On the Role of Data Normalization in Adversarial Robustness Evaluation: A Comparative Analysis of XGBoost and Random Forest for IoT Network Intrusion Detection

Intrusion detection systems (IDS) based on machine learning (ML) have demonstrated remarkable effectiveness in detecting cyber-attacks in Internet of Things (IoT) environments. Despite their high predictive performance, the robustness of these systems against adversarial attacks remains insufficiently understood, particularly with regard to the influence of data pre-processing techniques such as feature normalisation. This study examines the impact of Min-Max normalisation on the robustness of two widely used tree-based classifiers, XGBoost and Random Forest, against adversarial attacks of the Fast Gradient Method (FGM) and Projected Gradient Descent (PGD) types. Using the ACI-IoT-2023 dataset, we conduct comprehensive experiments across three scenarios: models trained on normalized data and evaluated using a fixed perturbation magnitude (ϵ), models trained on raw data and evaluated using the same fixed ϵ, and models trained on raw data and evaluated using an adaptive ϵ calibrated to the scale of each feature. Our results demonstrate that Min-Max normalization alone does not inherently make these models robust against adversarial attacks. The apparent robustness observed on non-normalised data with a fixed perturbation budget is an artefact caused by a misalignment in the scaling of the perturbation. When using an adaptive epsilon strategy calibrated according to feature scales, the accuracies of XGBoost and Random Forest decreased to 2.30% and 2.42% respectively under the L∞ norm with the PGD attack. These results highlight the crucial importance of taking feature scaling into account when assessing robustness against adversarial attacks and provide practical recommendations for the design of reliable evaluation protocols for intrusion detection systems in the Internet of Things.

Authors

Institutions

Publication Details

Journal
Future Internet
Published
2026-09-16
DOI
https://doi.org/10.3390/fi18090483
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

On the Role of Data Normalization in Adversarial Robustness Evaluation: A Comparative Analysis of XGBoost and Random Forest for IoT Network Intrusion Detection

Sofiane Boukli Hacene, Inas Mostefai, Abdelhafid Abouaïssa
Future Internet
Network Security and Intrusion Detection
article

On the Role of Data Normalization in Adversarial Robustness Evaluation: A Comparative Analysis of XGBoost and Random Forest for IoT Network Intrusion Detection

Sofiane Boukli Hacene, Inas Mostefai, Abdelhafid Abouaïssa
article en

Abstract

Intrusion detection systems (IDS) based on machine learning (ML) have demonstrated remarkable effectiveness in detecting cyber-attacks in Internet of Things (IoT) environments. Despite their high predictive performance, the robustness of these systems against adversarial attacks remains insufficiently understood, particularly with regard to the influence of data pre-processing techniques such as feature normalisation. This study examines the impact of Min-Max normalisation on the robustness of two widely used tree-based classifiers, XGBoost and Random Forest, against adversarial attacks of the Fast Gradient Method (FGM) and Projected Gradient Descent (PGD) types. Using the ACI-IoT-2023 dataset, we conduct comprehensive experiments across three scenarios: models trained on normalized data and evaluated using a fixed perturbation magnitude (ϵ), models trained on raw data and evaluated using the same fixed ϵ, and models trained on raw data and evaluated using an adaptive ϵ calibrated to the scale of each feature. Our results demonstrate that Min-Max normalization alone does not inherently make these models robust against adversarial attacks. The apparent robustness observed on non-normalised data with a fixed perturbation budget is an artefact caused by a misalignment in the scaling of the perturbation. When using an adaptive epsilon strategy calibrated according to feature scales, the accuracies of XGBoost and Random Forest decreased to 2.30% and 2.42% respectively under the L∞ norm with the PGD attack. These results highlight the crucial importance of taking feature scaling into account when assessing robustness against adversarial attacks and provide practical recommendations for the design of reliable evaluation protocols for intrusion detection systems in the Internet of Things.

Future InternetVol. 18(9)
Université de Haute-Alsace (FR), Université Djilali de Sidi Bel Abbès (DZ)
Life in Land
Openalex Percentile: Top 8%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.