İpekbayrak M., Gürkaş Aydın G. Z.
Electrica, cilt.26, ss.1-16, 2026 (ESCI, TRDizin)
-
Yayın Türü:
Makale / Tam Makale
-
Cilt numarası:
26
-
Basım Tarihi:
2026
-
Doi Numarası:
10.5152/electrica.2026.26378
-
Dergi Adı:
Electrica
-
Derginin Tarandığı İndeksler:
Emerging Sources Citation Index (ESCI), TR DİZİN (ULAKBİM)
-
Sayfa Sayıları:
ss.1-16
-
İstanbul Üniversitesi-Cerrahpaşa Adresli:
Evet
Özet
Intrusion detection for Internet of Things (IoT) networks must operate at a very low false-positive rate (FPR): attacks are rare, so even a small FPR floods analysts with alerts and a detection score is useful for triage only if it behaves like a real risk estimate. This study treats these two constraints as first-class requirements and evaluates detectors the way they are deployed. Logistic regression and XGBoost detectors are trained on one IoT-23 split (A); alert thresholds are fixed once on split-A validation negatives and applied unchanged (with no test-time retuning) to held-out split-A test data, a device- and family-disjoint split (B), and the cross-domain ToN_IoT dataset. Detector scores are calibrated with Platt scaling followed by isotonic regression, and a small Lipschitz-constrained Markov decision process decoder is added to give a deterministic, auditable bound on how much a decoded behavior summary can change under bounded input drift. Under these frozen thresholds, the true-positive rate at 1% FPR is 0.996 on split A but drops to 0.787 on split B and 0.182 on cross-domain ToN_IoT, exposing a realistic generalization gap that global ranking metrics alone conceal. Isotonic calibration lowers the expected calibration error to 0.003, 0.014, and 0.077 across the three settings without altering ranking, and the value-stability certificate is sound but conservative, improving on the trivial bound only for small input-drift radii. Threshold transfer thus yields a deployment-faithful, calibrated, and auditable evaluation of IoT intrusion detection under domain shift.