<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">82704</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2026.082704</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Cross-Domain Robust Dynamic Trust Evaluation for Industrial Internet of Things Edge Nodes</article-title>
<alt-title alt-title-type="left-running-head">Cross-Domain Robust Dynamic Trust Evaluation for Industrial Internet of Things Edge Nodes</alt-title>
<alt-title alt-title-type="right-running-head">Cross-Domain Robust Dynamic Trust Evaluation for Industrial Internet of Things Edge Nodes</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Guan</surname><given-names>Qiuguo</given-names></name></contrib>
<contrib id="author-2" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Ren</surname><given-names>Zhiyu</given-names></name><email>ren_ktzy@163.com</email></contrib>
<aff id="aff-1"><institution>School of Cryptography Engineering, Engineering University</institution>, <addr-line>Zhengzhou</addr-line>, <country>China</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Zhiyu Ren. Email: <email>ren_ktzy@163.com</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2026</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>15</day><month>06</month><year>2026</year>
</pub-date>
<volume>88</volume>
<issue>2</issue>
<elocation-id>99</elocation-id>
<history>
<date date-type="received">
<day>23</day>
<month>03</month>
<year>2026</year>
</date>
<date date-type="accepted">
<day>19</day>
<month>05</month>
<year>2026</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2026 The Authors. Published by Tech Science Press.</copyright-statement>
<copyright-year>2026</copyright-year>
<copyright-holder>The Authors</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_82704.pdf"></self-uri>
<abstract>
<p>To address trust-score drift and unsafe online adaptation under cross-domain attack-contaminated streams in Industrial Internet of Things (IIoT) edge environments, this paper proposes a risk-aware lightweight test-time adaptation (TTA) framework, named RaL-TTA, for dynamic trust evaluation of edge nodes. RaL-TTA constructs a low-dimensional robust feature space and a source-domain normal-entropy reference baseline, and performs selective online maintenance in the target domain through Kolmogorov&#x2013;Smirnov (KS) drift detection, SafeBrake risk gating, Adaptive Batch Normalization (AdaBN) anchor protection, and budgeted sample-level safeguards. Low-risk batches are adapted by updating only lightweight Batch Normalization (BN) parameters, whereas high-risk batches freeze online updates and invoke anchor-based protective inference. Experiments on Edge-IIoTset show that RaL-TTA substantially improves perturbation-stage attack detection and false-positive control compared with general TTA baselines while maintaining post-perturbation stability. In the main Edge-IIoTset setting, RaL-TTA achieves a perturbation-stage true positive rate (TPR) of 1.0000, false positive rate (FPR) of 0.0410, F1-score of 0.9544, and accuracy of 0.9713, while updating only 192 online parameters. External validation on X-IIoTID,a connectivity- and device-agnostic intrusion dataset for IIoT, further evaluates cross-service generalization under Modbus, Message Queuing Telemetry Transport (MQTT), and WebSocket target services. Additional sensitivity, startup-window robustness, calibration, and runtime-overhead analyses further characterize the stability, deployment assumptions, trust-score reliability, and edge-side feasibility of the proposed framework.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Industrial Internet of Things</kwd>
<kwd>dynamic trust evaluation</kwd>
<kwd>cross-domain intrusion detection</kwd>
<kwd>test-time adaptation</kwd>
<kwd>risk-constrained adaptation</kwd>
<kwd>edge security</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>National Natural Science Foundation of China</funding-source>
<award-id>62102449</award-id>
</award-group>
<award-group id="awg2">
<funding-source>Science and Technology Research Project of Henan Province</funding-source>
<award-id>252102211080</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>The Industrial Internet of Things (IIoT) has developed rapidly with the accelerated integration of next-generation information technology and industrial manufacturing. It extends computing capabilities from cloud infrastructures to edge devices and has become an important infrastructure for industrial intelligence. Its security and reliability are directly related to the continuous and stable operation of physical production processes [<xref ref-type="bibr" rid="ref-1">1</xref>&#x2013;<xref ref-type="bibr" rid="ref-3">3</xref>]. With the ubiquitous deployment of heterogeneous sensors and actuators, IIoT systems face complex security challenges arising from the coexistence of open connectivity and closed-loop physical processes. Dynamic trust evaluation is an important way to complement traditional static defense in heterogeneous edge scenarios and to support adaptive access control and edge-side risk decision-making [<xref ref-type="bibr" rid="ref-4">4</xref>,<xref ref-type="bibr" rid="ref-5">5</xref>].</p>
<p>Most existing studies on IIoT trust evaluation and industrial intrusion detection follow a static offline training mode [<xref ref-type="bibr" rid="ref-6">6</xref>&#x2013;<xref ref-type="bibr" rid="ref-8">8</xref>]. Whether traditional machine-learning methods, such as random forests and support vector machines, or deep neural-network-based anomaly detection models are employed, their performance usually depends heavily on the assumption that the training data and deployment data follow an independent and identically distributed (IID) setting [<xref ref-type="bibr" rid="ref-9">9</xref>,<xref ref-type="bibr" rid="ref-10">10</xref>]. Such models are typically trained once in the source domain, such as a laboratory environment, and then fixed, which limits their adaptability to non-stationary environments. However, in actual industrial settings, edge nodes face severe domain-shift challenges. The heterogeneity of underlying communication protocols, such as migration between Message Queuing Telemetry Transport (MQTT) and Modbus over Transmission Control Protocol (Modbus/TCP), and the time-varying nature of production conditions can make the target-domain data distribution deviate from the source-domain prior [<xref ref-type="bibr" rid="ref-6">6</xref>,<xref ref-type="bibr" rid="ref-8">8</xref>]. Violating the IID assumption can therefore degrade the detection performance of a source-domain model in the target domain and distort the corresponding trust scores.</p>
<p>To alleviate the degradation of source-domain models in the target domain, researchers have regarded cross-domain trust evaluation as a distribution-transfer problem under non-stationary environments and introduced mechanisms such as domain adaptation (DA) to reduce the impact of domain shift [<xref ref-type="bibr" rid="ref-11">11</xref>,<xref ref-type="bibr" rid="ref-12">12</xref>]. For example, Adaptive Batch Normalization (AdaBN) achieves distribution alignment by re-estimating normalization statistics in the target domain [<xref ref-type="bibr" rid="ref-13">13</xref>]; Source Hypothesis Transfer (SHOT) freezes the source-domain classifier without accessing source data and iteratively optimizes the target-domain feature extractor [<xref ref-type="bibr" rid="ref-14">14</xref>]. To address continuous distribution changes in industrial edge environments, methods such as EdgeFD combine drift detection with model-weight integration to reduce the overhead caused by frequent fine-tuning and to alleviate catastrophic forgetting [<xref ref-type="bibr" rid="ref-11">11</xref>]. However, such methods often still rely on phased adaptation processes or iterative optimization and are sensitive to statistical estimates from small batches, making it difficult to meet the requirements of edge-node security detection in online unlabeled scenarios. Therefore, the research focus has gradually shifted to test-time adaptation (TTA) methods that can operate without retraining after deployment.</p>
<p>TTA reduces the deployment cost of adaptation because it does not require source-domain data after deployment [<xref ref-type="bibr" rid="ref-15">15</xref>]. AdaBN rapidly aligns distributions by re-estimating Batch Normalization (BN) statistics [<xref ref-type="bibr" rid="ref-13">13</xref>]; fully test-time adaptation by entropy minimization (TENT) optimizes model parameters online through entropy minimization to increase prediction confidence in the target domain [<xref ref-type="bibr" rid="ref-16">16</xref>]. For continuously changing target-domain distributions, methods such as continual test-time adaptation (CoTTA) suppress error accumulation and catastrophic forgetting through teacher-student consistency, enhanced averaging, and random recovery [<xref ref-type="bibr" rid="ref-12">12</xref>]. Other studies construct adaptation objectives from energy functions and iterative sampling [<xref ref-type="bibr" rid="ref-17">17</xref>], or monitor entropy drift online and perform entropy-distribution matching for more robust trigger-based adaptation [<xref ref-type="bibr" rid="ref-18">18</xref>]. However, directly applying general TTA methods to adversarial IIoT edge environments still faces resource and security constraints. Frequent backpropagation, multiple data augmentations, or iterative sampling can increase inference latency on resource-limited edge nodes. In addition, entropy minimization may compress prediction uncertainty and cause overconfident erroneous convergence or model contamination when malicious attacks or high-noise disturbances appear, thereby reducing the reliability of trust scores [<xref ref-type="bibr" rid="ref-10">10</xref>].</p>
