{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,3]],"date-time":"2026-01-03T14:50:46Z","timestamp":1767451846775,"version":"3.44.0"},"reference-count":25,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,7,29]],"date-time":"2025-07-29T00:00:00Z","timestamp":1753747200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,7,29]],"date-time":"2025-07-29T00:00:00Z","timestamp":1753747200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Manipal Academy of Higher Education, Manipal"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int J Comput Intell Syst"],"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>The proliferation of Internet of Things (IoT) devices has introduced significant security challenges, particularly concerning the detection and mitigation of malware threats. This study presents a systematic approach to malware detection that aims to improve both the security and performance of IoT systems. Using the IoT23 dataset, which contains a wide range of network traffic patterns from various IoT devices and malware families, the research explores and evaluates multiple machine learning techniques. These include ensemble methods such as Bagging, Stacking, Voting, AdaBoost, and H2O AutoML, as well as advanced models such as sparse neural networks with pruning and feature selection and regularized classifiers L1. The primary objective is to develop lightweight yet highly accurate models suitable for deployment on resource-constrained IoT devices. A comprehensive comparison of these techniques demonstrates the importance of achieving a balance between detection accuracy and computational efficiency. Among the models evaluated, the SNIPE approach shows the best performance, achieving an accuracy of 91.9% while maintaining minimal computational overhead. This makes it particularly well suited for real-world IoT environments, where performance and energy efficiency are critical. The findings of this study provide valuable insights for the development of robust, scalable, and resource-aware malware detection systems, laying a strong foundation for future research and practical cybersecurity solutions in the rapidly evolving IoT landscape.<\/jats:p>","DOI":"10.1007\/s44196-025-00939-9","type":"journal-article","created":{"date-parts":[[2025,7,29]],"date-time":"2025-07-29T04:25:10Z","timestamp":1753763110000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Systematic Approach for Malware Detection in IoT Devices: Enhancing Security and Performance"],"prefix":"10.1007","volume":"18","author":[{"given":"Vasudeva","family":"Pai","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"B. H.","family":"Karthik Pai","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"G. S.","family":"Sudhiksha","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vandya","family":"Kamath","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"K.","family":"Varsha","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"S.","family":"Manjunatha","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,7,29]]},"reference":[{"key":"939_CR1","doi-asserted-by":"crossref","unstructured":"Abbas, M.F.B., Srikanthan, T.: Low-complexity signature-based malware detection for IoT devices. In: Applications and Techniques in Information Security: 8th International Conference, ATIS 2017, Auckland, New Zealand, July 6\u20137, 2017, Proceedings, pp. 181-189. Springer, Singapore (2017)","DOI":"10.1007\/978-981-10-5421-1_15"},{"issue":"5","key":"939_CR2","doi-asserted-by":"publisher","first-page":"8182","DOI":"10.1109\/JIOT.2019.2935189","volume":"6","author":"F Meneghello","year":"2019","unstructured":"Meneghello, F., Calore, M., Zucchetto, D., Polese, M., Zanella, A.: IoT: internet of threats? A survey of practical security vulnerabilities in real IoT devices. IEEE Internet Things J. 6(5), 8182\u20138201 (2019)","journal-title":"IEEE Internet Things J."},{"key":"939_CR3","doi-asserted-by":"crossref","unstructured":"Nath, H.V., Mehtre, B.M.: Static malware analysis using machine learning methods. In: Recent Trends in Computer Networks and Distributed Systems Security: Second International Conference, SNDS: Trivandrum, India, March 13\u201314, 2014, Proceedings 2, pp. 440\u2013450. Springer, Berlin Heidelberg (2014)","DOI":"10.1007\/978-3-642-54525-2_39"},{"key":"939_CR4","doi-asserted-by":"publisher","first-page":"96899","DOI":"10.1109\/ACCESS.2020.2995887","volume":"8","author":"J Jeon","year":"2020","unstructured":"Jeon, J., Park, J.H., Jeong, Y.S.: Dynamic analysis for IoT malware detection with convolution neural network model. IEEE Access 8, 96899\u201396911 (2020)","journal-title":"IEEE Access"},{"issue":"1","key":"939_CR5","doi-asserted-by":"publisher","first-page":"71","DOI":"10.1007\/s10207-019-00437-y","volume":"19","author":"H Takase","year":"2020","unstructured":"Takase, H., Kobayashi, R., Kato, M., Ohmura, R.: A prototype implementation and evaluation of the malware detection mechanism for IoT devices using the processor information. Int. J. Inf. Secur. 