Resource-Aware XAI for IoT IDS

Arxiv pdf 2026-08-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

Machine-learning intrusion-detection studies commonly emphasize predictive accuracy while treating explanation generation as a computationally free post-processing step. This study jointly evaluates predictive effectiveness, explanation cost, local explanation stability, and selective explanation for binary Internet of Things (IoT) intrusion detection. A leakage-safe CICIoT2023 corpus was constructed with respect to exact 39-feature hashes through nonfinite-value handling, exact-feature deduplication, conservative original-label collision removal, and deterministic hash-level partitioning. Logistic Regression, Decision Tree, Random Forest, and XGBoost were evaluated on natural and balanced test distributions. The computational cost of tree-based Shapley additive explanations (TreeSHAP) was measured, stability was assessed under prediction-preserving perturbations, and validation-calibrated policies were used to allocate explanation workload. XGBoost provided the strongest overall predictive profile, while Random Forest produced the lowest false-positive rate. Explanation cost differed sharply by architecture: at 5,000 samples, TreeSHAP required 700.759 s for Random Forest and 1.471 s for XGBoost. Random Forest showed the strongest overall base-level explanation stability, while Decision Tree also remained highly stable in top-feature membership and attribution rank; XGBoost retained high rank and directional consistency but exhibited greater top-feature turnover and attribution-magnitude drift. On the balanced test, approximately 90% false-negative explanation coverage permitted compute savings of 2832%, while approximately 95% coverage permitted savings of 1523%. These results show that the operational value of explainable IoT intrusion detection depends on predictive quality, architecture-dependent explanation cost, local stability, workload prevalence, and selective invocation rather than on detection accuracy or explanation availability alone.

Loading executive summary...

LINK COPIED TO CLIPBOARD