CORTEXA
← Browse
crossrefSensors2026-03-10Cited by 8

Systematic Evaluation of Machine Learning and Deep Learning Models for IoT Malware Detection Across Ransomware, Rootkit, Spyware, Trojan, Botnet, Worm, Virus, and Keylogger

Mazdak Maghanaki, Soraya Keramati, F. Frank Chen, Mohammad Shahin

The rapid growth of Internet-of-Things (IoT) deployments has substantially expanded the attack surface of modern cyber–physical systems, making accurate and computationally feasible malware detection essential for enterprise and industrial environments. This study presents a large-scale, systematic comparison of 27 machine learning (ML) and 18 deep learning (DL) models for IoT malware detection across eight major malware categories: Trojan, Botnet, Ransomware, Rootkit, Worm, Spyware, Keylogger, and Virus. A realistic dataset was constructed using 50,000 executable samples collected from the Any.Run platform, including 8000 malware instances (1000 per class) and 42,000 benign samples. Each sample was executed in a sandbox to extract detailed static and behavioral telemetry. A targeted feature-selection pipeline reduced the feature space to 47 diagnostic features spanning static properties, behavioral indicators, process/file/registry activity, debug signals, and network telemetry, yielding a compact representation suitable for malware detection in IoT settings. Experimental results demonstrate that ensemble tree-based ML models consistently dominate performance on the engineered tabular feature set as 7 of the top 10 models are ML, with CatBoost and LightGBM achieving near-ceiling accuracy and low false-positive rates. Per-malware analysis further shows that optimal model choice depends on malware behavior. CatBoost is best for Trojan/Spyware, LightGBM for Botnet, XGBoost for Worm, Extra Trees for Rootkit, and Random Forest for Keylogger, while DL models are competitive only for specific categories, with TabNet performing best for Ransomware and FT-Transformer for Virus. In addition, an end-to-end computational time analysis across all 45 models reveals a clear efficiency advantage for boosted tree ensembles relative to most DL architectures, supporting deployment feasibility on commodity CPU hardware. Overall, the study provides actionable guidance for designing adaptive IoT malware detection frameworks, recommending gradient-boosted ensemble ML models as the primary deployment choice, with selective DL models only when category-specific gains justify additional computational cost.

View free PDFSource page

Related papers

crossrefSensors2025-08-15Cited by 2

A Comparative Study of Hybrid Machine-Learning vs. Deep-Learning Approaches for Varroa Mite Detection and Counting

Amira Ghezal, Andreas König

This study presents a comparative evaluation of traditional machine-learning (ML) and deep-learning (DL) approaches for detecting and counting Varroa destructor mites in hyperspectral images. As Varroa infestations pose a serious threat to honeybee health, accurate and efficient…

View free PDFSource page
crossrefSensors2025-12-26

The Impact of the Accelerometer Sampling Rate on the Performance of Machine and Deep Learning Models in Wearable Fall-Detection Systems

Manny Villa, Eduardo Casilari

Population aging has intensified the prevalence of falls among older adults, making automatic Fall Detection Systems (FDS) a key component of telemonitoring and remote care. Among wearable-based approaches, inertial sensors, particularly accelerometers, offer an effective and low…

View free PDFSource page
crossrefSensors2026-02-13Cited by 2

A Comparative Study of Machine Learning and Deep Learning Models for Long-Term Snow Depth Inversion

Tingyu Lu, Rong Fan, Lijuan Zhang, Qiang Wang, Yufeng Zhao, Lei Wang, et al.

Snow depth is a critical parameter for characterizing snow dynamics and water resources, and its accurate inversion is essential for hydrological processes, climate studies, and disaster prevention in cold regions. Based on long-term daily ground meteorological observation data f…

View free PDFSource page
crossrefSensors2026-06-18

Linking Tea Aroma Chemistry to Quality Grades via a Single MOS Gas Sensor: Classical Machine Learning vs. Deep Learning

Ahmet Turan Tasdemir, Erkan Caner Ozkat, Gozde Yalcin Ozkat, Fatih Gul

Black tea quality is governed by aroma chemistry: terpene alcohols (linalool, geraniol, nerolidol), methyl salicylate, and short-chain aldehydes whose abundance and release kinetics from the polyphenol-rich leaf matrix shape perceived grade. Grade information lies not only in the…

View free PDFSource page
crossrefSensors2026-03-05

Statistical Feature Engineering for Robot Failure Detection: A Comparative Study of Machine Learning and Deep Learning Classifiers

Sertaç Savaş

Industrial robots are widely used in critical tasks such as assembly, welding, and material handling as core components of modern manufacturing systems. For the reliable operation of these systems, early and accurate detection of execution failures is crucial. In this study, a co…

View free PDFSource page
crossrefSensors2025-07-05Cited by 11

Human-Centric Cognitive State Recognition Using Physiological Signals: A Systematic Review of Machine Learning Strategies Across Application Domains

Kaizhe Jin, Adrian Rubio-Solis, Ravi Naik, Daniel Leff, James Kinross, George Mylonas

This systematic review analyses advancements in cognitive state recognition from 2010 to early 2024, evaluating 405 relevant articles from an initial pool of 2398 records identified through five databases: Scopus, Engineering Village, Web of Science, IEEE Xplore, and PubMed. Stud…

View free PDFSource page