<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.4 20241031//EN" "JATS-journalpublishing1-4.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="research-article" dtd-version="1.4" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">ojapps</journal-id>
      <journal-title-group>
        <journal-title>Open Journal of Applied Sciences</journal-title>
      </journal-title-group>
      <issn pub-type="epub">2165-3925</issn>
      <issn pub-type="ppub">2165-3917</issn>
      <publisher>
        <publisher-name>Scientific Research Publishing</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.4236/ojapps.2026.168152</article-id>
      <article-id pub-id-type="publisher-id">ojapps-153344</article-id>
      <article-categories>
        <subj-group>
          <subject>Article</subject>
        </subj-group>
        <subj-group>
          <subject>Biomedical</subject>
          <subject>Life Sciences</subject>
          <subject>Chemistry</subject>
          <subject>Materials Science</subject>
          <subject>Computer Science</subject>
          <subject>Communications</subject>
          <subject>Engineering</subject>
          <subject>Physics</subject>
          <subject>Mathematics</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>Stress-Testing Explainable Intrusion Detection in Agricultural IoT Networks against Noise and Evasion Attacks</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author" corresp="yes">
          <name name-style="western">
            <surname>Kanga</surname>
            <given-names>Alexandre Kouamé</given-names>
          </name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <name name-style="western">
            <surname>Diako</surname>
            <given-names>Doffou Jérôme</given-names>
          </name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <name name-style="western">
            <surname>Assielou</surname>
            <given-names>Kouamé Abel</given-names>
          </name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <name name-style="western">
            <surname>Oumtanaga</surname>
            <given-names>Souleymane</given-names>
          </name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <name name-style="western">
            <surname>Brou</surname>
            <given-names>Yao Casimir</given-names>
          </name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
      </contrib-group>
      <aff id="aff1"><label>1</label> Laboratoire de Recherche en Informatique et Télécommunication (LARIT), Institut National Polytechnique Félix Houphouët-Boigny (INP-HB), Yamoussoukro, Côte d’Ivoire </aff>
      <aff id="aff2"><label>2</label> École Supérieure Africaine des Technologies de l’Information et de la Communication (ESATIC), Abidjan, Côte d’Ivoire </aff>
      <author-notes>
        <fn fn-type="conflict" id="fn-conflict">
          <p>The authors declare no conflicts of interest regarding the publication of this paper.</p>
        </fn>
      </author-notes>
      <pub-date pub-type="epub">
        <day>11</day>
        <month>08</month>
        <year>2026</year>
      </pub-date>
      <pub-date pub-type="collection">
        <month>08</month>
        <year>2026</year>
      </pub-date>
      <volume>16</volume>
      <issue>08</issue>
      <fpage>2718</fpage>
      <lpage>2737</lpage>
      <history>
        <date date-type="received">
          <day>19</day>
          <month>07</month>
          <year>2026</year>
        </date>
        <date date-type="accepted">
          <day>21</day>
          <month>08</month>
          <year>2026</year>
        </date>
        <date date-type="published">
          <day>24</day>
          <month>08</month>
          <year>2026</year>
        </date>
      </history>
      <permissions>
        <copyright-statement>© 2026 by the authors and Scientific Research Publishing Inc.</copyright-statement>
        <copyright-year>2026</copyright-year>
        <license license-type="open-access">
          <license-p> This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license ( <ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by/4.0/">https://creativecommons.org/licenses/by/4.0/</ext-link> ). </license-p>
        </license>
      </permissions>
      <self-uri content-type="doi" xlink:href="https://doi.org/10.4236/ojapps.2026.168152">https://doi.org/10.4236/ojapps.2026.168152</self-uri>
      <abstract>
        <p>Agricultural Internet of Things networks operate under variable communication conditions and expose intrusion-detection systems to both environmental perturbations and deliberate evasion. This study presents a reproducible multi-seed stress-testing protocol for a CNN-IWHO-Lite-Random Forest intrusion-detection pipeline evaluated on CICIoT2023, Farm-Flow, and UNSW-NB15. Three independent model seeds were used, while Gaussian-noise and adversarial experiments included nested internal repetitions. Preprocessing, representation learning, latent-feature selection, calibration, and threshold optimization were restricted to mutually disjoint non-test partitions, and exact feature-vector overlaps were removed before evaluation. Clean F1-scores were 0.9953 ± 0.0001, 0.4724 ± 0.0131, and 0.7480 ± 0.0183 for CICIoT2023, Farm-Flow, and UNSW-NB15, respectively. At <italic>σ</italic> = 1.0, the corresponding F1-scores were 0.9940 ± 0.0002, 0.4118 ± 0.0013, and 0.6768 ± 0.0550. Conditional attack success rates at <italic>ε</italic> = 0.8 were 16.17% ± 22.66%, 13.58% ± 10.56%, and 98.43% ± 1.17%. TreeSHAP audits and complete false-positive and false-negative summaries were used to interpret selected latent dimensions and decision failures. The results show that robustness is strongly dataset- and seed-dependent: Farm-Flow is limited primarily by baseline false positives and noise sensitivity, whereas UNSW-NB15 is consistently vulnerable to the evaluated score-query evasion attack. These findings support deployment decisions based on explicit stress tests rather than nominal accuracy alone.</p>
      </abstract>
      <kwd-group kwd-group-type="author-generated" xml:lang="en">
        <kwd>Agricultural IoT</kwd>
        <kwd>Intrusion Detection</kwd>
        <kwd>Evasion Attack</kwd>
        <kwd>Explainable Artificial Intelligence</kwd>
        <kwd>Robustness Audit</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec1">
      <title>1. Introduction</title>
      <sec id="sec1dot1">
        <title>1.1. Background and Motivation</title>
        <p>Agricultural production increasingly relies on connected sensors, actuators, edge gateways, and cloud services to support irrigation, greenhouse regulation, equipment monitoring, livestock supervision, and agronomic decision-making. These components form agricultural Internet of Things (AG-IoT) environments in which cyber incidents can affect not only information systems but also physical and biological processes. Denial-of-service attacks, false data injection, unauthorized access, malware, ransomware, and manipulation of connected equipment have therefore become central concerns for Agriculture 4.0 and Agriculture 5.0 [<xref ref-type="bibr" rid="B1">1</xref>][<xref ref-type="bibr" rid="B2">2</xref>].</p>
        <p>Intrusion detection is an important protective layer in this setting. Edge gateways are natural deployment points because they aggregate device traffic and can identify suspicious activity before it reaches supervisory services or affects control functions. However, agricultural edge environments are constrained by memory, processing capacity, intermittent connectivity, wireless interference, and changing traffic loads [<xref ref-type="bibr" rid="B3">3</xref>]. An intrusion-detection system (IDS) must consequently be assessed as an operational component rather than only as a classifier.</p>
        <p>Domain relevance is also important. Generic IoT datasets provide broad benchmarks, but they do not necessarily reproduce the periodicity, synchronization patterns, and response-flow variability found in agricultural networks. Farm-Flow was introduced to support network-flow intrusion detection in a smart-agriculture setting and offers a domain-specific complement to large generic benchmarks [<xref ref-type="bibr" rid="B4">4</xref>]. A credible AG-IoT evaluation should therefore combine domain-specific and general datasets while avoiding the assumption that strong benchmark performance transfers directly to the field.</p>
      </sec>
      <sec id="sec1dot2">
        <title>1.2. Limits of Accuracy-Only Evaluation</title>
        <p>Accuracy, precision, recall, F1-score, and area-under-the-curve measures remain essential, but they do not reveal how an IDS behaves when inputs are perturbed. Reported performance is influenced by dataset composition, preprocessing, feature selection, validation strategy, class imbalance, threshold selection, and leakage-prone variables [<xref ref-type="bibr" rid="B5">5</xref>]. A model may obtain a high F1-score while generating a substantial false-positive burden, relying on unstable correlations, or failing under small adversarial changes.</p>
        <p>These limitations are particularly consequential in agricultural cyber-physical systems. A false positive may unnecessarily isolate a legitimate sensor or actuator, while a false negative may allow malicious traffic to remain active. Environmental noise and adversarial manipulation must therefore be examined separately. Gaussian perturbations can approximate sensitivity to continuous feature variability, whereas bounded evasion attacks test whether malicious observations can be moved across the decision boundary [<xref ref-type="bibr" rid="B6">6</xref>][<xref ref-type="bibr" rid="B7">7</xref>].</p>
        <p>Explainability provides an additional audit layer. SHAP-based explanations can identify which model inputs contribute to individual decisions and have been applied to privacy-aware and federated intrusion detection [<xref ref-type="bibr" rid="B8">8</xref>]. In a hybrid pipeline, however, the explained variables may be latent dimensions rather than original network descriptors. Interpretations must therefore remain faithful to the space in which the final classifier operates.</p>
      </sec>
      <sec id="sec1dot3">
        <title>1.3. Research Question and Contributions</title>
        <p>This study addresses the following question: How reliably does a compact CNN-IWHO-Lite-Random Forest pipeline behave across clean, noisy, adversarial, and hard-case conditions when the evaluation is repeated with independent model seeds?</p>
        <p>The contribution is an audit protocol rather than a claim of universal architectural superiority. Specifically, the study provides:</p>
        <p>a leakage-aware, train-only, overlap-audited evaluation with three independent model seeds and mutually disjoint model-selection, calibration, threshold, and test roles;a dataset-specific mutability policy for Gaussian noise and normalized bounded evasion, with protected variables preserved and derived constraints recomputed;a conditional Attack Success Rate (ASR) computed only on malicious samples detected under clean conditions, with clean false-negative rates and attack coverage reported separately;TreeSHAP global and local audits of the final Random Forest in the selected latent space, together with complete false-positive and false-negative statistics;a hierarchical reporting strategy that distinguishes variation between model seeds from repetitions nested within each model.</p>
        <p>The evaluated pipeline remains relevant as a compact representation-and-selection design, but it is not presented as uniformly superior to simpler baselines or as a proven adversarial defense.</p>
      </sec>
      <sec id="sec1dot4">
        <title>1.4. Paper Organization</title>
        <p>Section 2 reviews related work. Section 3 describes the evaluated architecture, datasets, partitioning, preprocessing, optimization, calibration, and repetition strategy. Section 4 defines the perturbation, evasion, explainability, and hard-case protocols. Section 5 reports clean, noise, evasion, SHAP, and error results. Section 6 discusses the implications, ablations, operational use, and limitations. Section 7 concludes the paper.</p>
      </sec>
    </sec>
    <sec id="sec2">
      <title>2. Related Work</title>
      <sec id="sec2dot1">
        <title>2.1. Intrusion Detection in IoT and Agricultural Networks</title>
        <p>IoT intrusion detection has been studied through signature-based, anomaly-based, machine-learning, deep-learning, and hybrid approaches. Reviews show substantial differences in deployment assumptions, validation strategies, attack coverage, and public datasets [<xref ref-type="bibr" rid="B5">5</xref>]. These differences complicate comparisons and make reproducible evaluation as important as model design.</p>
