Explainable IoT Intrusion Detection Using Random Forest, SMOTE, and SHAP

Authors

  • Julfikar Mawansyah Universitas Mbojo Bima, Universitas Negeri Malang
  • Anik Nur Handayani Universitas Negeri Malang
  • Aji Prasetya Wibawa Universitas Negeri Malang
  • Triyanna Widiyaningtyas Universitas Negeri Malang
  • Mokh. Sholihul Hadi Universitas Negeri Malang
  • Fidyah Ajeng Wulandari Mbojo Bima University

DOI:

https://doi.org/10.55981/jet.823

Keywords:

Explainable AI, Intrusion Detection System, Internet of Things, Random Forest, SMOTE, SHAP

Abstract

Class imbalance in Internet of Things (IoT) Intrusion Detection System (IDS) datasets is a major challenge that degrades the detection performance on minority attacks and complicates model interpretability. This study investigates the performance of an IoT IDS based on Random Forest (RF) combined with the Synthetic Minority Over-sampling Technique (SMOTE) and explainable AI analysis using SHapley Additive exPlanations (SHAP) on the public IoTID20 dataset. The research pipeline consists of data preprocessing (cleaning, numerical and categorical feature encoding, normalization), stratified train–test split into 7,000 training and 3,000 test samples, training an RF baseline on the imbalanced training set, applying SMOTE to balance the DoS, Scan, Normal, and MITM ARP Spoofing classes, and training an RF–SMOTE model. The models are compared using accuracy, precision, recall, and F1-score per class as well as macro averages. Afterwards, SHAP is employed to analyse global feature importance for both models. Experimental results show that the RF baseline already achieves very high performance with an accuracy of about 0.99 and a macro F1-score of approximately 0.984, while the RF–SMOTE model maintains the same accuracy with a macro F1-score of around 0.983. SMOTE substantially improves the class distribution in the training set but yields only minor differences in aggregate performance, RF–SMOTE slightly enhances sensitivity for some minority classes, whereas the F1-score for the MITM ARP Spoofing class decreases marginally compared to the baseline. SHAP analysis indicates that flow-related traffic features such as connection duration, packet counts, byte volume, and packet direction ratios are consistently the most influential features in both models. Changes in SHAP values for the RF–SMOTE model highlight an increased relative contribution of features representing rare attack patterns, making explanations for minority classes more prominent. Overall, the proposed RF–SMOTE–SHAP framework delivers a high-performing IoT IDS while providing improved transparency in explaining detection decisions, thereby supporting the development of trustworthy and interpretable IDS solutions for IoT environments.

Downloads

Download data is not yet available.

References

[1] J. Ashraf, G. M. Raza, B.-S. Kim, A. Wahid, and H.-Y. Kim, “Making a Real-Time IoT Network Intrusion-Detection System (INIDS) Using a Realistic BoT–IoT Dataset with Multiple Machine-Learning Classifiers,” Appl. Sci., vol. 15(4), Feb. 2025, doi: 10.3390/app15042043.

[2] E. G. Ribera, B. M. Alvarez, C. Samuel, P. P Ioulianou, and V. G. Vassilakis, “Intrusion Detection System for RPL-Based IoT Networks,” Electronics, vol. 11(23) 4041, 2022, doi: 10.3390/electronics11234041.

[3] A. Javed, et al., “Implementation of Lightweight Machine Learning-Based Intrusion Detection System on IoT Devices of Smart Homes,” Future Internet, vol. 16(6) 200, Jun. 2024, doi: 10.3390/fi16060200.

[4] V. Kelli et al., ”IDS for Industrial Applications: A Federated Learning Approach with Active Personalization,” Sensors, vol. 21(20) 6743, Oct 2021, doi: 10.3390/s21206743.

[5] Y. Alotaibi and M. Ilyas, “Ensemble-Learning Framework for Intrusion Detection to Enhance Internet of Things’ Devices Security,” Sensors, vol.23(12) 5568, Jun 2023, doi: 10.3390/s23125568.

