Feedback guided decision boundary adaptation for stable IoT intrusion detection under distribution shift

Abstract Intrusion detection in Internet of Things (IoT) environments is challenging under distribution shift because static detectors may lose sensitivity, whereas continuous model retraining can increase computational cost and temporal variability. This study investigates a lightweight alternative in which the classifier remains fixed during streaming operation and adaptation is performed through bounded decision-threshold updates. The proposed framework combines sample-level online statistical estimation, feature-specific abnormality states, a global abnormality gate, predictive uncertainty, and a bounded drift-intensity signal. Predictions and statistical states are updated in a test-then-update manner for every sample, whereas decision thresholds are updated once per non-overlapping batch of 200 samples using batch-averaged uncertainty and drift feedback. The framework therefore separates fast statistical tracking from slower decision-boundary adaptation. Across three IoT intrusion-detection benchmark datasets, the proposed method achieved an overall F1-score of $$0.9387 \pm 0.0092$$ , compared with $$0.9407 \pm 0.0081$$ for Adaptive Random Forest (ARF). This small F1 reduction was accompanied by a lower false-positive rate (0.0312 vs. 0.0349), lower temporal F1 variance (0.000142 vs. 0.000188), and lower total processing cost (2.79 vs. 4.15 ms/sample). In leave-one-attack-family-out evaluation, the proposed abnormality mechanism achieved an F1-score of 0.800 with an FPR of 0.031. A separate controlled-stream analysis was used to characterize batch-level adaptation dynamics, including temporal variability and criterion-based recovery behavior around the predefined distribution shift. These results characterize decision-boundary adaptation as an accuracy–stability–efficiency trade-off rather than as an accuracy-equivalent replacement for model adaptation. The study also establishes boundedness of the threshold states and one-step updates, while explicitly distinguishing such boundedness from convergence or adversarial-robustness guarantees.

Authors

Institutions

Publication Details

Journal
Discover Artificial Intelligence
Published
2026-10-07
DOI
https://doi.org/10.1007/s44163-026-02370-1
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Feedback guided decision boundary adaptation for stable IoT intrusion detection under distribution shift

Trung-Nghia Phung, Thanh Minh Ta, Ngoc-Tuat Dao, Quang-Hiep Nguyen et al.
Discover Artificial Intelligence
Network Security and Intrusion Detection
article

Feedback guided decision boundary adaptation for stable IoT intrusion detection under distribution shift

Trung-Nghia Phung, Thanh Minh Ta, Ngoc-Tuat Dao, Quang-Hiep Nguyen, Hung-Cuong Nguyen
article en

Abstract

Abstract Intrusion detection in Internet of Things (IoT) environments is challenging under distribution shift because static detectors may lose sensitivity, whereas continuous model retraining can increase computational cost and temporal variability. This study investigates a lightweight alternative in which the classifier remains fixed during streaming operation and adaptation is performed through bounded decision-threshold updates. The proposed framework combines sample-level online statistical estimation, feature-specific abnormality states, a global abnormality gate, predictive uncertainty, and a bounded drift-intensity signal. Predictions and statistical states are updated in a test-then-update manner for every sample, whereas decision thresholds are updated once per non-overlapping batch of 200 samples using batch-averaged uncertainty and drift feedback. The framework therefore separates fast statistical tracking from slower decision-boundary adaptation. Across three IoT intrusion-detection benchmark datasets, the proposed method achieved an overall F1-score of $$0.9387 \pm 0.0092$$ , compared with $$0.9407 \pm 0.0081$$ for Adaptive Random Forest (ARF). This small F1 reduction was accompanied by a lower false-positive rate (0.0312 vs. 0.0349), lower temporal F1 variance (0.000142 vs. 0.000188), and lower total processing cost (2.79 vs. 4.15 ms/sample). In leave-one-attack-family-out evaluation, the proposed abnormality mechanism achieved an F1-score of 0.800 with an FPR of 0.031. A separate controlled-stream analysis was used to characterize batch-level adaptation dynamics, including temporal variability and criterion-based recovery behavior around the predefined distribution shift. These results characterize decision-boundary adaptation as an accuracy–stability–efficiency trade-off rather than as an accuracy-equivalent replacement for model adaptation. The study also establishes boundedness of the threshold states and one-step updates, while explicitly distinguishing such boundedness from convergence or adversarial-robustness guarantees.

Discover Artificial IntelligenceVol. 6(1)
Le Quy Don Technical University (VN), Hung Vuong Hospital (VN), Hung Vuong University of Ho Chi Minh City (VN), Viet Tri University of Industry (VN), Trung Vuong University (VN), Thai Nguyen University of Information and Communication Technology (VN)
Openalex Percentile: Top 11%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.