{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,13]],"date-time":"2026-04-13T19:11:02Z","timestamp":1776107462355,"version":"3.50.1"},"reference-count":161,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100008675","name":"Zayed University","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100008675","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computer Science Review"],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1016\/j.cosrev.2026.100941","type":"journal-article","created":{"date-parts":[[2026,3,5]],"date-time":"2026-03-05T13:34:48Z","timestamp":1772717688000},"page":"100941","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["AI-driven botnet detection in IoT networks: A comprehensive research review"],"prefix":"10.1016","volume":"61","author":[{"given":"Azka","family":"Wani","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Niha Kamal","family":"Basha","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Masna","family":"Mohammed","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Iqra","family":"Hussain","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christo","family":"Ananth","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2557-3510","authenticated-orcid":false,"given":"Hari Mohan","family":"Rai","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.cosrev.2026.100941_bib0002","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2025.101728","article-title":"The evolving threat landscape of botnets: comprehensive analysis of detection techniques in the age of artificial intelligence","volume":"33","author":"Mahboubi","year":"2025","journal-title":"Internet Things"},{"issue":"3","key":"10.1016\/j.cosrev.2026.100941_bib0003","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3314023","article-title":"Leveraging user-related internet of things for continuous authentication: a survey","volume":"52","author":"Gonzalez-Manzano","year":"2020","journal-title":"ACM Comput. Surv."},{"issue":"3","key":"10.1016\/j.cosrev.2026.100941_bib0004","doi-asserted-by":"crossref","first-page":"366","DOI":"10.3390\/iot4030017","article-title":"Global models of smart cities and potential IoT applications: a review","volume":"4","author":"Hassebo","year":"2023","journal-title":"IoT"},{"key":"10.1016\/j.cosrev.2026.100941_bib0005","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2023.100780","article-title":"Internet of Things (IoT) security dataset evolution: challenges and future directions","volume":"22","author":"Kaur","year":"2023","journal-title":"Internet Things"},{"issue":"11","key":"10.1016\/j.cosrev.2026.100941_bib0006","doi-asserted-by":"crossref","first-page":"3571","DOI":"10.3390\/s24113571","article-title":"Systematic literature review of IoT botnet DDOS attacks and evaluation of detection techniques","volume":"24","author":"Gelgi","year":"2024","journal-title":"Sensors"},{"issue":"4","key":"10.1016\/j.cosrev.2026.100941_bib0007","doi-asserted-by":"crossref","first-page":"2759","DOI":"10.1007\/s11192-020-03819-5","article-title":"IoT-based botnet attacks systematic mapping study of literature","volume":"126","author":"Hamid","year":"2021","journal-title":"Scientometrics"},{"issue":"20","key":"10.1016\/j.cosrev.2026.100941_bib0008","doi-asserted-by":"crossref","DOI":"10.1016\/j.heliyon.2024.e39192","article-title":"A threat modeling framework for IoT-based botnet attacks","volume":"10","author":"Jin","year":"2024","journal-title":"Heliyon"},{"issue":"17","key":"10.1016\/j.cosrev.2026.100941_bib0009","doi-asserted-by":"crossref","first-page":"2154","DOI":"10.3390\/healthcare13172154","article-title":"Explainable AI in clinical decision support systems: a meta-analysis of methods, applications, and usability challenges","volume":"13","author":"Abbas","year":"2025","journal-title":"Healthcare"},{"key":"10.1016\/j.cosrev.2026.100941_bib0010","first-page":"1","article-title":"Blockchain based sensor system design for embedded IoT","author":"Praveena","year":"2023","journal-title":"J. Comput. Inf. Syst."},{"issue":"2","key":"10.1016\/j.cosrev.2026.100941_bib0011","doi-asserted-by":"crossref","DOI":"10.1016\/j.jksuci.2024.101939","article-title":"Collaborative threat intelligence: enhancing IoT security through blockchain and machine learning integration","volume":"36","author":"Nazir","year":"2024","journal-title":"J. King Saud Univ. Comput. Inf. Sci."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0012","first-page":"1","article-title":"Peer-to-peer botnets: exploring behavioural characteristics and machine\/deep learning-based detection","volume":"2024","author":"Kabla","year":"2024","journal-title":"EURASIP J. Inf. Secur."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0013","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/LNET.2023.3241867","article-title":"Optimized degree-aware random patching for thwarting IoT botnets","volume":"5","author":"Mohamed","year":"2023","journal-title":"IEEE Netw. Lett."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0014","doi-asserted-by":"crossref","first-page":"6","DOI":"10.3390\/fi14010006","article-title":"An automated behaviour-based clustering of IoT botnets","volume":"14","author":"Trajanovski","year":"2022","journal-title":"Future Internet"},{"issue":"3","key":"10.1016\/j.cosrev.2026.100941_bib0015","doi-asserted-by":"crossref","first-page":"281","DOI":"10.1049\/cit2.12003","article-title":"SDN-based intrusion detection system for IoT using deep learning classifier (IDSIoT-SDL)","volume":"6","author":"Wani","year":"2021","journal-title":"CAAI Trans. Intell. Technol."},{"key":"10.1016\/j.cosrev.2026.100941_bib0016","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.103064","article-title":"Intelligent IoT-BOTNET attack detection model with optimized hybrid classification model","volume":"126","author":"Bojarajulu","year":"2023","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100941_bib0017","series-title":"Proceedings of the International Conference on I-SMAC (IoT in Social, Mobile, Analytics and Cloud) (I-SMAC)","first-page":"32","article-title":"Security attacks in IoT: a survey","author":"Deogirikar","year":"2017"},{"issue":"3","key":"10.1016\/j.cosrev.2026.100941_bib0018","first-page":"16","article-title":"IOT-MDEDTL: IoT malware detection based on ensemble deep transfer learning","author":"Kadhim","year":"2022","journal-title":"Majlesi J. Electr. Eng."