International Journal of Engineering
Trends and Technology

Research Article | Open Access | Download PDF
Volume 74 | Issue 9 | Year 2026 | Article Id. IJETT-V74I9P107 | DOI : https://doi.org/10.14445/22315381/IJETT-V74I9P107

Reinforcement-Learning based Self-Healing Banking Transaction System against Malware Attacks in IoT Networks


M. Suganya, R. Kumudham, Z. Livinsa Mary, A K N Balaji

Received Revised Accepted Published
12 Mar 2026 25 Jul 2026 05 Aug 2026 30 Sep 2026

Citation :

M. Suganya, R. Kumudham, Z. Livinsa Mary, A K N Balaji, "Reinforcement-Learning based Self-Healing Banking Transaction System against Malware Attacks in IoT Networks," International Journal of Engineering Trends and Technology (IJETT), vol. 74, no. 9, pp. 77-90, 2026. Crossref, https://doi.org/10.14445/22315381/IJETT-V74I9P107

Abstract

The IoT technology that was at the height of popularity in the banking industry has resulted, improved real-time transaction processing, enhancing the availability of smart financial products and services, and the automated payment systems are more feasible than the traditional banking IoT security models. However, these implementations often fail to detect newly developed "zero-day” malware applications. In contrast, the proposed design for this research is based on developing a Reinforcement Learning (RL) system for banking IoT networks. As compared to traditional Intrusion Detection Systems, which send an alert and/or block the offending actions, the RL-based systems described herein treat the network as a continuous agent-environment dynamic loop that autonomously configures the network, including real-time/configurable routing protocol and resource allocation, in order to preserve transaction integrity during active malware propagation. The proposed research presents a banking transaction processing system that employs RL technology to identify, mitigate, and recover from malware-related events and intrusions in IoT-enab led financial networks by using real-time virus/abnormality detection via a deep Reinforcement Learning (RL) controller. The deep RL controller models the overall context of network security in accordance with the principles of Markov Decision Processes (MDPs). The RL agent creates an effective mitigation strategy by detecting and isolating weak nodes, blocking harmful traffic, redirecting ways to conduct transactions, re-verifying identities safely, and reinstating service to the customer. The growing acceptance of Web of Things, or IoT, technologies in monetary infrastructures will enhance operational efficacy; however, it will also create new risks associated with connecting the banking industry to the Internet. Currently, the majority of malware detection systems based on machine learning and security products do not have any self-healing mechanisms for systems to recover from interruptions. This paper presents a new framework called the Reinforcement Learning-based Self-Healing Banking Transaction (RL-SHBT), which uses hybrid malware detection and enables flexible responses to attacks as well as automated methods for recovering from these attacks. The IoT banking environment has been modelled as a system based on Markov, where the use of a Deep Network with a set of flexible rewards will allow the DQN to learn the most effective response methods. This RL-based security model differs from existing models for the protection of IoT devices in that it utilizes transaction-sensitive state modelling and an adaptable reward system that encourages a balance between security and performance. The results of the experiments showed that this model has a detection accuracy of 99.02% (95% confidence interval: ±0.41%), a false positive rate of 1.12%, an average recovery time of 4.8 seconds, and a self-healing success rate of 97.8%. The research shows that an adaptive reward system with reinforcement learning speeds up the rate of learning by 34% compared to a fixed reward system. The results also indicate that reinforcement-learning-driven autonomous recovery greatly enhances cyber resilience and continuity of transactions within IoT-based financial systems. Machine learning and malware detection techniques have been designed to detect malicious network activities.

Keywords

Reinforcement Learning (RL), Deep Q-Network (DQN), Self-Healing Banking Transaction, IoT-enabled financial networks, Markov Decision Process (MDP).

References

[1] Siraj Uddin Qureshi et al., “Systematic Review of Deep Learning Solutions for Malware Detection and Forensic Analysis in IoT,” Journal of King Saud University - Computer and Information Sciences, vol. 36, no. 8, pp. 1-34, 2024.
[CrossRef] [Google Scholar] [Publisher Link]   

[2] Curtis Rookard, and Anahita Khojandi, “RRIoT: Recurrent Reinforcement Learning for Cyber Threat Detection on IoT Devices,” Computers and Security, vol. 140, pp. 1-21, 2024.
[CrossRef] [Google Scholar] [Publisher Link]    

[3] Sauharda Kushal et al., “Self-Healing Hybrid Intrusion Detection System: An Ensemble Machine Learning Approach,” Discover Artificial Intelligence, vol. 4, no. 1, pp. 1-20, 2024.
[CrossRef] [Google Scholar] [Publisher Link]    

[4] Burak Taşcı, “Deep-Learning-based Approach for IoT Attack and Malware Classification,” Applied Sciences, vol. 14, no. 18, pp. 1-21, 2024.
[CrossRef] [Google Scholar] [Publisher Link]    

[5] Afrah Gueriani, Hamza Kheddar, and Ahmed Cherif Mazar, “Deep Reinforcement Learning for Intrusion Detection in IoT: A Survey,” 2023 2nd International Conference on Electronics, Energy and Measurement (IC2EM), Medea, Algeria, pp. 1-7, 2023.
[CrossRef] [Google Scholar] [Publisher Link]     

[6] Malek M. Al-Nawashi et al., “Deep Reinforcement Learning-based Framework for Enhancing Cybersecurity,” International Journal of Interactive Mobile Technologies, vol. 19, no. 3, pp. 170-190, 2025.
[CrossRef] [Google Scholar] [Publisher Link]     

