Integrity-Audited Intrusion Detection under Withheld IoT Traffic Contexts
DOI:
https://doi.org/10.21009/JKOMA.091.07Keywords:
IoT intrusion detection, data integrity, context shift, RT-IoT2022, ReproducibilityAbstract
Row-by-row examination of flow-based IoT intrusion detection would allow exact predictor replicas to exist in both train and test datasets. This research conducted auditing on RT-IoT2022 prior to modelling and focused on fixed baseline detectors under withheld traffic situations. The raw data consisted of 5,202 replicate rows besides the first replica and six predictor replicas with inconsistent labels in 128 rows. Data cleansing resulted in 117,909 flows. There were 6.59-6.90% of rows having an exact replica in training in the fixed five-fold raw split. Macro-F1 diagnostic random forest score for raw rows and cleansed rows were 0.9965 and 0.9968 respectively. On clean data, random forest scored 0.9968 with all 83 predictors and 0.9963 after ports and service were removed. Complete-service holdouts gave macro-F1 of 0.660–0.994. With disjoint normal pools, recall for an attack family absent from training ranged from 0.354 to 1.000. At an assumed attack prevalence of 1%, projected positive predictive value was 0.565. The benchmark supports strong interpolation inside one capture, but context changes still exposed failures.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Zainab Abbas Fadhil

This work is licensed under a Creative Commons Attribution 4.0 International License.