Beyond Detection Accuracy: Measuring Explanation Cost, Stability, and Utility for Resource-Aware IoT Intrusion Detection

πŸ“… 2026-08-10
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This study addresses the prevailing focus on prediction accuracy in existing IoT intrusion detection research, which often overlooks the computational overhead, stability, and practicality of explanation mechanisms. For the first time, it systematically evaluates binary intrusion detection models under resource-constrained IoT conditions across four dimensions: predictive performance, explanation cost, local stability, and selective explanation strategies. Leveraging a newly constructed leakage-safe dataset with feature hashing and deterministic preprocessing, the authors employ Logistic Regression, Decision Tree, Random Forest, and XGBoost models, generating explanations via TreeSHAP. Experimental results show that XGBoost achieves the best predictive performance, while Random Forest yields the lowest false positive rate and the most stable explanations. The proposed validation-calibrated selective explanation strategy reduces computational overhead by 15–32% on balanced test sets, underscoring the critical importance of multidimensional evaluation for real-world deployment.
πŸ“ Abstract
Machine-learning intrusion-detection studies commonly emphasize predictive accuracy while treating explanation generation as a computationally free post-processing step. This study jointly evaluates predictive effectiveness, explanation cost, local explanation stability, and selective explanation for binary Internet of Things (IoT) intrusion detection. A leakage-safe CICIoT2023 corpus was constructed using exact 39-feature hashes, non-finite-value handling, exact-feature deduplication, conservative label-collision removal, and deterministic hash-level partitioning. Logistic Regression, Decision Tree, Random Forest, and XGBoost were evaluated on natural and balanced test distributions. TreeSHAP cost was measured, stability was assessed under prediction-preserving perturbations, and validation-calibrated policies were used to allocate explanation workload. XGBoost provided the strongest overall predictive profile, while Random Forest produced the lowest false-positive rate. At 5,000 samples, TreeSHAP required 700.759 s for Random Forest and 1.471 s for XGBoost. Random Forest showed the strongest overall base-level explanation stability; XGBoost retained high rank and directional consistency but showed greater top-feature turnover and attribution-magnitude drift. On the balanced test, about 90% false-negative explanation coverage permitted 28-32% compute savings, while about 95% coverage permitted 15-23% savings. Savings were much smaller under the attack-heavy natural prevalence. These results show that operationally useful explainable IoT intrusion detection depends on predictive quality, explanation cost, local stability, workload prevalence, and selective invocation rather than detection accuracy alone.
Problem

Research questions and friction points this paper is trying to address.

IoT intrusion detection
explanation cost
explanation stability
resource-aware
selective explanation
Innovation

Methods, ideas, or system contributions that make the work stand out.

Explanation Cost
Local Explanation Stability
Selective Explanation
Resource-Aware IoT Security
TreeSHAP Efficiency
A
Abdurrahman Tolay
Independent Researcher, Istanbul, TΓΌrkiye