paper-with-me

홈 › Papers

Exploring Robust Intrusion Detection: A Benchmark Study of Feature Transferability in IoT Botnet Attack Detection

2026-02-27 · Alejandro Guerra-Manzanares, Jialin Huang arxiv

Cross-domain intrusion detection remains a critical challenge due to significant variability in network traffic characteristics and feature distributions across environments. This study evaluates the transferability of three widely used flow-based feature sets (Argus, Zeek and CICFlowMeter) across four widely used datasets representing heterogeneous IoT and Industrial IoT network conditions. Through extensive experiments, we evaluate in- and cross-domain performance across multiple classification models and analyze feature importance using SHapley Additive exPlanations (SHAP). Our results show that models trained on one domain suffer significant performance degradation when applied to a different target domain, reflecting the sensitivity of IoT intrusion detection systems to distribution shifts. Furthermore, the results evidence that the choice of classification algorithm and feature representations significantly impact transferability. Beyond reporting performance differences and thorough analysis of the transferability of features and feature spaces, we provide practical guidelines for feature engineering to improve robustness under domain variability. Our findings suggest that effective intrusion detection requires both high in-domain performance and resilience to cross-domain variability, achievable through careful feature space design, appropriate algorithm selection and adaptive strategies.

📄 PDF Abstract BibTeX arXiv:2602.23874

Code (0)

등록된 구현이 없습니다.

Tasks

Feature EngineeringIntrusion DetectionFeature Importance

Similar Papers 제목 키워드 기반

Explaining Network Intrusion Detection System Using Explainable AI Framework

2021-03-12 · Shraddha Mane, Dattaraj Rao

Cybersecurity is a domain where the data distribution is constantly changing with attackers exploring newer patterns to attack cyber infrastructure. Intrusion detection system is one of the important layers in cyber safe…

BIG-bench Machine LearningIntrusion DetectionNetwork Intrusion Detection

Intrusion Detection in IoT Networks Using Hyperdimensional Computing: A Case Study on the NSL-KDD Dataset

2025-03-04 · Ghazal Ghajari, Elaheh Ghajari, Hossein Mohammadi, Fathi Amsaad

The rapid expansion of Internet of Things (IoT) networks has introduced new security challenges, necessitating efficient and reliable methods for intrusion detection. In this study, a detection framework based on hyperdi…

Intrusion Detection

Feature selection for intrusion detection systems

2021-06-28 · Firuz Kamalov, Sherif Moussa, Rita Zgheib, Omar Mashaal

In this paper, we analyze existing feature selection methods to identify the key elements of network traffic data that allow intrusion detection. In addition, we propose a new feature selection method that addresses the …

feature selectionIntrusion Detection

A Hybrid Deep Learning Anomaly Detection Framework for Intrusion Detection

2022-12-02 · Rahul Kale, Zhi Lu, Kar Wai Fok, Vrizlynn L. L. Thing

Cyber intrusion attacks that compromise the users' critical and sensitive data are escalating in volume and intensity, especially with the growing connections between our daily life and the Internet. The large volume and…

Anomaly DetectionDeep LearningIntrusion DetectionUnsupervised Anomaly Detection

Investigating Application of Deep Neural Networks in Intrusion Detection System Design

2025-01-27 · Mofe O. Jeje

Despite decades of development, existing IDSs still face challenges in improving detection accuracy, evasion, and detection of unknown attacks. To solve these problems, many researchers have focused on designing and deve…

feature selectionIntrusion DetectionNetwork Intrusion Detection