Author
Listed:
- Abdalilah Alhalangy
(Department of Computer Engineering, College of Computer, Qassim University, Buraydah 52361, Saudi Arabia)
- Saleh Abdulrahman Alkhamis
(Department of Cybersecurity, College of Computer, Qassim University, Buraydah 52361, Saudi Arabia)
- Eman Abouelkheir
(Department of Computer Engineering, College of Computer, Qassim University, Buraydah 52361, Saudi Arabia
Department of Electrical Engineering, College of Engineering, Kafrelsheikh University, Kafrelsheikh 33511, Egypt)
Abstract
Effective intrusion detection for Internet of Things (IoT) environments requires balancing predictive performance, resource efficiency, and interpretability—particularly in real-world deployments where traffic distributions and attack scenarios vary. While many studies report near-perfect detection on benchmark datasets, this often overlooks model stability under distribution shifts. This paper addresses this gap by introducing a stability-focused evaluation of lightweight, explainable intrusion detection models using compact IoT-23 scenarios and a constrained set of 14 connection-level features for interpretability. Four lightweight models—logistic regression, random forest, XGBoost, and LightGBM—are assessed within a unified pipeline. Beyond standard internal validation, we implement a strict cross-scenario evaluation framework featuring a fully unseen malware capture. Our proposed Internal–External Stability Gap (IESG) framework, enhanced with normalized and multi-metric measures, highlights the degradation in consistency between internal and external metrics. Surprisingly, even models with high internal F1 scores (up to 0.9994) may experience considerable drops in external macro-F1 and specificity, exposing weaknesses in conventional evaluation. Experimentally, LightGBM provides the best trade-off between performance and compactness (606 KB) and shows the smallest stability gap for malicious detection. Nevertheless, all models show reduced balanced performance under scenario shift, underscoring that deployment readiness hinges on stability under changing conditions. Feature ablation reveals that leveraging high-impact features, such as port information, can boost internal accuracy at the expense of generalization. In summary, we demonstrate that while lightweight models deliver strong detection, only those proven stable across scenarios are viable for real-world IoT intrusion detection. Our evaluation framework offers a practical, interpretable tool for assessing model robustness.
Suggested Citation
Abdalilah Alhalangy & Saleh Abdulrahman Alkhamis & Eman Abouelkheir, 2026.
"A Stability-Centric Framework for Lightweight and Explainable Intrusion Detection,"
Future Internet, MDPI, vol. 18(6), pages 1-24, June.
Handle:
RePEc:gam:jftint:v:18:y:2026:i:6:p:305-:d:1960413
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jftint:v:18:y:2026:i:6:p:305-:d:1960413. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager The email address of this maintainer does not seem to be valid anymore. Please ask MDPI Indexing Manager to update the entry or send us the correct address
(email available below). General contact details of provider: https://www.mdpi.com .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.