The paper investigates whether machine learning models for IoT intrusion detection truly learn attack patterns or rely on dataset shortcuts. Using the CyberFlowIoT-GICAP benchmark, the authors evaluate four learning paradigms across different feature sets and split strategies, finding that performance is largely driven by feature representation and that tree-based models can exploit temporal artifacts. The study also highlights asymmetric attack detectability and proposes a four-point protocol checklist for realistic evaluation.
By Uday Shankar Roy, Mahbuba Jahan Minu
arXiv:2608. 10349v1 Announce Type: cross Abstract: Machine-learning intrusion-detection studies commonly emphasize predictive accuracy while treating explanation generation as a computationally free post-processing step.
By Abdurrahman Tolay
arXiv:2609.36039v1 Announce Type: cross
Abstract: Machine learning (ML) and deep learning (DL) have dominated Intrusion Detection System (IDS) research in recent years. Unfortunately, many existing s...
By Yufeng Xin, Bryant Goseland, Mohamed Rahouti
arXiv:2608. 15761v1 Announce Type: cross Abstract: Edge-IIoTset is the reference benchmark for machine-learning intrusion detection in the industrial Internet of Things, and results reported on it cluster above 99%.
By Mostafa M. Galal
arXiv:2607. 13203v1 Announce Type: cross Abstract: False alarms remain a major barrier to deploying network intrusion detection systems (NIDS).
By Abu Fuad Ahmad, Istiaque Ahmed
The paper presents a machine‑learning framework for classifying power‑system contingencies into safe, moderate, or severe categories. Using Newton‑Raphson load flow data, the study applies SMOTE, PCA, and classifiers (KNN, Random Forest, SVM) to IEEE‑14 and IEEE‑30 bus systems, evaluating performance with precision, recall, and F1 score. Random Forest achieved the highest F1 scores, while PCA improved overall performance more than SMOTE, which boosted recall at the cost of some false positives.
By Joshua Salako, Folajimi Osikomaiya, Olakorede Olamiju