IoT Botnet Detection: Application of Vision Transformer to Classification of Network Flow Traffic

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Wasswa, Hassan, Lynar, Timothy, Nanyonga, Aziida, Abbass, Hussein
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866912347239481344
author Wasswa, Hassan
Lynar, Timothy
Nanyonga, Aziida
Abbass, Hussein
author_facet Wasswa, Hassan
Lynar, Timothy
Nanyonga, Aziida
Abbass, Hussein
contents Despite the demonstrated effectiveness of transformer models in NLP, and image and video classification, the available tools for extracting features from captured IoT network flow packets fail to capture sequential patterns in addition to the absence of spatial patterns consequently limiting transformer model application. This work introduces a novel preprocessing method to adapt transformer models, the vision transformer (ViT) in particular, for IoT botnet attack detection using network flow packets. The approach involves feature extraction from .pcap files and transforming each instance into a 1-channel 2D image shape, enabling ViT-based classification. Also, the ViT model was enhanced to allow use any classifier besides Multilayer Perceptron (MLP) that was deployed in the initial ViT paper. Models including the conventional feed forward Deep Neural Network (DNN), LSTM and Bidirectional-LSTM (BLSTM) demonstrated competitive performance in terms of precision, recall, and F1-score for multiclass-based attack detection when evaluated on two IoT attack datasets.
format Preprint
id arxiv_https___arxiv_org_abs_2504_18781
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle IoT Botnet Detection: Application of Vision Transformer to Classification of Network Flow Traffic
Wasswa, Hassan
Lynar, Timothy
Nanyonga, Aziida
Abbass, Hussein
Computer Vision and Pattern Recognition
Artificial Intelligence
Despite the demonstrated effectiveness of transformer models in NLP, and image and video classification, the available tools for extracting features from captured IoT network flow packets fail to capture sequential patterns in addition to the absence of spatial patterns consequently limiting transformer model application. This work introduces a novel preprocessing method to adapt transformer models, the vision transformer (ViT) in particular, for IoT botnet attack detection using network flow packets. The approach involves feature extraction from .pcap files and transforming each instance into a 1-channel 2D image shape, enabling ViT-based classification. Also, the ViT model was enhanced to allow use any classifier besides Multilayer Perceptron (MLP) that was deployed in the initial ViT paper. Models including the conventional feed forward Deep Neural Network (DNN), LSTM and Bidirectional-LSTM (BLSTM) demonstrated competitive performance in terms of precision, recall, and F1-score for multiclass-based attack detection when evaluated on two IoT attack datasets.
title IoT Botnet Detection: Application of Vision Transformer to Classification of Network Flow Traffic
topic Computer Vision and Pattern Recognition
Artificial Intelligence
url https://arxiv.org/abs/2504.18781