},{"issue":"2","key":"10.1016\/j.cosrev.2026.100941_bib0019","first-page":"3085","article-title":"IoT-cloud assisted botnet detection using rat swarm optimizer with\u71daeep\u71e3earning","volume":"74","author":"Masoud Alshahrani","year":"2023","journal-title":"Comput. Mater. Contin."},{"key":"10.1016\/j.cosrev.2026.100941_bib0020","doi-asserted-by":"crossref","first-page":"3161","DOI":"10.1109\/OJCOMS.2024.3492919","article-title":"Harnessing federated learning for Digital forensics in IoT: a survey and introduction to the IoT-LF framework","volume":"6","author":"Mohamed","year":"2025","journal-title":"IEEE Open J. Commun. Soc."},{"key":"10.1016\/j.cosrev.2026.100941_bib0021","series-title":"IET Blockchain","article-title":"QIoTChain: quantum IoT-blockchain fusion for advanced data protection in industry 4.0","author":"Sharma","year":"2023"},{"key":"10.1016\/j.cosrev.2026.100941_bib0022","doi-asserted-by":"crossref","first-page":"94","DOI":"10.1016\/j.jpdc.2021.04.003","article-title":"SCAB - IoTA: secure communication and authentication for IoT applications using blockchain","volume":"154","author":"Vishwakarma","year":"2021","journal-title":"J. Parallel Distrib. Comput."},{"issue":"19","key":"10.1016\/j.cosrev.2026.100941_bib0023","doi-asserted-by":"crossref","first-page":"136","DOI":"10.3991\/ijim.v17i19.41379","article-title":"Performance evaluation of machine learning approaches in detecting IoT-botnet attacks","volume":"17","author":"Aljammal","year":"2023","journal-title":"Int. J. Interact. Mob. Technol."},{"issue":"3","key":"10.1016\/j.cosrev.2026.100941_bib0024","doi-asserted-by":"crossref","first-page":"2107","DOI":"10.1007\/s11277-021-08551-8","article-title":"Correction to: the impact of memory-efficient bots on IoTWSN botnet propagation","volume":"119","author":"Ibrahim","year":"2021","journal-title":"Wirel. Pers. Commun."},{"issue":"24","key":"10.1016\/j.cosrev.2026.100941_bib0025","doi-asserted-by":"crossref","first-page":"9837","DOI":"10.3390\/s22249837","article-title":"Review of botnet attack detection in SDN-enabled IoT using machine learning","volume":"22","author":"Negera","year":"2022","journal-title":"Sensors"},{"key":"10.1016\/j.cosrev.2026.100941_bib0026","doi-asserted-by":"crossref","first-page":"121975","DOI":"10.1109\/ACCESS.2021.3109886","article-title":"A review of security standards and frameworks for IoT-based Smart environments","volume":"9","author":"Karie","year":"2021","journal-title":"IEEE Access"},{"key":"10.1016\/j.cosrev.2026.100941_bib0027","doi-asserted-by":"crossref","first-page":"395","DOI":"10.1016\/j.future.2017.11.022","article-title":"IoT security: review, blockchain solutions, and open challenges","volume":"82","author":"Khan","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"10.1016\/j.cosrev.2026.100941_bib0028","first-page":"3761","article-title":"A comprehensive review on IoT-based infrastructure for smart grid applications","volume":"15","author":"Pal","year":"2021"},{"key":"10.1016\/j.cosrev.2026.100941_bib0029","doi-asserted-by":"crossref","first-page":"1405","DOI":"10.1016\/j.procs.2023.01.119","article-title":"Botnet detection using artificial intelligence","volume":"218","author":"Moorthy","year":"2023","journal-title":"Procedia Comput. Sci."},{"key":"10.1016\/j.cosrev.2026.100941_bib0030","doi-asserted-by":"crossref","DOI":"10.3390\/app15084562","article-title":"Survey of blockchain-based applications for IoT","author":"Enaya","year":"2025","journal-title":"Appl. Sci."},{"key":"10.1016\/j.cosrev.2026.100941_bib0031","series-title":"Proceedings of the 2011 Conference on Network and Information Systems Security","first-page":"1","article-title":"Botnets: lifecycle and taxonomy","author":"Hachem","year":"2011"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0032","doi-asserted-by":"crossref","DOI":"10.1093\/cybsec\/tyab003","article-title":"Breaking botnets: a quantitative analysis of individual, technical, isolationist, and multilateral approaches to cybersecurity","volume":"7","author":"Haner","year":"2021","journal-title":"J. Cybersecur."},{"key":"10.1016\/j.cosrev.2026.100941_bib0033","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.cose.2019.01.004","article-title":"Autonomously detecting sensors in fully distributed botnets","volume":"83","author":"B\u00f6ck","year":"2019","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100941_bib159","doi-asserted-by":"crossref","DOI":"10.1016\/j.jksuci.2023.101820","article-title":"Advancing IoT security: a systematic review of machine learning approaches for the detection of IoT botnets","author":"Nazir","year":"2023","journal-title":"J. King Saud Univ. - Comput. Inf. Sci."},{"key":"10.1016\/j.cosrev.2026.100941_bib161","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2025.104110","article-title":"Awan IU. Internet of things botnets: a survey on artificial intelligence based detection techniques","author":"Lefoane","year":"2025","journal-title":"J. Netw. Comput. Appl."},{"key":"10.1016\/j.cosrev.2026.100941_bib0034","first-page":"1","article-title":"Survey on botnet detection techniques: classification, methods, and evaluation","volume":"2021","author":"Xing","year":"2021","journal-title":"Math. Probl. Eng."},{"issue":"4","key":"10.1016\/j.cosrev.2026.100941_bib0035","doi-asserted-by":"crossref","first-page":"119","DOI":"10.1007\/s10462-025-11113-0","article-title":"Review of filtering based feature selection for botnet detection in the Internet of Things","volume":"58","author":"Saied","year":"2025","journal-title":"Artif. Intell. Rev."},{"key":"10.1016\/j.cosrev.2026.100941_bib162","first-page":"536","article-title":"Analyzing threats of IoT networks using SDN based intrusion detection system (SDIoT\u2010IDS)","volume":"828","author":"Wani","year":"2018","journal-title":"Commun. Comput. Inf. Sci."},{"key":"10.1016\/j.cosrev.2026.100941_bib163","doi-asserted-by":"crossref","first-page":"453","DOI":"10.1007\/s10462-021-10037-9","article-title":"A survey on intrusion detection system: feature selection, model, performance measures, application perspective, challenges, and future research directions","volume":"55","author":"Thakkar","year":"2022","journal-title":"Artif. Intell. Rev."