{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T05:05:28Z","timestamp":1787029528182,"version":"3.56.0"},"reference-count":30,"publisher":"MDPI AG","issue":"15","license":[{"start":{"date-parts":[[2022,7,29]],"date-time":"2022-07-29T00:00:00Z","timestamp":1659052800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"NSERC, Canada"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>As IoT devices\u2019 adoption grows rapidly, security plays an important role in our daily lives. As part of the effort to counter these security threats in recent years, many IoT intrusion detection datasets were presented, such as TON_IoT, BoT-IoT, and Aposemat IoT-23. These datasets were used to build many machine learning-based IoT intrusion detection models. In this research, we present an explainable and efficient method for selecting the most effective universal features from IoT intrusion detection datasets that can help in producing highly-accurate and efficient machine learning-based intrusion detection systems. The proposed method was applied to TON_IoT, Aposemat IoT-23, and IoT-ID datasets and resulted in the selection of six universal network-flow features. The proposed method was tested and produced a high accuracy of 99.62% with a prediction time reduced by up to 70%. To provide better insight into the operation of the classifier, a Shapley additive explanation was used to explain the selected features and to prove the alignment of the explanation with current attack techniques.<\/jats:p>","DOI":"10.3390\/s22155690","type":"journal-article","created":{"date-parts":[[2022,8,1]],"date-time":"2022-08-01T23:49:27Z","timestamp":1659397767000},"page":"5690","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":54,"title":["Towards an Explainable Universal Feature Set for IoT Intrusion Detection"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4324-1774","authenticated-orcid":false,"given":"Mohammed M.","family":"Alani","sequence":"first","affiliation":[{"name":"Computer Science Department, Toronto Metropolitan University, Toronto, ON M5B 2K3, Canada"},{"name":"School of IT Administration and Security, Seneca College of Applied Arts and Technology, Toronto, ON M2J 2X5, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ali","family":"Miri","sequence":"additional","affiliation":[{"name":"Computer Science Department, Toronto Metropolitan University, Toronto, ON M5B 2K3, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,7,29]]},"reference":[{"key":"ref_1","unstructured":"(2022, February 23). Global IoT Connections Data Volume 2019 and 2025|Statista. Available online: https:\/\/www.statista.com\/statistics\/1017863\/worldwide-iot-connected-devices-data-size\/."},{"key":"ref_2","unstructured":"(2022, January 21). Internet of Threats: IoT Botnets Drive Surge in Network Attacks. Available online: https:\/\/securityintelligence.com\/posts\/internet-of-threats-iot-botnets-network-attacks\/."},{"key":"ref_3","unstructured":"Seals, T. (2022, January 21). IoT Attacks Skyrocket, Doubling in 6 Months. Threatpost. Available online: https:\/\/threatpost.com\/iot-attacks-doubling\/169224."},{"key":"ref_4","unstructured":"Palmer, D. (2021). Critical IoT Security Camera Vulnerability Allows Attackers to Remotely Watch Live Video\u2014And Gain Access to Networks. ZDNet, Available online: https:\/\/www.zdnet.com\/article\/critical-iot-security-camera-vulnerability-allows-attackers-to-remotely-watch-live-video-and-gain-access-to-networks."},{"key":"ref_5","unstructured":"Antonakakis, M., April, T., Bailey, M., Bernhard, M., Bursztein, E., Cochran, J., Durumeric, Z., Halderman, J.A., Invernizzi, L., and Kallitsis, M. (2017, January 23). Understanding the Mirai Botnet. Proceedings of the 26th USENIX Security Symposium (USENIX Security 17), Vancouver, BC, Canada."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Liu, H., and Lang, B. (2019). Machine learning and deep learning methods for intrusion detection systems: A survey. Appl. Sci., 9.","DOI":"10.3390\/app9204396"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"107840","DOI":"10.1016\/j.comnet.2021.107840","article-title":"Machine learning methods for cyber security intrusion detection: Datasets and comparative study","volume":"188","author":"Kilincer","year":"2021","journal-title":"Comput. Netw."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Asharf, J., Moustafa, N., Khurshid, H., Debie, E., Haider, W., and Wahab, A. (2020). A review of intrusion detection systems using machine and deep learning in internet of things: Challenges, solutions and future directions. Electronics, 9.","DOI":"10.3390\/electronics9071177"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Alsoufi, M.A., Razak, S., Siraj, M.M., Nafea, I., Ghaleb, F.A., Saeed, F., and Nasser, M. (2021). Anomaly-based intrusion detection systems in iot using deep learning: A systematic literature review. Appl. Sci., 11.","DOI":"10.3390\/app11188383"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Fatani, A., Dahou, A., Al-Qaness, M.A., Lu, S., and Elaziz, M.A. (2021). Advanced feature extraction and selection approach using deep learning and Aquila optimizer for IoT intrusion detection system. Sensors, 22.","DOI":"10.3390\/s22010140"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Desai, M.G., Shi, Y., and Suo, K. (2020, January 28\u201331). IoT Bonet and Network Intrusion Detection using Dimensionality Reduction and Supervised Machine Learning. Proceedings of the 2020 11th IEEE Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON), New York, NY, USA.","DOI":"10.1109\/UEMCON51285.2020.9298146"},{"key":"ref_12","unstructured":"Kang, H., Ahn, D.H., Lee, G.M., Yoo, J.D., Park, K.H., and Kim, H.K. (2019). IoT Network Intrusion Dataset, IEEE."