        <p>Agricultural environments add domain-specific constraints. Smart farms combine sensing, actuation, wireless links, gateways, and cloud services in a cyber-physical workflow. Recent studies have emphasized both the diversity of agricultural threats [<xref ref-type="bibr" rid="B1">1</xref>][<xref ref-type="bibr" rid="B2">2</xref>] and the importance of edge-oriented detection under harsh operating conditions [<xref ref-type="bibr" rid="B3">3</xref>]. Hybrid deep-learning approaches have also been proposed for IoT-based smart farming [<xref ref-type="bibr" rid="B9">9</xref>]. Nevertheless, most reported evaluations continue to emphasize nominal classification metrics.</p>
      </sec>
      <sec id="sec2dot2">
        <title>2.2. Compact and Hybrid IDS Architectures</title>
        <p>Feature selection, dimensionality reduction, compact neural encoders, and ensemble classifiers are commonly used to reduce the computational cost of IoT intrusion detection. A survey by Thakkar and Lohiya identifies feature selection and evaluation methodology as persistent design issues [<xref ref-type="bibr" rid="B10">10</xref>]. Dataset heterogeneity further affects feature meaning and model transferability, as illustrated by the ToN-IoT analysis [<xref ref-type="bibr" rid="B11">11</xref>].</p>
        <p>The present pipeline uses a CNN as a representation encoder, IWHO-Lite to select latent dimensions, and a Random Forest for the final decision. The design separates representation learning from classification and allows the final classifier to operate on a reduced latent subset. This compactness is a design property; it does not by itself establish superiority, edge-device readiness, or adversarial resistance.</p>
      </sec>
      <sec id="sec2dot3">
        <title>2.3. Adversarial Evasion against Network IDS</title>
        <p>Adversarial machine learning demonstrates that strong nominal performance does not guarantee robustness. Network IDS attacks differ from image-domain attacks because traffic variables are heterogeneous, constrained, and often interdependent [<xref ref-type="bibr" rid="B6">6</xref>]. Qiu <italic>et al</italic>. showed that IoT intrusion detectors can be manipulated through adversarial traffic representations [<xref ref-type="bibr" rid="B7">7</xref>]. Valid evaluation must therefore define attacker knowledge, objective, budget, query access, mutable variables, bounds, and validity checks.</p>
        <p>For non-differentiable classifiers such as Random Forests, score-query attacks are a practical black-box alternative to gradient-based methods. Their results are meaningful only within the stated oracle and query budget. They do not imply robustness against white-box, transfer-based, poisoning, extraction, or packet-level adaptive attacks.</p>
      </sec>
      <sec id="sec2dot4">
        <title>2.4. Explainability and Leakage-Aware Evaluation</title>
        <p>SHAP provides additive feature attributions for global and local model interpretation [<xref ref-type="bibr" rid="B12">12</xref>]. Explainable IDS studies have used SHAP to improve transparency and support distributed or privacy-aware detection [<xref ref-type="bibr" rid="B8">8</xref>]. In hybrid systems, the explained features must be identified explicitly. When the Random Forest receives selected latent dimensions, SHAP describes contributions in that latent space and cannot be interpreted as a direct causal attribution to raw packet or flow variables.</p>
        <p>Leakage-aware evaluation is equally important. Identifiers, duplicate flows, capture artifacts, and test-informed preprocessing can inflate reported performance. Dataset heterogeneity and weak feature standardization increase this risk [<xref ref-type="bibr" rid="B11">11</xref>]. A defensible protocol must separate fitting and evaluation roles, audit overlap, and qualify claims when device, session, or temporal identifiers are unavailable.</p>
      </sec>
      <sec id="sec2dot5">
        <title>2.5. Research Gap</title>
        <p>Existing work has advanced agricultural IDS design, compact inference, adversarial evaluation, and explainability, but these elements are often assessed separately. Few studies jointly report independent model seeds, disjoint calibration and threshold roles, mutable-feature perturbations, conditional ASR denominators, attack coverage, complete hard-case totals, and latent-space SHAP additivity. This study addresses that gap through a single reproducible stress-testing protocol applied to three complementary datasets.</p>
      </sec>
    </sec>
    <sec id="sec3">
      <title>3. Evaluated Framework and Experimental Protocol</title>
      <sec id="sec3dot1">
        <title>3.1. Agricultural IoT Edge Scenario</title>
        <p>The evaluated scenario consists of field sensors and actuators communicating through an edge gateway to supervisory or cloud services. The gateway is the intended observation point for flow-based intrusion detection. The experimental study does not reproduce a specific commercial gateway; it evaluates the behavior of the detection pipeline on flow tables representative of agricultural, IoT, and general network-security contexts.</p>
      </sec>
      <sec id="sec3dot2">
        <title>3.2. CNN-IWHO-Lite-Random Forest Architecture</title>
        <p>After preprocessing, each observation is represented as a feature-axis sequence of shape <italic>d</italic><italic><sub>s</sub></italic> × 1, where (<italic>d</italic><italic><sub>s</sub></italic>) depends on the dataset and the training-seed-specific feature contract. A CNN-Lite encoder maps the preprocessed vector to a 128-dimensional representation:</p>
        <disp-formula id="FD1">
          <label>(1)</label>
          <mml:math>
            <mml:mrow>
              <mml:msub>
                <mml:mi>z</mml:mi>
                <mml:mi>i</mml:mi>
              </mml:msub>
              <mml:mo>=</mml:mo>
              <mml:msub>
                <mml:mi>g</mml:mi>
                <mml:mrow>
                  <mml:msub>
                    <mml:mi>θ</mml:mi>
                    <mml:mi>s</mml:mi>
                  </mml:msub>
                </mml:mrow>
              </mml:msub>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:msub>
                    <mml:mi>x</mml:mi>
                    <mml:mi>i</mml:mi>
                  </mml:msub>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>,</mml:mo>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:msub>
                <mml:mi>z</mml:mi>
                <mml:mi>i</mml:mi>
              </mml:msub>
              <mml:mo>∈</mml:mo>
              <mml:msup>
                <mml:mi>ℝ</mml:mi>
                <mml:mrow>
                  <mml:mn>128</mml:mn>
                </mml:mrow>
              </mml:msup>
              <mml:mo>.</mml:mo>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>The encoder comprises Conv1D (32, kernel size 5), batch normalization, ReLU, Conv1D (64, kernel size 3), batch normalization, ReLU, global average pooling, a 128-unit dense latent layer with layer normalization, a 128-unit ReLU layer, dropout of 0.1, and a sigmoid training output. The network contains 31,905 trainable parameters. Adam and binary cross-entropy are used with a batch size of 2048, a maximum of 15 epochs, learning-rate reduction, and early stopping.</p>
        <p>IWHO-Lite is a lightweight binary adaptation of the Improved Wild Horse Optimizer [<xref ref-type="bibr" rid="B13">13</xref>]. It searches a binary mask <inline-formula><mml:math display="inline"><mml:mrow><mml:msub><mml:mi> M </mml:mi><mml:mi> s </mml:mi></mml:msub><mml:mo> ∈ </mml:mo><mml:msup><mml:mrow><mml:mrow><mml:mo> { </mml:mo><mml:mrow><mml:mn> 0 </mml:mn><mml:mo> , </mml:mo><mml:mn> 1 </mml:mn></mml:mrow><mml:mo> } </mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mn> 128 </mml:mn></mml:mrow></mml:msup></mml:mrow></mml:math></inline-formula> . The selected representation is:</p>
        <disp-formula id="FD2">
          <label>(2)</label>
          <mml:math>
            <mml:mrow>
              <mml:msub>
                <mml:mover accent="true">
                  <mml:mi>z</mml:mi>
                  <mml:mo>˜</mml:mo>
                </mml:mover>
                <mml:mi>i</mml:mi>
              </mml:msub>
              <mml:mo>=</mml:mo>
              <mml:msub>
                <mml:mi>M</mml:mi>
                <mml:mi>s</mml:mi>
              </mml:msub>
              <mml:mo>⊙</mml:mo>
              <mml:msub>
                <mml:mi>z</mml:mi>
                <mml:mi>i</mml:mi>
              </mml:msub>
              <mml:mo>,</mml:mo>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:msub>
                <mml:mi>k</mml:mi>
                <mml:mi>s</mml:mi>
              </mml:msub>
              <mml:mo>=</mml:mo>
              <mml:msub>
                <mml:mrow>
                  <mml:mrow>
                    <mml:mo>‖</mml:mo>
                    <mml:mrow>
                      <mml:msub>
                        <mml:mi>M</mml:mi>
                        <mml:mi>s</mml:mi>
                      </mml:msub>
                    </mml:mrow>
                    <mml:mo>‖</mml:mo>
                  </mml:mrow>
                </mml:mrow>
                <mml:mn>0</mml:mn>
              </mml:msub>
              <mml:mo>.</mml:mo>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>The optimization objective is evaluated on the model-selection partition:</p>
        <disp-formula id="FD3">
          <label>(3)</label>
          <mml:math>
            <mml:mrow>
              <mml:mi>J</mml:mi>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:msub>
                    <mml:mi>M</mml:mi>
                    <mml:mi>s</mml:mi>
                  </mml:msub>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>=</mml:mo>
              <mml:mn>1</mml:mn>
              <mml:mo>−</mml:mo>
              <mml:mi>F</mml:mi>
              <mml:msub>
                <mml:mn>1</mml:mn>
                <mml:mrow>
                  <mml:mi>M</mml:mi>
                  <mml:mi>S</mml:mi>
                </mml:mrow>
              </mml:msub>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:msub>
                    <mml:mi>M</mml:mi>
                    <mml:mi>s</mml:mi>
                  </mml:msub>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>+</mml:mo>
              <mml:mn>0.05</mml:mn>
              <mml:mfrac>
                <mml:mrow>
                  <mml:msub>
                    <mml:mrow>
                      <mml:mrow>
                        <mml:mo>‖</mml:mo>
                        <mml:mrow>
                          <mml:msub>
                            <mml:mi>M</mml:mi>
                            <mml:mi>s</mml:mi>
                          </mml:msub>
                        </mml:mrow>
                        <mml:mo>‖</mml:mo>
                      </mml:mrow>
                    </mml:mrow>
                    <mml:mn>0</mml:mn>
                  </mml:msub>
                </mml:mrow>
                <mml:mrow>
                  <mml:mn>128</mml:mn>
                </mml:mrow>
              </mml:mfrac>
              <mml:mo>.</mml:mo>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>The search uses a population of 16, 25 iterations, three restarts, a sigmoid binary transfer, and successive multi-fidelity Random Forest evaluations with 25, 50, and 100 trees. The final classifier is a 300-tree Random Forest with Gini splitting, bootstrap sampling, square-root feature subsampling, unrestricted depth, and class weights derived from the full training distribution.</p>
        <p>A sigmoid calibrator <italic>C</italic><italic><sub>s</sub></italic>(·) is fitted on the calibration partition. The calibrated malicious score is:</p>
        <disp-formula id="FD4">
          <label>(4)</label>
          <mml:math>
            <mml:mrow>
              <mml:msub>
                <mml:mi>p</mml:mi>
                <mml:mi>i</mml:mi>
              </mml:msub>
              <mml:mo>=</mml:mo>
              <mml:msub>
                <mml:mi>C</mml:mi>
                <mml:mi>s</mml:mi>
              </mml:msub>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:msub>
                    <mml:mi>h</mml:mi>
                    <mml:mrow>
                      <mml:msub>
                        <mml:mi>ϕ</mml:mi>
                        <mml:mi>s</mml:mi>
                      </mml:msub>
                    </mml:mrow>
                  </mml:msub>
                  <mml:mrow>
                    <mml:mo>(</mml:mo>
                    <mml:mrow>
                      <mml:msub>
                        <mml:mover accent="true">
                          <mml:mi>z</mml:mi>
                          <mml:mo>˜</mml:mo>
                        </mml:mover>
                        <mml:mi>i</mml:mi>
                      </mml:msub>
                    </mml:mrow>
                    <mml:mo>)</mml:mo>
                  </mml:mrow>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>.</mml:mo>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>The threshold <inline-formula><mml:math><mml:mrow><mml:msubsup><mml:mi> t </mml:mi><mml:mi> s </mml:mi><mml:mtext> * </mml:mtext></mml:msubsup></mml:mrow></mml:math></inline-formula> is selected on the independent threshold partition by maximizing F1:</p>