},{"issue":"4","key":"10.1016\/j.cosrev.2026.100941_bib0044","doi-asserted-by":"crossref","first-page":"2458","DOI":"10.1109\/TNSE.2025.3548411","article-title":"A lightweight method for botnet detection in Internet of things environment","volume":"12","author":"Ma","year":"2025","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"issue":"11","key":"10.1016\/j.cosrev.2026.100941_bib0042","doi-asserted-by":"crossref","first-page":"6012","DOI":"10.3390\/app15116012","article-title":"A machine-learning-based approach for the detection and mitigation of distributed denial-of-service attacks in internet of things environments","volume":"15","author":"Berr\u00edos","year":"2025","journal-title":"Appl. Sci."},{"key":"10.1016\/j.cosrev.2026.100941_bib0115","doi-asserted-by":"crossref","DOI":"10.1016\/j.ecoinf.2025.103383","article-title":"AntPi: a Raspberry Pi based edge-cloud system for real-time ant species detection using YOLO","volume":"91","author":"Palazzetti","year":"2025","journal-title":"Ecol. Inform."},{"key":"10.1016\/j.cosrev.2026.100941_bib0045","doi-asserted-by":"crossref","first-page":"49319","DOI":"10.1109\/ACCESS.2023.3253432","article-title":"Reliable machine learning model for IIoT botnet detection","volume":"11","author":"Taher","year":"2023","journal-title":"IEEE Access"},{"issue":"8","key":"10.1016\/j.cosrev.2026.100941_bib0116","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3547330","article-title":"Adversarial attacks and defenses in deep learning: from a perspective of cybersecurity","volume":"55","author":"Zhou","year":"2023","journal-title":"ACM Comput. Surv."},{"issue":"2","key":"10.1016\/j.cosrev.2026.100941_bib0039","first-page":"1203","article-title":"Detection of botnet in IoT network through machine learning based optimized feature importance via ensemble models","volume":"16","author":"Ud din","year":"2024","journal-title":"Int. J. Inf. Technol."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0040","doi-asserted-by":"crossref","first-page":"4282","DOI":"10.1038\/s41598-023-31260-0","article-title":"Real-time botnet detection on large network bandwidths using machine learning","volume":"13","author":"Velasco-Mata","year":"2023","journal-title":"Sci. Rep."},{"issue":"6","key":"10.1016\/j.cosrev.2026.100941_bib0046","doi-asserted-by":"crossref","first-page":"1301","DOI":"10.1016\/j.dcan.2022.05.011","article-title":"Autonomous machine learning for early bot detection in the internet of things","volume":"9","author":"Araujo","year":"2023","journal-title":"Digit. Commun. Netw."},{"key":"10.1016\/j.cosrev.2026.100941_bib0037","doi-asserted-by":"crossref","first-page":"133","DOI":"10.1016\/j.procs.2021.11.082","article-title":"Exploring dataset manipulation via machine learning for botnet traffic","volume":"196","author":"Abrantes","year":"2022","journal-title":"Procedia Comput. Sci."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0038","doi-asserted-by":"crossref","first-page":"650","DOI":"10.3390\/eng4010039","article-title":"Ensemble machine learning techniques for accurate and efficient detection of botnet attacks in connected computers","volume":"4","author":"Afrifa","year":"2023","journal-title":"Eng"},{"key":"10.1016\/j.cosrev.2026.100941_bib0043","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103456","article-title":"Botnet attacks classification in AMI networks with recursive feature elimination (RFE) and machine learning algorithms","volume":"135","author":"Kornyo","year":"2023","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100941_bib0144","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2024.126149","article-title":"Dimensionality reduction with deep learning classification for botnet detection in the Internet of Things","volume":"267","author":"Abbasi","year":"2025","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.cosrev.2026.100941_bib0145","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2025.113802","article-title":"Hypergraph convolution networks for botnet detection","volume":"325","author":"Li","year":"2025","journal-title":"Knowl. Based Syst."},{"issue":"14","key":"10.1016\/j.cosrev.2026.100941_bib0146","doi-asserted-by":"crossref","first-page":"27481","DOI":"10.1109\/JIOT.2025.3562583","article-title":"Deep-reinforcement-learning-based botnet propagation control in the social internet of things","volume":"12","author":"Shen","year":"2025","journal-title":"IEEE Internet Things J."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0055","doi-asserted-by":"crossref","first-page":"250","DOI":"10.1080\/00051144.2023.2288486","article-title":"Botnet detection in the internet-of-things networks using convolutional neural network with pelican optimization algorithm","volume":"65","author":"Thota","year":"2024","journal-title":"Automatika"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0056","doi-asserted-by":"crossref","first-page":"3878","DOI":"10.1038\/s41598-024-54438-6","article-title":"Ensemble averaging deep neural network for botnet detection in heterogeneous Internet of Things devices","volume":"14","author":"Wardana","year":"2024","journal-title":"Sci. Rep."},{"key":"10.1016\/j.cosrev.2026.100941_bib0079","doi-asserted-by":"crossref","first-page":"294","DOI":"10.1016\/j.future.2023.09.011","article-title":"Deep reinforcement learning based Evasion Generative Adversarial Network for botnet detection","volume":"150","author":"Randhawa","year":"2024","journal-title":"Future Gener. Comput. Syst."},{"issue":"6","key":"10.1016\/j.cosrev.2026.100941_bib0059","doi-asserted-by":"crossref","first-page":"9610","DOI":"10.1109\/JIOT.2023.3324053","article-title":"MalBoT-DRL: malware botnet detection using deep reinforcement learning in IoT networks","volume":"11","author":"Al-Fawa\u2019reh","year":"2024","journal-title":"IEEE Internet Things J."},{"issue":"3","key":"10.1016\/j.cosrev.2026.100941_bib0054","doi-asserted-by":"crossref","first-page":"1999","DOI":"10.1007\/s11277-023-10695-8","article-title":"ACNN-BOT: an ant colony inspired feature selection approach for ANN based botnet detection","volume":"132","author":"Joshi","year":"2023","journal-title":"Wirel. Pers. Commun."},{"key":"10.1016\/j.cosrev.2026.100941_bib0057","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2023.100747","article-title":"XG-BoT: an explainable deep graph neural network for botnet detection and forensics","volume":"22","author":"Lo","year":"2023","journal-title":"Internet Things"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0058","doi-asserted-by":"crossref","DOI":"10.1038\/s41598-024-67865-2","article-title":"Enhanced botnet detection in IoT networks using zebra optimization and dual-channel GAN classification","volume":"14","author":"Shareef","year":"2024","journal-title":"Sci. Rep."