19(1), 71\u201381 (2020)","journal-title":"Int. J. Inf. Secur."},{"key":"939_CR6","doi-asserted-by":"publisher","first-page":"262","DOI":"10.1109\/OJCS.2020.3033974","volume":"1","author":"TL Wan","year":"2020","unstructured":"Wan, T.L., Ban, T., Cheng, S.M., Lee, Y.T., Sun, B., Isawa, R., Inoue, D.: Efficient detection and classification of internet-of-things malware based on byte sequences from executable files. IEEE Open J. Comput. Soc. 1, 262\u2013275 (2020)","journal-title":"IEEE Open J. Comput. Soc."},{"issue":"5","key":"939_CR7","doi-asserted-by":"publisher","first-page":"3770","DOI":"10.1109\/JIOT.2021.3100063","volume":"9","author":"B Yuan","year":"2021","unstructured":"Yuan, B., Wang, J., Wu, P., Qing, X.: IoT malware classification based on lightweight convolutional neural networks. IEEE Internet Things J. 9(5), 3770\u20133783 (2021)","journal-title":"IEEE Internet Things J."},{"key":"939_CR8","doi-asserted-by":"publisher","first-page":"108693","DOI":"10.1016\/j.comnet.2021.108693","volume":"204","author":"V Rey","year":"2022","unstructured":"Rey, V., S\u00e1nchez, P.M.S., Celdr\u00e1n, A.H., Bovet, G.: Federated learning for malware detection in IoT devices. Comput. Netw. 204, 108693 (2022)","journal-title":"Comput. Netw."},{"issue":"6249","key":"939_CR9","first-page":"6271","volume":"8","author":"\u00d6A Aslan","year":"2020","unstructured":"Aslan, \u00d6.A., Samet, R.: A comprehensive review of malware detection approaches. IEEE Access 8(6249), 6271 (2020)","journal-title":"IEEE Access"},{"issue":"4","key":"939_CR10","doi-asserted-by":"publisher","first-page":"280","DOI":"10.1016\/j.icte.2020.04.005","volume":"6","author":"QD Ngo","year":"2020","unstructured":"Ngo, Q.D., Nguyen, H.T., Le, V.H., Nguyen, D.H.: A survey of IoT malware and detection methods based on static features. ICT Express 6(4), 280\u2013286 (2020)","journal-title":"ICT Express"},{"key":"939_CR11","doi-asserted-by":"publisher","first-page":"141045","DOI":"10.1109\/ACCESS.2023.3256979","volume":"11","author":"NZ Gorment","year":"2023","unstructured":"Gorment, N.Z., Selamat, A., Cheng, L.K., Krejcar, O.: Machine learning algorithm for malware detection: taxonomy, current challenges and future directions. IEEE Access 11, 141045\u2013141089 (2023)","journal-title":"IEEE Access"},{"issue":"24","key":"939_CR12","doi-asserted-by":"publisher","first-page":"4147","DOI":"10.3390\/electronics11244147","volume":"11","author":"AR Khan","year":"2022","unstructured":"Khan, A.R., Yasin, A., Usman, S.M., Hussain, S., Khalid, S., Ullah, S.S.: Exploring lightweight deep learning solution for malware detection in IoT constraint environment. Electronics 11(24), 4147 (2022)","journal-title":"Electronics"},{"issue":"1","key":"939_CR13","doi-asserted-by":"publisher","first-page":"88","DOI":"10.1109\/TSUSC.2018.2809665","volume":"4","author":"A Azmoodeh","year":"2018","unstructured":"Azmoodeh, A., Dehghantanha, A., Choo, K.K.R.: Robust malware detection for internet of (battlefield) things devices using deep eigenspace learning. IEEE Trans. Sustain. Comput. 4(1), 88\u201395 (2018)","journal-title":"IEEE Trans. Sustain. Comput."},{"issue":"1","key":"939_CR14","volume":"1818","author":"P Sudhakaran","year":"2021","unstructured":"Sudhakaran, P., Malathy, C., Vardhan, T.H., Sainadh, T.: Detection of malware from IOT devices using deep learning techniques. J. Phys: Conf. Ser. 1818(1), 012219 (2021)","journal-title":"J. Phys: Conf. Ser."},{"key":"939_CR15","doi-asserted-by":"crossref","unstructured":"Mehrban, A., Ahadian, P.: Malware detection in IOT systems using machine learning techniques. arXiv preprint arXiv:2312.17683 (2023)","DOI":"10.5121\/ijwmn.2023.15602"},{"key":"939_CR16","doi-asserted-by":"publisher","first-page":"102526","DOI":"10.1016\/j.jnca.2019.102526","volume":"153","author":"D Gibert","year":"2020","unstructured":"Gibert, D., Mateu, C., Planes, J.: The rise of machine learning for detection and classification of malware: research developments, trends and challenges. J. Netw. Comput. Appl. 153, 102526 (2020)","journal-title":"J. Netw. Comput. Appl."