Beyond Detection Accuracy: Measuring Explanation Cost, Stability, and Utility for Resource-Aware IoT Intrusion Detection

arXiv:2608.10349 · cs.CR, cs.LG, cs.NI · Submitted 2026-08-11 · Read on arXiv

Abdurrahman Tolay

cs.CR, cs.LG, cs.NI

Submitted: 2026-08-11

Updated: 2026-08-12

Comments: 43 pages, 3 figures, 15 tables. Submitted to Internet of Things. Reproducibility materials are publicly archived on Zenodo

Code: https://github.com/AbdurrahmanTolay/resource-aware-iot-xai

License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/

Importance score: 75/100

The gist: This study jointly evaluates predictive effectiveness, explanation cost, local explanation stability, and selective explanation for binary Internet of Things (IoT) intrusion detection.

Terminology

Summary

This study jointly evaluates predictive effectiveness, explanation cost, local explanation stability, and selective explanation for binary Internet of Things (IoT) intrusion detection. A leakage-safe CICIoT2023 corpus was constructed with respect to exact 39-feature hashes through non-finite-value handling, exact-feature deduplication, conservative original-label collision removal, and deterministic hash-level partitioning. Logistic Regression, Decision Tree, Random Forest, and XGBoost were evaluated on natural and balanced test distributions. The computational cost of tree-based Shapley additive explanations (TreeSHAP) was measured, stability was assessed under prediction-preserving perturbations, and validation-calibrated policies were used to allocate explanation workload.

XGBoost provided the strongest overall predictive profile, while Random Forest produced the lowest false-positive rate. Explanation cost differed sharply by architecture: at 5,000 samples, TreeSHAP required 700.759 s for Random Forest and 1.471 s for XGBoost. Random Forest showed the strongest overall base-level explanation stability, while Decision Tree also remained highly stable in top-feature membership and attribution rank; XGBoost retained high rank and directional consistency but exhibited greater top-feature turnover and attribution-magnitude drift. On the balanced test, approximately 90% false-negative explanation coverage permitted compute savings of 28–32%, while approximately 95% coverage permitted savings of 15–23%. Savings were substantially smaller under the attack-heavy natural prevalence. These results show that the operational value of explainable IoT intrusion detection depends on predictive quality, architecture-dependent explanation cost, local stability, workload prevalence, and selective invocation rather than on detection accuracy or explanation availability alone.

Improvements for AI systems

Improvements to AI Systems:

  1. Add architecture-aware explanation cost budgeting. The AI system can dynamically choose between Random Forest and XGBoost (or other models) based on the inference-time explanation budget. For real-time IoT edge deployments, it can default to XGBoost when explanation latency is critical (1.471 s vs. 700.759 s at 5,000 samples), reserving Random Forest only for offline or low-throughput forensic analysis where lower false positives matter more.

  2. Implement selective explanation invocation with calibrated coverage thresholds. The system can predict which predictions require explanation and skip explanation generation for the rest, using validation-calibrated policies. On balanced attack distributions, it can achieve 28–32% compute savings at 90% false-negative explanation coverage, and 15–23% savings at 95% coverage, without sacrificing explanation reliability for the explained subset.

  3. Use stability-aware explanation caching and staleness detection. The system can track local explanation stability (top-feature membership, attribution rank, directional consistency) under prediction-preserving perturbations. For models like Random Forest with high base-level stability, it can cache explanations and reuse them for similar inputs, reducing redundant computation. For XGBoost, it can flag high top-feature turnover and attribution-magnitude drift, triggering re-explanation only when drift exceeds a threshold.

  4. Deploy prevalence-adaptive explanation policies. The system can adjust its selective explanation rate based on the attack prevalence in the current workload. Under attack-heavy natural prevalence (where savings are substantially smaller), it will explain a higher proportion of predictions to maintain coverage, while under balanced or benign-dominant conditions, it will aggressively skip explanations to save compute.

  5. Integrate leakage-safe data preprocessing for model training and explanation validation. The system can adopt the paper’s exact-feature hashing, deduplication, and deterministic hash-level partitioning to prevent data leakage in any downstream continual learning or model update pipeline. This ensures that explanation stability metrics and selective policies are not biased by duplicated or colliding samples.

  6. Build a dual-objective model selector. The system can rank candidate models not just by accuracy or F1, but by a composite score of predictive quality, explanation cost, and local stability. For instance, it can prefer XGBoost for high-throughput real-time detection, but switch to Random Forest when the operational priority is minimizing false positives and maximizing explanation stability for audit trails.

What the improved AI system can do:

  • Run real-time IoT intrusion detection with predictable explanation latency, choosing the optimal model per deployment context.

  • Reduce total explanation compute by up to 32% on balanced workloads without losing explanation coverage for critical false negatives.

  • Provide stable, trustworthy explanations for security analysts, with automatic detection of when an explanation is likely to be unstable (e.g., XGBoost’s top-feature turnover) and re-computation only when necessary.

  • Adapt its explanation behavior to the current threat prevalence, saving resources during normal operation and ensuring thorough analysis during active attacks.

  • Maintain model integrity over time by preventing data leakage in retraining, ensuring that explanation policies remain valid across model updates.

Related papers