        <disp-formula id="FD5">
          <label>(5)</label>
          <mml:math>
            <mml:mrow>
              <mml:msub>
                <mml:mover accent="true">
                  <mml:mi>y</mml:mi>
                  <mml:mo>^</mml:mo>
                </mml:mover>
                <mml:mi>i</mml:mi>
              </mml:msub>
              <mml:mo>=</mml:mo>
              <mml:mi mathvariant="double-struck">I</mml:mi>
              <mml:mrow>
                <mml:mo>[</mml:mo>
                <mml:mrow>
                  <mml:msub>
                    <mml:mi>p</mml:mi>
                    <mml:mi>i</mml:mi>
                  </mml:msub>
                  <mml:mo>≥</mml:mo>
                  <mml:msubsup>
                    <mml:mi>t</mml:mi>
                    <mml:mi>s</mml:mi>
                    <mml:mtext>*</mml:mtext>
                  </mml:msubsup>
                </mml:mrow>
                <mml:mo>]</mml:mo>
              </mml:mrow>
              <mml:mo>.</mml:mo>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>Calibration is treated as an explicit procedural stage rather than as a universally beneficial transformation because its effect on Brier score and expected calibration error varies across datasets and seeds.</p>
      </sec>
      <sec id="sec3dot3">
        <title>3.3. Datasets, Label Mapping, and Partitioning</title>
        <p>The evaluation uses CICIoT2023, Farm-Flow, and UNSW-NB15. CICIoT2023 is mapped to binary labels by treating recognized benign traffic as class 0 and all attack categories as class 1. Farm-Flow uses the binary is_attack label, and the traffic field is excluded. UNSW-NB15 uses the binary label field, while id and attack_cat are excluded from the model inputs.</p>
        <p>The experiments use model seeds 42, 2027, and 314159. Partitioning precedes all learned transformations. Same-label duplicate vectors are reduced to a single instance. Exact feature-vector overlaps across fitting and test roles are audited and removed. Conflicting-label feature groups are excluded from fitting partitions and retained without label rewriting in the test set for sensitivity analysis. CICIoT2023 contains no ambiguous test rows; Farm-Flow contains 51 rows in three ambiguous groups; and UNSW-NB15 contains eight rows in four groups.</p>
        <p>The released feature tables do not provide a consistent device, farm, session, capture, or timestamp identifier suitable for a harmonized grouped or temporal split across all datasets. Stratified seed-specific partitions and exact-vector overlap auditing were therefore used. The small variation in the CICIoT2023 test size results from overlap removal after seed-specific partitioning. The resulting seed-specific partitions, class distributions, validation roles, overlap audit, and ambiguous test rows/groups are summarized in <bold>Table 1</bold>.</p>
        <p><bold>Table 1.</bold> Seed-specific partitions, class distributions, validation roles, and overlap audit. B/M denotes benign/malicious; MS/Cal/Thr denotes model-selection/calibration/threshold.</p>
        <table-wrap id="tbl1">
          <label>Table 1</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Dataset</bold>
                </td>
                <td>
                  <bold>Seed</bold>
                </td>
                <td>
                  <bold>Train N (B/M)</bold>
                </td>
                <td>
                  <bold>Validation N (B/M)</bold>
                </td>
                <td>
                  <bold>Test N (B/M)</bold>
                </td>
                <td>
                  <bold>MS/Cal/Thr N</bold>
                </td>
                <td>
                  <bold>Exact overlaps before/after</bold>
                </td>
                <td>
                  <bold>Ambiguous test rows/groups</bold>
                </td>
              </tr>
              <tr>
                <td>CICIoT2023</td>
                <td>42</td>
                <td>498,924 (11,769/487,155)</td>
                <td>149,183 (3492/145,691)</td>
                <td>1,163,577 (27,395/1,136,182)</td>
                <td>74,591/37,296/37,296</td>
                <td>7622/0</td>
                <td>0/0</td>
              </tr>
              <tr>
                <td>CICIoT2023</td>
                <td>2027</td>
                <td>498,874 (11,768/487,106)</td>
                <td>149,200 (3490/145,710)</td>
                <td>1,163,579 (27,398/1,136,181)</td>
                <td>74,600/37,300/37,300</td>
                <td>7581/0</td>
                <td>0/0</td>
              </tr>
              <tr>
                <td>CICIoT2023</td>
                <td>314,159</td>
                <td>498,836 (11,773/487,063)</td>
                <td>149,272 (3489/145,783)</td>
                <td>1,163,586 (27,416/1,136,170)</td>
                <td>74,636/37,318/37,318</td>
                <td>7513/0</td>
                <td>0/0</td>
              </tr>
              <tr>
                <td>Farm-Flow</td>
                <td>42</td>
                <td>3510 (909/2601)</td>
                <td>620 (160/460)</td>
                <td>2348 (1768/580)</td>
                <td>310/155/155</td>
                <td>48/0</td>
                <td>51/3</td>
              </tr>
              <tr>
                <td>Farm-Flow</td>
                <td>2027</td>
                <td>3510 (909/2601)</td>
                <td>620 (160/460)</td>
                <td>2348 (1768/580)</td>
                <td>310/155/155</td>
                <td>48/0</td>
                <td>51/3</td>
              </tr>
              <tr>
                <td>Farm-Flow</td>
                <td>314,159</td>
                <td>3510 (909/2601)</td>
                <td>620 (160/460)</td>
                <td>2348 (1768/580)</td>
                <td>310/155/155</td>
                <td>48/0</td>
                <td>51/3</td>
              </tr>
              <tr>
                <td>UNSW-NB15</td>
                <td>42</td>
                <td>85,689 (43,912/41,777)</td>
                <td>15,122 (7749/7373)</td>
                <td>52,746 (33,759/18,987)</td>
                <td>7561/3780/3781</td>
                <td>1204/0</td>
                <td>8/4</td>
              </tr>
              <tr>
                <td>UNSW-NB15</td>
                <td>2027</td>
                <td>85,689 (43,912/41,777)</td>
                <td>15,122 (7749/7373)</td>
                <td>52,746 (33,759/18,987)</td>
                <td>7561/3780/3781</td>
                <td>1204/0</td>
                <td>8/4</td>
              </tr>
              <tr>
                <td>UNSW-NB15</td>
                <td>314,159</td>
                <td>85,689 (43,912/41,777)</td>
                <td>15,122 (7749/7373)</td>
                <td>52,746 (33,759/18,987)</td>
                <td>7561/3780/3781</td>
                <td>1204/0</td>
                <td>8/4</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
      </sec>
      <sec id="sec3dot4">
        <title>3.4. Leakage-Aware Preprocessing and Validation Roles</title>
        <p>Numeric features are imputed with the training median and standardized with training-only means and standard deviations. For UNSW-NB15, categorical variables (proto, service, and state) are imputed with the training mode and one-hot encoded with unknown categories ignored. Constant columns are identified within the training scope and removed. The fitted transformations are then applied unchanged to the model-selection, calibration, threshold, and test partitions.</p>
        <p>The validation partition is divided into three disjoint roles. The model-selection subset is used for CNN monitoring and IWHO-Lite fitness evaluation. The calibration subset is used only to fit the sigmoid score mapping. The threshold subset is used only to select <inline-formula><mml:math><mml:mrow><mml:msubsup><mml:mi> t </mml:mi><mml:mi> s </mml:mi><mml:mtext> * </mml:mtext></mml:msubsup></mml:mrow></mml:math></inline-formula> . The held-out test set is not used for preprocessing, CNN training, latent-mask selection, calibration, or threshold optimization.</p>
      </sec>
      <sec id="sec3dot5">
        <title>3.5. Model Selection, Calibration, and Computational Profile</title>
        <p><bold>Table 2</bold> reports seed-specific input dimensions, selected latent counts, epochs, thresholds, Random Forest sizes, and measured batch-inference latency. The selected latent count ranges from 37 to 39 for CICIoT2023, 59 to 65 for Farm-Flow, and 40 to 44 for UNSW-NB15.</p>
        <p>The final Random Forest class weights are approximately 21.19/0.512 for benign/malicious CICIoT2023 observations, 1.931/0.675 for Farm-Flow, and 0.976/1.026 for UNSW-NB15. The resulting model sizes show that the encoder is compact, whereas the Random Forest can occupy several to several tens of mebibytes. The term compact is therefore used for the representation and selected latent subset, not as evidence of deployment readiness on a specific agricultural gateway.</p>
        <p><bold>Table 2</bold><bold>.</bold> Seed-specific model configuration and measured computational profile. Latency was measured in the experimental environment and is not an edge-device benchmark.</p>
        <table-wrap id="tbl2">
          <label>Table 2</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Dataset</bold>
                </td>
                <td>
                  <bold>Seed</bold>
                </td>
                <td>
                  <bold>Input dimension</bold>
                </td>
                <td>
                  <bold>Epochs</bold>
                </td>
                <td>
                  <bold>Selected latent k</bold>
                </td>
                <td>
                  <bold>Threshold</bold>
                </td>
                <td>
                  <bold>RF size (MiB)</bold>
                </td>
                <td>
                  <bold>Latency (ms/sample)</bold>
                </td>
              </tr>
              <tr>
                <td>CICIoT2023</td>
                <td>42</td>
                <td>43</td>
                <td>4</td>
                <td>37</td>
                <td>0.734</td>
                <td>39.3</td>
                <td>0.098</td>
              </tr>
              <tr>
                <td>CICIoT2023</td>
                <td>2027</td>
                <td>40</td>
                <td>4</td>
                <td>37</td>
                <td>0.646</td>
                <td>40.8</td>
                <td>0.097</td>
              </tr>
              <tr>
                <td>CICIoT2023</td>
                <td>314,159</td>
                <td>43</td>
                <td>5</td>
                <td>39</td>
                <td>0.534</td>
                <td>38.7</td>
                <td>0.096</td>
              </tr>
              <tr>
                <td>Farm-Flow</td>
                <td>42</td>
                <td>28</td>
                <td>5</td>
                <td>65</td>
                <td>0.633</td>
                <td>5.5</td>
                <td>0.133</td>
              </tr>
              <tr>
                <td>Farm-Flow</td>
                <td>2027</td>
                <td>28</td>
                <td>7</td>
                <td>65</td>
                <td>0.583</td>
                <td>5.6</td>
                <td>0.135</td>
              </tr>
              <tr>
                <td>Farm-Flow</td>
                <td>314,159</td>
                <td>28</td>
                <td>5</td>
                <td>59</td>
                <td>0.597</td>
                <td>5.6</td>
                <td>0.135</td>
              </tr>
              <tr>
                <td>UNSW-NB15</td>
                <td>42</td>
                <td>193</td>
                <td>4</td>
                <td>44</td>
                <td>0.231</td>
                <td>61.9</td>
                <td>0.101</td>
              </tr>
              <tr>
                <td>UNSW-NB15</td>
                <td>2027</td>
                <td>193</td>
                <td>15</td>
                <td>40</td>
                <td>0.366</td>
                <td>53.9</td>
                <td>0.104</td>
              </tr>
              <tr>
                <td>UNSW-NB15</td>
                <td>314,159</td>
                <td>194</td>
                <td>15</td>
                <td>41</td>
                <td>0.412</td>
                <td>55.4</td>
                <td>0.103</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
      </sec>
      <sec id="sec3dot6">
        <title>3.6. Repetition Strategy and Reporting</title>
