PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
March 6, 2026Scientific Reports0 citationsOpen Access

Application of representation learning in detecting botnet attacks

HNHieu Le Ngoc

Key Points

  • The aim is to develop a robust method for detecting botnet attacks using advanced representation learning techniques.
  • Introduced novel feature engineering methods, including octet splitting for IP addresses.
  • Utilized the Hilbert space-filling curve to transform network flows into 2D images.
  • Employed SMOTE and Focal Loss to address class imbalance in the training dataset.
  • Implemented cross-scenario validation using the Murlo botnet for training and Rbot for testing.
  • Achieved an accuracy of 98.34% on the unseen Rbot botnet.
  • Obtained a weighted F1-score of 98.38%, indicating strong model performance.
  • Demonstrated superior generalization capabilities compared to traditional detection models.

Abstract

Botnet detection remains a perennial and critical challenge in cybersecurity. As long as the internet exists, threat actors will devise new ways to create and disguise these malicious networks, making the development of robust detection methods a task that will never be obsolete. Traditional approaches, relying on rigid signatures and manual feature engineering, are often locked in a reactive cycle. A more critical limitation is their poor generalization; models trained on known botnets frequently fail to detect novel, unseen threats, rendering them vulnerable in real-world scenarios. This paper introduces a robust framework that significantly enhances botnet detection by overcoming these limitations. We propose a novel methodology that combines advanced feature engineering, such as octet splitting for IP addresses, with a sophisticated representation learning technique using the Hilbert space-filling curve to transform network flows into 2D images. This approach preserves data locality and eliminates the noise introduced by traditional zero-padding. Furthermore, we address the critical issue of class imbalance using a combination of SMOTE, a weighted sampler, and Focal Loss to focus the model on more challenging samples. To rigorously evaluate the model's real-world applicability, we employed a challenging cross-scenario validation strategy, training the model on the Murlo botnet (Scenario 8) and testing it on the completely unseen Rbot botnet (Scenario 10) from the publicly available CTU-13 dataset. Our proposed model achieved an outstanding accuracy of 98.34% and a weighted F1-score of 98.38%, demonstrating a remarkable ability to generalize to novel botnet attacks. This result validates our approach and highlights the superiority of learned, spatially-aware representations over traditional models, which failed to detect the unseen botnet. Our work presents a significant step towards creating more adaptive and resilient intrusion detection systems capable of handling novel, unseen botnet families.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Hieu Le Ngoc (2026) studied this question.

synapsesocial.com/papers/69aa70a9531e4c4a9ff5a9cfhttps://doi.org/10.1038/s41598-026-40172-8
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Enhancing botnet attack detection using a hybrid deep learning model combining network flow and DNS query features with explainable AI for cybersecurity2026
  2. 2Comprehensive Botnet Detection by Mitigating Adversarial Attacks, Navigating the Subtleties of Perturbation Distances and Fortifying Predictions with Conformal Layers2024 · 4 citations
  3. 3Machine Learning Approaches for Botnet Detection in Network Traffic2024 · 2 citations
  4. 4Fortifying Network Security: Pioneering Hybrid Machine Learning for BotNet Attack Detection2024
  5. 5Robust and Noise-Resilient Botnet Detection Framework Using Heterogeneous Radial Basis Function Neural Network2026