An Adaptive Sample-Weighting Framework for Imbalanced IoT Malware Family Classification

Sufyan ALDABBAGH

Abstract


The extensive adoption of IoT devices raises the risk of malware attacks on IoT environments. Moreover, the increasing variety of malware families highlights the need for efficient malware family-level classification for network protection. However, the severe class imbalance problem when some major malware families represent the majority of the data while some minor families include only few instances of malware represents a challenging issue of IoT malware-family classification. Traditional machine-learning-based classifiers may demonstrate high overall accuracy but lack satisfactory performance in recognizing minority classes under imbalanced conditions. This paper introduces the approach of sample-weighting adjustment for imbalanced malware family-level classification without generating artificial instances or eliminating any existing instances. The approach is tested on the ARM subset of the CIC-YNU-IoTMal 2026 dataset, which includes 737,651 records divided between eight classes related to malware. XGBoost is used as the basic classifier model and two variations – one including all 36 features and another one with 22 features – are investigated. The accuracy of the standard 36 feature XGBoost model is 72.01%, whereas the balanced accuracy and macro-F1 score of this model are 23.37% and 20.99%, respectively, proving the insufficiency of accuracy in the presence of extreme class imbalance. On the other hand, the adaptive weight assignment technique has been able to increase the balanced accuracy to 41.43% and macro-F1 to 27.51%, which are 18.06 and 6.52 percent higher than the previous case. The 22 feature adaptive model is able to achieve similar balanced accuracy of 41.45%, proving that this smaller representation is also capable of carrying the classification capabilities of the full set of features in the context of class imbalance. Even though the adaptive method reduces the accuracy of the model, the results obtained show its capacity to improve minority class recognition without changing the size of the dataset.

Keywords


adaptive sample weighting; CIC-YNU-IoTMal 2026; class imbalance; cybersecurity; imbalanced learning; internet of things (IoT); machine learning; malware classification; malware family classification; XGBoost

Full Text:

PDF

References


M. Rabbani, J. Gui, F. Nejati, Z. Zhou, A. Kaniyamattam, M. Mirani, G. Piya, I. V. Opushnyev, R. Lu, and A. A. Ghorbani, “Device Identification and Anomaly Detection in IoT Environments,” IEEE Internet Things J., Vol. 12, No. 10, pp. 13625–13643, 2025, DOI: 10.1109/JIOT.2024.3522863.

M. A. Abuzaraida, S. A. L. Gaud, H. A. Hneish, and Z. S. Attarbashi, “Brewing Perfection: Real-Time Monitoring of Arabic Coffee using IoT and Machine Learning,” in Selected Papers from the International Conference on Artificial Intelligence, A. O. Albaji, Ed., Studies in Computational Intelligence, Vol. 1229. Cham, Switzerland: Springer, 2026, DOI: 10.1007/978-3-032-00232-7_32.

M. A. N. B. M. Tamron, Z. S. Attarbashi, M. A. Abuzaraida, N. Atitallah, S. Iftikhar, D. O. D. Handayani, and A. B. B. Basri, “IoT-based Heartbeats Monitoring System,” in Proc. 2023 IEEE 9th Int. Conf. Comput., Eng. Design (ICCED), Kuala Lumpur, Malaysia, 2023, pp. 1–5, DOI: 10.1109/ICCED60214.2023.10425281.

A. Alkandari, A. Alfoudery, M. A. Abuzaraida, and A. Alshehab, “Smart Automated Robot Changing Tires using Ultrasonic Sensors,” Int. J. Eng. Trends Technol., Vol. 71, No. 5, pp. 166–174, 2023, DOI: 10.14445/22315381/IJETT-V71I5P217.

Z. S. Attarbashi, T. A.-L. Thamodharan, M. A. Abuzaraida, S. Iftikhar, N. A. Alansari, A. B. B. Basri, and D. O. D. Handayani, “Using IoT-based Mobile Application to Build Smart Parking System,” in Proc. 2023 IEEE 9th Int. Conf. Comput., Eng. Design (ICCED), Kuala Lumpur, Malaysia, 2023, pp. 1–6, DOI: 10.1109/ICCED60214.2023.10425326.

M. A. Abuzaraida, N. A. H. Hilmy, N. F. M. Yaziz, and N. Alya, “IoT-Integrated Accident Detection and Automated Emergency Alert System,” International Grand Invention, Innovation and Design Expo (IGIIDEATION) 2026, p. 124, 2026.

Canadian Institute for Cybersecurity and Yunnan University, “CIC-YNU-IoTMal 2026,” University of New Brunswick, 2026. [Online]. Available: University of New Brunswick CIC dataset website.

R. Chaganti, V. Ravi, and T. D. Pham, “Deep Learning based Cross Architecture Internet of Things Malware Detection and Classification,” Comput. Secur., Vol. 120, Art. No. 102779, 2022, DOI: 10.1016/j.cose.2022.102779.

C. Wang, Z. Zhao, F. Wang, and Q. Li, “MSAAM: A Multiscale Adaptive Attention Module for IoT Malware Detection and family classification,” Secur. Commun. Netw., Vol. 2022, Art. No. 2206917, 2022, DOI: 10.1155/2022/2206917.

“Classification of Malware for Security Improvement in IoT using Heuristic Aided Adaptive Multi-Scale and Dilated ResNeXt with Gated Recurrent Unit,” Appl. Soft Comput., Vol. 163, Art. No. 111838, 2024, DOI: 10.1016/j.asoc.2024.111838.

M. R. B. Mosleh and S. Sharifian, “An Efficient Cloud-Integrated Distributed Deep Neural Network Framework for IoT Malware Classification,” Future Gener. Comput. Syst., Vol. 157, pp. 603–617, 2024, DOI: 10.1016/j.future.2024.03.051.

T. Shi, R. A. McCann, Y. Huang, W. Wang, and J. Kong, “Malware Detection for Internet of Things using One-Class Classification,” Sensors, Vol. 24, No. 13, Art. No. 4122, 2024, DOI: 10.3390/s24134122.

“Deep Image: A Precious Image based Deep Learning Method for Online Malware Detection in IoT Environment,” Internet Things, Vol. 27, Art. No. 101300, 2024, DOI: 10.1016/j.iot.2024.101300.

S. U. Qureshi, J. He, S. Tunio, N. Zhu, A. Nazir, A. Wajahat, F. Ullah, and A. Wadud, “Systematic Review of Deep Learning Solutions for Malware Detection and Forensic Analysis in IoT,” J. King Saud Univ. Comput. Inf. SCI., Vol. 36, No. 8, Art. No. 102164, 2024, DOI: 10.1016/j.jksuci.2024.102164.




DOI: https://doi.org/10.32520/stmsi.v15i9.6932

Article Metrics

Abstract view : 0 times
PDF - 0 times

Refbacks

  • There are currently no refbacks.


Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.