[7] Mohammad Zahid, and Taran Singh Bharati, “Enhancing Cybersecurity in IoT Systems: A Hybrid Deep Learning Approach for Real-Time Attack Detection,” Discover Internet of Things, vol. 5, no. 1, pp. 1-31, 2025.
[CrossRef] [Google Scholar] [Publisher Link]

[8] Abdullah Alfahaid et al., “Machine Learning-based Security Solutions for IoT Networks: A Comprehensive Survey,” Sensors, vol. 25, no. 11, pp. 1-48, 2025.
[CrossRef] [Google Scholar] [Publisher Link]       

[9] Ali Mehrban, and Pegah Ahadian, “Malware Detection in IOT Systems using Machine Learning Techniques,” arXiv, pp. 1-12, 2023.
[CrossRef] [Google Scholar] [Publisher Link] 

[10] Andres J. Aparcana-Tasayco, Xianjun Deng, and Jong Hyuk Park, “A Systematic Review of Anomaly Detection in IoT Security: Towards Quantum Machine Learning Approach,” EPJ Quantum Technology, vol. 12, no. 1, pp. 1-39, 2025.
[CrossRef] [Google Scholar] [Publisher Link]

[11] Jesús F. Cevallos et al., “Deep Reinforcement Learning for Intrusion Detection in Internet of Things: Best Practices, Lessons Learnt, and Open Challenges,” Computer Networks, vol. 236, pp. 1-24, 2023.
[CrossRef] [Google Scholar] [Publisher Link]

[12] Mohamed Amine Ferrag et al., “Revolutionizing Cyber Threat Detection with Large Language Models: A Privacy-Preserving BERT-based Lightweight Model for IoT/IIoT Devices,” IEEE Access, vol. 12, pp. 23733-23750, 2024.
[CrossRef] [Google Scholar] [Publisher Link]

[13] Nor Zakiah Gorment et al., “Machine Learning Algorithm for Malware Detection: Taxonomy, Current Challenges, and Future Directions,” IEEE Access, vol. 11, pp. 141045-141089, 2023.
[CrossRef] [Google Scholar] [Publisher Link]

[14] Nisha Kandhoul, and Sanjay K. Dhurandher, “Deep Q learning based Secure Routing Approach for OppIoT Networks,” Internet of Things, vol. 20, 2022.
[CrossRef] [Google Scholar] [Publisher Link] 

[15] Najm Us Sama et al., “Cutting-Edge Intrusion Detection in IoT Networks: A Focus on Ensemble Models,” IEEE Access, vol. 13, pp. 8375-8392, 2025.
[CrossRef] [Google Scholar] [Publisher Link]

[16] Mozamel M. Saeed, “An AI-Driven Cybersecurity Framework for IoT: Integrating LSTM-based Anomaly Detection, Reinforcement Learning, and Post-Quantum Encryption,” IEEE Access, vol. 13, pp. 104027-104036, 2025.
[CrossRef] [Google Scholar] [Publisher Link]

[17] Yutao Hu et al., “IoT-ONDDQN: A Detection Model based on Deep Reinforcement Learning for IoT Data Security,” Computer Communications, vol. 241, 2025.
[CrossRef] [Google Scholar] [Publisher Link]

[18] Chahira Mahjoub et al., “An Adversarial Environment Reinforcement Learning-Driven Intrusion Detection Algorithm for Internet of Things,” EURASIP Journal on Wireless Communications and Networking, vol. 2024, no. 1, pp. 1-23, 2024.
[CrossRef] [Google Scholar] [Publisher Link]

[19] Anit Kumar, and Dhanpratap Singh, “'Securing IoT Devices in Edge Computing through Reinforcement Learning,” Computers and Security, vol. 155, pp. 1-13, 2024.
[CrossRef] [Google Scholar] [Publisher Link] 

[20] Yihang Shi et al., “Autonomous Cyber Defense for a IoT using Graph Attention Network-Enhanced Reinforcement Learning,” Computer Communications, vol. 241, 2025.
[CrossRef] [Google Scholar] [Publisher Link]       

[21] Md Morshed Alam et al., “RESTRAIN: Reinforcement Learning-based Secure Framework for Trigger-Action IoT Environment,” 2025 International Wireless Communications and Mobile Computing (IWCMC), Abu Dhabi, United Arab Emirates, pp. 562-567, 2025.
[CrossRef] [Google Scholar] [Publisher Link]        

[22] Wenyi Zhu et al., “RT-A3C: Real-Time Asynchronous Advantage Actor–Critic for Optimally Defending Malicious Attacks in Edge-Enabled Industrial Internet of Things,” Journal of Information Security and Applications, vol. 91, 2025.
[CrossRef] [Google Scholar] [Publisher Link]         

[23] Abid Mohamed Nadhir et al., “Enhancing Cybersecurity in Healthcare IoT Systems using Reinforcement Learning,” Transportation Research Procedia, vol. 84, pp. 113-120, 2025.
[CrossRef] [Google Scholar] [Publisher Link]         

[24] Hyo Sun Lee, Min Geun Song, and Huy Kang Kim, “An Approach to Creating the Optimal Attack Path based on Reinforcement Learning,” 2025 IEEE 30th Pacific Rim International Symposium on Dependable Computing (PRDC), Seoul, Korea, pp. 152-157, 2025. 
[CrossRef] [Google Scholar] [Publisher Link]