","https://openalex.org/W3113308842","https://openalex.org/W3117906366","https://openalex.org/W3121022046","https://openalex.org/W3122864121","https://openalex.org/W3130916947","https://openalex.org/W3134843574","https://openalex.org/W3143219202","https://openalex.org/W3151872461","https://openalex.org/W3153204276","https://openalex.org/W3154459044","https://openalex.org/W3157156764","https://openalex.org/W3157680283","https://openalex.org/W3158350046","https://openalex.org/W3159151987","https://openalex.org/W3163848339","https://openalex.org/W3169649651","https://openalex.org/W3186826072","https://openalex.org/W6728757088","https://openalex.org/W6781689429"],"related_works":["https://openalex.org/W4324372666","https://openalex.org/W4225706866","https://openalex.org/W2914646191","https://openalex.org/W4322761281","https://openalex.org/W4238233472","https://openalex.org/W4313339048","https://openalex.org/W3111395152","https://openalex.org/W4386004629","https://openalex.org/W3023564924","https://openalex.org/W2942586735"],"abstract_inverted_index":{"Deep":[0],"learning":[1],"(DL)":[2],"has":[3,174,190],"been":[4],"widely":[5],"proposed":[6],"for":[7,54,79,182],"botnet":[8,33,56,136,161],"attack":[9,34,57,137],"detection":[10,58],"in":[11,64,96,139,206],"Internet":[12],"of":[13,41,92,122,185],"Things":[14],"(IoT)":[15],"networks.":[16],"However,":[17],"the":[18,29,37,42,49,89,93,101,126,131,145,155,183,195],"traditional":[19],"centralized":[20],"DL":[21,51,204],"(CDL)":[22],"method":[23,53,197],"cannot":[24],"be":[25],"used":[26,107],"to":[27,59,108],"detect":[28],"previously":[30],"unknown":[31],"(zero-day)":[32],"without":[35],"breaching":[36],"data":[38,61,149,169],"privacy":[39,62,170],"rights":[40],"users.":[43],"In":[44,67],"this":[45,68,207],"article,":[46],"we":[47],"propose":[48],"federated":[50,102],"(FDL)":[52],"zero-day":[55,135,160],"avoid":[60],"leakage":[63],"IoT-edge":[65,98,132,140],"devices.":[66,133],"method,":[69],"an":[70],"optimal":[71],"deep":[72],"neural":[73],"network":[74,80,192],"(DNN)":[75],"architecture":[76],"is":[77,106,117,142],"employed":[78],"traffic":[81],"classification.":[82],"A":[83,113],"model":[84,111,116,127],"parameter":[85,128],"server":[86,129],"remotely":[87],"coordinates":[88],"independent":[90],"training":[91,186],"DNN":[94,115],"models":[95],"multiple":[97],"devices,":[99],"while":[100],"averaging":[103],"(FedAvg)":[104],"algorithm":[105],"aggregate":[109],"local":[110],"updates.":[112],"global":[114],"produced":[118],"after":[119],"a":[120],"number":[121],"communication":[123,176],"rounds":[124],"between":[125],"and":[130,147,171,188,202],"The":[134],"scenarios":[138],"devices":[141],"simulated":[143],"with":[144,163],"Bot-IoT":[146],"N-BaIoT":[148],"sets.":[150],"Experiment":[151],"results":[152],"show":[153],"that":[154],"FDL":[156,196],"model:":[157],"1)":[158],"detects":[159],"attacks":[162],"high":[164],"classification":[165],"performance;":[166],"2)":[167],"guarantees":[168],"security;":[172],"3)":[173],"low":[175,191],"overhead;":[177],"4)":[178],"requires":[179],"low-memory":[180],"space":[181],"storage":[184],"data;":[187],"5)":[189],"latency.":[193],"Therefore,":[194],"outperformed":[198],"CDL,":[199],"localized":[200],"DL,":[201],"distributed":[203],"methods":[205],"application":[208],"scenario.":[209]},"counts_by_year":[{"year":2026,"cited_by_count":10},{"year":2025,"cited_by_count":81},{"year":2024,"cited_by_count":80},{"year":2023,"cited_by_count":87},{"year":2022,"cited_by_count":47},{"year":2021,"cited_by_count":7}],"updated_date":"2026-04-05T17:49:38.594831","created_date":"2025-10-10T00:00:00"}