        <p>Clean performance is reported as the mean and sample standard deviation across the three independent model seeds. Gaussian-noise experiments use five noise seeds within each model seed. Evasion experiments use three attack seeds within each model seed. For noise and evasion, internal repetitions are first averaged within each model seed; the reported uncertainty is then the standard deviation between the three model-seed means. This hierarchical procedure prevents nested repetitions from being treated as independent model trainings.</p>
      </sec>
    </sec>
    <sec id="sec4">
      <title>4. Threat, Perturbation, and Explainability Methodology</title>
      <sec id="sec4dot1">
        <title>4.1. Mutable-Feature Gaussian Noise</title>
        <p>Perturbations are applied in the cleaned continuous feature space before preprocessing. Let <italic>m</italic><italic><sub>d</sub></italic> be the dataset-specific binary mutability mask, <italic>a</italic><italic><sub>d</sub></italic> and <italic>b</italic><italic><sub>d</sub></italic> the admissible lower and upper bounds, and <italic>s</italic><italic><sub>d</sub></italic> the training standard-deviation vector. The noisy observation is:</p>
        <disp-formula id="FD6">
          <label>(6)</label>
          <mml:math>
            <mml:mrow>
              <mml:msub>
                <mml:mover accent="true">
                  <mml:mi>x</mml:mi>
                  <mml:mo>˜</mml:mo>
                </mml:mover>
                <mml:mi>i</mml:mi>
              </mml:msub>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mi>σ</mml:mi>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>=</mml:mo>
              <mml:msub>
                <mml:mi>Π</mml:mi>
                <mml:mrow>
                  <mml:mrow>
                    <mml:mo>[</mml:mo>
                    <mml:mrow>
                      <mml:msub>
                        <mml:mi>a</mml:mi>
                        <mml:mi>d</mml:mi>
                      </mml:msub>
                      <mml:mo>,</mml:mo>
                      <mml:msub>
                        <mml:mi>b</mml:mi>
                        <mml:mi>d</mml:mi>
                      </mml:msub>
                    </mml:mrow>
                    <mml:mo>]</mml:mo>
                  </mml:mrow>
                </mml:mrow>
              </mml:msub>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:msub>
                    <mml:mi>x</mml:mi>
                    <mml:mi>i</mml:mi>
                  </mml:msub>
                  <mml:mo>+</mml:mo>
                  <mml:msub>
                    <mml:mi>m</mml:mi>
                    <mml:mi>d</mml:mi>
                  </mml:msub>
                  <mml:mo>⊙</mml:mo>
                  <mml:msub>
                    <mml:mi>ξ</mml:mi>
                    <mml:mi>i</mml:mi>
                  </mml:msub>
                  <mml:mo>⊙</mml:mo>
                  <mml:msub>
                    <mml:mi>s</mml:mi>
                    <mml:mi>d</mml:mi>
                  </mml:msub>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>,</mml:mo>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:msub>
                <mml:mi>ξ</mml:mi>
                <mml:mi>i</mml:mi>
              </mml:msub>
              <mml:mo>~</mml:mo>
              <mml:mi mathvariant="script">N</mml:mi>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:mn>0</mml:mn>
                  <mml:mo>,</mml:mo>
                  <mml:msup>
                    <mml:mi>σ</mml:mi>
                    <mml:mn>2</mml:mn>
                  </mml:msup>
                  <mml:mi>I</mml:mi>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>.</mml:mo>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>The canonical grid is <inline-formula><mml:math display="inline"><mml:mrow><mml:mi> σ </mml:mi><mml:mo> ∈ </mml:mo><mml:mrow><mml:mo> { </mml:mo><mml:mrow><mml:mn> 0 </mml:mn><mml:mo> , </mml:mo><mml:mn> 0.2 </mml:mn><mml:mo> , </mml:mo><mml:mn> 0.5 </mml:mn><mml:mo> , </mml:mo><mml:mn> 1.0 </mml:mn></mml:mrow><mml:mo> } </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> . Five noise seeds are used per model seed. CICIoT2023 and UNSW-NB15 are evaluated on fixed test cohorts capped at 50,000 observations for this stage, whereas Farm-Flow uses its complete test set. The <italic>σ</italic> = 0 condition uses the same reference cohort as the nonzero conditions.</p>
        <p>The mutable continuous features and the validity policy are reported in <bold>Table 3(b)</bold>. Discrete, categorical, label, identifier-like, and protected variables are preserved exactly.</p>
      </sec>
      <sec id="sec4dot2">
        <title>4.2. Bounded Score-Query Evasion</title>
        <p>The attacker can query the calibrated malicious score and knows the feature schema, preprocessing procedure, and mutability policy. The attacker does not access CNN parameters, the internal IWHO-Lite mask values, Random Forest trees, gradients, or training data.</p>
        <p>Budgets are normalized by the admissible feature ranges. For a mutable feature <italic>j</italic>, the constraint is:</p>
        <disp-formula id="FD7">
          <label>(7)</label>
          <mml:math>
            <mml:mrow>
              <mml:mrow>
                <mml:mo>|</mml:mo>
                <mml:mrow>
                  <mml:msub>
                    <mml:mi>δ</mml:mi>
                    <mml:mrow>
                      <mml:mi>i</mml:mi>
                      <mml:mi>j</mml:mi>
                    </mml:mrow>
                  </mml:msub>
                </mml:mrow>
                <mml:mo>|</mml:mo>
              </mml:mrow>
              <mml:mo>≤</mml:mo>
              <mml:mi>ε</mml:mi>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:msub>
                    <mml:mi>b</mml:mi>
                    <mml:mrow>
                      <mml:mi>d</mml:mi>
                      <mml:mi>j</mml:mi>
                    </mml:mrow>
                  </mml:msub>
                  <mml:mo>−</mml:mo>
                  <mml:msub>
                    <mml:mi>a</mml:mi>
                    <mml:mrow>
                      <mml:mi>d</mml:mi>
                      <mml:mi>j</mml:mi>
                    </mml:mrow>
                  </mml:msub>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>,</mml:mo>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:msub>
                <mml:mi>δ</mml:mi>
                <mml:mrow>
                  <mml:mi>i</mml:mi>
                  <mml:mi>j</mml:mi>
                </mml:mrow>
              </mml:msub>
              <mml:mo>=</mml:mo>
              <mml:mn>0</mml:mn>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>for</mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>protected</mml:mtext>
              <mml:mtext>
                 
              </mml:mtext>
              <mml:mtext>features</mml:mtext>
              <mml:mo>.</mml:mo>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>The objective is to minimize the calibrated malicious score of the complete pipeline:</p>
        <disp-formula id="FD8">
          <label>(8)</label>
          <mml:math>
            <mml:mrow>
              <mml:munder>
                <mml:mrow>
                  <mml:mtext>min</mml:mtext>
                </mml:mrow>
                <mml:mrow>
                  <mml:msub>
                    <mml:mi>δ</mml:mi>
                    <mml:mi>i</mml:mi>
                  </mml:msub>
                </mml:mrow>
              </mml:munder>
              <mml:msub>
                <mml:mi>C</mml:mi>
                <mml:mi>s</mml:mi>
              </mml:msub>
              <mml:mrow>
                <mml:mo>[</mml:mo>
                <mml:mrow>
                  <mml:msub>
                    <mml:mi>h</mml:mi>
                    <mml:mrow>
                      <mml:msub>
                        <mml:mi>ϕ</mml:mi>
                        <mml:mi>s</mml:mi>
                      </mml:msub>
                    </mml:mrow>
                  </mml:msub>
                  <mml:mrow>
                    <mml:mo>(</mml:mo>
                    <mml:mrow>
                      <mml:msub>
                        <mml:mi>M</mml:mi>
                        <mml:mi>s</mml:mi>
                      </mml:msub>
                      <mml:mo>⊙</mml:mo>
                      <mml:msub>
                        <mml:mi>g</mml:mi>
                        <mml:mrow>
                          <mml:msub>
                            <mml:mi>θ</mml:mi>
                            <mml:mi>s</mml:mi>
                          </mml:msub>
                        </mml:mrow>
                      </mml:msub>
                      <mml:mrow>
                        <mml:mo>(</mml:mo>
                        <mml:mrow>
                          <mml:msub>
                            <mml:mi>x</mml:mi>
                            <mml:mi>i</mml:mi>
                          </mml:msub>
                          <mml:mo>+</mml:mo>
                          <mml:msub>
                            <mml:mi>δ</mml:mi>
                            <mml:mi>i</mml:mi>
                          </mml:msub>
                        </mml:mrow>
                        <mml:mo>)</mml:mo>
                      </mml:mrow>
                    </mml:mrow>
                    <mml:mo>)</mml:mo>
                  </mml:mrow>
                </mml:mrow>
                <mml:mo>]</mml:mo>
              </mml:mrow>
              <mml:mo>.</mml:mo>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>The minimization is subject to Equation (7), admissible feature bounds, protected-field preservation, and the dataset-specific validity rules. The implemented attack is a batched, nested, constrained coordinate score-descent procedure. It uses three restarts, at most three coordinate sweeps, step fractions 0.5, 0.25, and 0.125, and at most 128 score queries per sample and per nonzero budget. The nested budgets are <italic>ε</italic> = {0.0, 0.2, 0.5, 0.8}, and successful adversarial observations are carried forward. Candidate values are projected to admissible bounds, protected variables are restored, and invalid candidates are rejected. For UNSW-NB15, tcprtt is recomputed as synack + ackdat.</p>
        <p>Algorithm 1. Nested constrained coordinate score descent</p>
        <p>Select a fixed cohort of malicious test observations correctly detected under clean conditions.For each attack seed, initialize the cohort at ε = 0.For each increasing nonzero budget, start from the best valid observation obtained at the previous budget.Generate coordinate-wise candidates over the approved mutable continuous variables using the scheduled step fractions.Project candidates to admissible ranges, restore protected variables, and recompute dataset-specific derived constraints.Query the calibrated malicious score and retain a candidate only when it is valid and improves the objective.Stop when the score crosses the operating threshold, the query limit is reached, or no further improvement occurs.Carry successful observations forward to the next budget and report valid successes, queries, coverage, and rejected candidates.</p>
        <p>The experiment characterizes a bounded black-box score-query threat model. It is not a robustness proof against white-box, transfer-based, poisoning, model-extraction, or packet-level adaptive attacks.</p>
      </sec>
      <sec id="sec4dot3">
        <title>4.3. Conditional Attack Success Rate and Clean False-Negative Rate</title>
        <p>For dataset <italic>d</italic> and model seed <italic>s</italic>, the eligible population is the set of malicious test observations detected correctly before perturbation:</p>
        <disp-formula id="FD9">
          <label>(9)</label>
          <mml:math>
            <mml:mrow>
              <mml:msub>
                <mml:mi>E</mml:mi>
                <mml:mrow>
                  <mml:mi>d</mml:mi>
                  <mml:mo>,</mml:mo>
                  <mml:mi>s</mml:mi>
                </mml:mrow>
              </mml:msub>
              <mml:mo>=</mml:mo>
              <mml:mrow>
                <mml:mo>{</mml:mo>
                <mml:mrow>
                  <mml:mi>i</mml:mi>
                  <mml:mo>:</mml:mo>
                  <mml:msub>
                    <mml:mi>y</mml:mi>
                    <mml:mi>i</mml:mi>
                  </mml:msub>
                  <mml:mo>=</mml:mo>
                  <mml:mn>1</mml:mn>
                  <mml:mtext>
                     
                  </mml:mtext>
                  <mml:mo>∧</mml:mo>
                  <mml:mtext>
                     
                  </mml:mtext>
                  <mml:msub>
                    <mml:mover accent="true">
                      <mml:mi>y</mml:mi>
                      <mml:mo>^</mml:mo>
                    </mml:mover>
                    <mml:mi>i</mml:mi>
                  </mml:msub>
                  <mml:mrow>
                    <mml:mo>(</mml:mo>
                    <mml:mn>0</mml:mn>
                    <mml:mo>)</mml:mo>
                  </mml:mrow>
                  <mml:mo>=</mml:mo>
                  <mml:mn>1</mml:mn>
                </mml:mrow>