<p>However, directly applying existing TTA methods to IIoT trust evaluation remains insufficient. AdaBN mainly recalibrates BN statistics and does not explicitly distinguish benign domain shift from attack-contaminated drift. TENT performs entropy minimization during testing, but may become overconfident on abnormal or adversarial target samples. Protected Online Entropy Matching (POEM) improves online entropy matching, but it is not specifically designed for dynamic trust evaluation under attack-risk constraints. In contrast, the proposed risk-aware lightweight test-time adaptation (RaL-TTA) framework introduces a risk-aware maintenance strategy that combines entropy-distribution shift detection, SafeBrake risk gating, AdaBN-based anchor protection, and budgeted sample-level safeguards. Therefore, the proposed method is not only an adaptation mechanism but also a security-oriented dynamic trust evaluation framework for edge-side IIoT streams. <xref ref-type="table" rid="table-1">Table 1</xref> summarizes the key differences.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Comparison between RaL-TTA and representative TTA methods.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Method</th>
<th>Primary Adaptation Target</th>
<th>Risk Gate</th>
<th>Anchor Protection</th>
<th>Sample Safeguard</th>
<th>Trust-Score Output</th>
</tr>
</thead>
<tbody>
<tr>
<td>AdaBN</td>
<td>BN statistics</td>
<td>No</td>
<td>No</td>
<td>No</td>
<td>No</td>
</tr>
<tr>
<td>TENT</td>
<td>BN affine parameters</td>
<td>No</td>
<td>No</td>
<td>No</td>
<td>No</td>
</tr>
<tr>
<td>POEM</td>
<td>Entropy matching</td>
<td>Partial</td>
<td>No</td>
<td>No</td>
<td>No</td>
</tr>
<tr>
<td>POEM&#x002B;SafeBrake</td>
<td>Entropy matching &#x002B; risk gate</td>
<td>Yes</td>
<td>Partial</td>
<td>Partial</td>
<td>No</td>
</tr>
<tr>
<td>RaL-TTA</td>
<td>BN maintenance &#x002B; protection</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn id="table-1fn1" fn-type="other">
<p>Note: &#x201C;Partial&#x201D; indicates that the corresponding mechanism is only indirectly or incompletely included and is not formulated as a complete trust-score safeguard.</p>
</fn>
</table-wrap-foot>
</table-wrap>
<p>To address resource constraints, cross-domain distribution shifts, and attack-stream contamination in unlabeled online updates for IIoT edge nodes, this paper proposes the RaL-TTA framework for cross-domain dynamic trust evaluation. Unlike general TTA strategies that lack explicit risk constraints, RaL-TTA builds an &#x201C;offline trust baseline&#x2013;online risk gating&#x201D; mechanism. In the source-domain stage, it uses the low-dimensional feature set for Industrial Internet of Things (LoFT-IIoT) [<xref ref-type="bibr" rid="ref-19">19</xref>] and label-smoothed training to establish a normal-entropy reference baseline. In the target-domain stage, it combines shift detection with SafeBrake risk gating, freezes updates for high-risk batches, invokes Adaptive Batch Normalization (AdaBN) anchor protection, and performs restricted BN maintenance only for low-risk batches. Budgeted sample-level arbitration is used only as a supplementary safety boundary for a small number of highly ambiguous samples. This framework enhances detection performance, trust-score stability, and maintenance security in cross-domain online streams while controlling online overhead.</p>
<p>The main contributions of this work are summarized as follows:<list list-type="simple">
<list-item>
<label>1.</label>
<p>We formulate security-oriented dynamic trust evaluation for IIoT edge nodes under cross-domain online streams, where the task-level trust score is derived from the estimated attack risk.</p></list-item>
<list-item>
<label>2.</label>
<p>We develop RaL-TTA, a lightweight TTA framework that combines a low-dimensional source-domain trust baseline with risk-constrained online maintenance for edge-side deployment.</p></list-item>
<list-item>
<label>3.</label>
<p>We introduce a protective online adaptation strategy integrating KS-based shift detection, SafeBrake risk gating, AdaBN-calibrated anchor inference, and budgeted sample-level safeguards to reduce unsafe adaptation under attack-contaminated streams.</p></list-item>
<list-item>
<label>4.</label>
<p>We validate the proposed framework on Edge-IIoTset and an external service-holdout setting based on X-IIoTID, a connectivity- and device-agnostic intrusion dataset for IIoT, with ablation, sensitivity, calibration, startup-window robustness, and runtime-overhead analyses.</p></list-item>
</list></p>
</sec>
<sec id="s2">
<label>2</label>
<title>RaL-TTA Cross-Domain Dynamic Trust Evaluation Framework</title>
<sec id="s2_1">
<label>2.1</label>
<title>System Architecture</title>
<p>To address the domain-shift problem caused by cross-protocol communication and continuous online streaming in IIoT edge nodes, this paper constructs the RaL-TTA cross-domain dynamic trust evaluation framework, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>. This framework consists of two phases: offline trust modeling in the source domain and online risk-constrained maintenance in the target domain. In the source-domain phase, labeled traffic is taken as input, and low-dimensional feature selection is completed through LoFT-IIoT [<xref ref-type="bibr" rid="ref-19">19</xref>], followed by training a lightweight trust evaluation model under the label-smoothing constraint. Meanwhile, the empirical cumulative distribution function (ECDF) of normal entropy is constructed based only on normal samples in the source domain, serving as a reference baseline for the target-domain online phase. Before deployment, a short target-domain startup window collected during controlled initialization is used for AdaBN anchor-model calibration, target-domain normal-reference statistics estimation, and threshold initialization. In the target-domain phase, unlabeled online streams are taken as input. First, Kolmogorov&#x2013;Smirnov (KS)-based entropy-shift detection is executed, and then SafeBrake determines the risk status in combination with batch volatility. For low-risk batches, only restricted maintenance of BN affine parameters is performed, while for high-risk batches, updates are frozen and anchor protection is invoked. Sample-level arbitration is used only as a supplementary safety boundary. Finally, dynamic trust scores are output at the task level.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Overall framework of RaL-TTA for cross-domain dynamic trust evaluation. The source-domain phase constructs a low-dimensional feature space, trains the TrustMLP model, and builds a normal-entropy ECDF reference baseline. The target-domain phase processes unlabeled online batches, performs KS-based entropy-shift detection and SafeBrake risk gating, updates only BN affine parameters for low-risk batches, and invokes the AdaBN-calibrated anchor model with sample-level safeguards for high-risk batches. The startup window <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> is used only for calibration, reference-statistics estimation, and threshold initialization.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_82704-fig-1.tif"/>
</fig>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>Source-Domain Trust Baseline Construction</title>
<p>The construction of the source-domain trust baseline includes three steps: feature selection, model training, and estimation of the normal-entropy baseline. First, in the candidate feature space after removing protocol-specific fields, LoFT-IIoT [<xref ref-type="bibr" rid="ref-19">19</xref>] is used to select low-dimensional robust features to reduce reliance on protocol identifiers in cross-domain scenarios. Second, a lightweight multilayer perceptron (MLP) trust evaluator with label smoothing is trained on the selected low-dimensional feature space. Finally, a normal-entropy ECDF is constructed solely from the predicted entropy of normal samples in the source domain, serving as the normal reference baseline for the target-domain online phase.</p>
</sec>
<sec id="s2_3">
<label>2.3</label>
<title>Online Risk-Aware Adaptation Mechanism</title>
<p>During the online phase, edge nodes receive unlabeled target-domain traffic in online batches. First, the prediction entropy of the current batch is calculated, and the KS statistic is used to measure the discrepancy between the current batch and the source-domain normal-entropy baseline. Then, SafeBrake determines the current state as no drift, low-risk drift, or high-risk drift according to both entropy-distribution shift and batch-level feature volatility.</p>
<p>If no significant drift is detected, the current batch is directly evaluated by the online model, and the model state remains unchanged. If a low-risk drift is detected, restricted online maintenance is executed by updating only the BN affine parameters through entropy distribution alignment, attack-ratio prior regularization, and BN regularization. If a high-risk drift is detected, the online model update is frozen, and the AdaBN-calibrated anchor model is invoked to perform protective inference. Distance gating and budget-based sample-level arbitration are used only as supplementary security boundaries for a small number of highly ambiguous samples, thereby suppressing contamination-induced erroneous adaptation.</p>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>Algorithm Design</title>
<sec id="s3_1">
<label>3.1</label>
<title>Problem Formulation and Notation</title>
<p>In IIoT edge scenarios, edge nodes continuously receive unlabeled network traffic from the target environment. This study considers cross-domain dynamic trust evaluation in a setting where the source domain is labeled, the target domain is unlabeled, and the online distribution changes over time. The goal is to balance anomaly detection capability, output stability, and online maintenance security in continuous online streams.</p>
<p>Let the labeled source-domain reference set be defined as
