DOI: 10.28979/jarnas.2001271 ISSN: 2757-5195

Causal-Convolutional Architectures for IoT Intrusion Detection: A Systematic Comparison Against Classical Machine Learning Baselines and a Bidirectionality Ablation

Ömer Faruk Sarıtaş
Intrusion detection for the Internet of Things (IoT) increasingly runs on IoT gateways and enterprise sensors that need architectures accurate enough to trust without being computationally heavy. Causal convolution offers gated, dilated, and multi-scale receptive-field mechanisms at low cost compared with recurrent or attention-based models. Whether such mechanisms need a bidirectional wrapper to approach classical machine-learning classifiers on tabular network-flow data remains unexamined. This study compares three causal-convolution mechanisms, dilated gated convolution, depthwise-separable gated convolution, and multi-scale causal inception, each trained bidirectionally and unidirectionally. A three-seed comparison on Telemetry, Operating system, and Network dataset (TON IoT) finds no significant accuracy difference between the two forms for any mechanism although the bidirectional wrapper roughly doubles the parameter count. Two feature-grouped variants split the token sequence into two or four groups before a late fusion step. All architectures are benchmarked against classical baselines, including Random Forest and Extreme Gradient Boosting, on TON IoT. The three bidirectional mechanisms and Extreme Gradient Boosting are additionally run once, under seed 42, on Canadian Institute for Cybersecurity IoT dataset (CIC-IoT-2023) as a limited external check. Dataset structure is characterized through mutual-information and principal-component analysis. The best unidirectional architecture, dilated gated convolution with only 402,000 parameters, reaches a three-seed mean macro F1-score of 95.47 percent and a Matthews Correlation Coefficient (MCC) of 0.9798 on TON IoT. This is 0.97 points below Extreme Gradient Boosting’s 96.44 percent. A pre-specified equivalence test confirms that this architecture’s bidirectional and unidirectional forms are statistically equivalent within half a macro-F1 point. Gradient-boosted trees remain strongest, but the margin is narrow enough for causal convolution to work as a lightweight alternative. A feature-ordering check across four tokenization orders, each averaged over three seeds, shows this margin depends on the specific order used. The order adopted throughout this study was the strongest of the four for two of the three mechanisms, and statistically indistinguishable from the strongest for the third. Principal-component analysis shows TON IoT’s signal concentrates in a low-dimensional subspace, a pattern mutual information corroborates through the large share of near-uninformative raw features, together explaining k-Nearest Neighbors’ competitive performance there. On TON IoT, a single-direction causal-convolution pass is a compact alternative to tree ensembles and to its own bidirectional counterpart. Measured Central Processing Unit (CPU) cost is reported with the results.