CCA-ID: Confidence-calibrated adaptive intrusion detection with selective routing for IoT networks

The rapid expansion of Internet of Things (IoT) deployments has extended the cyber-attack surface. In resource-constrained IoT monitoring environments, maintaining always-on deep or ensemble-based intrusion detection can be challenging for high-rate, real-time traffic. This study presents CCA-ID, Confidence Calibrated Adaptive Intrusion Detection which integrates calibrated decision confidence with selective, resource-aware inference for IoT intrusion detection. CCA-ID combines an isotonic-calibrated logistic regression gate, heterogeneous heavy learners including DNN, XGBoost, and LightGBM, and a stacking meta-classifier within a class-specific confidence-driven routing mechanism. High-confidence samples are finalized by the lightweight calibrated gate, whereas low-confidence samples are selectively routed to the heavy ensemble for deeper analysis. The proposed CCA-ID is evaluated on the large-scale Gotham Dataset 2025, using a final experimental dataset comprising 7,792,438 packet-level samples across 18 traffic classes. Experimental results indicate that CCA-ID achieves 89.92% accuracy, 61.70% macro F1-score, and 98.93% macro ROC-AUC, while routing only 6.28% of samples to the heavy ensemble. The method also achieves an Expected Calibration Error (ECE) of 7.66%, showing improved confidence reliability for routing decisions. An inference-time analysis further indicates that CCA-ID achieves a 13.94 × speedup over the always-on heavy stack on a fixed stratified subset of the held-out test set. Overall, CCA-ID provides a calibrated trade-off between selective inference and heavy-model invocation for IoT intrusion detection. It reduces unnecessary heavy-model usage while maintaining strong threshold-free discriminative performance under severe class imbalance.

Authors

Institutions

Publication Details

Journal
Expert Systems with Applications
Published
2026-09-22
DOI
https://doi.org/10.1016/j.eswa.2026.134403
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

CCA-ID: Confidence-calibrated adaptive intrusion detection with selective routing for IoT networks

Bin Luo, Yong Yu, Aamir Munir, Jin Zhang
Expert Systems with Applications
Network Security and Intrusion Detection
article

CCA-ID: Confidence-calibrated adaptive intrusion detection with selective routing for IoT networks

Bin Luo, Yong Yu, Aamir Munir, Jin Zhang
article en

Abstract

The rapid expansion of Internet of Things (IoT) deployments has extended the cyber-attack surface. In resource-constrained IoT monitoring environments, maintaining always-on deep or ensemble-based intrusion detection can be challenging for high-rate, real-time traffic. This study presents CCA-ID, Confidence Calibrated Adaptive Intrusion Detection which integrates calibrated decision confidence with selective, resource-aware inference for IoT intrusion detection. CCA-ID combines an isotonic-calibrated logistic regression gate, heterogeneous heavy learners including DNN, XGBoost, and LightGBM, and a stacking meta-classifier within a class-specific confidence-driven routing mechanism. High-confidence samples are finalized by the lightweight calibrated gate, whereas low-confidence samples are selectively routed to the heavy ensemble for deeper analysis. The proposed CCA-ID is evaluated on the large-scale Gotham Dataset 2025, using a final experimental dataset comprising 7,792,438 packet-level samples across 18 traffic classes. Experimental results indicate that CCA-ID achieves 89.92% accuracy, 61.70% macro F1-score, and 98.93% macro ROC-AUC, while routing only 6.28% of samples to the heavy ensemble. The method also achieves an Expected Calibration Error (ECE) of 7.66%, showing improved confidence reliability for routing decisions. An inference-time analysis further indicates that CCA-ID achieves a 13.94 × speedup over the always-on heavy stack on a fixed stratified subset of the held-out test set. Overall, CCA-ID provides a calibrated trade-off between selective inference and heavy-model invocation for IoT intrusion detection. It reduces unnecessary heavy-model usage while maintaining strong threshold-free discriminative performance under severe class imbalance.

Expert Systems with ApplicationsVol. 334
Sichuan University (CN), Shaanxi Normal University (CN)
Reduced inequalities
Openalex Percentile: Top 9%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.