},{"key":"10.1016\/j.cosrev.2026.100941_bib0060","doi-asserted-by":"crossref","DOI":"10.1016\/j.micpro.2022.104753","article-title":"Discover botnets in IoT sensor networks: a lightweight deep learning framework with hybrid self-organizing maps","volume":"97","author":"Khan","year":"2023","journal-title":"Microprocess. Microsyst."},{"issue":"2","key":"10.1016\/j.cosrev.2026.100941_bib0063","first-page":"2331","article-title":"An optimized approach to deep learning for botnet detection and classification for cybersecurity in internet of things environment","volume":"80","author":"Alzahrani","year":"2024","journal-title":"Comput. Mater. Contin."},{"key":"10.1016\/j.cosrev.2026.100941_bib0053","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2024.126149","article-title":"Dimensionality reduction with deep learning classification for botnet detection in the Internet of Things","volume":"267","author":"Abbasi","year":"2025","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.cosrev.2026.100941_bib0062","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103195","article-title":"A lightweight deep learning framework for botnet detecting at the IoT edge","volume":"129","author":"Wei","year":"2023","journal-title":"Comput. Secur."},{"issue":"2","key":"10.1016\/j.cosrev.2026.100941_bib0061","doi-asserted-by":"crossref","first-page":"837","DOI":"10.3390\/app13020837","article-title":"A deep learning method for lightweight and cross-device IoT botnet detection","volume":"13","author":"Catillo","year":"2023","journal-title":"Appl. Sci."},{"key":"10.1016\/j.cosrev.2026.100941_bib0147","article-title":"Computationally efficient deep federated learning with optimized feature selection for IoT botnet attack detection","volume":"25","author":"Danquah","year":"2025","journal-title":"Intell. Syst. Appl."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0065","doi-asserted-by":"crossref","DOI":"10.1038\/s41598-023-48230-1","article-title":"A novel hybrid feature selection and ensemble-based machine learning approach for botnet detection","volume":"13","author":"Hossain","year":"2023","journal-title":"Sci. Rep."},{"key":"10.1016\/j.cosrev.2026.100941_bib0066","doi-asserted-by":"crossref","first-page":"40682","DOI":"10.1109\/ACCESS.2024.3376400","article-title":"Hybrid machine learning model for efficient botnet attack detection in IoT environment","volume":"12","author":"Ali","year":"2024","journal-title":"IEEE Access"},{"key":"10.1016\/j.cosrev.2026.100941_bib0070","doi-asserted-by":"crossref","DOI":"10.61185\/SMIJ.2023.22105","article-title":"Protecting IoT devices from BotNet threats: a federated machine learning solution","volume":"2","author":"Metwaly","year":"2023","journal-title":"Sustain. Mach. Intell. J."},{"key":"10.1016\/j.cosrev.2026.100941_bib164","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2025.111479","article-title":"Federated learning of explainable AI (FedXAI) for deep learning-based intrusion detection in IoT networks","author":"Kalakoti","year":"2025","journal-title":"Comput. Netw."},{"key":"10.1016\/j.cosrev.2026.100941_bib0148","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.103064","article-title":"Intelligent IoT-BOTNET attack detection model with optimized hybrid classification model","volume":"126","author":"Bojarajulu","year":"2023","journal-title":"Comput. Secur."},{"issue":"12","key":"10.1016\/j.cosrev.2026.100941_bib0068","doi-asserted-by":"crossref","first-page":"5547","DOI":"10.1007\/s12652-021-03185-x","article-title":"Detecting IoT botnets based on the combination of cooperative game theory with deep and machine learning approaches","volume":"13","author":"Asadi","year":"2022","journal-title":"J. Ambient Intell. Humaniz. Comput."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0078","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1007\/s10922-022-09690-4","article-title":"VAE-based latent representations learning for botnet detection in IoT networks","volume":"31","author":"Snoussi","year":"2023","journal-title":"J. Netw. Syst. Manag."},{"key":"10.1016\/j.cosrev.2026.100941_bib0069","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2023.100952","article-title":"A multi-objective mutation-based dynamic Harris Hawks optimization for botnet detection in IoT","volume":"24","author":"Gharehchopogh","year":"2023","journal-title":"Internet Things"},{"key":"10.1016\/j.cosrev.2026.100941_bib0077","doi-asserted-by":"crossref","DOI":"10.1016\/j.engappai.2022.105669","article-title":"Imbalanced tabular data modelization using CTGAN and machine learning to improve IoT botnet attacks detection","volume":"118","author":"Habibi","year":"2023","journal-title":"Eng. Appl. Artif. Intell."},{"issue":"14","key":"10.1016\/j.cosrev.2026.100941_bib0071","doi-asserted-by":"crossref","first-page":"6305","DOI":"10.3390\/s23146305","article-title":"Botnet detection and mitigation model for IoT networks using federated Learning","volume":"23","author":"de Caldas Filho","year":"2023","journal-title":"Sensors"},{"key":"10.1016\/j.cosrev.2026.100941_bib0072","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2025.111937","article-title":"Interpretable intrusion detection for IoT security: a SHAP-enhanced NGBoost model","volume":"275","author":"Dong","year":"2026","journal-title":"Comput. Netw."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0036","doi-asserted-by":"crossref","DOI":"10.1038\/s41598-024-62861-y","article-title":"Using machine learning algorithms to enhance IoT system security","volume":"14","author":"El-Sofany","year":"2024","journal-title":"Sci. Rep."},{"key":"10.1016\/j.cosrev.2026.100941_bib0041","unstructured":"Zhou, J., Xu, Z., Rush, A.M., & Yu, M. (2020). Automating botnet detection with graph neural networks. http:\/\/arxiv.org\/abs\/2003.06344."},{"issue":"12","key":"10.1016\/j.cosrev.2026.100941_bib0047","doi-asserted-by":"crossref","first-page":"1950","DOI":"10.3390\/math13121950","article-title":"Enhanced credit card fraud detection using deep hybrid CLST model","volume":"13","author":"Jabeen","year":"2025","journal-title":"Mathematics"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0048","first-page":"33","article-title":"An effective deep learning scheme for android malware detection leveraging performance metrics and computational resources","volume":"18","author":"Wajahat","year":"2024","journal-title":"Intell. Decis. Technol."