PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 4, 2026Future Internet2 citationsOpen Access

Cross-Dataset Temporal and Semantic Generalization of Intrusion Detection Models for the Future Internet

View Full Paper
RERajesh ElangovanPDP Durga DeviMJM. Jawahar

Key Points

  • This study aims to assess the temporal robustness and cross-domain generalization of intrusion detection systems using multiple datasets.
  • Evaluated five machine-learning models: Random Forest, Gradient Boosting, Multi-Layer Perceptron, Autoencoder, and 1D-CNN.
  • Conducted in-dataset, forward temporal, and cross-domain evaluations without retraining.
  • Utilized datasets collected from 2017 to 2024 to test model performance over time.
  • Models achieved Macro-F1 scores between 0.84 and 0.96 on in-dataset evaluation.
  • Performance dropped by approximately ΔF1 of 0.20–0.27 on forward temporal testing from 2017 to 2023-2024 datasets.
  • Under cross-domain transfer, Macro-F1 scores ranged from 0.69 to 0.78, with false-positive rates rising up to 0.30.

Abstract

The increasing heterogeneity of cloud, enterprise, and Internet of Things (IoT) environments raises concerns about the long-term reliability of machine-learning-based intrusion detection systems (IDSs). This study evaluates temporal robustness and cross-domain generalization using four publicly available datasets collected between 2017 and 2024. Five representative models—Random Forest, Gradient Boosting, Multi-Layer Perceptron, Autoencoder, and a lightweight 1D-CNN—are assessed under in-dataset, forward temporal, enterprise-to-IoT transfer, and dataset-agnostic evaluation protocols without retraining. In the dataset evaluation, models achieve Macro-F1 scores between 0.84 and 0.96. However, forward temporal testing reveals consistent degradation, with performance reductions reaching ΔF1 ≈ 0.20–0.27 when models trained on 2017 enterprise traffic are applied to IoT datasets from 2023 to 2024. Under cross-domain transfer, Macro-F1 decreases to 0.69–0.78, and benign false-positive rates increase up to 0.30, indicating substantial sensitivity to traffic distribution shifts. Tree-based ensemble models show comparatively lower degradation (≈6–23%) and reduced performance variance across datasets. Semantic feature analysis further indicates that flow intensity and temporal activity features exhibit higher cross-dataset stability than protocol-dependent indicators. These findings demonstrate that IDS robustness in evolving Internet environments depends strongly on evaluation methodology and feature stability, highlighting the need for generalization-oriented assessment strategies.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Elangovan et al. (2026) studied this question.

synapsesocial.com/papers/69d0af52659487ece0fa54d8https://doi.org/10.3390/fi18040194
Ask AI
Helpful
Bookmark
Share
View Full Paper