DEA-IDS: Drift-Aware Feature Selection and Few-Shot Adaptation for Cross-Domain IoT–IoMT Intrusion Detection

Intrusion Detection Systems (IDSs) are essential for securing Internet of Things (IoT) and Internet of Medical Things (IoMT) environments, yet most machine learning-based IDSs assume that training and testing data follow similar distributions. In practice, domain shifts arising from differences in device characteristics, communication protocols, and traffic patterns can substantially increase false positive rates (FPRs), reducing operational reliability. This study proposes DEA-IDS (Drift-aware, Explainable and Adaptive Intrusion Detection System), a unified framework integrating SHAP-based explainability, statistical drift analysis via the Kolmogorov–Smirnov statistic and Wasserstein distance, drift-aware stable feature selection, and few-shot adaptation, evaluated on a CICIoT2023-to-CICIoMT2024 cross-domain transfer scenario. Under a leakage-free protocol in which drift statistics and few-shot samples are drawn exclusively from the target training split, DEA-IDS reduces FPR from 0.5468 to 0.0004 while maintaining an F1-score of 0.9944; threshold-, sample-size-, and feature-selection-control sensitivity analyses confirm this reduction reflects drift-aware stable feature selection rather than test-set leakage or dimensionality reduction alone. A per-attack-family analysis shows this improvement is concentrated in high-volume flood-style attacks and is accompanied by reduced detection of ARP spoofing, malformed-MQTT, and reconnaissance traffic, reported here as an explicit limitation. These results demonstrate that explicitly modeling feature stability before adaptation improves operational robustness for cross-domain intrusion detection in heterogeneous IoT–IoMT environments.

Authors

Institutions

Publication Details

Journal
Sensors
Published
2026-09-30
DOI
https://doi.org/10.3390/s26196200
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

DEA-IDS: Drift-Aware Feature Selection and Few-Shot Adaptation for Cross-Domain IoT–IoMT Intrusion Detection

Mehmet Yavuz Yağcı, Büşra GÜNAY
Sensors
Network Security and Intrusion Detection
article

DEA-IDS: Drift-Aware Feature Selection and Few-Shot Adaptation for Cross-Domain IoT–IoMT Intrusion Detection

Mehmet Yavuz Yağcı, Büşra GÜNAY
article en

Abstract

Intrusion Detection Systems (IDSs) are essential for securing Internet of Things (IoT) and Internet of Medical Things (IoMT) environments, yet most machine learning-based IDSs assume that training and testing data follow similar distributions. In practice, domain shifts arising from differences in device characteristics, communication protocols, and traffic patterns can substantially increase false positive rates (FPRs), reducing operational reliability. This study proposes DEA-IDS (Drift-aware, Explainable and Adaptive Intrusion Detection System), a unified framework integrating SHAP-based explainability, statistical drift analysis via the Kolmogorov–Smirnov statistic and Wasserstein distance, drift-aware stable feature selection, and few-shot adaptation, evaluated on a CICIoT2023-to-CICIoMT2024 cross-domain transfer scenario. Under a leakage-free protocol in which drift statistics and few-shot samples are drawn exclusively from the target training split, DEA-IDS reduces FPR from 0.5468 to 0.0004 while maintaining an F1-score of 0.9944; threshold-, sample-size-, and feature-selection-control sensitivity analyses confirm this reduction reflects drift-aware stable feature selection rather than test-set leakage or dimensionality reduction alone. A per-attack-family analysis shows this improvement is concentrated in high-volume flood-style attacks and is accompanied by reduced detection of ARP spoofing, malformed-MQTT, and reconnaissance traffic, reported here as an explicit limitation. These results demonstrate that explicitly modeling feature stability before adaptation improves operational robustness for cross-domain intrusion detection in heterogeneous IoT–IoMT environments.

SensorsVol. 26(19)
Istanbul University-Cerrahpaşa (TR), Atlas Üniversitesi, Istanbul University (TR)
Openalex Percentile: Top 9%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

DEA-IDS: Drift-Aware Feature Selection and Few-Shot Adaptation for Cross-Domain IoT–IoMT Intrusion Detection — Mehmet Yavuz Yağcı, Büşra GÜNAY · Sensors (2026) | TGRS Research Map | TGRS