},{"key":"10.1016\/j.cosrev.2026.100941_bib0049","unstructured":"Wambui, R. (2026). Cross-entropy loss and its applications in deep learning. Https:\/\/Neptune.Ai\/Blog\/Cross-Entropy-Loss-and-Its-Applications-in-Deep-Learning."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0050","doi-asserted-by":"crossref","first-page":"181","DOI":"10.1016\/j.icte.2025.01.005","article-title":"Deep learning-driven methods for network-based intrusion detection systems: a systematic review","volume":"11","author":"Chinnasamy","year":"2025","journal-title":"ICT Express"},{"issue":"5","key":"10.1016\/j.cosrev.2026.100941_bib0051","article-title":"Optimization of malware detection and defense algorithm based on hybrid convolutional graph neural network","volume":"8","author":"Peng","year":"2025","journal-title":"Secur. Priv."},{"issue":"3","key":"10.1016\/j.cosrev.2026.100941_bib0052","article-title":"Reinforcement learning for an efficient and effective malware investigation during cyber incident response","volume":"5","author":"Dunsin","year":"2025","journal-title":"High-Confid. Comput."},{"issue":"1-2","key":"10.1016\/j.cosrev.2026.100941_bib0064","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1007\/s44443-025-00021-6","article-title":"Generative adversarial message passing-based anomaly detection","volume":"37","author":"Ma","year":"2025","journal-title":"J. King Saud Univ. Comput. Inf. Sci."},{"issue":"10","key":"10.1016\/j.cosrev.2026.100941_bib0067","doi-asserted-by":"crossref","first-page":"18237","DOI":"10.1109\/JIOT.2024.3360626","article-title":"Improving IoT security with explainable AI: quantitative evaluation of explainability for IoT botnet detection","volume":"11","author":"Kalakoti","year":"2024","journal-title":"IEEE Internet Things J."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0073","doi-asserted-by":"crossref","first-page":"431","DOI":"10.5753\/jisa.2025.5247","article-title":"Optimizing compliance: comparative study of data laws and privacy frameworks","volume":"16","author":"Rocha","year":"2025","journal-title":"J. Internet Serv. Appl."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0074","first-page":"2025","article-title":"Enhancing IoT security via federated learning: a comprehensive approach to intrusion detection","author":"Bai","year":"2025","journal-title":"IET Inf. Secur."},{"issue":"5","key":"10.1016\/j.cosrev.2026.100941_bib0075","doi-asserted-by":"crossref","first-page":"4456","DOI":"10.1109\/TNET.2024.3423780","article-title":"Federated PCA on Grassmann Manifold for IoT anomaly detection","volume":"32","author":"Nguyen","year":"2024","journal-title":"IEEE\/ACM Trans. Netw."},{"key":"10.1016\/j.cosrev.2026.100941_bib0076","series-title":"Proceedings of the 2024 IEEE 5th World AI IoT Congress, AIIoT","first-page":"265","article-title":"Enhancing IoT botnet attack detection in SOCs with an explainable active learning framework","volume":"2024","author":"Kalakoti","year":"2024"},{"key":"10.1016\/j.cosrev.2026.100941_bib165","article-title":"Concept drift and cross-device behavior: challenges and implications for effective android malware detection","author":"Guerra-Manzanares","year":"2022","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100941_bib166","first-page":"101252","article-title":"Enhancing cybersecurity in edge IIoT networks: an asynchronous federated learning approach with a deep hybrid detection model","author":"Bukhari","year":"2024","journal-title":"Int. Thin."},{"key":"10.1016\/j.cosrev.2026.100941_bib0080","doi-asserted-by":"crossref","unstructured":"Meidan, Y., Bohadana, M., Mathov, Y., Mirsky, Y., Breitenbacher, D., Shabtai, A., & Elovici, Y. (2018). N-BaIoT: network-based detection of IoT botnet attacks using deep autoencoders. 13 (9), 1-8.","DOI":"10.1109\/MPRV.2018.03367731"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0081","doi-asserted-by":"crossref","DOI":"10.1088\/1742-6596\/2319\/1\/012029","article-title":"Cyber attack detection dataset: a review","volume":"2319","author":"Mohd Yusof","year":"2022","journal-title":"J. Phys. Conf. Ser."},{"issue":"4","key":"10.1016\/j.cosrev.2026.100941_bib0082","doi-asserted-by":"crossref","first-page":"577","DOI":"10.1177\/15485129221094881","article-title":"Machine learning to combat cyberattack: a survey of datasets and challenges","volume":"20","author":"Prasad","year":"2023","journal-title":"J. Def. Model. Simul."},{"key":"10.1016\/j.cosrev.2026.100941_bib0083","unstructured":"Sinanovi, H. (2025). Analysis of mirai malicious software."},{"issue":"31","key":"10.1016\/j.cosrev.2026.100941_bib0084","first-page":"45","article-title":"D-link cameras, parent target of cyberattack","volume":"41","author":"Casacchia","year":"2018","journal-title":"Orange Cty. Bus. J."},{"key":"10.1016\/j.cosrev.2026.100941_bib0085","first-page":"35","article-title":"IoT device security protection approach based on ME app","author":"Liang","year":"2019","journal-title":"Dianxin Kexue"},{"issue":"20","key":"10.1016\/j.cosrev.2026.100941_bib0086","doi-asserted-by":"crossref","DOI":"10.1016\/j.heliyon.2024.e39192","article-title":"A threat modeling framework for IoT-based botnet attacks","volume":"10","author":"Jin","year":"2024","journal-title":"Heliyon"},{"key":"10.1016\/j.cosrev.2026.100941_bib0149","doi-asserted-by":"crossref","DOI":"10.1007\/s00500-023-08348-w","article-title":"Adapting deep learning-LSTM method using optimized dataset in SDN controller for secure IoT","author":"Tayfour","year":"2023","journal-title":"Soft Comput."},{"key":"10.1016\/j.cosrev.2026.100941_bib0150","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2024.101231","article-title":"MULTI-BLOCK: a novel ML-based intrusion detection framework for SDN-enabled IoT networks using new pyramidal structure","volume":"26","author":"Toony","year":"2024","journal-title":"Internet Things"},{"key":"10.1016\/j.cosrev.2026.100941_bib0151","article-title":"Class imbalance and concept drift invariant online botnet threat detection framework for heterogeneous IoT edge","volume":"141","author":"Nitish","year":"2024","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100941_bib0152","doi-asserted-by":"crossref","DOI":"10.1145\/3691634","article-title":"Distributed and collaborative lightweight edge federated learning for IoT zombie devices detection","author":"Han","year":"2024","journal-title":"ACM Trans. Sens. Netw."