                <mml:mo>}</mml:mo>
              </mml:mrow>
              <mml:mo>.</mml:mo>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>When the eligible population exceeds the cohort cap, a fixed sample is drawn from the eligible set. Conditional ASR is then:</p>
        <disp-formula id="FD10">
          <label>(10)</label>
          <mml:math>
            <mml:mrow>
              <mml:msub>
                <mml:mrow>
                  <mml:mtext>ASR</mml:mtext>
                </mml:mrow>
                <mml:mrow>
                  <mml:mi>d</mml:mi>
                  <mml:mo>,</mml:mo>
                  <mml:mi>s</mml:mi>
                </mml:mrow>
              </mml:msub>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mi>ε</mml:mi>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>=</mml:mo>
              <mml:mfrac>
                <mml:mn>1</mml:mn>
                <mml:mrow>
                  <mml:mrow>
                    <mml:mo>|</mml:mo>
                    <mml:mrow>
                      <mml:msub>
                        <mml:mi>A</mml:mi>
                        <mml:mrow>
                          <mml:mi>d</mml:mi>
                          <mml:mo>,</mml:mo>
                          <mml:mi>s</mml:mi>
                        </mml:mrow>
                      </mml:msub>
                    </mml:mrow>
                    <mml:mo>|</mml:mo>
                  </mml:mrow>
                </mml:mrow>
              </mml:mfrac>
              <mml:mstyle displaystyle="true">
                <mml:munder>
                  <mml:mo>∑</mml:mo>
                  <mml:mrow>
                    <mml:mi>i</mml:mi>
                    <mml:mo>∈</mml:mo>
                    <mml:msub>
                      <mml:mi>A</mml:mi>
                      <mml:mrow>
                        <mml:mi>d</mml:mi>
                        <mml:mo>,</mml:mo>
                        <mml:mi>s</mml:mi>
                      </mml:mrow>
                    </mml:msub>
                  </mml:mrow>
                </mml:munder>
                <mml:mi mathvariant="double-struck">I</mml:mi>
              </mml:mstyle>
              <mml:mrow>
                <mml:mo>[</mml:mo>
                <mml:mrow>
                  <mml:msub>
                    <mml:mover accent="true">
                      <mml:mi>y</mml:mi>
                      <mml:mo>^</mml:mo>
                    </mml:mover>
                    <mml:mi>i</mml:mi>
                  </mml:msub>
                  <mml:mrow>
                    <mml:mo>(</mml:mo>
                    <mml:mi>ε</mml:mi>
                    <mml:mo>)</mml:mo>
                  </mml:mrow>
                  <mml:mo>=</mml:mo>
                  <mml:mn>0</mml:mn>
                </mml:mrow>
                <mml:mo>]</mml:mo>
              </mml:mrow>
              <mml:mo>.</mml:mo>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>Clean false negatives are excluded from the ASR numerator and denominator. The clean false-negative rate is reported separately as FNR = FN/(TP + FN). Under this definition, ASR(0) = 0 for every dataset, model seed, and attack seed.</p>
      </sec>
      <sec id="sec4dot4">
        <title>4.4. TreeSHAP Audit in the Selected Latent Space</title>
        <p>TreeExplainer is applied to the final Random Forest with raw model output and tree-path-dependent perturbation. Global explanations use 1000 observations per dataset and seed. Local explanations use representative false-positive and false-negative cases selected from the hard-case sample.</p>
        <p>The additive decomposition is:</p>
        <disp-formula id="FD11">
          <label>(11)</label>
          <mml:math>
            <mml:mrow>
              <mml:mi>f</mml:mi>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:msub>
                    <mml:mover accent="true">
                      <mml:mi>z</mml:mi>
                      <mml:mo>˜</mml:mo>
                    </mml:mover>
                    <mml:mi>i</mml:mi>
                  </mml:msub>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>=</mml:mo>
              <mml:msub>
                <mml:mi>ϕ</mml:mi>
                <mml:mn>0</mml:mn>
              </mml:msub>
              <mml:mo>+</mml:mo>
              <mml:mstyle displaystyle="true">
                <mml:munder>
                  <mml:mo>∑</mml:mo>
                  <mml:mrow>
                    <mml:mi>j</mml:mi>
                    <mml:mo>∈</mml:mo>
                    <mml:msub>
                      <mml:mi>M</mml:mi>
                      <mml:mi>s</mml:mi>
                    </mml:msub>
                  </mml:mrow>
                </mml:munder>
                <mml:mrow>
                  <mml:msub>
                    <mml:mi>ϕ</mml:mi>
                    <mml:mrow>
                      <mml:mi>i</mml:mi>
                      <mml:mi>j</mml:mi>
                    </mml:mrow>
                  </mml:msub>
                </mml:mrow>
              </mml:mstyle>
              <mml:mo>.</mml:mo>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>Strict additivity checks pass for all nine dataset-seed combinations without fallback. The explanations refer to selected latent dimensions <italic>z</italic><italic><sub>j</sub></italic>. Because independently trained CNN encoders do not align their latent coordinates, a label such as <italic>z</italic><sub>029</sub> is seed-specific and cannot be mapped directly to a raw flow variable or interpreted causally without a separate linkage analysis.</p>
      </sec>
      <sec id="sec4dot5">
        <title>4.5. Hard-Case Analysis</title>
        <p>False positives and false negatives are identified after thresholding. The signed decision margin is:</p>
        <disp-formula id="FD12">
          <label>(12)</label>
          <mml:math>
            <mml:mrow>
              <mml:msub>
                <mml:mi>r</mml:mi>
                <mml:mi>i</mml:mi>
              </mml:msub>
              <mml:mo>=</mml:mo>
              <mml:msub>
                <mml:mi>p</mml:mi>
                <mml:mi>i</mml:mi>
              </mml:msub>
              <mml:mo>−</mml:mo>
              <mml:msubsup>
                <mml:mi>t</mml:mi>
                <mml:mi>s</mml:mi>
                <mml:mtext>*</mml:mtext>
              </mml:msubsup>
              <mml:mo>.</mml:mo>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>A positive margin for a false positive indicates confidence above the alert threshold, whereas a negative margin for a false negative indicates that the malicious score remained below the threshold. Complete error totals are reported separately from the limited samples used for local SHAP explanations.</p>
      </sec>
    </sec>
    <sec id="sec5">
      <title>5. Results</title>
      <sec id="sec5dot1">
        <title>5.1. Clean Classification Performance and Perturbation Policy</title>
        <p><bold>Table 3(a)</bold> reports clean performance across the three model seeds. CICIoT2023 obtains a very high F1-score, but its specificity is materially lower because benign observations form a small minority. Farm-Flow combines high malicious recall with low precision and specificity, indicating a substantial baseline false-positive burden. UNSW-NB15 occupies an intermediate position, with high recall but lower specificity and seed-dependent F1.</p>
        <p><bold>Table 3</bold><bold>.</bold>(a) Clean test performance, mean ± standard deviation across three independent model seeds; (b) Dataset-specific mutable continuous features and validity controls.</p>
        <table-wrap id="tbl3">
          <label>Table 3</label>
          <table>
            <tbody>
              <tr>
                <td colspan="11">
                  <bold>(a)</bold>
                </td>
              </tr>
              <tr>
                <td colspan="2">
                  <bold>Dataset</bold>
                </td>
                <td>
                  <bold>F1</bold>
                </td>
                <td>
                  <bold>Balanced accuracy</bold>
                </td>
                <td colspan="2">
                  <bold>Specificity</bold>
                </td>
                <td colspan="2">
                  <bold>MCC</bold>
                </td>
                <td colspan="2">
                  <bold>Clean FNR</bold>
                </td>
                <td>
                  <bold>FPR</bold>
                </td>
              </tr>
              <tr>
                <td colspan="2">CICIoT2023</td>
                <td>0.9953 ± 0.0001</td>
                <td>0.9052 ± 0.0202</td>
                <td colspan="2">0.8153 ± 0.0411</td>
                <td colspan="2">0.8035 ± 0.0115</td>
                <td colspan="2">0.489% ± 0.079%</td>
                <td>18.47% ± 4.11%</td>
              </tr>
              <tr>
                <td colspan="2">Farm-Flow</td>
                <td>0.4724 ± 0.0131</td>
                <td>0.6345 ± 0.0187</td>
                <td colspan="2">0.3167 ± 0.0560</td>
                <td colspan="2">0.2684 ± 0.0209</td>
                <td colspan="2">4.770% ± 1.891%</td>
                <td>68.33% ± 5.60%</td>
              </tr>
              <tr>
                <td colspan="2">UNSW-NB15</td>
                <td>0.7480 ± 0.0183</td>
                <td>0.8097 ± 0.0183</td>
                <td colspan="2">0.6369 ± 0.0428</td>
                <td colspan="2">0.6041 ± 0.0289</td>
                <td colspan="2">1.754% ± 0.810%</td>
                <td>36.31% ± 4.28%</td>
              </tr>
              <tr>
                <td colspan="11">
                  <bold>(b)</bold>
                </td>
              </tr>
              <tr>
                <td>
                  <bold>Dataset</bold>
                </td>
                <td colspan="4">
                  <bold>Mutable continuous features</bold>
                </td>
                <td colspan="2">
                  <bold>Mutable/</bold>
                  <bold>protected N</bold>
                </td>
                <td colspan="2">
                  <bold>Derived validity rule</bold>
                </td>
                <td colspan="2">
                  <bold>Validity scope</bold>
                </td>
              </tr>
              <tr>
                <td>CICIoT2023</td>
                <td colspan="4">flow_duration, Header_Length, Duration, Rate, Srate, Drate, IAT</td>
                <td colspan="2">7/33-36</td>
                <td colspan="2">None</td>
                <td colspan="2">Feature-space bounds and protected-field preservation</td>
              </tr>
              <tr>
                <td>Farm-Flow</td>
                <td colspan="4">orig_ip_bytes, resp_ip_bytes, fwd_pkts_per_sec, bwd_pkts_per_sec, flow_pkts_per_sec</td>
                <td colspan="2">5/23-23</td>
                <td colspan="2">None</td>
                <td colspan="2">Feature-space bounds and protected-field preservation</td>
              </tr>
              <tr>
                <td>UNSW-NB15</td>
                <td colspan="4">dur, sinpkt, dinpkt, sjit, djit, synack, ackdat</td>
                <td colspan="2">7/34-34</td>
                <td colspan="2">tcprtt = synack + ackdat</td>
                <td colspan="2">Feature-space bounds and protected-field preservation</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <p>The selected perturbation variables are conservative subsets of the continuous flow descriptors. All other model inputs remain protected. The resulting validity claim is limited to bounded feature-space plausibility; packet-capture reconstructibility is not asserted.</p>
      </sec>
      <sec id="sec5dot2">
        <title>5.2. Global and Local TreeSHAP Audits</title>
        <p><xref ref-type="fig" rid="fig1">Figure 1</xref> shows the top selected latent dimensions for the representative model seed 314159. Importance is concentrated in a subset of the selected representation for every dataset. The identities and magnitudes differ across datasets, and the selected masks contain 39, 59, and 41 dimensions for CICIoT2023, Farm-Flow, and UNSW-NB15, respectively.</p>
        <fig id="fig1">
          <label>Figure 1</label>
          <graphic xlink:href="https://html.scirp.org/file/2313921-rId45.jpeg?20260824021702" />
        </fig>
        <fig id="fig2">
          <label>Figure 2</label>
          <graphic xlink:href="https://html.scirp.org/file/2313921-rId46.jpeg?20260824021702" />
        </fig>
        <p><bold>Figure 1</bold>. Global TreeSHAP importance of selected latent dimensions for model seed 314159: (a) CICIoT2023, (b) Farm-Flow, and (c) UNSW-NB15. The labels refer to seed-specific latent coordinates and do not denote raw traffic variables.</p>
        <p><xref ref-type="fig" rid="fig2">Figure 2</xref> presents representative false-positive and false-negative explanations for the same model seed. Positive SHAP contributions increase the Random Forest output, while negative contributions decrease it. The plots demonstrate that individual errors can be decomposed additively, but they do not provide a direct semantic mapping from latent coordinates to packet-level mechanisms.</p>
