Expert Systems with Applications· 2026Q1
CCA-ID: Confidence-calibrated adaptive intrusion detection with selective routing for IoT networks
- 0citations
- Q1SCImago
- 2026year
Short summary
CCA-ID, a new intrusion detection system for IoT, uses confidence calibration to route traffic: high-confidence samples are processed by a lightweight model, while low-confidence ones go to a heavy ensemble, achieving 89.92% accuracy and a 13.94x speedup over always-on heavy models.
AI-generated from the title and abstract; the full text is not read.
Key points
- CCA-ID employs a confidence-driven routing mechanism for IoT intrusion detection.
- High-confidence samples are finalized by a lightweight calibrated gate, while low-confidence samples are routed to a heavy ensemble.
- The system achieves 89.92% accuracy and 61.70% macro F1-score on the Gotham Dataset 2025.
- CCA-ID provides a 13.94x speedup over always-on heavy models with an Expected Calibration Error (ECE) of 7.66%.
AI-generated from the title and abstract; the full text is not read.
Abstract
The rapid expansion of Internet of Things (IoT) deployments has extended the cyber-attack surface. In resource-constrained IoT monitoring environments, maintaining always-on deep or ensemble-based intrusion detection can be challenging for high-rate, real-time traffic. This study presents CCA-ID, Confidence Calibrated Adaptive Intrusion Detection which integrates calibrated decision confidence with selective, resource-aware inference for IoT intrusion detection. CCA-ID combines an isotonic-calibrated logistic regression gate, heterogeneous heavy learners including DNN, XGBoost, and LightGBM, and a stacking meta-classifier within a class-specific confidence-driven routing mechanism. High-confidence samples are finalized by the lightweight calibrated gate, whereas low-confidence samples are selectively routed to the heavy ensemble for deeper analysis. The proposed CCA-ID is evaluated on the large-scale Gotham Dataset 2025, using a final experimental dataset comprising 7,792,438 packet-level samples across 18 traffic classes. Experimental results indicate that CCA-ID achieves 89.92% accuracy, 61.70% macro F1-score, and 98.93% macro ROC-AUC, while routing only 6.28% of samples to the heavy ensemble. The method also achieves an Expected Calibration Error (ECE) of 7.66%, showing improved confidence reliability for routing decisions. An inference-time analysis further indicates that CCA-ID achieves a 13.94 × speedup over the always-on heavy stack on a fixed stratified subset of the held-out test set. Overall, CCA-ID provides a calibrated trade-off between selective inference and heavy-model invocation for IoT intrusion detection. It reduces unnecessary heavy-model usage while maintaining strong threshold-free discriminative performance under severe class imbalance.
The authors' abstract, as published at the source. Expert Systems with Applications, 2026 · DOI ↗
Continue with a free account
Ask the paper: 3 free questions a day about this paper; save it, get its citation, new summaries every day for your field. Takeaways are Premium.
Continue free on the webSign in with Google or Apple; no card needed. You come back to this paper.
On your phone:
Field: Computer Networks and Communications
Computer Networks and CommunicationsComputer Science