},{"key":"10.1016\/j.cosrev.2026.100941_bib0153","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103195","article-title":"A lightweight deep learning framework for botnet detecting at the IoT edge","volume":"129","author":"Wei","year":"2023","journal-title":"Comput. Secur."},{"issue":"5","key":"10.1016\/j.cosrev.2026.100941_bib0154","first-page":"26","article-title":"Lightly secured cloud, with a chance of IoT attacks","volume":"29","author":"Abel","year":"2018","journal-title":"SC Mag."},{"issue":"3","key":"10.1016\/j.cosrev.2026.100941_bib0087","doi-asserted-by":"crossref","first-page":"2979","DOI":"10.32604\/iasc.2023.040019","article-title":"Design the IoT botnet defense process for cybersecurity in smart city","volume":"37","author":"Kim","year":"2023","journal-title":"Intell. Autom. Soft Comput."},{"issue":"3","key":"10.1016\/j.cosrev.2026.100941_bib0088","first-page":"4225","article-title":"Improving thyroid disorder diagnosis via ensemble stacking and bidirectional feature selection","volume":"78","author":"Latif","year":"2024","journal-title":"Comput. Mater. Contin."},{"key":"10.1016\/j.cosrev.2026.100941_bib0089","series-title":"Proceedings of the 2023 International Conference on Machine Learning and Applications (ICMLA)","first-page":"2200","article-title":"Detecting stealthy Cobalt Strike C&C activities via Multi-flow based machine learning","author":"Ramos","year":"2023"},{"issue":"5","key":"10.1016\/j.cosrev.2026.100941_bib0090","doi-asserted-by":"crossref","first-page":"1511","DOI":"10.3390\/s24051511","article-title":"Advancements and challenges in IoT simulators: a comprehensive review","volume":"24","author":"Almutairi","year":"2024","journal-title":"Sensors"},{"issue":"10","key":"10.1016\/j.cosrev.2026.100941_bib0091","doi-asserted-by":"crossref","first-page":"3744","DOI":"10.3390\/s22103744","article-title":"Intrusion detection in Internet of Things systems: a review on design approaches leveraging multi-access edge computing, machine learning, and datasets","volume":"22","author":"Gyamfi","year":"2022","journal-title":"Sensors"},{"issue":"22","key":"10.1016\/j.cosrev.2026.100941_bib0092","doi-asserted-by":"crossref","first-page":"7506","DOI":"10.3390\/s21227506","article-title":"Memory-based pruning of deep neural networks for IoT devices applied to flood detection","volume":"21","author":"Fernandes Junior","year":"2021","journal-title":"Sensors"},{"key":"10.1016\/j.cosrev.2026.100941_bib0093","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2024.101403","article-title":"Combinative model compression approach for enhancing 1D CNN efficiency for EIT-based Hand Gesture recognition on IoT edge devices","volume":"28","author":"Mnif","year":"2024","journal-title":"Internet Things"},{"key":"10.1016\/j.cosrev.2026.100941_bib0094","series-title":"Proceedings of the 24th Pan-Hellenic Conference on Informatics","first-page":"268","article-title":"A review on hardware security countermeasures for IoT: emerging mechanisms and machine learning solutions","author":"Michailidis","year":"2020"},{"key":"10.1016\/j.cosrev.2026.100941_bib0095","unstructured":"Vu, C. (2026). Optimizing deep learning models with weight quantization. Https:\/\/Medium.Com\/Data-Science\/Optimizing-Deep-Learning-Models-with-Weight-Quantization-C786ffc6d6c1."},{"key":"10.1016\/j.cosrev.2026.100941_bib0096","doi-asserted-by":"crossref","DOI":"10.1016\/j.compeleceng.2024.109370","article-title":"A review of explainable artificial Intelligence in healthcare","volume":"118","author":"Sadeghi","year":"2024","journal-title":"Comput. Electr. Eng."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0097","doi-asserted-by":"crossref","first-page":"7632","DOI":"10.1038\/s41598-025-90420-6","article-title":"Explainable artificial intelligence for botnet detection in internet of things","volume":"15","author":"Saied","year":"2025","journal-title":"Sci. Rep."},{"key":"10.1016\/j.cosrev.2026.100941_bib0098","doi-asserted-by":"crossref","unstructured":"Joshi, A., Chakraborty, S., Akshay, S., Shah, S., Torfah, H., & Seshia, S. (2026). Locally pareto-optimal interpretations for black-box machine learning models (pp. 321-341). 10.1007\/978-3-032-08707-2_15.","DOI":"10.1007\/978-3-032-08707-2_15"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0099","doi-asserted-by":"crossref","first-page":"724","DOI":"10.1038\/s41746-025-02105-z","article-title":"A systematic review of explainable artificial intelligence methods for speech-based cognitive decline detection","volume":"8","author":"Shankar","year":"2025","journal-title":"NPJ. Digit. Med."},{"issue":"4","key":"10.1016\/j.cosrev.2026.100941_bib0100","doi-asserted-by":"crossref","first-page":"2967","DOI":"10.3390\/ai5040143","article-title":"Machine learning-based network anomaly detection: design, implementation, and evaluation","volume":"5","author":"Schummer","year":"2024","journal-title":"AI"},{"issue":"10","key":"10.1016\/j.cosrev.2026.100941_bib0101","doi-asserted-by":"crossref","first-page":"422","DOI":"10.1007\/s40747-025-02001-9","article-title":"A novel federated learning approach for IoT botnet intrusion detection using SHAP-based knowledge distillation","volume":"11","author":"Hossain","year":"2025","journal-title":"Complex Intell. Syst."},{"key":"10.1016\/j.cosrev.2026.100941_bib0102","doi-asserted-by":"crossref","DOI":"10.1016\/j.artint.2024.104179","article-title":"Assessing fidelity in XAI post-hoc techniques: a comparative study with ground truth explanations datasets","volume":"335","author":"Mir\u00f3-Nicolau","year":"2024","journal-title":"Artif. Intell."},{"key":"10.1016\/j.cosrev.2026.100941_bib0103","doi-asserted-by":"crossref","unstructured":"Mariotti, E., Sivaprasad, A., & Moral, J.M.A. (2023). Beyond prediction similarity: ShapGAP for evaluating faithful surrogate models in XAI (pp. 160-173). 