Trustworthy and Adaptive Intrusion Detection for Imbalanced IoT Traffic
Abstract
Internet of Things (IoT) intrusion detection is frequently reported as a near-solved classification problem, yet operational deployments remain vulnerable to class imbalance, distribution shift, dataset leakage, poor probability calibration, unstable explanations, and cross-network failure. This review synthesizes 28 verified sources spanning benchmark datasets, adaptive learning, generalization, explainable artificial intelligence, imbalance handling, ensemble models, probability quality, and review methodology. It develops a unified taxonomy in which data integrity, model intelligence, temporal resilience, human trust, and evaluation rigor are treated as interdependent design requirements. Mathematical foundations are provided for class-weighted risk, macro-averaged performance, Matthews correlation coefficient, calibration error, drift detection, soft voting, and additive explanations. Major findings are that random record splits can materially overstate readiness; accuracy alone obscures minority-class failure; oversampling must be confined to training folds; post-hoc explanations need stability tests; and drift adaptation requires governance, not only retraining. A reproducibility case study using an audited RT-IoT2022 copy illustrates how index leakage, duplicates, conflicting labels, and extreme skew can coexist with apparently excellent scores. The review concludes with an evidence-driven architecture and a research agenda for device-aware evaluation, calibrated uncertainty, explanation monitoring, and safe rollback. The article is intended as both a critical survey and a practical blueprint for thesis-level experimental work.