This research proposes a comprehensive and repeatable machine learning system for IoT IDS, covering leakage-aware pre-processing, comparison of five ML models, class imbalance, explainability using SHAP and a lightweight 15 feature IDS. The framework also assesses the robustness to zero day attacks under a Leave-One-Attack-Out approach and compares the supervised detection approach with an Isolation Forest baseline. Furthermore, bidirectional cross-dataset evaluation between TON_IoT and UNSW_NB15 is conducted to evaluate the model in different network environments. The results show that explainability, resistance to unseen attacks, and cross-dataset validation are necessary to measure the usability of intrusion detection systems in IoT.