10.1007\/978-3-031-44064-9_10.","DOI":"10.1007\/978-3-031-44064-9_10"},{"key":"10.1016\/j.cosrev.2026.100941_bib0104","doi-asserted-by":"crossref","DOI":"10.1016\/j.inffus.2024.102301","article-title":"Explainable Artificial Intelligence (XAI) 2.0: a manifesto of open challenges and interdisciplinary research directions","volume":"106","author":"Longo","year":"2024","journal-title":"Inf. Fusion"},{"key":"10.1016\/j.cosrev.2026.100941_bib0105","article-title":"Licensing high-risk artificial intelligence: toward ex ante justification for a disruptive technology","volume":"52","author":"Malgieri","year":"2024","journal-title":"Comput. Law Secur. Rev."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0106","doi-asserted-by":"crossref","first-page":"1568","DOI":"10.1057\/s41599-024-04044-8","article-title":"Trust in AI: progress, challenges, and future directions","volume":"11","author":"Afroogh","year":"2024","journal-title":"Humanit. Soc. Sci. Commun."},{"key":"10.1016\/j.cosrev.2026.100941_bib0107","doi-asserted-by":"crossref","DOI":"10.1016\/j.neucom.2024.127969","article-title":"US-LIME: increasing fidelity in LIME using uncertainty sampling on tabular data","volume":"597","author":"Saadatfar","year":"2024","journal-title":"Neurocomputing"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0108","doi-asserted-by":"crossref","first-page":"21","DOI":"10.3390\/make7010021","article-title":"Comparative analysis of perturbation techniques in LIME for intrusion detection enhancement","volume":"7","author":"Bacevicius","year":"2025","journal-title":"Mach. Learn. Knowl. Extr."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0109","doi-asserted-by":"crossref","DOI":"10.1038\/s41598-024-62861-y","article-title":"Using machine learning algorithms to enhance IoT system security","volume":"14","author":"El-Sofany","year":"2024","journal-title":"Sci. Rep."},{"issue":"11","key":"10.1016\/j.cosrev.2026.100941_bib0110","doi-asserted-by":"crossref","first-page":"515","DOI":"10.3390\/technologies13110515","article-title":"SHEAB: a novel automated benchmarking framework for Edge AI","volume":"13","author":"Abdulkadhim","year":"2025","journal-title":"Technologies"},{"issue":"5","key":"10.1016\/j.cosrev.2026.100941_bib0111","doi-asserted-by":"crossref","first-page":"119","DOI":"10.1007\/s10462-024-10748-9","article-title":"Artificial intelligence and edge computing for machine maintenance-review","volume":"57","author":"Bala","year":"2024","journal-title":"Artif. Intell. Rev."},{"key":"10.1016\/j.cosrev.2026.100941_bib0112","doi-asserted-by":"crossref","DOI":"10.1038\/s41598-025-27856-3","article-title":"Revisiting convolutional design for efficient CNN architectures in edge-aware applications","author":"Korkmaz","year":"2025","journal-title":"Sci. Rep."},{"key":"10.1016\/j.cosrev.2026.100941_bib0113","doi-asserted-by":"crossref","DOI":"10.1016\/j.cosrev.2024.100636","article-title":"A comprehensive review on applications of Raspberry Pi","volume":"52","author":"Mathe","year":"2024","journal-title":"Comput. Sci. Rev."},{"key":"10.1016\/j.cosrev.2026.100941_bib0114","series-title":"Proceedings of the SoutheastCon 2025","first-page":"1384","article-title":"Benchmarking edge AI platforms: performance analysis of NVIDIA Jetson and Raspberry Pi 5 with Coral TPU","author":"Minott","year":"2025"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0117","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1109\/TSC.2023.3329081","article-title":"Resisting deep learning models against adversarial attack transferability via feature randomization","volume":"17","author":"Nowroozi","year":"2024","journal-title":"IEEE Trans. Serv. Comput."},{"issue":"6","key":"10.1016\/j.cosrev.2026.100941_bib0118","doi-asserted-by":"crossref","first-page":"5168","DOI":"10.1109\/TDSC.2023.3241428","article-title":"Detecting adversarial examples on deep neural networks with mutual information neural estimation","volume":"20","author":"Gao","year":"2023","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"10.1016\/j.cosrev.2026.100941_bib0119","series-title":"Proceedings of the 1st ACM Workshop on Security and Privacy on Artificial Intelligence","first-page":"47","article-title":"Evaluating robustness of AI models against adversarial attacks","author":"Chang","year":"2020"},{"key":"10.1016\/j.cosrev.2026.100941_bib0120","doi-asserted-by":"crossref","DOI":"10.1016\/j.imavis.2025.105743","article-title":"Understanding adversarial robustness of deep neural networks via decision reliance","volume":"163","author":"Won","year":"2025","journal-title":"Image Vis. Comput."},{"key":"10.1016\/j.cosrev.2026.100941_bib0121","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2025.112519","article-title":"On the robustness of adversarial training against uncertainty attacks","volume":"172","author":"Ledda","year":"2026","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.cosrev.2026.100941_bib0155","doi-asserted-by":"crossref","DOI":"10.1155\/2018\/3029638","article-title":"Shielding IoT against cyber-attacks: an event-based approach using SIEM","volume":"2018","author":"D\u00edaz L\u00f3pez","year":"2018","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"10.1016\/j.cosrev.2026.100941_bib0156","doi-asserted-by":"crossref","DOI":"10.1016\/j.cosrev.2025.100769","article-title":"Edge-AI empowered cyber-physical systems: a comprehensive review on performance analysis","volume":"58","author":"Singh","year":"2025","journal-title":"Comput. Sci. Rev."},{"key":"10.1016\/j.cosrev.2026.100941_bib0122","unstructured":"Blumauer-Hiessl, T., Scharinger, B., Kaufmann, T., Schwulera, E., Schmidt, K., & Kuehne-Schlinkert, M. (2023). How siemens mastered federated learning with katulu. https:\/\/www.hannovermesse.de\/apollo\/hannover_messe_2024\/obs\/Binary\/A1354672\/Katulu%20Whitepaper%20-%20How%20Siemens%20mastered%20Federated%20Learning%20with%20Katulu.pdf."},{"key":"10.1016\/j.cosrev.2026.100941_bib0123","doi-asserted-by":"crossref","unstructured":"Nguyen, T.D., Marchal, S., Miettinen, M., Fereidooni, H., Asokan, N., & Sadeghi, A.R. (2019). D\u00cfoT: a federated self-learning anomaly detection system for IoT. https:\/\/arxiv.org\/abs\/1804.07474.","DOI":"10.1109\/ICDCS.2019.00080"},{"key":"10.1016\/j.cosrev.2026.100941_bib0124","unstructured":"Yuan, Z., Guo, L., Li, X., Zhu, Y., Wang, W., & Qu, M. (2025). FedSA-GCL: a semi-asynchronous federated graph learning framework with personalized aggregation and cluster-aware broadcasting. 10.48550\/arXiv.2507.18219."