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mi>s</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mi>H</mml:mi></mml:msub><mml:mo>&#x222A;</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mi>A</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mo>{</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mi>i</mml:mi><mml:mi>s</mml:mi></mml:msubsup><mml:mo>,</mml:mo><mml:msubsup><mml:mi>y</mml:mi><mml:mi>i</mml:mi><mml:mi>s</mml:mi></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mo>}</mml:mo></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mi>S</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mspace width="1em" /><mml:msubsup><mml:mi>y</mml:mi><mml:mi>i</mml:mi><mml:mi>s</mml:mi></mml:msubsup><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mi>H</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mo>{</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msubsup><mml:mo>}</mml:mo></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mi>H</mml:mi></mml:msub></mml:mrow></mml:msubsup></mml:math></inline-formula> denotes the set of normal samples in the source domain, and <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mi>A</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mo>{</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mi>j</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mo>,</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mo>}</mml:mo></mml:mrow><mml:mrow><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mi>A</mml:mi></mml:msub></mml:mrow></mml:msubsup></mml:math></inline-formula> denotes the set of attack samples in the source domain. The unlabeled online stream from the target domain is denoted by
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:msub><mml:mrow><mml:mi>&#x1D4AE;</mml:mi></mml:mrow><mml:mi>T</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mo>{</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mi>t</mml:mi><mml:mi>T</mml:mi></mml:msubsup><mml:mo>}</mml:mo></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x221E;</mml:mi></mml:mrow></mml:msubsup><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>To reduce the redundancy of the original traffic features and enhance the cross-domain transferability, the samples are mapped to a low-dimensional feature space through a feature mapping function <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>:<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mi>z</mml:mi><mml:mo>=</mml:mo><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mspace width="1em" /><mml:mi>z</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi></mml:mrow></mml:msup><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:mi>m</mml:mi></mml:math></inline-formula> is the retained feature dimension.</p>
<p>A lightweight trust evaluator <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">c</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is trained in a supervised manner on the source domain. During online deployment, the model state corresponding to the <inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:mi>t</mml:mi></mml:math></inline-formula>-th batch is denoted by <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula>. For any sample <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:mi>x</mml:mi></mml:math></inline-formula>, its attack risk is defined as
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:msub><mml:mi>r</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>y</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2223;</mml:mo><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>y</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2223;</mml:mo><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is the predicted probability that the current online model <inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> assigns sample <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:mi>x</mml:mi></mml:math></inline-formula> to the attack class.</p>
<p>Accordingly, the task-level trust score is defined as
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:msub><mml:mi>T</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>r</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>y</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x2223;</mml:mo><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:msub><mml:mi>T</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mspace width="thinmathspace" /><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula>, and a larger value indicates that the sample is more trustworthy under the current online model state. Here, trust assessment refers to task-level dynamic trust-score output for edge-side security decision-making, rather than a general entity-reputation propagation model. Its dynamic nature arises from the fact that the model state <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> changes over online batches.</p>
<p>To characterize the uncertainty of the model prediction for the current sample, the predictive entropy is introduced:<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:msub><mml:mi>h</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mo>&#x2212;</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>c</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:munderover><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>y</mml:mi><mml:mo>=</mml:mo><mml:mi>c</mml:mi><mml:mo>&#x2223;</mml:mo><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>y</mml:mi><mml:mo>=</mml:mo><mml:mi>c</mml:mi><mml:mo>&#x2223;</mml:mo><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>Here, <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>y</mml:mi><mml:mo>=</mml:mo><mml:mi>c</mml:mi><mml:mo>&#x2223;</mml:mo><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denotes the probability predicted by the current online model <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> that sample <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:mi>x</mml:mi></mml:math></inline-formula> belongs to class <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mi>c</mml:mi></mml:math></inline-formula>, and <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:msub><mml:mi>h</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denotes the predictive entropy of sample <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mi>x</mml:mi></mml:math></inline-formula> at time <inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:mi>t</mml:mi></mml:math></inline-formula>.</p>
<p>During the online stage, target-domain traffic arrives batch by batch. Let the current batch at time <inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:mi>t</mml:mi></mml:math></inline-formula> be
<disp-formula id="eqn-7"><label>(7)</label><mml:math id="mml-eqn-7" display="block"><mml:msub><mml:mrow><mml:mi>&#x0212C;</mml:mi></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mo>{</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:mo>}</mml:mo></mml:mrow><mml:mrow><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>b</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:msub><mml:mi>b</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> is the batch size.</p>
<p>Based on the predictive entropy of normal source-domain samples, the empirical cumulative distribution function (ECDF) is defined as
<disp-formula id="eqn-8"><label>(8)</label><mml:math id="mml-eqn-8" display="block"><mml:msub><mml:mi>F</mml:mi><mml:mi>H</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>h</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>N</mml:mi><mml:mi>H</mml:mi></mml:msub></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mi>H</mml:mi></mml:msub></mml:mrow></mml:munderover><mml:mrow><mml:mi mathvariant="double-struck">I</mml:mi></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mtext>src</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2264;</mml:mo><mml:mi>h</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:msub><mml:mi>F</mml:mi><mml:mi>H</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>h</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> represents the ECDF of predictive entropy over normal source-domain samples, <inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">c</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is the predictive entropy of the source-domain reference model <inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">c</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> on the normal sample <inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:msubsup><mml:mi>x</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msubsup></mml:math></inline-formula>, and <inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:msub><mml:mi>N</mml:mi><mml:mi>H</mml:mi></mml:msub></mml:math></inline-formula> is the number of normal source-domain samples.</p>
<p>Similarly, the empirical entropy distribution of the current batch is defined as
<disp-formula id="eqn-9"><label>(9)</label><mml:math id="mml-eqn-9" display="block"><mml:msub><mml:mrow><mml:mover><mml:mi>F</mml:mi><mml:mo>&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>h</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>b</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>b</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow></mml:munderover><mml:mrow><mml:mi mathvariant="double-struck">I</mml:mi></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2264;</mml:mo><mml:mi>h</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:mrow><mml:mi mathvariant="double-struck">I</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is the indicator function.</p>
<p>The distribution shift of the current batch with respect to the normal source-domain reference is then defined as
<disp-formula id="eqn-10"><label>(10)</label><mml:math id="mml-eqn-10" display="block"><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:munder><mml:mo movablelimits="true" form="prefix">sup</mml:mo><mml:mrow><mml:mi>h</mml:mi></mml:mrow></mml:munder><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mi>F</mml:mi><mml:mo>&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>h</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>F</mml:mi><mml:mi>H</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>h</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>|</mml:mo></mml:mrow><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>A larger <inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> indicates a more pronounced deviation of the current batch from the normal source-domain reference in terms of model uncertainty and can therefore serve as evidence of potential domain change during online deployment.</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Construction of the Source-Domain Reference Model and Normal Baseline</title>
<sec id="s3_2_1">
<label>3.2.1</label>
<title>Lightweight Feature Construction Based on LoFT-IIoT</title>
