首个跨域IoT僵尸网络检测基准,解决多数据集训练难题。
BRIDGE and TCH-Net: Heterogeneous Benchmark and Multi-Branch Baseline for Cross-Domain IoT Botnet Detection

- 构建统一语义特征空间的异构数据集基准BRIDGE,支持5个真实数据集融合。
- 提出TCH-Net多分支网络,在跨域测试中达F1=0.8296,显著优于12种基线。
- 首次建立社区通用性基线(LODO F1=0.5577),推动模型泛化研究。
IoT僵尸网络检测虽有进展,但多数系统仅在单一数据集上验证,难以跨环境泛化。异构特征空间使多数据集训练几乎不可能,且常牺牲语义可解释性或引发数据完整性问题。本文首次提出正式可复现的方法。引入BRIDGE(IoT领域泛化评估基准),首个形式化定义的异构多数据集基准,通过46维语义规范词汇表整合CICIDS-2017、CIC-IoT-2023、Bot-IoT、Edge-IIoTset和N-BaIoT,基于CICFlowMeter命名体系,采用仅等价映射、显式零填充,各数据集覆盖率达15%至93%。采用留一数据集外(LODO)协议,精确测量泛化差距:所有五种架构的平均LODO F1为0.39至0.47,建立首个社区泛化基线,均值为0.5577。提出TCH-Net多分支网络,融合三路径时序分支(残差卷积-BiGRU、步长下采样BiGRU、预归一化Transformer)、溯源条件上下文分支与统计分支,通过交叉分支门控注意力融合(CB-GAF)实现动态特征加权。在五次随机种子下,TCH-Net取得F1=0.8296±0.0028,AUC=0.9380±0.0025,MCC=0.6972±0.0056,显著优于12种基线(p<0.05,Wilcoxon),LODO F1最高。BRIDGE及完整流程开源:https://github.com/Ammar-ss/TCH-Net。
原文摘要 · Abstract (English)
IoT botnet detection has advanced, yet most published systems are validated on a single dataset and rarely generalise across environments. Heterogeneous feature spaces make multi-dataset training practically impossible without discarding semantic interpretability or introducing data integrity violations. No prior work has addressed both problems with a formally specified, reproducible methodology. This paper does. We introduce BRIDGE (Benchmark Reference for IoT Domain Generalisation Evaluation), the first formally specified heterogeneous multi-dataset benchmark for IoT intrusion detection, unifying CICIDS-2017, CIC-IoT-2023, Bot-IoT, Edge-IIoTset, and N-BaIoT through a 46-feature semantic canonical vocabulary grounded in CICFlowMeter nomenclature, with genuine-equivalence-only feature mapping, explicit zero-filling, and per-dataset coverage from 15% to 93%. A leave-one-dataset-out (LODO) protocol makes the generalisation gap precisely measurable: all five evaluated architectures achieve mean LODO F1 between 0.39 and 0.47, and we establish the first community generalisation baseline at mean LODO F1 = 0.5577, a result that shifts the agenda from single-benchmark optimisation toward cross-environment generalisation. We propose TCH-Net, a multi-branch network fusing a three-path Temporal branch (residual convolutional-BiGRU, stride-downsampled BiGRU, pre-LayerNorm Transformer), a provenance-conditioned Contextual branch, and a Statistical branch via Cross-Branch Gated Attention Fusion (CB-GAF) with learnable sigmoid gates for dynamic feature-wise mixing. Across five random seeds, TCH-Net achieves F1 = 0.8296 +/- 0.0028, AUC = 0.9380 +/- 0.0025, and MCC = 0.6972 +/- 0.0056, outperforming all twelve baselines (p < 0.05, Wilcoxon) and recording the highest LODO F1 overall. BRIDGE and the full pipeline are at https://github.com/Ammar-ss/TCH-Net.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。