DEA-IDS: Drift-Aware Feature Selection and Few-Shot Adaptation for Cross-Domain IoT–IoMT Intrusion Detection
Büşra Günay, Mehmet Yavuz YağcıIntrusion Detection Systems (IDSs) are essential for securing Internet of Things (IoT) and Internet of Medical Things (IoMT) environments, yet most machine learning-based IDSs assume that training and testing data follow similar distributions. In practice, domain shifts arising from differences in device characteristics, communication protocols, and traffic patterns can substantially increase false positive rates (FPRs), reducing operational reliability. This study proposes DEA-IDS (Drift-aware, Explainable and Adaptive Intrusion Detection System), a unified framework integrating SHAP-based explainability, statistical drift analysis via the Kolmogorov–Smirnov statistic and Wasserstein distance, drift-aware stable feature selection, and few-shot adaptation, evaluated on a CICIoT2023-to-CICIoMT2024 cross-domain transfer scenario. Under a leakage-free protocol in which drift statistics and few-shot samples are drawn exclusively from the target training split, DEA-IDS reduces FPR from 0.5468 to 0.0004 while maintaining an F1-score of 0.9944; threshold-, sample-size-, and feature-selection-control sensitivity analyses confirm this reduction reflects drift-aware stable feature selection rather than test-set leakage or dimensionality reduction alone. A per-attack-family analysis shows this improvement is concentrated in high-volume flood-style attacks and is accompanied by reduced detection of ARP spoofing, malformed-MQTT, and reconnaissance traffic, reported here as an explicit limitation. These results demonstrate that explicitly modeling feature stability before adaptation improves operational robustness for cross-domain intrusion detection in heterogeneous IoT–IoMT environments.