<p>IIoT traffic features typically exhibit significant cross-scale differences, with large variations across different fields. Such scale differences can make statistical estimation vulnerable to extreme values. Meanwhile, some application-layer fields in heterogeneous protocols have strong protocol specificity. If directly used as input, these fields may cause the model to over-rely on protocol-specific semantics, thereby weakening generalization in cross-domain scenarios. To address these issues, this paper adopts a lightweight feature construction strategy based on LoFT-IIoT [<xref ref-type="bibr" rid="ref-19">19</xref>] to filter and reduce the dimension of the original traffic features. The overall process is shown in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>LoFT-IIoT-based lightweight feature construction pipeline. Raw high-dimensional traffic features are first filtered to remove labels, timestamps, host identifiers, and protocol-specific shortcut fields, and log-smoothing is applied to reduce scale differences and extreme-value effects. Candidate features are grouped into statistical, behavioral, and protocol-related categories, scored by the mutual-information&#x2013;variance joint score, and ranked to select the top-<inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:mi>k</mml:mi></mml:math></inline-formula> transferable features for cross-domain trust evaluation.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_82704-fig-2.tif"/>
</fig>
<p>First, the numerical fields are retained from the original traffic features, while the label column, time column, host identification fields, and sequence-number-like fields that may introduce identity shortcuts are removed. Meanwhile, the protocol-specific fields of MQTT, Hypertext Transfer Protocol (HTTP), Modbus, Domain Name System (DNS), Address Resolution Protocol (ARP), and Internet Control Message Protocol (ICMP) are masked, and only transferable low-level statistical and behavioral features are retained. Subsequently, logarithmic smoothing is performed on the candidate numerical features:<disp-formula id="eqn-11"><label>(11)</label><mml:math id="mml-eqn-11" display="block"><mml:msubsup><mml:mi>f</mml:mi><mml:mi>j</mml:mi><mml:mrow><mml:mi>log</mml:mi></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mn>1</mml:mn><mml:mo>+</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>|</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>which compresses scale differences and reduces the influence of extreme values.</p>
<p>Second, the candidate features are classified into three semantic buckets, namely statistics, behavior, and protocol, based on the field semantics. A joint scoring strategy of mutual information and variance is adopted to describe their category discrimination ability and information activity. For the <inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:mi>j</mml:mi></mml:math></inline-formula>-th candidate feature <inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:msub><mml:mi>f</mml:mi><mml:mi>j</mml:mi></mml:msub></mml:math></inline-formula>, the overall score is defined as
<disp-formula id="eqn-12"><label>(12)</label><mml:math id="mml-eqn-12" display="block"><mml:msub><mml:mi>s</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>I</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>;</mml:mo><mml:mi>y</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mrow><mml:mtext>Var</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>f</mml:mi><mml:mi>j</mml:mi><mml:mrow><mml:mi>log</mml:mi></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:mi>I</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>;</mml:mo><mml:mi>y</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denotes the mutual information between the feature and the class label, and <inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:mrow><mml:mi mathvariant="normal">V</mml:mi><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">r</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>f</mml:mi><mml:mi>j</mml:mi><mml:mrow><mml:mi>log</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denotes the sample variance of the feature in the log domain.</p>
<p>Finally, features are pre-selected within each semantic bucket according to the joint score, and global ranking is then used for supplementation and trimming to obtain the low-dimensional feature subset <inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:mrow><mml:mi>&#x02133;</mml:mi></mml:mrow></mml:math></inline-formula> for subsequent model training, thereby forming the final feature mapping <inline-formula id="ieqn-37"><mml:math id="mml-ieqn-37"><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>.</p>
</sec>
<sec id="s3_2_2">
<label>3.2.2</label>
<title>TrustMLP: A Lightweight Trust Assessment Model</title>
<p>After obtaining the low-dimensional feature representation, a lightweight MLP, named TrustMLP, is constructed as the source-domain trust evaluator. Let the model parameters be denoted by <inline-formula id="ieqn-38"><mml:math id="mml-ieqn-38"><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">c</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>. The network consists of an input layer, two hidden layers, and an output layer, with width <inline-formula id="ieqn-39"><mml:math id="mml-ieqn-39"><mml:mi>m</mml:mi><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mn>64</mml:mn><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mn>32</mml:mn><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mn>2</mml:mn></mml:math></inline-formula>, where <inline-formula id="ieqn-40"><mml:math id="mml-ieqn-40"><mml:mi>m</mml:mi></mml:math></inline-formula> is the input dimension after feature selection, as shown in <xref ref-type="fig" rid="fig-3">Fig. 3</xref>. Batch Normalization (BN) and Rectified Linear Unit (ReLU) activation are introduced after both hidden layers to improve training stability and to provide interfaces for the restricted BN updates used in the subsequent online stage.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>TrustMLP architecture for task-level trust-score estimation. The selected <inline-formula id="ieqn-41"><mml:math id="mml-ieqn-41"><mml:mi>m</mml:mi></mml:math></inline-formula>-dimensional feature vector is passed through two fully connected hidden layers with Hypertext Transfer Protocol (HTTP) Rectified Linear Unit (ReLU) activation, followed by a binary output layer. The attack-class probability is used as the risk score, the normal-class probability is used as the trust score, and only BN affine parameters are updated during online adaptation.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_82704-fig-3.tif"/>
</fig>
<p>Given the input feature <inline-formula id="ieqn-42"><mml:math id="mml-ieqn-42"><mml:mi>z</mml:mi><mml:mo>=</mml:mo><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, the model outputs a logits vector <inline-formula id="ieqn-43"><mml:math id="mml-ieqn-43"><mml:msub><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">c</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>z</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula>. After the Softmax mapping, the predicted probability for class <inline-formula id="ieqn-44"><mml:math id="mml-ieqn-44"><mml:mi>c</mml:mi></mml:math></inline-formula> is obtained as
<disp-formula id="eqn-13"><label>(13)</label><mml:math id="mml-eqn-13" display="block"><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mtext>src</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>y</mml:mi><mml:mo>=</mml:mo><mml:mi>c</mml:mi><mml:mo>&#x2223;</mml:mo><mml:mi>z</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mtext>src</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>z</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>)</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:munderover><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mtext>src</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>z</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:mfrac><mml:mo>,</mml:mo><mml:mspace width="1em" /><mml:mi>c</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>Here, <inline-formula id="ieqn-45"><mml:math id="mml-ieqn-45"><mml:msub><mml:mi>g</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">c</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>z</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denotes the logit output of the model for class <inline-formula id="ieqn-46"><mml:math id="mml-ieqn-46"><mml:mi>c</mml:mi></mml:math></inline-formula>. In the binary setting considered in this work, <inline-formula id="ieqn-47"><mml:math id="mml-ieqn-47"><mml:mi>c</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula> denotes normal and <inline-formula id="ieqn-48"><mml:math id="mml-ieqn-48"><mml:mi>c</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> denotes attack. Since both the attack risk and the task-level trust score are derived from the same output probability space, no additional scoring head is required, which helps reduce inference overhead.</p>
</sec>
<sec id="s3_2_3">
<label>3.2.3</label>
<title>Offline Training with Label Smoothing</title>
<p>If the standard cross-entropy loss is directly adopted for source-domain supervised training, the model is prone to output extremely high or low probabilities close to 0 or 1 in the later stage of training, thereby causing an overconfidence problem [<xref ref-type="bibr" rid="ref-20">20</xref>]. For scenarios where a statistical baseline needs to be constructed based on the prediction entropy subsequently, this will cause the entropy values of normal samples to overly concentrate in the low range, weakening the statistical sensitivity of the entropy distribution to domain shifts. Therefore, a label smoothing strategy is introduced in the source-domain offline training stage.</p>
<p>Let the number of classes be <inline-formula id="ieqn-49"><mml:math id="mml-ieqn-49"><mml:mi>C</mml:mi></mml:math></inline-formula>, the smoothing factor be <inline-formula id="ieqn-50"><mml:math id="mml-ieqn-50"><mml:mi>&#x03B5;</mml:mi></mml:math></inline-formula>, and the ground-truth class be <inline-formula id="ieqn-51"><mml:math id="mml-ieqn-51"><mml:mi>y</mml:mi></mml:math></inline-formula>. The smoothed target value for the <inline-formula id="ieqn-52"><mml:math id="mml-ieqn-52"><mml:mi>k</mml:mi></mml:math></inline-formula>-th class is defined as
