cs.CRSep 23, 2026

Unmasking Shortcut Learning in IoT Intrusion Detection: A Forensic, Multi-Paradigm Evaluation of Feature Dependence and Data Leakage

Authors: Uday Shankar Roy, Mahbuba Jahan Minu

Organizations: Computer Science and Engineering Khulna University of Engineering & Technology Khulna, Bangladesh

Abstract

Machine learning-based Network Intrusion Detection Systems often report near-perfect performance on IoT benchmarks. However, whether these models learn generalizable attack behavior or exploit spurious dataset shortcuts- such as static testbed IP/MAC addresses and chronological recording artifacts-remains an important question. We evaluate the CyberFlowIoT-GICAP benchmark, containing 3,617,388 flow records across 126 PCAP sessions with 849,395 benign flows. Four learning paradigms are evaluated across four feature configurations using PCAP-disjoint splits; LightGBM is additionally evaluated using conventional random-flow splitting. When only statistical flow behavior is used (Fbehav), LightGBM (92.58% +/- 8.18%), Random Forest (92.59% +/- 8.18%), and Deep MLP (92.55% +/- 8.18%) achieve nearly identical Macro-F1, indicating that performance is constrained by feature representation rather than model complexity. With raw timestamps (Ftstamp), tree-based models reach 99.28% Macro-F1, while the linear model remains at 90.62%, showing that nonlinear models can exploit dataset-specific temporal structure. Attack detectability is highly asymmetric: high-rate and active attacks maintain >99.8% recall from flow behavior alone in nonlinear models, whereas the DNS Beaconing drops from 27.78% to 0.00% recall when contextual features are removed. Conventional random-flow splitting increases attack recall by up to 14.00%, highlighting the effect of placing flows from the same sessions in both training and test sets. We conclude with a 4-point protocol checklist for realistic IoT NIDS evaluation.

Figures & tables

Explore similar work

CardsList
  1. Cross-Domain Generalization Failure in Lightweight Intrusion Detection Models for IIoT Networks

    Jul 1, 2026MD Azizul Hakim, Md Shihab Uddin, Talha Ibne AnisInternet Of ThingIntrusion Detection

  2. Evaluating Tabular Representation Learning for Network Intrusion Detection

    May 4, 2026Muhammad Usman Butt, Andreas Hotho, Daniel SchlörIntrusion DetectionTabular Learning

  3. Improving IoT Intrusion Detection Through SMOTE-Based Oversampling and Extended Multi-Model Evaluation on Side-Channel Power Data

    May 29, 2026Muhammad Khuram Shahzad, Haseeb Khan, Muhammad Masood Khan +1Intrusion DetectionOversampling