Eguavoen, V., Amadin, F. (2026). Illusion of Generalisation: Zero-Padding-Induced Distributional Collapse in Cross-Dataset IoT DDoS Detection. , (), -. doi: 10.69513/njitcs.2026.172241.1064
Victor Osasu Eguavoen; Frank I. Amadin. "Illusion of Generalisation: Zero-Padding-Induced Distributional Collapse in Cross-Dataset IoT DDoS Detection". , , , 2026, -. doi: 10.69513/njitcs.2026.172241.1064
Eguavoen, V., Amadin, F. (2026). 'Illusion of Generalisation: Zero-Padding-Induced Distributional Collapse in Cross-Dataset IoT DDoS Detection', , (), pp. -. doi: 10.69513/njitcs.2026.172241.1064
Eguavoen, V., Amadin, F. Illusion of Generalisation: Zero-Padding-Induced Distributional Collapse in Cross-Dataset IoT DDoS Detection. , 2026; (): -. doi: 10.69513/njitcs.2026.172241.1064
Illusion of Generalisation: Zero-Padding-Induced Distributional Collapse in Cross-Dataset IoT DDoS Detection
Al-Noor Journal for Information Technology and Cybersecurity
Articles in Press, Corrected Proof, Available Online from 26 September 2026
1Department of Computing, College of Science and Computing, Wellspring University, Benin City, Edo State, Nigeria.
2Department of Computer Science, Faculty of Physical Sciences, University of Benin, Benin City, Edo State, Nigeria
Abstract
Distributed Denial of Service (DDoS) attacks threaten the availability of Internet of Things (IoT) networks, yet detection models are typically validated only on the dataset used to train them. This study tests whether a high-performing deep-learning DDoS detector generalises to an independent benchmark, following six steps: (1) DDoS and benign flows were extracted from the CICIoT2023 and TON_IoT datasets and cleaned, deduplicated, and converted to numerical features; (2) SMOTE corrected the severe class imbalance in the CICIoT2023 training partition; (3) flows were grouped into 20-flow sliding-window sequences; (4) a hybrid CNN-BiGRU-MHA network was trained on CICIoT2023 alone; (5) the trained model was evaluated internally on held-out CICIoT2023 sequences and externally on TON_IoT without retraining, zero-padding TON_IoT's non-overlapping features to match the 39-feature model input; and (6) SHAP GradientExplainer values quantified the features driving internal predictions. Internal accuracy reached 100.00% (F1 = 1.0000), whereas external accuracy on 792 TON_IoT sequences collapsed to 24.49% (F1 = 0.0000, ROC-AUC = 0.50), a failure traced to zero-padding rather than to network architecture. SHAP attributed the internal decision boundary chiefly to packet-count rate and time-to-live anomalies. Within-dataset accuracy alone cannot certify cross-dataset generalisation, and zero-padding is not a valid substitute for semantically compatible features in cross-dataset IoT intrusion-detection evaluation.