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"102994","DOI":"10.1016\/j.scs.2021.102994","article-title":"A new distributed architecture for evaluating AI-based security systems at the edge: Network TON_IoT datasets","volume":"72","author":"Moustafa","year":"2021","journal-title":"Sustain. Cities Soc."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Moustafa, N., Ahmed, M., and Ahmed, S. (2020, January 10\u201313). Data Analytics-Enabled Intrusion Detection: Evaluations of ToN_IoT Linux Datasets. Proceedings of the 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), Guangzhou, China.","DOI":"10.1109\/TrustCom50675.2020.00100"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"177","DOI":"10.1016\/j.icte.2021.04.012","article-title":"Feature selection for intrusion detection system in Internet-of-Things (IoT)","volume":"7","author":"Nimbalkar","year":"2021","journal-title":"ICT Express"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"357","DOI":"10.1007\/s11036-021-01843-0","article-title":"Towards a standard feature set for network intrusion detection system datasets","volume":"27","author":"Sarhan","year":"2022","journal-title":"Mob. Netw. Appl."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"165130","DOI":"10.1109\/ACCESS.2020.3022862","article-title":"TON_IoT telemetry dataset: A new generation dataset of IoT and IIoT for data-driven intrusion detection systems","volume":"8","author":"Alsaedi","year":"2020","journal-title":"IEEE Access"},{"key":"ref_18","unstructured":"(2022, June 23). Stratosphere IPS. Available online: https:\/\/www.stratosphereips.org\/datasets-iot23."},{"key":"ref_19","unstructured":"(2022, January 29). The Zeek Network Security Monitor. Available online: https:\/\/zeek.org."},{"key":"ref_20","unstructured":"(2022, January 29). Parsebrologs. Available online: https:\/\/pypi.org\/project\/parsebrologs."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"100378","DOI":"10.1016\/j.cosrev.2021.100378","article-title":"Conceptual and empirical comparison of dimensionality reduction algorithms (pca, kpca, lda, mds, svd, lle, isomap, le, ica, t-sne)","volume":"40","author":"Anowar","year":"2021","journal-title":"Comput. Sci. Rev."},{"key":"ref_22","unstructured":"Raschka, S., Liu, Y., and Mirjalili, V. (2022). Machine Learning with PyTorch and Scikit-Learn, Packt Publishing."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"105","DOI":"10.1186\/s40537-020-00379-6","article-title":"Performance Analysis of Intrusion Detection Systems Using a Feature Selection Method on the UNSW-NB15 Dataset","volume":"7","author":"Kasongo","year":"2020","journal-title":"J. Big Data"},{"key":"ref_24","unstructured":"G\u00e9ron, A. (2019). Hands-on Machine Learning with Scikit-Learn, Keras, and TensorFlow: Concepts, Tools, and Techniques to Build Intelligent Systems, O\u2019Reilly Media."},{"key":"ref_25","unstructured":"(2022, July 15). Nmap: The Network Mapper\u2014Free Security Scanner. Available online: https:\/\/nmap.org."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Molnar, C., Casalicchio, G., and Bischl, B. (2020, January 13\u201317). Interpretable machine learning\u2014A brief history, state-of-the-art and challenges. Proceedings of the Joint European Conference on Machine Learning and Knowledge Discovery in Databases, Bilbao, Spain.","DOI":"10.1007\/978-3-030-65965-3_28"},{"key":"ref_27","unstructured":"Lundberg, S.M., and Lee, S.I. (2017, January 4\u20139). A Unified Approach to Interpreting Model Predictions. Proceedings of the NIPS\u201917, Long Beach, CA, USA."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Khan, N.M., Nalina Madhav, C., Negi, A., and Thaseen, I.S. (2019). Analysis on Improving the Performance of Machine Learning Models Using Feature Selection Technique. Intelligent Systems Design and Applications, Springer.","DOI":"10.1007\/978-3-030-16660-1_7"},{"key":"ref_29","first-page":"443","article-title":"UNSW-NB15 Dataset Feature Selection and Network Intrusion Detection Using Deep Learning","volume":"7","author":"Kanimozhi","year":"2019","journal-title":"Int. J. Recent Technol. Eng."},{"key":"ref_30","first-page":"484","article-title":"ToN_IoT: The Role of Heterogeneity and the Need for Standardization of Features and Attack Types in IoT Network Intrusion Datasets","volume":"9","author":"Booij","year":"2021","journal-title":"IEEE Internet Things J."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/15\/5690\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:59:19Z","timestamp":1760140759000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/15\/5690"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,7,29]]},"references-count":30,"journal-issue":{"issue":"15","published-online":{"date-parts":[[2022,8]]}},"alternative-id":["s22155690"],"URL":"https:\/\/doi.org\/10.3390\/s22155690","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,7,29]]}}}