[6] A. Javed et al., “Embedding Tree-Based Intrusion Detection System in Smart Thermostats for Enhanced IoT Security,” Sensors, vol. 24 no. 22, 7320, Nov. 2024, 10.3390/s24227320.

[7] G. Zachos, et al., “An Anomaly-Based Intrusion Detection System for Internet of Medical Things Networks,” Electronics, vol. 10(21), 2562, Oct. 2021, doi: 10.3390/electronics10212562.

[8] F. B. Saghezchi, G. Mantas, M. A. Violas, A. J. de Oliveira Duarte, and D. Guimarães, ”Machine Learning for DDoS Attack Detection in Industry 4.0 CPPSs,” Electronics, vol. 11(4) 602, Feb. 2022, doi :10.3390/electronics11040602.

[9] M. Alsharif and D. B. Rawat, “ Study of Machine Learning for Cloud Assisted IoT Security as a Service,” Sensors, vol. 21(4) 1034, Feb. 2021, doi: 10.3390/s21041034.

[10] A. Churcher et al., “An Experimental Analysis of Attack Classification Using Machine Learning in IoT Networks,” Sensors, vol. 21 (2) 446, Jan 2021, doi: 10.3390/s21020446.

[11] C. D. Morales-Molina et al., “A Dense Neural Network Approach for Detecting Clone ID Attacks on the RPL Protocol of the IoT,” Sensors, vol. 21(9) 3173, May 2021, doi: 10.3390/s21093173.

[12] S. Ullah et al., “HDL-IDS: A Hybrid Deep Learning Architecture for Intrusion Detection in the Internet of Vehicles,” Sensors, vol 22(4) 1340, Feb. 2022, doi: 10.3390/s22041340.

[13] S. K. Erskine, “Real-Time Large-Scale Intrusion Detection and Prevention Assessment Based on Deep Learning,” Appl. Syst. Innov., vol. 8(2), April. 2025, doi: 10.3390/asi8020052.

[14] B. Sousa, N. Magaia, and S. Silva, “Intelligent Intrusion Detection System for 5G-Enabled Internet of Vehicles,” Electronics, vol. 12(8) 1757, 2023, doi: 10.3390/electronics12081757.

[15] I. Aliyu, S. Van Engelenburg, M. B. Mu'azu, J. Kim, and C. G. Lim, "Statistical detection of adversarial examples in blockchain-based federated forest in-vehicle network intrusion detection systems," IEEE Access, vol. 10, pp. 109366–109384, 2022, doi: 10.1109/ACCESS.2022.3212412.

[16] S. More, M. Idrissi, H. Mahmoud, and A. T. Asyhari, “Enhanced Intrusion Detection Systems Performance with UNSW-NB15 Data Analysis,” Algorithms, vol. 17(2), Feb. 2024, doi: 10.3390/a17020064.

[17] G. Abdelmoumin, D. B. Rawat, and M. A. Rahman, “Studying Imbalanced Learning for Anomaly-Based Intelligent IDS for Mission-Critical Internet of Things,” J. Cybersecur. Priv., vol. 3(4), pp. 706–743, Oct. 2023, doi: 10.3390/jcp3040032.

[18] K. Harahsheh, R. Al-Naimat, and C.-H. Chen, ”Using Feature Selection Enhancement to Evaluate Attack Detection in the Internet of Things Environment,” Electronics, vol. 13(9) 1678, Apr. 2024, doi: 10.3390/electronics13091678.

[19] G. C. Amaizu, A. M. V. V. Sai, M. Siddula, and D.-S Kim, “Cost-Efficient Hybrid Filter-Based Parameter Selection Scheme for Intrusion Detection System in IoT,” Electronics, vol. 14(4) 726, 2025, doi: 10.3390/electronics14040726.