        <fig id="fig3">
          <label>Figure 3</label>
          <graphic xlink:href="https://html.scirp.org/file/2313921-rId47.jpeg?20260824021702" />
        </fig>
        <fig id="fig4">
          <label>Figure 4</label>
          <graphic xlink:href="https://html.scirp.org/file/2313921-rId48.jpeg?20260824021702" />
        </fig>
        <p><bold>Figure 2</bold><bold>.</bold>Local TreeSHAP explanations of representative false-positive and false-negative cases for model seed 314159. The explanations are computed in the IWHO-Lite-selected latent space.</p>
      </sec>
      <sec id="sec5dot3">
        <title>5.3. Robustness under Gaussian Noise</title>
        <p>The hierarchical F1 results are shown in <bold>Table 4</bold> and <xref ref-type="fig" rid="fig3">Figure 3</xref>. CICIoT2023 remains nearly stable across the canonical noise grid. Farm-Flow declines immediately from its already low clean baseline and then approaches a plateau. UNSW-NB15 degrades progressively, with increasing between-seed variability at larger noise levels.</p>
        <p><bold>Table 4.</bold>F1-score under Gaussian noise, hierarchical mean ± between-model-seed standard deviation; five noise seeds are nested within each model seed.</p>
        <table-wrap id="tbl4">
          <label>Table 4</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Dataset</bold>
                </td>
                <td>
                  <italic>
                    <bold>σ</bold>
                  </italic>
                  <bold>=</bold>
                  <bold>0.0</bold>
                </td>
                <td>
                  <italic>
                    <bold>σ</bold>
                  </italic>
                  <bold>=</bold>
                  <bold>0.2</bold>
                </td>
                <td>
                  <italic>
                    <bold>σ</bold>
                  </italic>
                  <bold>=</bold>
                  <bold>0.5</bold>
                </td>
                <td>
                  <italic>
                    <bold>σ</bold>
                  </italic>
                  <bold>=</bold>
                  <bold>1.0</bold>
                </td>
              </tr>
              <tr>
                <td>CICIoT2023</td>
                <td>0.9954 ± 0.0002</td>
                <td>0.9953 ± 0.0002</td>
                <td>0.9949 ± 0.0002</td>
                <td>0.9940 ± 0.0002</td>
              </tr>
              <tr>
                <td>Farm-Flow</td>
                <td>0.4724 ± 0.0131</td>
                <td>0.4184 ± 0.0025</td>
                <td>0.4130 ± 0.0016</td>
                <td>0.4118 ± 0.0013</td>
              </tr>
              <tr>
                <td>UNSW-NB15</td>
                <td>0.7479 ± 0.0182</td>
                <td>0.7439 ± 0.0205</td>
                <td>0.7192 ± 0.0358</td>
                <td>0.6767 ± 0.0550</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <p>At <italic>σ</italic> = 1.0, the F1-score is 0.9940 ± 0.0002 for CICIoT2023, 0.4118 ± 0.0013 for Farm-Flow, and 0.6768 ± 0.0550 for UNSW-NB15. These results indicate that environmental robustness cannot be inferred from clean F1 alone. Farm-Flow is primarily constrained by baseline separability and false positives, while UNSW-NB15 displays a clearer perturbation-dependent decline.</p>
        <fig id="fig5">
          <label>Figure 5</label>
          <graphic xlink:href="https://html.scirp.org/file/2313921-rId49.jpeg?20260824021702" />
        </fig>
        <p><bold>Figure 3</bold><bold>.</bold>F1-score under Gaussian noise. Points are within-model-seed means and error bars represent the standard deviation between three independent model-seed means.</p>
      </sec>
      <sec id="sec5dot4">
        <title>5.4. Conditional Evasion Results</title>
        <p><bold>Table 5(a)</bold> distinguishes the full malicious test population, the clean-detected eligible population, the attacked cohort, attack coverage, valid adversarial observations, rejected candidates, and clean FNR. Farm-Flow is evaluated exhaustively on all clean-detected malicious observations. CICIoT2023 and UNSW-NB15 use fixed cohorts capped at 2000 observations per model seed.</p>
        <p><bold>Table 5</bold><bold>.</bold> (a) Conditional-ASR denominators, attack coverage, and clean false-negative rate. Ranges refer to the three model seeds; (b) Conditional ASR under normalized L∞ budgets, hierarchical mean ± between-model-seed standard deviation; three attack seeds are nested within each model seed.</p>
        <table-wrap id="tbl5">
          <label>Table 5</label>
          <table>
            <tbody>
              <tr>
                <td colspan="12">
                  <bold>(a)</bold>
                </td>
              </tr>
              <tr>
                <td>
                  <bold>Dataset</bold>
                </td>
                <td colspan="2">
                  <bold>Malicious test N</bold>
                </td>
                <td colspan="2">
                  <bold>Clean-detected eligible N</bold>
                </td>
                <td>
                  <bold>Attacked N</bold>
                </td>
                <td colspan="2">
                  <bold>Coverage</bold>
                </td>
                <td>
                  <bold>Valid adversarial N</bold>
                </td>
                <td colspan="2">
                  <bold>Invalid N</bold>
                </td>
                <td>
                  <bold>Clean FNR</bold>
                </td>
              </tr>
              <tr>
                <td>CICIoT2023</td>
                <td colspan="2">1,136,170 - 1,136,182</td>
                <td colspan="2">1,130,001 - 1,131,640</td>
                <td>2000</td>
                <td colspan="2">0.177% - 0.177%</td>
                <td>2000</td>
                <td colspan="2">0</td>
                <td>0.489% ± 0.079%</td>
              </tr>
              <tr>
                <td>Farm-Flow</td>
                <td colspan="2">580</td>
                <td colspan="2">540 - 561</td>
                <td>540 - 561</td>
                <td colspan="2">100.0%</td>
                <td>540 - 561</td>
                <td colspan="2">0</td>
                <td>4.770% ± 1.891%</td>
              </tr>
              <tr>
                <td>UNSW-NB15</td>
                <td colspan="2">18,987</td>
                <td colspan="2">18,490 - 18,795</td>
                <td>2000</td>
                <td colspan="2">10.641% - 10.817%</td>
                <td>2 000</td>
                <td colspan="2">0</td>
                <td>1.754% ± 0.810%</td>
              </tr>
              <tr>
                <td colspan="12">
                  <bold>(</bold>
                  <bold>b</bold>
                  <bold>)</bold>
                </td>
              </tr>
              <tr>
                <td colspan="2">
                  <bold>Dataset</bold>
                </td>
                <td colspan="2">
                  <italic>
                    <bold>ε</bold>
                  </italic>
                  <bold>= 0.0</bold>
                </td>
                <td colspan="3">
                  <italic>
                    <bold>ε</bold>
                  </italic>
                  <bold>= 0.2</bold>
                </td>
                <td colspan="3">
                  <italic>
                    <bold>ε</bold>
                  </italic>
                  <bold>= 0.5</bold>
                </td>
                <td colspan="2">
                  <italic>
                    <bold>ε</bold>
                  </italic>
                  <bold>= 0.8</bold>
                </td>
              </tr>
              <tr>
                <td colspan="2">CICIoT2023</td>
                <td colspan="2">0.00% ± 0.00%</td>
                <td colspan="3">3.53% ± 2.24%</td>
                <td colspan="3">14.40% ± 19.85%</td>
                <td colspan="2">16.17% ± 22.66%</td>
              </tr>
              <tr>
                <td colspan="2">Farm-Flow</td>
                <td colspan="2">0.00% ± 0.00%</td>
                <td colspan="3">11.64% ± 8.70%</td>
                <td colspan="3">13.05% ± 10.08%</td>
                <td colspan="2">13.58% ± 10.56%</td>
              </tr>
              <tr>
                <td colspan="2">UNSW-NB15</td>
                <td colspan="2">0.00% ± 0.00%</td>
                <td colspan="3">87.93% ± 4.20%</td>
                <td colspan="3">96.70% ± 2.03%</td>
                <td colspan="2">98.43% ± 1.17%</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <fig id="fig6">
          <label>Figure 6</label>
          <graphic xlink:href="https://html.scirp.org/file/2313921-rId50.jpeg?20260824021703" />
        </fig>
        <p><bold>Figure 4</bold>. Conditional Attack Success Rate under normalized L∞ budgets. Error bars represent the standard deviation between three independent model-seed means.</p>
        <p><xref ref-type="fig" rid="fig4">Figure 4</xref> shows the conditional Attack Success Rate (ASR) as a function of the normalized L∞ budget for the three datasets. Nested-budget monotonicity holds within every model-seed and attack-seed combination. As shown in <bold>Table 5(b)</bold>, UNSW-NB15 is consistently vulnerable: ASR is 87.93% ± 4.20% at <italic>ε</italic> = 0.2 and 98.43% ± 1.17% at <italic>ε</italic> = 0.8. CICIoT2023 and Farm-Flow show much larger between-seed uncertainty relative to their means. CICIoT2023 ranges from very low ASR in two seeds to substantially higher values in seed 42, while Farm-Flow ranges from low to moderate evasion success. These datasets therefore cannot be characterized reliably from a single model initialization.</p>
      </sec>
      <sec id="sec5dot5">
        <title>5.5. Complete False-Positive and False-Negative Statistics</title>
        <p><bold>Table 6</bold> reports complete error totals rather than limiting the counts to the observations displayed by SHAP. Farm-Flow produces approximately 1208 false positives per seed against only 27.7 false negatives, which is consistent with its high recall and low specificity. UNSW-NB15 also produces a large false-positive burden. CICIoT2023 has high absolute error counts because of its much larger test set, although its relative F1 remains high.</p>
        <p><bold>Table 6.</bold>Complete hard-case statistics, mean ± standard deviation across three model seeds. The SHAP sample is a diagnostic subset and is not the total error count.</p>
        <table-wrap id="tbl6">
          <label>Table 6</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Dataset</bold>
                </td>
                <td>
                  <bold>Error</bold>
                </td>
                <td>
                  <bold>Total cases</bold>
                </td>
                <td>
                  <bold>Mean score</bold>
                </td>
                <td>
                  <bold>Mean margin</bold>
                </td>
                <td>
                  <bold>SHAP sample N</bold>
                </td>
              </tr>
              <tr>
                <td>CICIoT2023</td>
                <td>FP</td>
                <td>5060.3 ± 1129.4</td>
                <td>0.856 ± 0.043</td>
                <td>+0.218 ± 0.057</td>
                <td>100</td>
              </tr>
              <tr>
                <td>CICIoT2023</td>
                <td>FN</td>
                <td>5555.7 ± 895.3</td>
                <td>0.280 ± 0.047</td>
                <td>-0.358 ± 0.056</td>
                <td>100</td>
              </tr>
              <tr>
                <td>Farm-Flow</td>
                <td>FP</td>
                <td>1208.0 ± 99.0</td>
                <td>0.746 ± 0.006</td>
                <td>+0.142 ± 0.020</td>
                <td>100</td>
              </tr>
              <tr>
                <td>Farm-Flow</td>
                <td>FN</td>
                <td>27.7 ± 11.0</td>
                <td>0.515 ± 0.025</td>
                <td>−0.089 ± 0.015</td>
                <td>19 - 40</td>
              </tr>
              <tr>
                <td>UNSW-NB15</td>
                <td>FP</td>
                <td>12259.0 ± 1444.0</td>
                <td>0.733 ± 0.031</td>
                <td>+0.397 ± 0.063</td>
                <td>100</td>
              </tr>
              <tr>
                <td>UNSW-NB15</td>
                <td>FN</td>
                <td>333.0 ± 153.8</td>
                <td>0.219 ± 0.079</td>
                <td>−0.117 ± 0.016</td>
                <td>100</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <p>False-positive mean scores remain well above their corresponding thresholds, particularly for CICIoT2023 and UNSW-NB15. False-negative margins are negative for all datasets, showing that some malicious observations remain confidently below the operating threshold. These results support the use of score distributions and local explanations alongside aggregate classification metrics.</p>
