Skip to content
#small language model Open access

When Cost Objectives Delete Capability: Accuracy-Constrained Tool Selection for Multi-Component Intrusion Detection in IoT Networks

Aug 2026 · Future Internet · 0 citations · 52 references

TL;DR

A constrained formulation in which the tools that carry class discriminative signal form a mandatory core placed outside the policy’s reach, while the remaining choice minimizes the measured invocation cost, which is subjected to an explicit relative accuracy floor.

Abstract

Agentic systems built on large language models are increasingly being allowed to decide for themselves which diagnostic tools to run and the obvious way to keep the resulting expense under control is to train that decision against a cost objective. We evaluate this question in a routed multi-component detection pipeline in which evidence fusion is deterministic so that the results characterize the tool selection layer in place of a full language-model-mediated inference loop. We show that cost-only optimization is unsafe in a repeatable and specific way. When the informative tools in a registry are also the expensive ones then a cost-driven policy removes exactly the detectors which the system exists to use and multiclass attack attribution collapses on both the datasets we study, with most attack families never predicted at all. The loss is invisible to the summary metric most often reported in this field because attack vs. normal detection remains high on an attack-heavy evaluation split even when the underlying predictions carry no information. We propose a constrained formulation in which the tools that carry class discriminative signal form a mandatory core placed outside the policy’s reach, while the remaining choice minimizes the measured invocation cost, which is subjected to an explicit relative accuracy floor. Classifier capacity is offered at three tiers rather than being fixed, so the floor decides how much model to buy for each traffic group rather than only which auxiliary tools to drop. On both the corpora the constrained policy runs at a small fraction of the cost of calling every tool and is statistically equivalent to it under a pre-specified margin. On both it converged exactly to its mandatory core so the demonstrated benefit is the preservation of signal-bearing tools and the correct choice of classifier capacity rather than dynamic selection among many useful alternatives. Removing the core reproduces the original collapse. Sweeping the floor traces an explicit cost-accuracy frontier and exposes its practical limit. The rarest attack family, and not the average across families, determines how far the tolerance can safely be relaxed since macro-averaging distributes a severe loss on one class across all of them. Every invocation cost reported here is timed, and we report indirect prompt injection as a null result.

Read PDF

Similar papers

Conference 2026

CARE-Bench: A Capability-Stratified, Cost-Aware Benchmark for Agentic Software-Security Detection

Agentic systems for software-security detection have advanced quickly, from passive classifiers to cyber reasoning systems that autonomously find and patch vulnerabilities. Yet progress is hard to measure: systems are reported on incomparable datasets, with metrics that ignore cost, and on corpora whose labels are know...

Andi Xia · 0 citations
Open access Aug 2026

LLM-Integrated Anomaly Detection for IoT Networks: Framework Structure

A machine learning-based framework to tackle issues in traditional systems in traditional systems is introduced by combining large language models (LLMs) and is effective in identifying possible threats as well as filling the semantic gap.

Mamoon M. Saeed, Rashid A. Saeed, Salah Hagahmoodi et al. · 0 citations
Open access Aug 2026

Application of C4.5 Decision Tree Algorithm for Detecting Cyber Attacks Using IDS

This work constructs a web-based Intrusion Detection System prototype by training an entropy-based Decision Tree classifier, conceptually grounded in the C4.5 framework, on the NSL-KDD benchmark.

Daniel Erick Witopo, Hartana Wijaya · 0 citations
Preprint Aug 2026

When Relationships Break: Interpreting Network Traffic Anomalies via Dependency Violations

Current research on security monitoring is increasingly focusing on machine-learning-based approaches, but caveats remain. In addition to huge computational overhead, one concern is the lack of insights into"why"alerts are raised. Existing interpretability approaches rely on feature attribution methods that ignore depe...

Federica Uccello, Simin Nadjm-Tehrani · 0 citations
Open access Aug 2026

BOSE: A Bayesian-Optimized Stacked Ensemble Framework for Explainable Fine-Grained Industrial IoT Intrusion Detection

Industrial Internet of Things (IIoT) environments are increasingly exposed to sophisticated cyberattacks, creating a growing need for intrusion detection systems (IDSs) that balance high accuracy with computational efficiency. Although existing studies primarily focus on classification performance, they often overlook...

Mesut Uğurlu, I. Dogru · 0 citations

Related blog posts

MIT News · Artificial Intelligence Sep 30, 2026

This game-playing AI is the new champ at Stratego

Able to defeat top-ranked human players and more efficient than other models, the new system could help decision-makers in military maneuvers or business negotiations.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.