This paper trains four lightweight intrusion-detection architectures on one IIoT dataset and evaluates them without retraining on two structurally different datasets, using only features shared across all three sources. The models generalize poorly across networks and rely heavily on coarse port-category features. The most influential category appears in source-domain attack traffic at 96 to 435 times the rate observed in the target domains, suggesting that feature coarsening relocates rather than removes a shortcut. The study also finds that evaluation protocols under natural class imbalance can reverse the apparent difficulty of target networks, while adversarial robustness does not predict cross-network generalization.
No heat snapshots are available in the last 24 hours.