MARATTO

software · Zenodo (CERN European Organization for Nuclear Research)

Auditing Collection Artefacts in IoT Intrusion Detection Datasets

2026Open accessMohamed I University

Abstract

Single-feature probing protocol and progressive ablation harness for auditing collection artefacts in network intrusion detection corpora. Reproduces every figure and table of the accompanying manuscript. Central result: in CICIoT2023, the feature Number, which records the size of the aggregation window used during feature extraction, separates benign from malicious traffic at 97.96% accuracy on a class-balanced test set, against 98.81% for all 39 features combined. The corpus contains no port, address, duration or timestamp, and is therefore compliant with the standing recommendation to exclude metadata features. Corpora are not redistributed here; they are obtained from their original distributors.

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.5281/zenodo.21577565

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.