Illusion of Generalisation: Zero-Padding-Induced Distributional Collapse in Cross-Dataset IoT DDoS Detection

المؤلفون

1 Department of Computing, College of Science and Computing, Wellspring University, Benin City, Edo State, Nigeria.

2 Department of Computer Science, Faculty of Physical Sciences, University of Benin, Benin City, Edo State, Nigeria

10.69513/njitcs.2026.172241.1064
المستخلص
Distributed Denial of Service (DDoS) attacks threaten the availability of Internet of Things (IoT) networks, yet detection models are typically validated only on the dataset used to train them. This study tests whether a high-performing deep-learning DDoS detector generalises to an independent benchmark, following six steps: (1) DDoS and benign flows were extracted from the CICIoT2023 and TON_IoT datasets and cleaned, deduplicated, and converted to numerical features; (2) SMOTE corrected the severe class imbalance in the CICIoT2023 training partition; (3) flows were grouped into 20-flow sliding-window sequences; (4) a hybrid CNN-BiGRU-MHA network was trained on CICIoT2023 alone; (5) the trained model was evaluated internally on held-out CICIoT2023 sequences and externally on TON_IoT without retraining, zero-padding TON_IoT's non-overlapping features to match the 39-feature model input; and (6) SHAP GradientExplainer values quantified the features driving internal predictions. Internal accuracy reached 100.00% (F1 = 1.0000), whereas external accuracy on 792 TON_IoT sequences collapsed to 24.49% (F1 = 0.0000, ROC-AUC = 0.50), a failure traced to zero-padding rather than to network architecture. SHAP attributed the internal decision boundary chiefly to packet-count rate and time-to-live anomalies. Within-dataset accuracy alone cannot certify cross-dataset generalisation, and zero-padding is not a valid substitute for semantically compatible features in cross-dataset IoT intrusion-detection evaluation.

الكلمات الرئيسية

الموضوعات الرئيسية


المقالات الجاهزة للنشر، النسخة المصححة
استمارة إلكترونية متاحة 26 September 2026