[20] K. Albulayhi, Q. Abu Al-Haija, S. A. Alsuhibany, and A. Jillepalli, “IoT Intrusion Detection using Machine Learning with a Novel High Performing Feature Selection Method,” Appl. Sci., vol. 12(10), 5015, May. 2022, doi: 10.3390/app12105015.

[21] N. Abosata, S. Al-Rubaye, and G. Inalhan, “Customised Intrusion Detection for an Industrial IoT Heterogeneous Network Based on Machine Learning Algorithms Called FTL-CID,” Sensors. vol. 23(1) 321, Dec. 2022, doi: 10.3390/s23010321.

[22] A. Alrefaei and M. Ilyas, “Using Machine Learning Multiclass Classification Technique to Detect IoT Attacks in Real Time,” Sensors, vol 24(14) 4516, Jul. 2024, doi: 10.3390/s24144516.

[23] R. Lazzarini, H. Tianfield, and V. Charissis, “Federated Learning for IoT Intrusion Detection,” AI, vol. 4, pp. 509–530, 2023, doi: 10.3390/ai4030028.

[24] M. M. Mahmoud, Y. O. Youssef, and A. A. Abdel-Hamid, “ XI2S-IDS: An Explainable Intelligent 2-Stage Intrusion Detection System,” Future Internet, vol. 17(1) 25, Jan. 2025, doi: 10.3390/fi17010025.

[25] S. Ullah et al., “A New Intrusion Detection System for the Internet of Things via Deep Convolutional Neural Network and Feature Engineering,” Sensors, vol. 22(10) 3607, May 2022, doi: 10.3390/s22103607.

[26] A. Al Hanif, and M. Ilyas, “ Effective Feature Engineering Framework for Securing MQTT Protocol in IoT Environments,” Sensors, vol. 24(6) 1782, Mar. 2024, doi: 10.3390/s24061782.

[27] S. Alabdulwahab, Y.-T. Kim, and Y. Son, “Privacy-Preserving Synthetic Data Generation Method for IoT-Sensor Network IDS Using CTGAN,” Sensors, vol. 24(22) 7389, Nov. 2024, doi: 10.3390/s24227389.

[28] I. Ioannou et al., “GEMLIDS-MIoT: A Green Effective Machine Learning Intrusion Detection System Based on Federated Learning for Medical IoT Network Security Hardening,” Comput. Commun., vol. 218, pp. 209–239, Mar. 2024, doi: 10.1016/j.comcom.2024.02.023.

[29] M. Roopak, G. Y. Tian, and J. Chambers, “Multi-Objective-Based Feature Selection for DDoS Attack Detection in IoT Networks,” IET Netw., vol. 9, no. 4, pp. 214–222, 2020, doi: 10.1049/iet-net.2018.5206.

[30] A. Zahoor, W. Abbasi, M. Z. Babar, and A. Aljohani, “Robust IoT Security Using Isolation Forest and One-Class SVM Algorithms,” Sci. Rep., 15, Oct. 2025, doi: 10.1038/s41598-025-20445-4.

[31] Z. Deng, A. Torim, S. Ben Yahia, and H. Bahsi, “Generative AI in Intrusion Detection Systems for Internet of Things: A Systematic Literature Review,” IEEE Open J. Commun. Soc., pp. 4689 – 4717, May 2025, doi: 10.1109/OJCOMS.2025.3573194.

Downloads

Published

2026-08-31

Issue

Section

Articles

How to Cite

[1]
J. Mawansyah, A. Nur Handayani, A. P. Wibawa, T. Widiyaningtyas, M. S. Hadi, and F. A. Wulandari, “Explainable IoT Intrusion Detection Using Random Forest, SMOTE, and SHAP”, Jurnal Elektronika dan Telekomunikasi, vol. 26, no. 1, pp. 45–53, Aug. 2026, doi: 10.55981/jet.823.