      </sec>
      <sec id="sec5dot6">
        <title>5.6. Ablation Perspective</title>
        <p><bold>Table 7</bold> compares the evaluated pipeline with a full-latent Random Forest, a Random Forest trained on preprocessed raw features, and an end-to-end CNN. The raw-feature Random Forest obtains the highest mean F1 on CICIoT2023 and UNSW-NB15 and is competitive on Farm-Flow. The evaluated pipeline therefore should not be interpreted as uniformly superior. Its scientific role in this paper is to provide a concrete compact hybrid system for a controlled stress-testing and explainability audit.</p>
        <p><bold>Table 7.</bold>F1-score ablation audit, mean ± standard deviation across three model seeds.</p>
        <table-wrap id="tbl7">
          <label>Table 7</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Dataset</bold>
                </td>
                <td>
                  <bold>CNN</bold>
                  <bold>-</bold>
                  <bold>IWHO-Lite</bold>
                  <bold>-</bold>
                  <bold>RF</bold>
                </td>
                <td>
                  <bold>CNN full-latent RF</bold>
                </td>
                <td>
                  <bold>Raw-feature RF</bold>
                </td>
                <td>
                  <bold>CNN end-to-end</bold>
                </td>
              </tr>
              <tr>
                <td>CICIoT2023</td>
                <td>0.9953 ± 0.0001</td>
                <td>0.9949 ± 0.0001</td>
                <td>0.9982 ± 0.0001</td>
                <td>0.9929 ± 0.0005</td>
              </tr>
              <tr>
                <td>Farm-Flow</td>
                <td>0.4724 ± 0.0131</td>
                <td>0.4550 ± 0.0058</td>
                <td>0.4669 ± 0.0276</td>
                <td>0.3981 ± 0.0034</td>
              </tr>
              <tr>
                <td>UNSW-NB15</td>
                <td>0.7480 ± 0.0183</td>
                <td>0.7578 ± 0.0045</td>
                <td>0.7989 ± 0.0193</td>
                <td>0.7071 ± 0.0629</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
      </sec>
    </sec>
    <sec id="sec6">
      <title>6. Discussion</title>
      <sec id="sec6dot1">
        <title>6.1. Dataset-Specific Failure Modes</title>
        <p>The three datasets expose different failure modes. CICIoT2023 combines extremely high malicious recall and F1 with lower benign specificity. Its behavior under Gaussian noise is stable, but its evasion sensitivity varies markedly across model seeds. This pattern shows that a high aggregate F1 does not imply a stable adversarial boundary or a low operational false-positive rate.</p>
        <p>Farm-Flow is the most relevant dataset for the agricultural application, yet its main limitation is visible before adversarial testing. The model detects most malicious observations, but it labels a large proportion of benign flows as malicious. Gaussian perturbation further reduces F1, while conditional ASR remains low to moderate and highly seed-dependent. The central Farm-Flow finding is therefore a baseline separability and false-alarm problem rather than a claim that agricultural traffic is uniquely susceptible to evasion.</p>
        <p>UNSW-NB15 shows intermediate clean performance and progressive noise degradation, but its decisive weakness is adversarial. Nearly all attacked clean-detected malicious observations cross the threshold at the largest budget. This result demonstrates that compact representation learning and latent selection do not constitute a proven defense against score-query evasion.</p>
      </sec>
      <sec id="sec6dot2">
        <title>6.2. Interpretation of Latent Selection and Calibration</title>
        <p>IWHO-Lite reduces the 128-dimensional representation to smaller seed-dependent subsets. On Farm-Flow, the selected subset is larger than on the other datasets, which is consistent with a more difficult separation problem but does not establish causality. The ablation results show that raw-feature Random Forests can outperform the hybrid pipeline. Latent compression should therefore be understood as a representation choice and an audit target, not as a guaranteed performance or robustness advantage.</p>
        <p>Sigmoid calibration and threshold selection are methodologically separated from the test set. Nevertheless, calibration does not improve Brier score or expected calibration error uniformly. The procedure standardizes the score-to-decision workflow and enables a disjoint threshold stage, but its empirical benefit remains dataset- and seed-dependent.</p>
      </sec>
      <sec id="sec6dot3">
        <title>6.3. Operational Implications for Agricultural Security Monitoring</title>
        <p>A deployment-oriented IDS should monitor more than a single accuracy value. The following controls are particularly important for agricultural gateways and security operations:</p>
        <p>false-positive rate and alert volume on benign operational traffic;clean false-negative rate, reported separately from adversarial success;periodic stress tests under the approved mutable-feature policy;repeated model training to quantify seed sensitivity;threshold review when devices, firmware, seasons, or operational schedules change;local latent-space explanations for representative high-confidence errors;explicit coverage reporting when adversarial testing uses capped cohorts.</p>
        <p>The measured latency values indicate that batch inference is technically feasible in the experimental environment, but no conclusion is drawn about a specific gateway, memory budget, energy profile, or thermal constraint. Hardware deployment requires direct benchmarking.</p>
      </sec>
      <sec id="sec6dot4">
        <title>6.4. Scientific Positioning</title>
        <p>The principal contribution is the evaluation protocol: disjoint fitting roles, overlap auditing, independent model seeds, hierarchical uncertainty, conditional ASR, denominator transparency, feature-space validity controls, and additive explainability checks. The pipeline is the system under examination. The results do not support a general claim that CNN-IWHO-Lite-Random Forest is superior to simpler classifiers, uniformly lightweight, or adversarially robust.</p>
        <p>This positioning is consistent with the broader IDS literature, which emphasizes that validation strategy and dataset structure can affect conclusions as strongly as the classifier itself [<xref ref-type="bibr" rid="B5">5</xref>][<xref ref-type="bibr" rid="B11">11</xref>]. A stress-testing study is valuable when it identifies both strengths and failure boundaries without converting dataset-specific observations into universal claims.</p>
      </sec>
      <sec id="sec6dot5">
        <title>6.5. Limitations</title>
        <p>Several limitations remain. First, reliable device, session, farm, capture, and timestamp identifiers are not consistently available across the released feature tables. Group-based and temporal splits could therefore not be imposed across all datasets. The protocol removes exact feature-vector overlaps and separates all learned stages from the test set, but it does not claim that every possible source of deployment-level leakage has been eliminated.</p>
        <p>Second, CICIoT2023 and UNSW-NB15 use fixed adversarial cohorts capped at 2000 clean-detected malicious observations per model seed. Their conditional ASR estimates characterize the sampled cohorts, and coverage is reported explicitly. Farm-Flow is evaluated exhaustively because its eligible population is smaller.</p>
        <p>Third, validity is assessed in the cleaned feature space. Continuous mutable values are bounded, protected variables are restored, and the UNSW-NB15 tcprtt relationship is recomputed. No packet-capture reconstruction or protocol execution is performed. In particular, the released Farm-Flow representation includes cleaned model-input values, so perturbations cannot be claimed to correspond to original physical network units.</p>
        <p>Fourth, the evaluated attack is a bounded black-box score-query coordinate search. White-box, transfer-based, poisoning, model-extraction, and packet-level adaptive attacks remain outside its scope. The results therefore describe a defined threat model rather than a complete security proof.</p>
        <p>Fifth, SHAP explanations operate on selected latent dimensions. The latent coordinates are seed-specific and are not directly mapped to raw network variables. The explanations establish additive attribution for the final Random Forest but not causal or packet-level semantics.</p>
        <p>Finally, the computational measurements were obtained in the experimental environment rather than on an agricultural gateway. Model size, latency, memory, energy consumption, thermal behavior, and packet-processing overhead require hardware-specific validation.</p>
      </sec>
    </sec>
    <sec id="sec7">
      <title>7. Conclusions</title>
      <p>This study evaluated a CNN-IWHO-Lite-Random Forest intrusion-detection pipeline through a reproducible multi-seed protocol that combines clean testing, Gaussian perturbation, conditional score-query evasion, TreeSHAP explanation, and complete hard-case analysis. The protocol separates model selection, calibration, threshold optimization, and final testing; removes exact feature-vector overlaps; constrains perturbations to approved continuous variables; and reports attack denominators and coverage explicitly.</p>
      <p>The results reveal distinct failure modes. CICIoT2023 maintains a very high F1-score and strong noise stability, but benign specificity and adversarial sensitivity vary across seeds. Farm-Flow is limited mainly by baseline false positives and degrades under Gaussian noise. UNSW-NB15 is consistently vulnerable to the evaluated evasion procedure despite reasonable clean performance. These findings demonstrate that robustness cannot be inferred from nominal F1, latent compression, or a single model initialization.</p>
      <p>The main practical implication is that AG-IoT IDS evaluation should include repeated training, denominator-correct adversarial testing, feature-valid perturbations, and decision-level error analysis before deployment. Future work should extend the protocol to grouped and temporal agricultural captures, packet-realizable adversarial traffic, multiclass detection, online drift, and direct benchmarking on resource-constrained gateways.</p>
    </sec>
    <sec id="sec8">
      <title>Author Contributions</title>
      <p>Conceptualization, A.K.K.; methodology, A.K.K., D.J.D. and K.A.A.; software, A.K.K.; formal analysis, A.K.K.; investigation, A.K.K.; data curation, A.K.K.; writing—original draft preparation, A.K.K.; writing—review and editing, A.K.K., D.J.D. and K.A.A.; visualization, A.K.K.; supervision, S.O. and Y.C.B. All authors have read and agreed to the published version of the manuscript.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <title>References</title>
      <ref id="B1">
        <label>1.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Maraveas, C., Rajarajan, M., Arvanitis, K.G. and Vatsanidou, A. (2024) Cybersecurity Threats and Mitigation Measures in Agriculture 4.0 and 5.0. <italic>Smart Agricultural Technology</italic>, 9, Article 100616. https://doi.org/10.1016/j.atech.2024.100616 <pub-id pub-id-type="doi">10.1016/j.atech.2024.100616</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.atech.2024.100616">https://doi.org/10.1016/j.atech.2024.100616</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Maraveas, C.</string-name>
              <string-name>Rajarajan, M.</string-name>
              <string-name>Arvanitis, K.G.</string-name>
              <string-name>Vatsanidou, A.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Cybersecurity Threats and Mitigation Measures in Agriculture 4</article-title>
            <source>0 and 5.0. Smart Agricultural Technology</source>
            <volume>9</volume>
            <elocation-id>100616</elocation-id>
            <pub-id pub-id-type="doi">10.1016/j.atech.2024.100616</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B2">
        <label>2.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Campoverde-Molina, M. and Luján-Mora, S. (2025) Cybersecurity in Smart Agriculture: A Systematic Literature Review. <italic>Computers &amp; Security</italic>, 150, Article 104284. https://doi.org/10.1016/j.cose.2024.104284 <pub-id pub-id-type="doi">10.1016/j.cose.2024.104284</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2024.104284">https://doi.org/10.1016/j.cose.2024.104284</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Campoverde-Molina, M.</string-name>
              <string-name>Mora, S.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Cybersecurity in Smart Agriculture: A Systematic Literature Review</article-title>