<disp-formula id="eqn-14"><label>(14)</label><mml:math id="mml-eqn-14" display="block"><mml:msubsup><mml:mi>y</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mrow><mml:mtext>LS</mml:mtext></mml:mrow></mml:mrow></mml:msubsup><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mtable columnalign="left left" rowspacing=".2em" columnspacing="1em" displaystyle="false"><mml:mtr><mml:mtd><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mi>&#x03B5;</mml:mi><mml:mo>,</mml:mo></mml:mtd><mml:mtd><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mi>y</mml:mi><mml:mo>,</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mi>&#x03B5;</mml:mi><mml:mrow><mml:mi>C</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:mfrac></mml:mstyle><mml:mo>,</mml:mo></mml:mtd><mml:mtd><mml:mi>k</mml:mi><mml:mo>&#x2260;</mml:mo><mml:mi>y</mml:mi><mml:mo>.</mml:mo></mml:mtd></mml:mtr></mml:mtable><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>Here, <inline-formula id="ieqn-53"><mml:math id="mml-ieqn-53"><mml:msubsup><mml:mi>y</mml:mi><mml:mi>k</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">L</mml:mi><mml:mi mathvariant="normal">S</mml:mi></mml:mrow></mml:mrow></mml:msubsup></mml:math></inline-formula> denotes the <inline-formula id="ieqn-54"><mml:math id="mml-ieqn-54"><mml:mi>k</mml:mi></mml:math></inline-formula>-th component of the smoothed label vector, and <inline-formula id="ieqn-55"><mml:math id="mml-ieqn-55"><mml:mi>k</mml:mi></mml:math></inline-formula> is the class index.</p>
<p>Based on this, offline training is completed by minimizing the cross-entropy between the predicted distribution and the soft label distribution. Before the features are input into the model, logarithmic compression and standardization processing are still adopted to eliminate the scale differences among different features. After the offline training is completed, the model parameters with the best performance on the validation set are selected as the source-domain reference model <inline-formula id="ieqn-56"><mml:math id="mml-ieqn-56"><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">c</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>.</p>
</sec>
<sec id="s3_2_4">
<label>3.2.4</label>
<title>Construction of the Source-Domain Normal-Entropy Baseline</title>
<p>To build the normal reference baseline required for online shift detection in the target domain, predictive entropy is computed only over the normal source-domain sample set <inline-formula id="ieqn-57"><mml:math id="mml-ieqn-57"><mml:msub><mml:mrow><mml:mi>&#x1D49F;</mml:mi></mml:mrow><mml:mi>H</mml:mi></mml:msub></mml:math></inline-formula> after the source-domain reference model has been obtained. The resulting normal-entropy set is
<disp-formula id="eqn-15"><label>(15)</label><mml:math id="mml-eqn-15" display="block"><mml:msub><mml:mrow><mml:mi>&#x2130;</mml:mi></mml:mrow><mml:mi>H</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mi>h</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mtext>src</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi>s</mml:mi><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mo>}</mml:mo></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mi>H</mml:mi></mml:msub></mml:mrow></mml:msubsup><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>Based on the entropy set in <xref ref-type="disp-formula" rid="eqn-15">Eq. (15)</xref>, the corresponding empirical distribution function is still defined by <xref ref-type="disp-formula" rid="eqn-8">Eq. (8)</xref>.</p>
<p>This distribution characterizes the typical uncertainty structure of the model under normal behavior conditions and can be used as a reference to determine the degree of distribution shift in the target domain during the online phase. It is necessary to emphasize that the entropy baseline constructed in this paper is only derived from normal samples in the source domain and does not include attack samples, in order to reduce the contamination of abnormal samples on the normal reference distribution.</p>
</sec>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Risk-Constrained Online Trust Maintenance Mechanism</title>
<sec id="s3_3_1">
<label>3.3.1</label>
<title>Calibration with a Target-Domain Normal Window</title>
<p>To enhance the statistical matching in the early stage of deployment, this paper introduces an explicit deployment assumption: a short controlled trial period containing normal target-domain traffic is available at the beginning of deployment. The corresponding target-domain normal calibration window is denoted by
<disp-formula id="eqn-16"><label>(16)</label><mml:math id="mml-eqn-16" display="block"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mo>{</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi>T</mml:mi><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msubsup><mml:mo>}</mml:mo></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mrow></mml:msubsup><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-58"><mml:math id="mml-ieqn-58"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> is not used for supervised training. Instead, it is used only for target-domain statistical calibration and reference-baseline estimation, and it does not overlap with the online evaluation stream.</p>
<p>In practical IIoT deployment, such a startup window can be collected during system commissioning, scheduled maintenance, device restart, or a short trusted initialization period in which the production process operates under known normal conditions. This assumption does not require attack labels and does not expose target-domain class labels to training or online updates. If a clean startup window cannot be guaranteed, the system should operate in a conservative mode by disabling online updates until operator-confirmed normal traffic is available. The startup-window robustness analysis in <xref ref-type="sec" rid="s4_7">Section 4.7</xref> further evaluates this assumption under limited and contaminated calibration data.</p>
<p>At deployment initialization, the collected <inline-formula id="ieqn-59"><mml:math id="mml-ieqn-59"><mml:msub><mml:mi>N</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> normal samples form the startup window <inline-formula id="ieqn-60"><mml:math id="mml-ieqn-60"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula>, which is used only for AdaBN-based anchor calibration, target-domain normal-reference estimation, and sample-level threshold initialization.</p>
<p>Based on <inline-formula id="ieqn-61"><mml:math id="mml-ieqn-61"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula>, the BN statistics of the source-domain reference model <inline-formula id="ieqn-62"><mml:math id="mml-ieqn-62"><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">s</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">c</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> are recalibrated to obtain a frozen anchor model:<disp-formula id="eqn-17"><label>(17)</label><mml:math id="mml-eqn-17" display="block"><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mtext>anc</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>CalibBN</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mtext>src</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-63"><mml:math id="mml-ieqn-63"><mml:mi>CalibBN</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denotes a forward-only calibration procedure that updates only the running mean and running variance of BN layers using <inline-formula id="ieqn-64"><mml:math id="mml-ieqn-64"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula>, without modifying the weights of fully connected layers.</p>
<p>The online model is initialized as
<disp-formula id="eqn-18"><label>(18)</label><mml:math id="mml-eqn-18" display="block"><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mtext>src</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>Meanwhile, in the low-dimensional feature space, the mean vector and covariance matrix of the target-domain normal reference are estimated from <inline-formula id="ieqn-65"><mml:math id="mml-ieqn-65"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> as
<disp-formula id="eqn-19"><label>(19)</label><mml:math id="mml-eqn-19" display="block"><mml:msub><mml:mi>&#x03BC;</mml:mi><mml:mi>T</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>N</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mrow></mml:munderover><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi>T</mml:mi><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>and
<disp-formula id="eqn-20"><label>(20)</label><mml:math id="mml-eqn-20" display="block"><mml:msub><mml:mi mathvariant="normal">&#x03A3;</mml:mi><mml:mi>T</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>Cov</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mrow><mml:mo>{</mml:mo><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mi>T</mml:mi><mml:mo>,</mml:mo><mml:mn>0</mml:mn></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mo>}</mml:mo></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>N</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>These statistics are used later for sample-level protection in high-risk stages.</p>
<p>Next, <inline-formula id="ieqn-66"><mml:math id="mml-ieqn-66"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> is partitioned into calibration mini-batches <inline-formula id="ieqn-67"><mml:math id="mml-ieqn-67"><mml:msubsup><mml:mrow><mml:mo>{</mml:mo><mml:msubsup><mml:mrow><mml:mi>&#x0212C;</mml:mi></mml:mrow><mml:mi>k</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>}</mml:mo></mml:mrow><mml:mrow><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>K</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mrow></mml:msubsup><mml:mo>.</mml:mo></mml:math></inline-formula> Here, <inline-formula id="ieqn-68"><mml:math id="mml-ieqn-68"><mml:msub><mml:mi>K</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> is determined by the startup-window size and the online batch size. The hyperparameter adabn_calib_batches is implemented as a maximum calibration cap <inline-formula id="ieqn-69"><mml:math id="mml-ieqn-69"><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:mo movablelimits="true" form="prefix">max</mml:mo></mml:mrow></mml:msub></mml:math></inline-formula>, rather than a requirement that exactly <inline-formula id="ieqn-70"><mml:math id="mml-ieqn-70"><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:mo movablelimits="true" form="prefix">max</mml:mo></mml:mrow></mml:msub></mml:math></inline-formula> mini-batches must exist. The effective number of AdaBN calibration mini-batches is therefore
