Feedback guided decision boundary adaptation for stable IoT intrusion detection under distribution shift
Abstract Intrusion detection in Internet of Things (IoT) environments is challenging under distribution shift because static detectors may lose sensitivity, whereas continuous model retraining can increase computational cost and temporal variability. This study investigates a lightweight alternative in which the classifier remains fixed during streaming operation and adaptation is performed through bounded decision-threshold updates. The proposed framework combines sample-level online statistical estimation, feature-specific abnormality states, a global abnormality gate, predictive uncertainty, and a bounded drift-intensity signal. Predictions and statistical states are updated in a test-then-update manner for every sample, whereas decision thresholds are updated once per non-overlapping batch of 200 samples using batch-averaged uncertainty and drift feedback. The framework therefore separates fast statistical tracking from slower decision-boundary adaptation. Across three IoT intrusion-detection benchmark datasets, the proposed method achieved an overall F1-score of $$0.9387 \pm 0.0092$$ , compared with $$0.9407 \pm 0.0081$$ for Adaptive Random Forest (ARF). This small F1 reduction was accompanied by a lower false-positive rate (0.0312 vs. 0.0349), lower temporal F1 variance (0.000142 vs. 0.000188), and lower total processing cost (2.79 vs. 4.15 ms/sample). In leave-one-attack-family-out evaluation, the proposed abnormality mechanism achieved an F1-score of 0.800 with an FPR of 0.031. A separate controlled-stream analysis was used to characterize batch-level adaptation dynamics, including temporal variability and criterion-based recovery behavior around the predefined distribution shift. These results characterize decision-boundary adaptation as an accuracy–stability–efficiency trade-off rather than as an accuracy-equivalent replacement for model adaptation. The study also establishes boundedness of the threshold states and one-step updates, while explicitly distinguishing such boundedness from convergence or adversarial-robustness guarantees.
Authors
- Trung-Nghia Phung (ORCID: https://orcid.org/0000-0003-0075-3427)
- Thanh Minh Ta
- Ngoc-Tuat Dao
- Quang-Hiep Nguyen
- Hung-Cuong Nguyen
Institutions
- Le Quy Don Technical University (VN)
- Hung Vuong Hospital (VN)
- Hung Vuong University of Ho Chi Minh City (VN)
- Viet Tri University of Industry (VN)
- Trung Vuong University (VN)
- Thai Nguyen University of Information and Communication Technology (VN)
Publication Details
- Journal
- Discover Artificial Intelligence
- Published
- 2026-10-07
- DOI
- https://doi.org/10.1007/s44163-026-02370-1
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00