Explainable IoT Intrusion Detection Using Random Forest, SMOTE, and SHAP
DOI:
https://doi.org/10.55981/jet.823Keywords:
Explainable AI, Intrusion Detection System, Internet of Things, Random Forest, SMOTE, SHAPAbstract
Class imbalance in Internet of Things (IoT) Intrusion Detection System (IDS) datasets is a major challenge that degrades the detection performance on minority attacks and complicates model interpretability. This study investigates the performance of an IoT IDS based on Random Forest (RF) combined with the Synthetic Minority Over-sampling Technique (SMOTE) and explainable AI analysis using SHapley Additive exPlanations (SHAP) on the public IoTID20 dataset. The research pipeline consists of data preprocessing (cleaning, numerical and categorical feature encoding, normalization), stratified train–test split into 7,000 training and 3,000 test samples, training an RF baseline on the imbalanced training set, applying SMOTE to balance the DoS, Scan, Normal, and MITM ARP Spoofing classes, and training an RF–SMOTE model. The models are compared using accuracy, precision, recall, and F1-score per class as well as macro averages. Afterwards, SHAP is employed to analyse global feature importance for both models. Experimental results show that the RF baseline already achieves very high performance with an accuracy of about 0.99 and a macro F1-score of approximately 0.984, while the RF–SMOTE model maintains the same accuracy with a macro F1-score of around 0.983. SMOTE substantially improves the class distribution in the training set but yields only minor differences in aggregate performance, RF–SMOTE slightly enhances sensitivity for some minority classes, whereas the F1-score for the MITM ARP Spoofing class decreases marginally compared to the baseline. SHAP analysis indicates that flow-related traffic features such as connection duration, packet counts, byte volume, and packet direction ratios are consistently the most influential features in both models. Changes in SHAP values for the RF–SMOTE model highlight an increased relative contribution of features representing rare attack patterns, making explanations for minority classes more prominent. Overall, the proposed RF–SMOTE–SHAP framework delivers a high-performing IoT IDS while providing improved transparency in explaining detection decisions, thereby supporting the development of trustworthy and interpretable IDS solutions for IoT environments.
Downloads
References
[1] J. Ashraf, G. M. Raza, B.-S. Kim, A. Wahid, and H.-Y. Kim, “Making a Real-Time IoT Network Intrusion-Detection System (INIDS) Using a Realistic BoT–IoT Dataset with Multiple Machine-Learning Classifiers,” Appl. Sci., vol. 15(4), Feb. 2025, doi: 10.3390/app15042043.
[2] E. G. Ribera, B. M. Alvarez, C. Samuel, P. P Ioulianou, and V. G. Vassilakis, “Intrusion Detection System for RPL-Based IoT Networks,” Electronics, vol. 11(23) 4041, 2022, doi: 10.3390/electronics11234041.
[3] A. Javed, et al., “Implementation of Lightweight Machine Learning-Based Intrusion Detection System on IoT Devices of Smart Homes,” Future Internet, vol. 16(6) 200, Jun. 2024, doi: 10.3390/fi16060200.
[4] V. Kelli et al., ”IDS for Industrial Applications: A Federated Learning Approach with Active Personalization,” Sensors, vol. 21(20) 6743, Oct 2021, doi: 10.3390/s21206743.
[5] Y. Alotaibi and M. Ilyas, “Ensemble-Learning Framework for Intrusion Detection to Enhance Internet of Things’ Devices Security,” Sensors, vol.23(12) 5568, Jun 2023, doi: 10.3390/s23125568.
[6] A. Javed et al., “Embedding Tree-Based Intrusion Detection System in Smart Thermostats for Enhanced IoT Security,” Sensors, vol. 24 no. 22, 7320, Nov. 2024, 10.3390/s24227320.
[7] G. Zachos, et al., “An Anomaly-Based Intrusion Detection System for Internet of Medical Things Networks,” Electronics, vol. 10(21), 2562, Oct. 2021, doi: 10.3390/electronics10212562.
[8] F. B. Saghezchi, G. Mantas, M. A. Violas, A. J. de Oliveira Duarte, and D. Guimarães, ”Machine Learning for DDoS Attack Detection in Industry 4.0 CPPSs,” Electronics, vol. 11(4) 602, Feb. 2022, doi :10.3390/electronics11040602.
[9] M. Alsharif and D. B. Rawat, “ Study of Machine Learning for Cloud Assisted IoT Security as a Service,” Sensors, vol. 21(4) 1034, Feb. 2021, doi: 10.3390/s21041034.
[10] A. Churcher et al., “An Experimental Analysis of Attack Classification Using Machine Learning in IoT Networks,” Sensors, vol. 21 (2) 446, Jan 2021, doi: 10.3390/s21020446.
[11] C. D. Morales-Molina et al., “A Dense Neural Network Approach for Detecting Clone ID Attacks on the RPL Protocol of the IoT,” Sensors, vol. 21(9) 3173, May 2021, doi: 10.3390/s21093173.
[12] S. Ullah et al., “HDL-IDS: A Hybrid Deep Learning Architecture for Intrusion Detection in the Internet of Vehicles,” Sensors, vol 22(4) 1340, Feb. 2022, doi: 10.3390/s22041340.
[13] S. K. Erskine, “Real-Time Large-Scale Intrusion Detection and Prevention Assessment Based on Deep Learning,” Appl. Syst. Innov., vol. 8(2), April. 2025, doi: 10.3390/asi8020052.
[14] B. Sousa, N. Magaia, and S. Silva, “Intelligent Intrusion Detection System for 5G-Enabled Internet of Vehicles,” Electronics, vol. 12(8) 1757, 2023, doi: 10.3390/electronics12081757.