},{"issue":"11","key":"10.1016\/j.cosrev.2026.100941_bib0125","doi-asserted-by":"crossref","first-page":"529","DOI":"10.3390\/fi17110529","article-title":"Top-K feature selection for IoT intrusion detection: contributions of XGBoost, LightGBM, and random forest","volume":"17","author":"Kouassi","year":"2025","journal-title":"Future Internet"},{"key":"10.1016\/j.cosrev.2026.100941_bib0126","doi-asserted-by":"crossref","first-page":"169314","DOI":"10.1109\/ACCESS.2025.3614388","article-title":"A comprehensive survey on cognitive cyber security analysis using machine learning approaches","volume":"13","author":"Khan","year":"2025","journal-title":"IEEE Access"},{"key":"10.1016\/j.cosrev.2026.100941_bib0157","unstructured":"Wasswa, H., Abbass, H., & Lynar, T. (2025). A quantized VAE-MLP botnet detection model: a systematic evaluation of quantization-aware training and post-training quantization strategies. 10.48550\/arXiv.2511.03201."},{"key":"10.1016\/j.cosrev.2026.100941_bib0158","doi-asserted-by":"crossref","unstructured":"Jiang, J., Meng, Y., Tang, C., Yu, H., Li, Q., Wang, Z., & Zhu, W. (2025). Quantization meets OOD: generalizable quantization-aware training from a flatness perspective. 10.48550\/arXiv.2509.00859.","DOI":"10.1145\/3746027.3755856"},{"issue":"4","key":"10.1016\/j.cosrev.2026.100941_bib0127","doi-asserted-by":"crossref","first-page":"454","DOI":"10.63278\/1471","article-title":"A comprehensive review of security issues and solutions in IoT smart homes","volume":"31","author":"Bagga","year":"2025","journal-title":"Metall. Mater. Eng."},{"key":"10.1016\/j.cosrev.2026.100941_bib0128","first-page":"181","article-title":"Security behavior analysis in web of things smart environments using deep belief networks","volume":"3","author":"Premkumar","year":"2022","journal-title":"Int. J. Intell. Netw."},{"key":"10.1016\/j.cosrev.2026.100941_bib0129","article-title":"Active learning approach to label network traffic datasets","volume":"49","author":"Torres","year":"2019","journal-title":"J. Inf. Secur. Appl."},{"issue":"6","key":"10.1016\/j.cosrev.2026.100941_bib0130","article-title":"Explainable artificial intelligence envisioned security mechanism for cyber threat hunting","volume":"6","author":"Kumar","year":"2023","journal-title":"Secur. Priv."},{"key":"10.1016\/j.cosrev.2026.100941_bib0131","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2025.101505","article-title":"A systematic evaluation of white-box explainable AI methods for anomaly detection in IoT systems","volume":"30","author":"Gummadi","year":"2025","journal-title":"Internet Things"},{"key":"10.1016\/j.cosrev.2026.100941_bib0132","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103988","article-title":"Adversarial machine learning in industry: a systematic literature review","volume":"145","author":"Jedrzejewski","year":"2024","journal-title":"Comput. Secur."},{"issue":"3","key":"10.1016\/j.cosrev.2026.100941_bib0133","doi-asserted-by":"crossref","DOI":"10.1061\/AJRUA6.0001078","article-title":"Risk and advantages of federated learning for health care data collaboration","volume":"6","author":"Bogdanova","year":"2020","journal-title":"ASCE-ASME J. Risk Uncertain. Eng. Syst. Part A Civ. Eng."},{"key":"10.1016\/j.cosrev.2026.100941_bib0134","doi-asserted-by":"crossref","DOI":"10.1016\/j.bdr.2025.100510","article-title":"Efficient training: federated learning cost analysis","volume":"40","author":"Teixeira","year":"2025","journal-title":"Big Data Res."},{"key":"10.1016\/j.cosrev.2026.100941_bib0135","article-title":"One or two things we know about concept drift-a survey on monitoring in evolving environments. Part A: detecting concept drift","volume":"7","author":"Hinder","year":"2024","journal-title":"Front. Artif. Intell."},{"key":"10.1016\/j.cosrev.2026.100941_bib0136","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2025.104197","article-title":"An Internet of Things platform for heterogeneous data integration: methodology and application examples","volume":"240","author":"Mu\u00f1oz","year":"2025","journal-title":"J. Netw. Comput. Appl."},{"issue":"6","key":"10.1016\/j.cosrev.2026.100941_bib0137","doi-asserted-by":"crossref","first-page":"246","DOI":"10.3390\/fi17060246","article-title":"An AI-driven framework for integrated security and privacy in internet of things using quantum-resistant blockchain","volume":"17","author":"Elkhodr","year":"2025","journal-title":"Future Internet"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100941_bib0138","doi-asserted-by":"crossref","DOI":"10.1038\/s41598-024-62861-y","article-title":"Using machine learning algorithms to enhance IoT system security","volume":"14","author":"El-Sofany","year":"2024","journal-title":"Sci. Rep."},{"issue":"8","key":"10.1016\/j.cosrev.2026.100941_bib0139","doi-asserted-by":"crossref","first-page":"201","DOI":"10.1007\/s10462-024-10805-3","article-title":"A review of digital twins and their application in cybersecurity based on artificial intelligence","volume":"57","author":"Homaei","year":"2024","journal-title":"Artif. Intell. Rev."},{"key":"10.1016\/j.cosrev.2026.100941_bib0140","doi-asserted-by":"crossref","DOI":"10.1016\/j.comcom.2025.108158","article-title":"A survey on security enhancing Digital Twins: models, applications and tools","volume":"238","author":"Qureshi","year":"2025","journal-title":"Comput. Commun."}],"container-title":["Computer Science Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1574013726000493?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1574013726000493?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,4,13]],"date-time":"2026-04-13T17:43:32Z","timestamp":1776102212000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1574013726000493"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,8]]},"references-count":161,"alternative-id":["S1574013726000493"],"URL":"https:\/\/doi.org\/10.1016\/j.cosrev.2026.100941","relation":{},"ISSN":["1574-0137"],"issn-type":[{"value":"1574-0137","type":"print"}],"subject":[],"published":{"date-parts":[[2026,8]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"AI-driven botnet detection in IoT networks: A comprehensive research review","name":"articletitle","label":"Article Title"},{"value":"Computer Science Review","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.cosrev.2026.100941","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Inc. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"100941"}}