},{"key":"939_CR17","doi-asserted-by":"crossref","unstructured":"Pai, V., Rao, A.S., Devidas, Prapthi, B.: An intelligent behavior-based system to recognize and detect the malware variants based on their characteristics using machine learning techniques. In: International Conference on Advanced Network Technologies and Intelligent Computing, pp. 73-88. Springer Nature Switzerland, Cham (2022)","DOI":"10.1007\/978-3-031-28180-8_6"},{"issue":"1","key":"939_CR18","doi-asserted-by":"publisher","DOI":"10.1088\/1757-899X\/1013\/1\/012038","volume":"1013","author":"V Pai","year":"2021","unstructured":"Pai, V., Adesh, N.D.: Comparative analysis of machine learning algorithms for intrusion detection. IOP Conf. Ser. Mater. Sci. Eng. 1013(1), 012038 (2021)","journal-title":"IOP Conf. Ser. Mater. Sci. Eng."},{"issue":"12","key":"939_CR19","doi-asserted-by":"publisher","first-page":"771","DOI":"10.1016\/j.ifacol.2022.07.406","volume":"55","author":"M Chemmakha","year":"2022","unstructured":"Chemmakha, M., Habibi, O., Lazaar, M.: Improving machine learning models for malware detection using embedded feature selection method. IFAC-PapersOnLine 55(12), 771\u2013776 (2022)","journal-title":"IFAC-PapersOnLine"},{"key":"939_CR20","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2024.123808","author":"H Nandanwar","year":"2024","unstructured":"Nandanwar, H., Katarya, R.: Deep learning enabled intrusion detection system for Industrial IOT environment. Expert Syst. Appl. (2024). https:\/\/doi.org\/10.1016\/j.eswa.2024.123808","journal-title":"Expert Syst. Appl."},{"key":"939_CR21","doi-asserted-by":"publisher","first-page":"1251","DOI":"10.1007\/s10207-023-00787-8","volume":"23","author":"H Nandanwar","year":"2024","unstructured":"Nandanwar, H., Katarya, R.: TL-BILSTM IoT: transfer learning model for prediction of intrusion detection system in IoT environment. Int. J. Inf. Secur. 23, 1251\u20131277 (2024). https:\/\/doi.org\/10.1007\/s10207-023-00787-8","journal-title":"Int. J. Inf. Secur."},{"key":"939_CR22","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2025.110161","author":"H Nandanwar","year":"2025","unstructured":"Nandanwar, H., Katarya, R.: Securing Industry 5.0: an explainable deep learning model for intrusion detection in cyber-physical systems. Comput. Electr. Eng. (2025). https:\/\/doi.org\/10.1016\/j.compeleceng.2025.110161","journal-title":"Comput. Electr. Eng."},{"key":"939_CR23","doi-asserted-by":"publisher","unstructured":"Kauhsik, B., Nandanwar, H., Katarya, R.: IoT Security: a deep learning-based approach for intrusion detection and prevention. In: 2023 International Conference on Evolutionary Algorithms and Soft Computing Techniques (EASCT), Bengaluru, India, pp. 1\u20137 (2023). https:\/\/doi.org\/10.1109\/EASCT59475.2023.10392490.","DOI":"10.1109\/EASCT59475.2023.10392490."},{"key":"939_CR24","doi-asserted-by":"publisher","unstructured":"Nandanwar, H., Katarya, R.: A systematic literature review: approach toward blockchain future research trends. In: 2023 International Conference on Device Intelligence, Computing and Communication Technologies, (DICCT), Dehradun, India, pp. 259\u2013264 (2023). https:\/\/doi.org\/10.1109\/DICCT56244.2023.10110088","DOI":"10.1109\/DICCT56244.2023.10110088"},{"key":"939_CR25","doi-asserted-by":"publisher","unstructured":"Garcia, S., Parmisano, A., Erquiaga, M.J.: IoT-23: a labeled dataset with malicious and benign IoT network traffic (Version 1.0.0) [Data set]. Zenodo. https:\/\/doi.org\/10.5281\/zenodo.4743746 (2020)","DOI":"10.5281\/zenodo.4743746"}],"container-title":["International Journal of Computational Intelligence Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s44196-025-00939-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s44196-025-00939-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s44196-025-00939-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,8]],"date-time":"2025-09-08T05:38:13Z","timestamp":1757309893000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s44196-025-00939-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,29]]},"references-count":25,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["939"],"URL":"https:\/\/doi.org\/10.1007\/s44196-025-00939-9","relation":{},"ISSN":["1875-6883"],"issn-type":[{"type":"electronic","value":"1875-6883"}],"subject":[],"published":{"date-parts":[[2025,7,29]]},"assertion":[{"value":"12 May 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 July 2025","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 July 2025","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 July 2025","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"196"}}