AI & Computingarticle2026-08-27

When Cost Objectives Delete Capability: Accuracy-Constrained Tool Selection for Multi-Component Intrusion Detection in IoT Networks

Open access0 citations

Abstract

Agentic systems built on large language models are increasingly being allowed to decide for themselves which diagnostic tools to run and the obvious way to keep the resulting expense under control is to train that decision against a cost objective. We evaluate this question in a routed multi-component detection pipeline in which evidence fusion is deterministic so that the results characterize the tool selection layer in place of a full language-model-mediated inference loop. We show that cost-only optimization is unsafe in a repeatable and specific way. When the informative tools in a registry are also the expensive ones then a cost-driven policy removes exactly the detectors which the system exists to use and multiclass attack attribution collapses on both the datasets we study, with most attack families never predicted at all. The loss is invisible to the summary metric most often reported in this field because attack vs. normal detection remains high on an attack-heavy evaluation split even when the underlying predictions carry no information. We propose a constrained formulation in which the tools that carry class discriminative signal form a mandatory core placed outside the policy’s reach, while the remaining choice minimizes the measured invocation cost, which is subjected to an explicit relative accuracy floor. Classifier capacity is offered at three tiers rather than being fixed, so the floor decides how much model to buy for each traffic group rather than only which auxiliary tools to drop. On both the corpora the constrained policy runs at a small fraction of the cost of calling every tool and is statistically equivalent to it under a pre-specified margin. On both it converged exactly to its mandatory core so the demonstrated benefit is the preservation of signal-bearing tools and the correct choice of classifier capacity rather than dynamic selection among many useful alternatives. Removing the core reproduces the original collapse. Sweeping the floor traces an explicit cost-accuracy frontier and exposes its practical limit. The rarest attack family, and not the average across families, determines how far the tolerance can safely be relaxed since macro-averaging distributes a severe loss on one class across all of them. Every invocation cost reported here is timed, and we report indirect prompt injection as a null result.

// Source

View paper (DOI)Open access versionOpenAlexFuture InternetPublished 2026-08-27

Authors: Aakarsh Etar, Jayesh Soni, Himanshu Upadhyay

Institutions: Florida International University