Dataset Integrity, Feature Leakage Discovery, in IoT Intrusion Detection: A Verified, Reproducible Evaluation on IoT-23, ToN-IoT and Edge-IIoTset
Abstract
Machine-learning-based intrusion detection for the Internet of Things is a rapidly growing literature that is nonetheless frequently undermined by two under-examined threats to validity: unverified dataset provenance and undisclosed feature leakage. This paper proposes XAI-FedFog-HybridNet, a federated intrusion-detection architecture for 6G fog-IoT environments that combines a three-branch Bi-LSTM-RNNCNN classifier, differential-privacy-bounded secure aggregation with Byzantine-robust selection, a permissioned blockchain audit layer, and a dual explainability module built on SHAP and Grad-CAM. In this it adopts the operational-transparency reporting discipline established in the network-and-servicemanagement literature - explicit training-time accounting, multi-dataset statistical validation, and deployability-relevant metrics beyond raw accuracy -This paper reports a fully verified, mathematically formalized evaluation of an intrusion-detection pipeline on three independently checked open-source benchmarks - IoT-23, ToN-IoT and Edge-IIoTset. the specified deep hybrid architecture, the study measured binary and multiclass detection accuracy, training/validation convergence, confusion matrices, ROC/AUC, feature importance, correlation structure, oversampling-coefficient sensitivity, training time and statistical significance across all three datasets. We formalize every preprocessing operator mathematically and report binary and multi-class results - accuracy, macro-F1, AUC, Matthews Correlation Coefficient, confusion matrices, ROC curves, feature importance, and ANOVA/t-test statistical validation with Cohen's d - measured directly. Binary test accuracy reached 97.52% (ToN-IoT), 97.41% (Edge-IIoTset) and 88.53% (IoT-23). We discovered and quantified a schema artifact in Edge-IIoTset - MQTT/DNS protocol-presence fields that leak attack-category identity, inflating naive accuracy to a non-generalizable 100.00% until removed. Benchmarked against real baseline classifiers, gradient-boosted tree ensembles outperformed our neuralnetwork framework on every one of six configurations tested. We contend that verified provenance result reporting are themselves scientific contributions this paper is structured to demonstrate.