            <source>Computers &amp; Security</source>
            <volume>150</volume>
            <elocation-id>104284</elocation-id>
            <pub-id pub-id-type="doi">10.1016/j.cose.2024.104284</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B3">
        <label>3.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Javeed, D., Gao, T., Saeed, M.S. and Kumar, P. (2024) An Intrusion Detection System for Edge-Envisioned Smart Agriculture in Extreme Environment. <italic>IEEE Internet of Things Journal</italic>, 11, 26866-26876. https://doi.org/10.1109/jiot.2023.3288544 <pub-id pub-id-type="doi">10.1109/jiot.2023.3288544</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/jiot.2023.3288544">https://doi.org/10.1109/jiot.2023.3288544</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Javeed, D.</string-name>
              <string-name>Gao, T.</string-name>
              <string-name>Saeed, M.S.</string-name>
              <string-name>Kumar, P.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>An Intrusion Detection System for Edge-Envisioned Smart Agriculture in Extreme Environment</article-title>
            <source>IEEE Internet of Things Journal</source>
            <volume>11</volume>
            <pub-id pub-id-type="doi">10.1109/jiot.2023.3288544</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B4">
        <label>4.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Ferreira, R., Bispo, I.A., Rabadão, C., Santos, L. and Costa, R.L.D.C. (2025) Farm-Flow Dataset: Intrusion Detection in Smart Agriculture Based on Network Flows. <italic>Computers and Electrical Engineering</italic>, 121, Article 109892. https://doi.org/10.1016/j.compeleceng.2024.109892 <pub-id pub-id-type="doi">10.1016/j.compeleceng.2024.109892</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.compeleceng.2024.109892">https://doi.org/10.1016/j.compeleceng.2024.109892</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Ferreira, R.</string-name>
              <string-name>Bispo, I.A.</string-name>
              <string-name>Santos, L.</string-name>
              <string-name>Costa, R.L.D.C.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Farm-Flow Dataset: Intrusion Detection in Smart Agriculture Based on Network Flows</article-title>
            <source>Computers and Electrical Engineering</source>
            <volume>121</volume>
            <elocation-id>109892</elocation-id>
            <pub-id pub-id-type="doi">10.1016/j.compeleceng.2024.109892</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B5">
        <label>5.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Khraisat, A. and Alazab, A. (2021) A Critical Review of Intrusion Detection Systems in the Internet of Things: Techniques, Deployment Strategy, Validation Strategy, Attacks, Public Datasets and Challenges. <italic>Cybersecurity</italic>, 4, Article 18. https://doi.org/10.1186/s42400-021-00077-7 <pub-id pub-id-type="doi">10.1186/s42400-021-00077-7</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1186/s42400-021-00077-7">https://doi.org/10.1186/s42400-021-00077-7</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Khraisat, A.</string-name>
              <string-name>Alazab, A.</string-name>
              <string-name>Techniques, D</string-name>
              <string-name>Strategy, V</string-name>
              <string-name>Strategy, A</string-name>
            </person-group>
            <year>2021</year>
            <article-title>A Critical Review of Intrusion Detection Systems in the Internet of Things: Techniques, Deployment Strategy, Validation Strategy, Attacks, Public Datasets and Challenges</article-title>
            <source>Cybersecurity</source>
            <volume>4</volume>
            <elocation-id>18</elocation-id>
            <pub-id pub-id-type="doi">10.1186/s42400-021-00077-7</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B6">
        <label>6.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">He, K., Kim, D.D. and Asghar, M.R. (2023) Adversarial Machine Learning for Network Intrusion Detection Systems: A Comprehensive Survey. <italic>IEEE Communications Surveys &amp; Tutorials</italic>, 25, 538-566. https://doi.org/10.1109/comst.2022.3233793 <pub-id pub-id-type="doi">10.1109/comst.2022.3233793</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/comst.2022.3233793">https://doi.org/10.1109/comst.2022.3233793</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>He, K.</string-name>
              <string-name>Kim, D.D.</string-name>
              <string-name>Asghar, M.R.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>Adversarial Machine Learning for Network Intrusion Detection Systems: A Comprehensive Survey</article-title>
            <source>IEEE Communications Surveys &amp; Tutorials</source>
            <volume>25</volume>
            <pub-id pub-id-type="doi">10.1109/comst.2022.3233793</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B7">
        <label>7.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Qiu, H., Dong, T., Zhang, T., Lu, J., Memmi, G. and Qiu, M. (2021) Adversarial Attacks against Network Intrusion Detection in IoT Systems. <italic>IEEE Internet of Things Journal</italic>, 8, 10327-10335. https://doi.org/10.1109/jiot.2020.3048038 <pub-id pub-id-type="doi">10.1109/jiot.2020.3048038</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/jiot.2020.3048038">https://doi.org/10.1109/jiot.2020.3048038</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Qiu, H.</string-name>
              <string-name>Dong, T.</string-name>
              <string-name>Zhang, T.</string-name>
              <string-name>Lu, J.</string-name>
              <string-name>Memmi, G.</string-name>
              <string-name>Qiu, M.</string-name>
            </person-group>
            <year>2021</year>
            <article-title>Adversarial Attacks against Network Intrusion Detection in IoT Systems</article-title>
            <source>IEEE Internet of Things Journal</source>
            <volume>8</volume>
            <pub-id pub-id-type="doi">10.1109/jiot.2020.3048038</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B8">
        <label>8.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Fatema, K., Dey, S.K., Anannya, M., Khan, R.T., Rashid, M.M., Su, C., <italic>et al</italic>. (2025) Federated XAI IDS: An Explainable and Safeguarding Privacy Approach to Detect Intrusion Combining Federated Learning and SHAP. <italic>Future Internet</italic>, 17, Article 234. https://doi.org/10.3390/fi17060234 <pub-id pub-id-type="doi">10.3390/fi17060234</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/fi17060234">https://doi.org/10.3390/fi17060234</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Fatema, K.</string-name>
              <string-name>Dey, S.K.</string-name>
              <string-name>Anannya, M.</string-name>
              <string-name>Khan, R.T.</string-name>
              <string-name>Rashid, M.M.</string-name>
              <string-name>Su, C.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Federated XAI IDS: An Explainable and Safeguarding Privacy Approach to Detect Intrusion Combining Federated Learning and SHAP</article-title>
            <source>Future Internet</source>
            <volume>17</volume>
            <elocation-id>234</elocation-id>
            <pub-id pub-id-type="doi">10.3390/fi17060234</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B9">
        <label>9.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Kethineni, K. and Pradeepini, G. (2024) Intrusion Detection in Internet of Things-Based Smart Farming Using Hybrid Deep Learning Framework. <italic>Cluster Computing</italic>, 27, 1719-1732. https://doi.org/10.1007/s10586-023-04052-4 <pub-id pub-id-type="doi">10.1007/s10586-023-04052-4</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/s10586-023-04052-4">https://doi.org/10.1007/s10586-023-04052-4</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Kethineni, K.</string-name>
              <string-name>Pradeepini, G.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Intrusion Detection in Internet of Things-Based Smart Farming Using Hybrid Deep Learning Framework</article-title>
            <source>Cluster Computing</source>
            <volume>27</volume>
            <pub-id pub-id-type="doi">10.1007/s10586-023-04052-4</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B10">
        <label>10.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Thakkar, A. and Lohiya, R. (2022) A Survey on Intrusion Detection System: Feature Selection, Model, Performance Measures, Application Perspective, Challenges, and Future Research Directions. <italic>Artificial Intelligence Review</italic>, 55, 453-563. https://doi.org/10.1007/s10462-021-10037-9 <pub-id pub-id-type="doi">10.1007/s10462-021-10037-9</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/s10462-021-10037-9">https://doi.org/10.1007/s10462-021-10037-9</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Thakkar, A.</string-name>
              <string-name>Lohiya, R.</string-name>
              <string-name>Selection, M</string-name>
              <string-name>Measures, A</string-name>
              <string-name>Perspective, C</string-name>
            </person-group>
            <year>2022</year>
            <article-title>A Survey on Intrusion Detection System: Feature Selection, Model, Performance Measures, Application Perspective, Challenges, and Future Research Directions</article-title>
            <source>Artificial Intelligence Review</source>
            <volume>55</volume>
            <pub-id pub-id-type="doi">10.1007/s10462-021-10037-9</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B11">
        <label>11.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Booij, T.M., Chiscop, I., Meeuwissen, E., Moustafa, N. and Hartog, F.T.H.D. (2022) Ton_IoT: The Role of Heterogeneity and the Need for Standardization of Features and Attack Types in IoT Network Intrusion Data Sets. <italic>IEEE Internet of Things Journal</italic>, 9, 485-496. https://doi.org/10.1109/jiot.2021.3085194 <pub-id pub-id-type="doi">10.1109/jiot.2021.3085194</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/jiot.2021.3085194">https://doi.org/10.1109/jiot.2021.3085194</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Booij, T.M.</string-name>
              <string-name>Chiscop, I.</string-name>
              <string-name>Meeuwissen, E.</string-name>
              <string-name>Moustafa, N.</string-name>
              <string-name>Hartog, F.T.H.D.</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Ton_IoT: The Role of Heterogeneity and the Need for Standardization of Features and Attack Types in IoT Network Intrusion Data Sets</article-title>
            <source>IEEE Internet of Things Journal</source>
            <volume>9</volume>
            <pub-id pub-id-type="doi">10.1109/jiot.2021.3085194</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B12">
        <label>12.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Lundberg, S.M. and Lee, S.-I. (2017) A Unified Approach to Interpreting Model Predictions. <italic>Proceedings of the</italic>31 <italic>st International Conference on Neural Information Processing Systems</italic>, New York, 4-9 December 2017, 4768-4777.</mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Lundberg, S.M.</string-name>
              <string-name>Lee, S.</string-name>
              <string-name>Systems, N</string-name>
            </person-group>
            <year>2017</year>
            <article-title>A Unified Approach to Interpreting Model Predictions</article-title>
            <source>Proceedings of the 31st International Conference on Neural Information Processing Systems</source>
            <volume>4</volume>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B13">
        <label>13.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Zheng, R., Hussien, A.G., Jia, H., Abualigah, L., Wang, S. and Wu, D. (2022) An Improved Wild Horse Optimizer for Solving Optimization Problems. <italic>Mathematic</italic><italic>s</italic>, 10, Article 1311. https://doi.org/10.3390/math10081311 <pub-id pub-id-type="doi">10.3390/math10081311</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/math10081311">https://doi.org/10.3390/math10081311</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Zheng, R.</string-name>
              <string-name>Hussien, A.G.</string-name>
              <string-name>Jia, H.</string-name>
              <string-name>Abualigah, L.</string-name>
              <string-name>Wang, S.</string-name>
              <string-name>Wu, D.</string-name>
            </person-group>
            <year>2022</year>
            <article-title>An Improved Wild Horse Optimizer for Solving Optimization Problems</article-title>
            <source>Mathematics</source>
            <volume>10</volume>
            <elocation-id>1311</elocation-id>
            <pub-id pub-id-type="doi">10.3390/math10081311</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
    </ref-list>
  </back>
</article>