arXiv:2607. 00553v1 Announce Type: cross Abstract: Lightweight machine learning models are increasingly proposed for intrusion detection in Industrial Internet of Things (IIoT) networks due to their suitability for resource-constrained edge deployment.
By MD Azizul Hakim, Md Shihab Uddin, Talha Ibne Anis
The paper introduces a framework for detecting performance drift in Machine Learning as a Service (MLaaS) tailored to Internet of Things (IoT) settings. It first builds an extraction model that learns the service’s behavior from input‑output pairs, then uses this to jointly monitor changes in data and service behavior. An adaptive temporal mechanism adjusts monitoring frequency, and experiments on real datasets show significant accuracy gains and reduced miss‑detection rates compared to baseline methods.
By Deepak Kanneganti, Sajib Mistry, Sheik Mohammad Mostakim Fattah, Erik Elmroth, Aneesh Krishna, Monowar Bhuyan
arXiv:2510. 13817v2 Announce Type: replace Abstract: The growth of IoT devices in shared environments has outpaced our ability to identify them, posing urgent risks to privacy, safety, and accountability.
By Rameen Mahmood, Tousif Ahmed, Sai Teja Peddinti, Danny Yuxing Huang
arXiv:2606. 30701v1 Announce Type: cross Abstract: As the Internet of Things (IoT) continues its rapid expansion, the attack surface grows accordingly, with emerging threats targeting smart objects and their interactions.
By Marco Arazzi, Mert Cihangiroglu, Serena Nicolazzo, Antonino Nocera, Vinod P
arXiv:2608.30745v1 Announce Type: new
Abstract: The widespread adoption of encrypted traffic poses severe challenges to current security situational awareness systems based on network traffic monitor...
By Ze Chen, Qiming Yu, Zijia Song, Guozheng Yang, Wei Yan
arXiv:2508. 00042v2 Announce Type: replace-cross Abstract: Machine learning models deployed in non-stationary environments degrade silently, since as the input distribution drifts their accuracy decays without an error signal and without labels to reveal it.
By Athanasios Tziouvaras, Carolina Fortuna, George Floros, Kostas Kolomvatsos, Panagiotis Sarigiannidis, Marko Grobelnik, Bla\v{z} Bertalani\v{c}
The paper proposes a human-centered framework for validating the semantic soundness of machine learning models used in network traffic classification. It extends existing knowledge-generation methods by integrating data, models, explainability tools, visualizations, and expert reasoning to iteratively explore, verify, and refine model behavior and preprocessing steps. The framework is built on literature findings, benchmark analyses, XAI experience, and expert feedback, offering practical guidance for ensuring models learn trustworthy, semantically meaningful patterns rather than spurious correlations.
By Igor Cherepanov, David Sessler, Alex Ulmer, Thorsten May, J\"orn Kohlhammer
arXiv:2609.36039v1 Announce Type: cross
Abstract: Machine learning (ML) and deep learning (DL) have dominated Intrusion Detection System (IDS) research in recent years. Unfortunately, many existing s...
By Yufeng Xin, Bryant Goseland, Mohamed Rahouti
arXiv:2603.25507v2 Announce Type: replace-cross
Abstract: Network Traffic Classification (NTC) increasingly relies on data-driven models, yet its practical deployment is often constrained by limited...
By Giampaolo Bovenzi, Domenico Ciuonzo, Jonatan Krolikowski, Antonio Montieri, Alfredo Nascita, Antonio Pescap\`e, Dario Rossi
arXiv:2606. 00134v1 Announce Type: cross Abstract: Intrusion Detection Systems (IDS) in Internet of Things (IoT) environments face significant challenges due to data heterogeneity, lack of labeled data, and limited model interpretability.
By Ambreen Aslam, Maaz Hassan, Bibi Zahra, Muhammad Khuram Shahzad
arXiv:2608. 13575v1 Announce Type: cross Abstract: Recent machine learning (ML) advances have demonstrated that deep learning (DL) achieves impressive results in different application domains, including the classification of computer network traffic to corresponding applications.
By Igor Cherepanov, David Sessler, Alex Ulmer, Felix Wagner, Throsten May, J\"orn Kohlhammer
The paper investigates whether machine learning models for IoT intrusion detection truly learn attack patterns or rely on dataset shortcuts. Using the CyberFlowIoT-GICAP benchmark, the authors evaluate four learning paradigms across different feature sets and split strategies, finding that performance is largely driven by feature representation and that tree-based models can exploit temporal artifacts. The study also highlights asymmetric attack detectability and proposes a four-point protocol checklist for realistic evaluation.
By Uday Shankar Roy, Mahbuba Jahan Minu