[15] I. Aliyu, S. Van Engelenburg, M. B. Mu'azu, J. Kim, and C. G. Lim, "Statistical detection of adversarial examples in blockchain-based federated forest in-vehicle network intrusion detection systems," IEEE Access, vol. 10, pp. 109366–109384, 2022, doi: 10.1109/ACCESS.2022.3212412.
[16] S. More, M. Idrissi, H. Mahmoud, and A. T. Asyhari, “Enhanced Intrusion Detection Systems Performance with UNSW-NB15 Data Analysis,” Algorithms, vol. 17(2), Feb. 2024, doi: 10.3390/a17020064.
[17] G. Abdelmoumin, D. B. Rawat, and M. A. Rahman, “Studying Imbalanced Learning for Anomaly-Based Intelligent IDS for Mission-Critical Internet of Things,” J. Cybersecur. Priv., vol. 3(4), pp. 706–743, Oct. 2023, doi: 10.3390/jcp3040032.
[18] K. Harahsheh, R. Al-Naimat, and C.-H. Chen, ”Using Feature Selection Enhancement to Evaluate Attack Detection in the Internet of Things Environment,” Electronics, vol. 13(9) 1678, Apr. 2024, doi: 10.3390/electronics13091678.
[19] G. C. Amaizu, A. M. V. V. Sai, M. Siddula, and D.-S Kim, “Cost-Efficient Hybrid Filter-Based Parameter Selection Scheme for Intrusion Detection System in IoT,” Electronics, vol. 14(4) 726, 2025, doi: 10.3390/electronics14040726.
[20] K. Albulayhi, Q. Abu Al-Haija, S. A. Alsuhibany, and A. Jillepalli, “IoT Intrusion Detection using Machine Learning with a Novel High Performing Feature Selection Method,” Appl. Sci., vol. 12(10), 5015, May. 2022, doi: 10.3390/app12105015.
[21] N. Abosata, S. Al-Rubaye, and G. Inalhan, “Customised Intrusion Detection for an Industrial IoT Heterogeneous Network Based on Machine Learning Algorithms Called FTL-CID,” Sensors. vol. 23(1) 321, Dec. 2022, doi: 10.3390/s23010321.
[22] A. Alrefaei and M. Ilyas, “Using Machine Learning Multiclass Classification Technique to Detect IoT Attacks in Real Time,” Sensors, vol 24(14) 4516, Jul. 2024, doi: 10.3390/s24144516.
[23] R. Lazzarini, H. Tianfield, and V. Charissis, “Federated Learning for IoT Intrusion Detection,” AI, vol. 4, pp. 509–530, 2023, doi: 10.3390/ai4030028.
[24] M. M. Mahmoud, Y. O. Youssef, and A. A. Abdel-Hamid, “ XI2S-IDS: An Explainable Intelligent 2-Stage Intrusion Detection System,” Future Internet, vol. 17(1) 25, Jan. 2025, doi: 10.3390/fi17010025.
[25] S. Ullah et al., “A New Intrusion Detection System for the Internet of Things via Deep Convolutional Neural Network and Feature Engineering,” Sensors, vol. 22(10) 3607, May 2022, doi: 10.3390/s22103607.
[26] A. Al Hanif, and M. Ilyas, “ Effective Feature Engineering Framework for Securing MQTT Protocol in IoT Environments,” Sensors, vol. 24(6) 1782, Mar. 2024, doi: 10.3390/s24061782.
[27] S. Alabdulwahab, Y.-T. Kim, and Y. Son, “Privacy-Preserving Synthetic Data Generation Method for IoT-Sensor Network IDS Using CTGAN,” Sensors, vol. 24(22) 7389, Nov. 2024, doi: 10.3390/s24227389.
[28] I. Ioannou et al., “GEMLIDS-MIoT: A Green Effective Machine Learning Intrusion Detection System Based on Federated Learning for Medical IoT Network Security Hardening,” Comput. Commun., vol. 218, pp. 209–239, Mar. 2024, doi: 10.1016/j.comcom.2024.02.023.
[29] M. Roopak, G. Y. Tian, and J. Chambers, “Multi-Objective-Based Feature Selection for DDoS Attack Detection in IoT Networks,” IET Netw., vol. 9, no. 4, pp. 214–222, 2020, doi: 10.1049/iet-net.2018.5206.
[30] A. Zahoor, W. Abbasi, M. Z. Babar, and A. Aljohani, “Robust IoT Security Using Isolation Forest and One-Class SVM Algorithms,” Sci. Rep., 15, Oct. 2025, doi: 10.1038/s41598-025-20445-4.
[31] Z. Deng, A. Torim, S. Ben Yahia, and H. Bahsi, “Generative AI in Intrusion Detection Systems for Internet of Things: A Systematic Literature Review,” IEEE Open J. Commun. Soc., pp. 4689 – 4717, May 2025, doi: 10.1109/OJCOMS.2025.3573194.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 National Research and Innovation Agency

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.
Authors who publish with this journal agree to the following terms:
The copyright to this article is transferred to BRIN if and when the article is accepted for publication. The undersigned hereby transfers any and all rights in and to the paper including without limitation all copyrights to BRIN. The undersigned hereby represents and warrants that the paper is original and that he/she is the author of the paper, except for material that is clearly identified as to its original source, with permission notices from the copyright owners where required. The undersigned represents that he/she has the power and authority to make and execute this assignment. The copyright transfer form can be downloaded here.
The corresponding author signs for and accepts responsibility for releasing this material on behalf of any and all co-authors. This agreement is to be signed by at least one of the authors who have obtained the assent of the co-author(s) where applicable. After submission of this agreement signed by the corresponding author, changes of authorship or in the order of the authors listed will not be accepted.

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.


