arXiv Machine Learning

Maintaining IoT Device Identification under Concept Drift via Budget-Aware Traffic Labeling

arXiv:2608. 15465v1 Announce Type: cross Abstract: Identification of IoT device types from passive traffic is increasingly used for security management in enterprise and ISP networks.

arXiv AI
Aug 20

Performance Drift Detection in Machine Learning as a Service (MLaaS) for IoT Environments

The paper introduces a framework for detecting performance drift in Machine Learning as a Service (MLaaS) tailored to Internet of Things (IoT) settings. It first builds an extraction model that learns the service’s behavior from input‑output pairs, then uses this to jointly monitor changes in data and service behavior. An adaptive temporal mechanism adjusts monitoring frequency, and experiments on real datasets show significant accuracy gains and reduced miss‑detection rates compared to baseline methods.

By Deepak Kanneganti, Sajib Mistry, Sheik Mohammad Mostakim Fattah, Erik Elmroth, Aneesh Krishna, Monowar Bhuyan
arXiv Machine Learning
Jul 20

Label-Free Concept Drift Assessment for Reliable AI in Emerging Wireless Applications

arXiv:2508. 00042v2 Announce Type: replace-cross Abstract: Machine learning models deployed in non-stationary environments degrade silently, since as the input distribution drifts their accuracy decays without an error signal and without labels to reveal it.

By Athanasios Tziouvaras, Carolina Fortuna, George Floros, Kostas Kolomvatsos, Panagiotis Sarigiannidis, Marko Grobelnik, Bla\v{z} Bertalani\v{c}
arXiv Machine Learning
Sep 16

Beyond Measurement Metrics: A Human-Centered Framework for Semantic Validation of Network Traffic Classification

The paper proposes a human-centered framework for validating the semantic soundness of machine learning models used in network traffic classification. It extends existing knowledge-generation methods by integrating data, models, explainability tools, visualizations, and expert reasoning to iteratively explore, verify, and refine model behavior and preprocessing steps. The framework is built on literature findings, benchmark analyses, XAI experience, and expert feedback, offering practical guidance for ensuring models learn trustworthy, semantically meaningful patterns rather than spurious correlations.

By Igor Cherepanov, David Sessler, Alex Ulmer, Thorsten May, J\"orn Kohlhammer
arXiv AI
Aug 17

Interactive Analysis of Global Explanations using Aggregated Class Activation Maps for Network Data

arXiv:2608. 13575v1 Announce Type: cross Abstract: Recent machine learning (ML) advances have demonstrated that deep learning (DL) achieves impressive results in different application domains, including the classification of computer network traffic to corresponding applications.

By Igor Cherepanov, David Sessler, Alex Ulmer, Felix Wagner, Throsten May, J\"orn Kohlhammer
arXiv Machine Learning
Sep 25

Unmasking Shortcut Learning in IoT Intrusion Detection: A Forensic, Multi-Paradigm Evaluation of Feature Dependence and Data Leakage

The paper investigates whether machine learning models for IoT intrusion detection truly learn attack patterns or rely on dataset shortcuts. Using the CyberFlowIoT-GICAP benchmark, the authors evaluate four learning paradigms across different feature sets and split strategies, finding that performance is largely driven by feature representation and that tree-based models can exploit temporal artifacts. The study also highlights asymmetric attack detectability and proposes a four-point protocol checklist for realistic evaluation.

By Uday Shankar Roy, Mahbuba Jahan Minu