TITLE:
Stress-Testing Explainable Intrusion Detection in Agricultural IoT Networks against Noise and Evasion Attacks
AUTHORS:
Alexandre Kouamé Kanga, Doffou Jérôme Diako, Kouamé Abel Assielou, Souleymane Oumtanaga, Yao Casimir Brou
KEYWORDS:
Agricultural IoT, Intrusion Detection, Evasion Attack, Explainable Artificial Intelligence, Robustness Audit
JOURNAL NAME:
Open Journal of Applied Sciences,
Vol.16 No.8,
August
24,
2026
ABSTRACT: Agricultural Internet of Things networks operate under variable communication conditions and expose intrusion-detection systems to both environmental perturbations and deliberate evasion. This study presents a reproducible multi-seed stress-testing protocol for a CNN-IWHO-Lite-Random Forest intrusion-detection pipeline evaluated on CICIoT2023, Farm-Flow, and UNSW-NB15. Three independent model seeds were used, while Gaussian-noise and adversarial experiments included nested internal repetitions. Preprocessing, representation learning, latent-feature selection, calibration, and threshold optimization were restricted to mutually disjoint non-test partitions, and exact feature-vector overlaps were removed before evaluation. Clean F1-scores were 0.9953 ± 0.0001, 0.4724 ± 0.0131, and 0.7480 ± 0.0183 for CICIoT2023, Farm-Flow, and UNSW-NB15, respectively. At σ = 1.0, the corresponding F1-scores were 0.9940 ± 0.0002, 0.4118 ± 0.0013, and 0.6768 ± 0.0550. Conditional attack success rates at ε = 0.8 were 16.17% ± 22.66%, 13.58% ± 10.56%, and 98.43% ± 1.17%. TreeSHAP audits and complete false-positive and false-negative summaries were used to interpret selected latent dimensions and decision failures. The results show that robustness is strongly dataset- and seed-dependent: Farm-Flow is limited primarily by baseline false positives and noise sensitivity, whereas UNSW-NB15 is consistently vulnerable to the evaluated score-query evasion attack. These findings support deployment decisions based on explicit stress tests rather than nominal accuracy alone.