CORTEXA
← Browse
crossrefSensors2026-03-10Cited by 8

Systematic Evaluation of Machine Learning and Deep Learning Models for IoT Malware Detection Across Ransomware, Rootkit, Spyware, Trojan, Botnet, Worm, Virus, and Keylogger

Mazdak Maghanaki, Soraya Keramati, F. Frank Chen, Mohammad Shahin

The rapid growth of Internet-of-Things (IoT) deployments has substantially expanded the attack surface of modern cyber–physical systems, making accurate and computationally feasible malware detection essential for enterprise and industrial environments. This study presents a large-scale, systematic comparison of 27 machine learning (ML) and 18 deep learning (DL) models for IoT malware detection across eight major malware categories: Trojan, Botnet, Ransomware, Rootkit, Worm, Spyware, Keylogger, and Virus. A realistic dataset was constructed using 50,000 executable samples collected from the Any.Run platform, including 8000 malware instances (1000 per class) and 42,000 benign samples. Each sample was executed in a sandbox to extract detailed static and behavioral telemetry. A targeted feature-selection pipeline reduced the feature space to 47 diagnostic features spanning static properties, behavioral indicators, process/file/registry activity, debug signals, and network telemetry, yielding a compact representation suitable for malware detection in IoT settings. Experimental results demonstrate that ensemble tree-based ML models consistently dominate performance on the engineered tabular feature set as 7 of the top 10 models are ML, with CatBoost and LightGBM achieving near-ceiling accuracy and low false-positive rates. Per-malware analysis further shows that optimal model choice depends on malware behavior. CatBoost is best for Trojan/Spyware, LightGBM for Botnet, XGBoost for Worm, Extra Trees for Rootkit, and Random Forest for Keylogger, while DL models are competitive only for specific categories, with TabNet performing best for Ransomware and FT-Transformer for Virus. In addition, an end-to-end computational time analysis across all 45 models reveals a clear efficiency advantage for boosted tree ensembles relative to most DL architectures, supporting deployment feasibility on commodity CPU hardware. Overall, the study provides actionable guidance for designing adaptive IoT malware detection frameworks, recommending gradient-boosted ensemble ML models as the primary deployment choice, with selective DL models only when category-specific gains justify additional computational cost.

View free PDFSource page

Related papers

crossrefSensors2024-08-16Cited by 10

Comparison of the Accuracy of Ground Reaction Force Component Estimation between Supervised Machine Learning and Deep Learning Methods Using Pressure Insoles

Amal Kammoun, Philippe Ravier, Olivier Buttelli

The three Ground Reaction Force (GRF) components can be estimated using pressure insole sensors. In this paper, we compare the accuracy of estimating GRF components for both feet using six methods: three Deep Learning (DL) methods (Artificial Neural Network, Long Short-Term Memor…

View free PDFSource page
crossrefSensors2025-04-26Cited by 38

Advanced Deep Learning and Machine Learning Techniques for MRI Brain Tumor Analysis: A Review

Rim Missaoui, Wided Hechkel, Wajdi Saadaoui, Abdelhamid Helali, Marco Leo

A brain tumor is the result of abnormal growth of cells in the central nervous system (CNS), widely considered as a complex and diverse clinical entity that is difficult to diagnose and cure. In this study, we focus on current advances in medical imaging, particularly magnetic re…

View free PDFSource page
crossrefSensors2024-11-27Cited by 7

Ultrasound Versus Elastography in the Diagnosis of Hepatic Steatosis: Evaluation of Traditional Machine Learning Versus Deep Learning

Rodrigo Marques, Jaime Santos, Alexandra André, José Silva

The prevalence of fatty liver disease is on the rise, posing a significant global health concern. If left untreated, it can progress into more serious liver diseases. Therefore, accurately diagnosing the condition at an early stage is essential for more effective intervention and…

View free PDFSource page
crossrefSensors2025-12-26

The Impact of the Accelerometer Sampling Rate on the Performance of Machine and Deep Learning Models in Wearable Fall-Detection Systems

Manny Villa, Eduardo Casilari

Population aging has intensified the prevalence of falls among older adults, making automatic Fall Detection Systems (FDS) a key component of telemonitoring and remote care. Among wearable-based approaches, inertial sensors, particularly accelerometers, offer an effective and low…

View free PDFSource page
crossrefSensors2024-05-24Cited by 4

Development of a Method for Soil Tilth Quality Evaluation from Crumbling Roller Baskets Using Deep Machine Learning Models

Mehari Z. Tekeste, Junxian Guo, Desale Habtezgi, Jia-Hao He, Marcin Waz

A combination tillage with disks, rippers, and roller baskets allows the loosening of compacted soils and the crumbling of soil clods. Statistical methods for evaluating the soil tilth quality of combination tillage are limited. Light Detection and Ranging (LiDAR) data and machin…

View free PDFSource page
crossrefSensors2024-02-08Cited by 17

Gait Characterization in Duchenne Muscular Dystrophy (DMD) Using a Single-Sensor Accelerometer: Classical Machine Learning and Deep Learning Approaches

Albara Ah Ramli, Xin Liu, Kelly Berndt, Erica Goude, Jiahui Hou, Lynea B. Kaethler, et al.

Differences in gait patterns of children with Duchenne muscular dystrophy (DMD) and typically developing (TD) peers are visible to the eye, but quantifications of those differences outside of the gait laboratory have been elusive. In this work, we measured vertical, mediolateral,…

View free PDFSource page