<disp-formula id="eqn-21"><label>(21)</label><mml:math id="mml-eqn-21" display="block"><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:mrow><mml:mtext>cal</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo movablelimits="true" form="prefix">min</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:mo movablelimits="true" form="prefix">max</mml:mo></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>K</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>In the main setting, <inline-formula id="ieqn-71"><mml:math id="mml-ieqn-71"><mml:msub><mml:mi>N</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mn>1000</mml:mn></mml:math></inline-formula> and the online batch size is 256, so <inline-formula id="ieqn-72"><mml:math id="mml-ieqn-72"><mml:msub><mml:mi>K</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">&#x2308;</mml:mo><mml:mn>1000</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>256</mml:mn><mml:mo fence="false" stretchy="false">&#x2309;</mml:mo><mml:mo>=</mml:mo><mml:mn>4</mml:mn></mml:math></inline-formula>. Thus, when <inline-formula id="ieqn-73"><mml:math id="mml-ieqn-73"><mml:msub><mml:mi>K</mml:mi><mml:mrow><mml:mo movablelimits="true" form="prefix">max</mml:mo></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>20</mml:mn></mml:math></inline-formula>, AdaBN calibration uses all available four startup mini-batches.</p>
<p>For the <inline-formula id="ieqn-74"><mml:math id="mml-ieqn-74"><mml:mi>k</mml:mi></mml:math></inline-formula>-th calibration batch, its log-domain batch volatility is defined as
<disp-formula id="eqn-22"><label>(22)</label><mml:math id="mml-eqn-22" display="block"><mml:msub><mml:mi>v</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mi>m</mml:mi></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>&#x2113;</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>m</mml:mi></mml:mrow></mml:munderover><mml:msub><mml:mi>Var</mml:mi><mml:mrow><mml:mi>x</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msubsup><mml:mrow><mml:mi>&#x0212C;</mml:mi></mml:mrow><mml:mi>k</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup></mml:mrow></mml:msub><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>f</mml:mi><mml:mrow><mml:mi>&#x2113;</mml:mi></mml:mrow><mml:mrow><mml:mi>log</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-75"><mml:math id="mml-ieqn-75"><mml:msubsup><mml:mi>f</mml:mi><mml:mrow><mml:mi>&#x2113;</mml:mi></mml:mrow><mml:mrow><mml:mi>log</mml:mi></mml:mrow></mml:msubsup><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denotes the log-smoothed value of the <inline-formula id="ieqn-76"><mml:math id="mml-ieqn-76"><mml:mi>&#x2113;</mml:mi></mml:math></inline-formula>-th retained feature for sample <inline-formula id="ieqn-77"><mml:math id="mml-ieqn-77"><mml:mi>x</mml:mi></mml:math></inline-formula>.</p>
<p>Accordingly, the volatility baseline of the target-domain normal window is estimated by
<disp-formula id="eqn-23"><label>(23)</label><mml:math id="mml-eqn-23" display="block"><mml:msub><mml:mi>&#x03BC;</mml:mi><mml:mi>v</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>K</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>K</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mrow></mml:munderover><mml:msub><mml:mi>v</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:mspace width="2em" /><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>v</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msqrt><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>K</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>K</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mrow></mml:munderover><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>v</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>&#x03BC;</mml:mi><mml:mi>v</mml:mi></mml:msub><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mn>2</mml:mn></mml:msup></mml:msqrt><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>In addition, based on the Mahalanobis-distance distribution of samples in <inline-formula id="ieqn-78"><mml:math id="mml-ieqn-78"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> to the target-domain normal-reference center, a quantile threshold <inline-formula id="ieqn-79"><mml:math id="mml-ieqn-79"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">t</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> for strong-outlier protection and a score threshold <inline-formula id="ieqn-80"><mml:math id="mml-ieqn-80"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:math></inline-formula> for subsequent selective fallback are further estimated.</p>
</sec>
<sec id="s3_3_2">
<label>3.3.2</label>
<title>Entropy-Distribution Shift Detection</title>
<p>In the online stage, target-domain traffic arrives batch by batch. For the current batch defined in <xref ref-type="disp-formula" rid="eqn-7">Eq. (7)</xref>, the predictive entropy of each sample is first computed using the current online model <inline-formula id="ieqn-81"><mml:math id="mml-ieqn-81"><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula>, and its empirical cumulative distribution function <inline-formula id="ieqn-82"><mml:math id="mml-ieqn-82"><mml:msub><mml:mrow><mml:mover><mml:mi>F</mml:mi><mml:mo>&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>h</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is constructed as in <xref ref-type="disp-formula" rid="eqn-9">Eq. (9)</xref>. This empirical distribution is then compared with the source-domain normal-entropy baseline <inline-formula id="ieqn-83"><mml:math id="mml-ieqn-83"><mml:msub><mml:mi>F</mml:mi><mml:mi>H</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>h</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, and the Kolmogorov&#x2013;Smirnov (KS) statistic is used to quantify their discrepancy, namely, the shift measure <inline-formula id="ieqn-84"><mml:math id="mml-ieqn-84"><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> defined in <xref ref-type="disp-formula" rid="eqn-10">Eq. (10)</xref>.</p>
<p>When <inline-formula id="ieqn-85"><mml:math id="mml-ieqn-85"><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> is small, the current batch remains close to the source-domain normal reference in terms of model-uncertainty structure. Conversely, a large <inline-formula id="ieqn-86"><mml:math id="mml-ieqn-86"><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> indicates that the current input has significantly deviated from the normal reference distribution. Therefore, <inline-formula id="ieqn-87"><mml:math id="mml-ieqn-87"><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> serves as evidence for identifying potential domain change during the online target-domain stage.</p>
</sec>
<sec id="s3_3_3">
<label>3.3.3</label>
<title>SafeBrake Risk Gatekeeping</title>
<p>Relying solely on entropy-distribution shift detection may still be affected by local noisy samples and short-term abnormal fluctuations. To improve decision robustness, we further introduce a batch-volatility statistic. Let the log-domain value of the <inline-formula id="ieqn-88"><mml:math id="mml-ieqn-88"><mml:mi>&#x2113;</mml:mi></mml:math></inline-formula>-th retained feature for the <inline-formula id="ieqn-89"><mml:math id="mml-ieqn-89"><mml:mi>j</mml:mi></mml:math></inline-formula>-th sample in the current batch <inline-formula id="ieqn-90"><mml:math id="mml-ieqn-90"><mml:msub><mml:mrow><mml:mi>&#x0212C;</mml:mi></mml:mrow><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> be denoted by <inline-formula id="ieqn-91"><mml:math id="mml-ieqn-91"><mml:msubsup><mml:mi>f</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x2113;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>log</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>. The average log-domain volatility of the current batch is defined as
<disp-formula id="eqn-24"><label>(24)</label><mml:math id="mml-eqn-24" display="block"><mml:msub><mml:mi>v</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mi>m</mml:mi></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>&#x2113;</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>m</mml:mi></mml:mrow></mml:munderover><mml:msub><mml:mi>Var</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>f</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x2113;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>log</mml:mi></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-92"><mml:math id="mml-ieqn-92"><mml:mi>m</mml:mi></mml:math></inline-formula> is the dimension of the retained low-dimensional feature space, and <inline-formula id="ieqn-93"><mml:math id="mml-ieqn-93"><mml:msub><mml:mi>Var</mml:mi><mml:mrow><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denotes the sample variance over the current batch.</p>
<p>Based on the normal volatility baseline <inline-formula id="ieqn-94"><mml:math id="mml-ieqn-94"><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>&#x03BC;</mml:mi><mml:mi>v</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>v</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> in <xref ref-type="disp-formula" rid="eqn-23">Eq. (23)</xref>, the SafeBrake risk-gating rule is defined as
