A hybrid CNN-BiLSTM edge-cloud intrusion detection system with online incremental learning and SHAP explainability for smart city IoT
Abstract
Abstract Smart city IoT deployments interconnect safety-critical infrastructure across millions of heterogeneous devices, creating an attack surface that signature-based intrusion detection systems (IDS) cannot defend against zero-day exploits, polymorphic malware, or concept drift. Prior deep-learning IDS proposals address the detection accuracy gap but typically evaluate on a single benchmark with a single random seed, omit structured ablation evidence, lack on-line adaptation, and provide no model-explanation interface for security analysts. This paper presents MI-IDS, a hybrid Convolutional Neural Network–Bidirectional Long Short-Term Memory (CNN-BiLSTM) ensemble deployed on a two-tier edge-cloud framework that integrates reservoir-sampling-based incremental learning and SHAP explainability under a single experimentally validated pipeline. The experimental results reveals that across five random seeds, MI-IDS achieves 96.7 ± 0.2% accuracy and 95.8 ± 0.2% F1-score on a 73,100-instance composite benchmark spanning seven traffic classes, one of which is a held-out group of synthetically mutated attack variants used as a partial-novelty proxy rather than a genuine zero-day family. A held-out UNSW-NB15 partition ( n = 82,332) yields 97.4 ± 0.2% accuracy; because UNSW-NB15 also contributes to the composite, this figure reflects within-benchmark held-out performance rather than independent cross-dataset generalisation. A six-variant ablation study isolates the contribution of each architectural component. Under a 48-hour concept-drift simulation, reservoir sampling bounds accuracy loss to 1.2% points versus a 20.4-point degradation for the non-adaptive baseline. The hybrid edge-cloud deployment achieves 14.1 ms mean detection latency and 61.2% lower bandwidth than cloud-only deployment, and SHAP attributions lowered analyst mean time-to-decision by 57.1% in a small preliminary study with five experts, a result we treat as indicative rather than confirmatory. All improvements over six baselines are statistically significant at Bonferroni-corrected α = 0.0083. A central contribution is the integration and disciplined evaluation of multi-seed validation, structured ablation, on-line incremental learning, and model-agnostic explainability within a single smart city IoT pipeline, a combination that remains uncommon in the prior IDS literature rather than one we can demonstrate to be unprecedented.
// Source
Institutions: Manipal University Jaipur, Lovely Professional University