DOI: 10.3390/app16167919 ISSN: 2076-3417

BOSE: A Bayesian-Optimized Stacked Ensemble Framework for Explainable Fine-Grained Industrial IoT Intrusion Detection

Mesut Uğurlu, İbrahim Alper Doğru

Industrial Internet of Things (IIoT) environments are increasingly exposed to sophisticated cyberattacks, creating a growing need for intrusion detection systems (IDSs) that balance high accuracy with computational efficiency. Although existing studies primarily focus on classification performance, they often overlook deployment costs and model interpretability. To address these challenges, this study presents BOSE (Bayesian-Optimized Stacked Ensemble), an intrusion detection system that combines hybrid feature selection, Bayesian hyperparameter optimization, Out-of-Fold (OOF) stacking with leakage-free meta-feature generation, and SHAP-based explainability. Hybrid feature selection reduces the original feature space from 84 to 46 informative features, while Bayesian Optimization is used to determine the hyperparameter configuration of the ensemble models and leakage-free OOF stacking enables reliable meta-learning. Experimental results on the 50-class DataSense benchmark show that BOSE achieves a Macro-F1 score of 88.43% over ten independent runs, outperforming all directly comparable baseline models evaluated under the same end-to-end 50-class classification setting while remaining competitive with recent hierarchical multi-stage frameworks. In addition, the proposed model achieves an inference latency of 0.1421 ms, a throughput of 7035 packets/s, a runtime memory footprint of 19.11 MB, and a model size of 309.12 MB. These results demonstrate the CPU-based inference feasibility of the suggested framework under the evaluated workstation configuration and indicate its potential applicability to industrial edge gateways and industrial PCs. The proposed dual-level SHAP solution improves model transparency by explaining both feature-level contributions and ensemble-level decisions, making BOSE an accurate, computationally efficient, and interpretable solution for fine-grained IIoT intrusion detection.

More from our Archive