Zero-Day Botnet Attack Detection in IoV: A Modular Approach Using Isolation Forests and Particle Swarm Optimization

Korba, Abdelaziz Amara, Karabadji, Nour Elislem, Ghamri-Doudane, Yacine

arXiv.org Artificial Intelligence 

Zero-Day Botnet Attack Detection in IoV: A Modular Approach Using Isolation Forests and Particle Swarm Optimization Abdelaziz Amara korba 2, Nour Elislem Karabadji 1, and Y acine Ghamri-Doudane 2 1 National Higher School of T echnology and Engineering, LTSE, E3360100, Annaba, Algeria. 2 L3I, University of La Rochelle, France Abstract --The Internet of V ehicles (IoV) is transforming transportation by enhancing connectivity and enabling autonomous driving. However, this increased interconnectivity introduces new security vulnerabilities. Bot malware and cyberattacks pose significant risks to Connected and Autonomous V ehicles (CA Vs), as demonstrated by real-world incidents involving remote vehicle system compromise. T o address these challenges, we propose an edge-based Intrusion Detection System (IDS) that monitors network traffic to and from CA Vs. Our detection model is based on a meta-ensemble classifier capable of recognizing known (N-day) attacks and detecting previously unseen (zero-day) attacks. The approach involves training multiple Isolation Forest (IF) models on Multi-access Edge Computing (MEC) servers, with each IF specialized in identifying a specific type of botnet attack. These IFs, either trained locally or shared by other MEC nodes, are then aggregated using a Particle Swarm Optimization (PSO) based stacking strategy to construct a robust meta-classifier . The proposed IDS has been evaluated on a vehicular botnet dataset, achieving an average detection rate of 92.80% for N-day attacks and 77.32% for zero-day attacks.