Evidence map›Paper›PMID 42740058›Full record

ArticleSensors (Basel, Switzerland)2026

XAI-Driven Intrusion Detection for Internet of Things Networks.

Awatif Alqahtani, Fatimah Alakeel, Lujain Abuhaimed

Abstract read
In one paragraph

Article in Sensors (Basel, Switzerland), 2026. The graph could read no effect estimate from its abstract, so it casts no vote on the map. Not yet cited in PubMed.

0numbers the graph read from it
0cells of the map it votes in
0citing papers in PubMed
–field-weighted citation impact
1 · What the graph read from it

What it found

Each row is one number read from the abstract, on the scale the paper reported it, with its interval. Left of the dashed line favours the treatment, right favours the comparator. Under each row is the sentence it came from. New to these charts? A ten-minute tutorial.

The abstract states no effect estimate the extractor could read, or names no intervention and outcome on the map, so this paper lights no cell and moves no belief. It is still indexed, cited and linked below.

2 · The registry

The trial behind it

Trials whose registry record cites this paper, or whose number appears in the abstract. A trial that started after this paper was published is citing it as background, not reporting it.

Neither the registry nor the abstract names a trial number. If this is a trial report, that itself is worth knowing.

3 · Its place in the literature

Who cites it

0 citing papers in PubMed.

No citing paper in PubMed yet.

4 · The record

Corrections and comments

PubMed lists nothing against this paper. Absence here is not a guarantee, only a check that was made.

5 · Who and what money

Authors and funding

3 authors.

Awatif AlqahtaniComputer Science and Engineering Department, College of Applied Studies, King Saud University, Riyadh 11451, Saudi Arabia.ORCID 0000-0002-9794-6390
Fatimah AlakeelComputer Science and Engineering Department, College of Applied Studies, King Saud University, Riyadh 11451, Saudi Arabia.ORCID 0000-0002-9379-8159
Lujain AbuhaimedMaster's of Cybersecurity Program, College of Computer and Information Sciences, King Saud University, Riyadh 11451, Saudi Arabia.ORCID 0009-0001-4289-0123

Funding

King Saud University ORF-2026-1693
6 · The paper itself

Abstract

Systems that can reliably detect intrusion are increasingly in demand as the scale and heterogeneity of Internet of Things (IoT) networks rise. However, when strong tabular models are employed as a benchmark, it is not clear whether the complexity of ensembling actually pays off. The aim of this work is to systematically assess the reliability and accuracy of soft-voting ensembles across three benchmark datasets (CICIoT2023, TON_IoT, and Edge-IIoTset), applying a leakage-free protocol with twice-repeated stratified 10-fold cross-validation. Ensembles of varying sizes and compositions were benchmarked against Decision Tree, KNN, Random Forest, LightGBM, XGBoost, and CatBoost and the results revealed that ensemble complexity did not lead to a consistent increase in performance. For example, SoftVote-2 increased macro-F1 over LightGBM on CICIoT2023 from 0.8506 to 0.8563, whereas LightGBM remained superior on TON_IoT and Edge-IIoTset. A leakage analysis demonstrated that resampling before data partitioning increased accuracy by around 8 percentage points and macro-F1 by 14 to 17 percentage points. To assess the trade-off between performance and complexity, training time, inference latency, memory, and model size were all evaluated, and LIME and SHAP were also assessed for explanation stability, local fidelity, and attribution agreement. XAI-guided feature selection showed that the 15 most important features retained 98.4-99.4% of the original macro-F1 and decreased inference latency by up to 38%. The results indicate that the value of ensemble complexity varies by dataset and should be weighed against its computational cost. The main contribution of this study is a leakage-aware and explainability-informed framework that can be used to judge when ensemble complexity yields genuine predictive and practical benefits for the detection of IoT intrusion.

Indexed as

CICIoT2023cybersecurityEdge-IIoTsetensemble learningexplainabilityintrusion detection systemsIoT attacksLIMESHAPTON_IoT

Identifiers

PMID42740058
PMCPMC13567995

What OpenQuestion holds

Textmetadata
Read underepoch 390

Registered trials

None linked

Read under generation 80e0d062 · epoch 390. Bibliography from PubMed, PubMed Central and OpenAlex; grants from NIH RePORTER; trial links from ClinicalTrials.gov; estimates, votes and beliefs from the OpenQuestion graph.