<disp-formula id="eqn-25"><label>(25)</label><mml:math id="mml-eqn-25" display="block"><mml:msub><mml:mrow><mml:mtext>State</mml:mtext></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mtable columnalign="left left" rowspacing=".2em" columnspacing="1em" displaystyle="false"><mml:mtr><mml:mtd><mml:mrow><mml:mtext>NoShift</mml:mtext></mml:mrow><mml:mo>,</mml:mo></mml:mtd><mml:mtd><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2264;</mml:mo><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mtext>KS</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>,</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mtext>LowRiskShift</mml:mtext></mml:mrow><mml:mo>,</mml:mo></mml:mtd><mml:mtd><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x003E;</mml:mo><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mtext>KS</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mtext>&#xA0;</mml:mtext><mml:mrow><mml:mtext>and</mml:mtext></mml:mrow><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mi>v</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2264;</mml:mo><mml:msub><mml:mi>&#x03BC;</mml:mi><mml:mi>v</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>v</mml:mi></mml:msub><mml:mo>,</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mtext>HighRiskShift</mml:mtext></mml:mrow><mml:mo>,</mml:mo></mml:mtd><mml:mtd><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x003E;</mml:mo><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mtext>KS</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mtext>&#xA0;</mml:mtext><mml:mrow><mml:mtext>and</mml:mtext></mml:mrow><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mi>v</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x003E;</mml:mo><mml:msub><mml:mi>&#x03BC;</mml:mi><mml:mi>v</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:msub><mml:mi>&#x03C3;</mml:mi><mml:mi>v</mml:mi></mml:msub><mml:mo>,</mml:mo></mml:mtd></mml:mtr></mml:mtable><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo></mml:mrow></mml:math></disp-formula>where <inline-formula id="ieqn-95"><mml:math id="mml-ieqn-95"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">S</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> is the entropy-distribution shift threshold, and <inline-formula id="ieqn-96"><mml:math id="mml-ieqn-96"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> is the volatility adjustment coefficient. When significant entropy shift and abnormal batch volatility occur simultaneously, the current batch is judged as a high-risk shift and SafeBrake is triggered. If a significant shift is detected but the batch volatility remains within the normal range, the batch is judged as a low-risk shift. If <inline-formula id="ieqn-97"><mml:math id="mml-ieqn-97"><mml:msub><mml:mi mathvariant="normal">&#x0394;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> does not exceed the threshold, the batch is regarded as remaining in a no-shift state.</p>
</sec>
<sec id="s3_3_4">
<label>3.3.4</label>
<title>Constrained Online Update and Budgeted Selective Protection</title>
<p>When the current batch is determined to have a low-risk deviation, we adopt a restricted online update strategy to improve adaptation to target-domain data. Specifically, only the learnable affine parameters of the BN layers are updated, while all other weights are frozen. Let the set of learnable BN parameters at time <inline-formula id="ieqn-98"><mml:math id="mml-ieqn-98"><mml:mi>t</mml:mi></mml:math></inline-formula> be denoted by <inline-formula id="ieqn-99"><mml:math id="mml-ieqn-99"><mml:msub><mml:mi mathvariant="normal">&#x0398;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">B</mml:mi><mml:mi mathvariant="normal">N</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. The optimization objective is defined as
<disp-formula id="eqn-26"><label>(26)</label><mml:math id="mml-eqn-26" display="block"><mml:msub><mml:mi>L</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mrow><mml:mtext>align</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>&#x03BB;</mml:mi><mml:mi>p</mml:mi></mml:msub><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mrow><mml:mtext>prior</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>&#x03BB;</mml:mi><mml:mi>b</mml:mi></mml:msub><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mrow><mml:mtext>reg</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-100"><mml:math id="mml-ieqn-100"><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">l</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">g</mml:mi><mml:mi mathvariant="normal">n</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> is the entropy-quantile alignment term, <inline-formula id="ieqn-101"><mml:math id="mml-ieqn-101"><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">p</mml:mi><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">i</mml:mi><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">r</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> is the attack-ratio prior constraint, <inline-formula id="ieqn-102"><mml:math id="mml-ieqn-102"><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">r</mml:mi><mml:mi mathvariant="normal">e</mml:mi><mml:mi mathvariant="normal">g</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> is the BN-parameter regularization term, and <inline-formula id="ieqn-103"><mml:math id="mml-ieqn-103"><mml:msub><mml:mi>&#x03BB;</mml:mi><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-104"><mml:math id="mml-ieqn-104"><mml:msub><mml:mi>&#x03BB;</mml:mi><mml:mi>b</mml:mi></mml:msub></mml:math></inline-formula> are weighting coefficients.</p>
<p>The entropy-quantile alignment term is defined as
<disp-formula id="eqn-27"><label>(27)</label><mml:math id="mml-eqn-27" display="block"><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mrow><mml:mtext>align</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mi>Q</mml:mi></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>Q</mml:mi></mml:mrow></mml:munderover><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mi>e</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mi>e</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>k</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup><mml:mo>,</mml:mo><mml:mspace width="2em" /><mml:msub><mml:mrow><mml:mover><mml:mi>e</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mrow><mml:mover><mml:mi>F</mml:mi><mml:mo>&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>q</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mrow><mml:mover><mml:mi>e</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>k</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:msubsup><mml:mi>F</mml:mi><mml:mi>H</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>q</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mi>q</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0.1</mml:mn><mml:mo>,</mml:mo><mml:mn>0.2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mn>0.9</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-105"><mml:math id="mml-ieqn-105"><mml:mi>Q</mml:mi></mml:math></inline-formula> denotes the number of selected quantile points, and <inline-formula id="ieqn-106"><mml:math id="mml-ieqn-106"><mml:msubsup><mml:mrow><mml:mover><mml:mi>F</mml:mi><mml:mo>&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and <inline-formula id="ieqn-107"><mml:math id="mml-ieqn-107"><mml:msubsup><mml:mi>F</mml:mi><mml:mi>H</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denote the inverse distribution functions of the current-batch entropy distribution and the source-domain normal-entropy baseline, respectively.</p>
<p>The attack-ratio prior constraint is defined as
<disp-formula id="eqn-28"><label>(28)</label><mml:math id="mml-eqn-28" display="block"><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mrow><mml:mtext>prior</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mi>&#x03C0;</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>&#x03C0;</mml:mi><mml:mi>a</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:msup><mml:mo>,</mml:mo><mml:mspace width="2em" /><mml:msub><mml:mrow><mml:mover><mml:mi>&#x03C0;</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msub><mml:mi>b</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mfrac><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>b</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow></mml:munderover><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>y</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2223;</mml:mo><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mi>x</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi></mml:mrow><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-108"><mml:math id="mml-ieqn-108"><mml:msub><mml:mrow><mml:mover><mml:mi>&#x03C0;</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> is the average attack risk of the current batch, and <inline-formula id="ieqn-109"><mml:math id="mml-ieqn-109"><mml:msub><mml:mi>&#x03C0;</mml:mi><mml:mi>a</mml:mi></mml:msub></mml:math></inline-formula> is the attack-ratio prior. The prior <inline-formula id="ieqn-110"><mml:math id="mml-ieqn-110"><mml:msub><mml:mi>&#x03C0;</mml:mi><mml:mi>a</mml:mi></mml:msub></mml:math></inline-formula> is not used as a direct estimate of the true attack proportion in the current batch. Instead, it serves as a conservative regularizer in the low-risk update objective, preventing systematic underestimation of attack probabilities under unlabeled conditions.</p>
<p>The BN-parameter regularization term is defined as
<disp-formula id="eqn-29"><label>(29)</label><mml:math id="mml-eqn-29" display="block"><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mrow><mml:mtext>reg</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>&#x2113;</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mtext>BN</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:mrow></mml:munder><mml:mrow><mml:mo>(</mml:mo><mml:msubsup><mml:mrow><mml:mo symmetric="true">&#x2016;</mml:mo><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mrow><mml:mi>&#x2113;</mml:mi><mml:mo>,</mml:mo><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo symmetric="true">&#x2016;</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mn>2</mml:mn></mml:msubsup><mml:mo>+</mml:mo><mml:msubsup><mml:mrow><mml:mo symmetric="true">&#x2016;</mml:mo><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mrow><mml:mi>&#x2113;</mml:mi><mml:mo>,</mml:mo><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo symmetric="true">&#x2016;</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mn>2</mml:mn></mml:msubsup><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-111"><mml:math id="mml-ieqn-111"><mml:msub><mml:mrow><mml:mi>&#x02112;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">B</mml:mi><mml:mi mathvariant="normal">N</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> denotes the set of all BN layers, and <inline-formula id="ieqn-112"><mml:math id="mml-ieqn-112"><mml:msub><mml:mi>&#x03B3;</mml:mi><mml:mrow><mml:mi>&#x2113;</mml:mi><mml:mo>,</mml:mo><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-113"><mml:math id="mml-ieqn-113"><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mrow><mml:mi>&#x2113;</mml:mi><mml:mo>,</mml:mo><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> are the scale and shift parameters of the <inline-formula id="ieqn-114"><mml:math id="mml-ieqn-114"><mml:mi>&#x2113;</mml:mi></mml:math></inline-formula>-th BN layer, respectively.</p>
