Factors Influencing LSTM Model Generalizability for IoT Intrusion Detection
Amin Kaveh, Noah Wassberg, Christian Rohner, Andreas Johnsson · 2025
Intrusion Detection Systems (IDS) are crucial for monitoring and managing critical infrastructure; however, their prominence makes them attractive targets for network attacks. Machine Learning (ML) techniques incorporated into IDS have shown promise in detecting and mitigating these threats. Unfortunately, the scarcity of attack samples presents challenges for model training and generalizability, and attackers can easily bypass detection systems by introducing temporal variations in their attacks. This paper develops strategies for detecting network attacks and specifically examines the impact of network configurations on the generalizability of detection models. As an illustrative example, we investigate the performance of Long Short-Term Memory (LSTM) models in capturing temporal changes in network behavior during attacks, and its resilience against distributional changes. Our study considers multiple factors in terms of attack types, variations, and network configurations, including different topologies and numbers of nodes. We provide insights into how these factors impact the generalizability of models trained using knowledge sharing. To support our research, we implemented Blackhole and DIS-flooding attack variations using the Cooja network simulator. Our objective was to generate a large dataset that enables a comprehensive analysis of attack variations across a diverse set of network configurations, focusing on the impact on LSTM-based IDS for IoT networks.