arXiv:2607. 00763v1 Announce Type: cross Abstract: Digital forensic investigations of network intrusions require analytical outputs that are traceable, reproducible, and court-defensible - requirements existing machine learning pipelines do not satisfy, since they treat original evidence as training data and produce opaque classifications without instance-level justification.
By Jose Luis Vela Alonso, Carmen Pellicer
arXiv:2608. 01454v1 Announce Type: cross Abstract: Provenance-based intrusion detection systems (PIDS) frequently report strong performance, but the conclusions drawn from these results can be highly sensitive to benchmarking choices and evaluation protocols.
By Lorenzo Guerra, Thomas Chapuis, Guillaume Duc, Pavlo Mozharovskyi, Van-Tam Nguyen
The paper investigates whether machine learning models for IoT intrusion detection truly learn attack patterns or rely on dataset shortcuts. Using the CyberFlowIoT-GICAP benchmark, the authors evaluate four learning paradigms across different feature sets and split strategies, finding that performance is largely driven by feature representation and that tree-based models can exploit temporal artifacts. The study also highlights asymmetric attack detectability and proposes a four-point protocol checklist for realistic evaluation.
By Uday Shankar Roy, Mahbuba Jahan Minu
arXiv:2607. 00553v1 Announce Type: cross Abstract: Lightweight machine learning models are increasingly proposed for intrusion detection in Industrial Internet of Things (IIoT) networks due to their suitability for resource-constrained edge deployment.
By MD Azizul Hakim, Md Shihab Uddin, Talha Ibne Anis
The study compares XGBoost and RoBERTa‑LoRA for network intrusion detection across three evaluation axes: same‑dataset performance, cross‑dataset transfer, and adversarial evasion. Both models perform similarly on the same dataset, but XGBoost outperforms RoBERTa‑LoRA by 15 F1 points and 25 balanced accuracy points when transferred to a different network, while RoBERTa‑LoRA wins by about 17 F1 points under adversarial evasion. Feature‑leakage ablation shows that cross‑dataset transfer improvements are non‑monotonic and directional, suggesting leakage is spread across features rather than isolated.
"whyItMatters":"The findings demonstrate that a model’s superiority depends on the specific robustness axis evaluated, underscoring the need for multi‑axis, multi‑metric testing in network intrusion detection research."
By Muhammad Ebad Atif, Muhammad Haider Ali
arXiv:2609.36039v1 Announce Type: cross
Abstract: Machine learning (ML) and deep learning (DL) have dominated Intrusion Detection System (IDS) research in recent years. Unfortunately, many existing s...
By Yufeng Xin, Bryant Goseland, Mohamed Rahouti
arXiv:2608. 10349v1 Announce Type: cross Abstract: Machine-learning intrusion-detection studies commonly emphasize predictive accuracy while treating explanation generation as a computationally free post-processing step.
By Abdurrahman Tolay
arXiv:2607. 13203v1 Announce Type: cross Abstract: False alarms remain a major barrier to deploying network intrusion detection systems (NIDS).
By Abu Fuad Ahmad, Istiaque Ahmed
arXiv:2607. 13801v1 Announce Type: cross Abstract: Large language model (LLM)-based intrusion detection systems (IDS) are increasingly studied for security monitoring, yet their robustness against feasible traffic manipulation remains largely empirical.
By Zhenpeng Li
arXiv:2606. 11098v1 Announce Type: cross Abstract: Recent deep learning approaches for network intrusion detection increasingly incorporate temporal architectures such as recurrent networks and Transformers, often reporting near-perfect performance on CIC-IDS2017.
By Zach Moczkodan (Royal Military College of Canada, Kingston, Canada), Hany Ragab (Royal Military College of Canada, Kingston, Canada)
arXiv:2603. 17717v4 Announce Type: replace-cross Abstract: Supervised detection of network attacks has always been a critical part of network intrusion detection systems (NIDS).
By Iakovos-Christos Zarkadis, Christos Douligeris
arXiv:2604. 12431v2 Announce Type: replace-cross Abstract: Organisations increasingly outsource privacy-sensitive data transformations to cloud providers, yet no practical mechanism lets the data owner verify that the contracted algorithm was faithfully executed.
By Miit Daga, Swarna Priya Ramu