Skip to content
Conference

A Comparative Study of Machine Learning-Based Intrusion Detection for IoT Networks: Performance and Explainability Evaluation

Aug 2026 · 2026 International Conference on Smart Science and Technology (IncoSST) · pp. 76-81 · 0 citations · 23 references

Abstract

The attack surface of contemporary networks has significantly increased due to the rapid proliferation of Internet of Things (IoT) devices, making intrusion detection a critical security requirement. This study presents a comparative evaluation of machine learning based intrusion detection models in Internet of Things (IoT) environments with emphasis on classification performance and explainability. A total of 5000 Internet of Things (IoT) device activity instances were generated through controlled scenario based simulations, representing compromised 3185 samples, counterfeit 1060 samples, and genuine 755 samples under realistic network conditions. Each instance captures network and device level attributes including packet characteristics, entropy measures, authentication attempts, resource usage, and operational signals. Three supervised learning algorithms were evaluated including Random Forest (RF), Support Vector Machine (SVM) with radial basis function (RBF) kernel, and Logistic Regression (LR). Data preprocessing involved feature encoding, normalization, and class balanced training. Model performance was assessed using accuracy, macro average F1 score, and confusion matrix analysis. Shapley Additive Explanations (SHAP) was applied to enhance interpretability and identify key contributing features. Experimental results indicate that Random Forest (RF) achieves the highest performance with 99.73 percent accuracy and 0.9957 macro averaged F1 score, followed by Support Vector Machine with radial basis function kernel at 90.38 percent and Logistic Regression (LR) at 76.31 percent. SHAP analysis highlights payload entropy, abnormal port access, failed authentication attempts, and central processing unit usage as dominant discriminative features, demonstrating robust and interpretable intrusion detection in simulated Internet of Things (IoT) environments.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.