<p>Accordingly, the BN-parameter update under low-risk conditions is written as
<disp-formula id="eqn-30"><label>(30)</label><mml:math id="mml-eqn-30" display="block"><mml:msub><mml:mi mathvariant="normal">&#x0398;</mml:mi><mml:mrow><mml:mrow><mml:mtext>BN</mml:mtext></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi mathvariant="normal">&#x0398;</mml:mi><mml:mrow><mml:mrow><mml:mtext>BN</mml:mtext></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>&#x03B7;</mml:mi><mml:msub><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:mrow><mml:msub><mml:mi mathvariant="normal">&#x0398;</mml:mi><mml:mrow><mml:mrow><mml:mtext>BN</mml:mtext></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:msub><mml:msub><mml:mi>L</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-115"><mml:math id="mml-ieqn-115"><mml:mi>&#x03B7;</mml:mi></mml:math></inline-formula> is the learning rate.</p>
<p>When the current batch is judged as a high-risk shift, online updating is suspended, i.e.,
<disp-formula id="eqn-31"><label>(31)</label><mml:math id="mml-eqn-31" display="block"><mml:msub><mml:mi mathvariant="normal">&#x0398;</mml:mi><mml:mrow><mml:mrow><mml:mtext>BN</mml:mtext></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi mathvariant="normal">&#x0398;</mml:mi><mml:mrow><mml:mrow><mml:mtext>BN</mml:mtext></mml:mrow><mml:mo>,</mml:mo><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>Under high-risk conditions, the system enters a protection mode. Based on the calibrated anchor model <inline-formula id="ieqn-116"><mml:math id="mml-ieqn-116"><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">a</mml:mi><mml:mi mathvariant="normal">n</mml:mi><mml:mi mathvariant="normal">c</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> and the target-domain normal-reference statistics, budgeted selective protection is performed for the current batch. First, the Mahalanobis distance from a sample to the target-domain normal-reference center is computed as
<disp-formula id="eqn-32"><label>(32)</label><mml:math id="mml-eqn-32" display="block"><mml:msub><mml:mi>d</mml:mi><mml:mi>M</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:msqrt><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>&#x03BC;</mml:mi><mml:mi>T</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mi mathvariant="normal">&#x22A4;</mml:mi></mml:msup><mml:msubsup><mml:mi mathvariant="normal">&#x03A3;</mml:mi><mml:mi>T</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mrow><mml:mo>(</mml:mo><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>&#x03BC;</mml:mi><mml:mi>T</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:msqrt><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-117"><mml:math id="mml-ieqn-117"><mml:msub><mml:mi>&#x03BC;</mml:mi><mml:mi>T</mml:mi></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-118"><mml:math id="mml-ieqn-118"><mml:msub><mml:mi mathvariant="normal">&#x03A3;</mml:mi><mml:mi>T</mml:mi></mml:msub></mml:math></inline-formula> are given by <xref ref-type="disp-formula" rid="eqn-19">Eqs. (19)</xref> and <xref ref-type="disp-formula" rid="eqn-20">(20)</xref>, respectively.</p>
<p>For strongly outlying samples, the anchor-model output is directly used instead. Let the strong-outlier set be
<disp-formula id="eqn-33"><label>(33)</label><mml:math id="mml-eqn-33" display="block"><mml:msub><mml:mrow><mml:mi>&#x1D4AA;</mml:mi></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mi>x</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi>&#x0212C;</mml:mi></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2223;</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>M</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2265;</mml:mo><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mtext>out</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-119"><mml:math id="mml-ieqn-119"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">t</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> is the strong-outlier threshold. The attack risk given by the anchor model is defined as
<disp-formula id="eqn-34"><label>(34)</label><mml:math id="mml-eqn-34" display="block"><mml:msub><mml:mi>r</mml:mi><mml:mrow><mml:mrow><mml:mtext>anc</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mrow><mml:mtext>anc</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>y</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2223;</mml:mo><mml:mi mathvariant="normal">&#x03A6;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>For the remaining samples, a budgeted selective-fallback mechanism is further constructed. In the final configuration, only samples predicted as normal by the online model and not identified as strong outliers are considered for arbitration. The candidate set is therefore defined as
<disp-formula id="eqn-35"><label>(35)</label><mml:math id="mml-eqn-35" display="block"><mml:msub><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mi>x</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi>&#x0212C;</mml:mi></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2223;</mml:mo><mml:msub><mml:mi>r</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x003C;</mml:mo><mml:mn>0.5</mml:mn><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mi>d</mml:mi><mml:mi>M</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x003C;</mml:mo><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mtext>out</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>To measure the necessity of correcting the current sample by the anchor model, the following score is defined:<disp-formula id="eqn-36"><label>(36)</label><mml:math id="mml-eqn-36" display="block"><mml:msub><mml:mi>s</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>a</mml:mi><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>rank</mml:mi><mml:mrow><mml:mn>01</mml:mn></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>logit</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>r</mml:mi><mml:mrow><mml:mrow><mml:mtext>anc</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>b</mml:mi><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>rank</mml:mi><mml:mrow><mml:mn>01</mml:mn></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>logit</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>r</mml:mi><mml:mrow><mml:mrow><mml:mtext>anc</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mi>logit</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>r</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>c</mml:mi><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>rank</mml:mi><mml:mrow><mml:mn>01</mml:mn></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>d</mml:mi><mml:mi>M</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-120"><mml:math id="mml-ieqn-120"><mml:msub><mml:mi>rank</mml:mi><mml:mrow><mml:mn>01</mml:mn></mml:mrow></mml:msub><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denotes rank-based normalization to the interval <inline-formula id="ieqn-121"><mml:math id="mml-ieqn-121"><mml:mo stretchy="false">[</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">]</mml:mo></mml:math></inline-formula> within the candidate set, <inline-formula id="ieqn-122"><mml:math id="mml-ieqn-122"><mml:mi>logit</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>log</mml:mi><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">(</mml:mo></mml:mrow></mml:mstyle><mml:mi>p</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mi>p</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mstyle scriptlevel="0"><mml:mrow><mml:mo maxsize="1.2em" minsize="1.2em">)</mml:mo></mml:mrow></mml:mstyle></mml:math></inline-formula>, and <inline-formula id="ieqn-123"><mml:math id="mml-ieqn-123"><mml:mi>a</mml:mi></mml:math></inline-formula>, <inline-formula id="ieqn-124"><mml:math id="mml-ieqn-124"><mml:mi>b</mml:mi></mml:math></inline-formula>, and <inline-formula id="ieqn-125"><mml:math id="mml-ieqn-125"><mml:mi>c</mml:mi></mml:math></inline-formula> are weighting coefficients.</p>
<p>The fallback-eligible subset and the selective-fallback budget are then defined as
<disp-formula id="eqn-37"><label>(37)</label><mml:math id="mml-eqn-37" display="block"><mml:mtable columnalign="right left right left right left right left right left right left" rowspacing="3pt" columnspacing="0em 2em 0em 2em 0em 2em 0em 2em 0em 2em 0em" displaystyle="true"><mml:mtr><mml:mtd><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi></mml:msub></mml:mtd><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mi>x</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x2223;</mml:mo><mml:msub><mml:mi>r</mml:mi><mml:mrow><mml:mrow><mml:mtext>anc</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2265;</mml:mo><mml:mn>0.5</mml:mn><mml:mo>,</mml:mo><mml:mtext>&#xA0;</mml:mtext><mml:msub><mml:mi>s</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2265;</mml:mo><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>}</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:msub><mml:mi>k</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:mtd><mml:mtd><mml:mi></mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:mo>&#x2308;</mml:mo><mml:mi>&#x03C1;</mml:mi><mml:mspace width="thinmathspace" /><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2309;</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>where <inline-formula id="ieqn-126"><mml:math id="mml-ieqn-126"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:math></inline-formula> is the score threshold estimated from the calibration window <inline-formula id="ieqn-127"><mml:math id="mml-ieqn-127"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula>, and <inline-formula id="ieqn-128"><mml:math id="mml-ieqn-128"><mml:mi>&#x03C1;</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is the budget ratio for selective fallback.</p>
<p>Accordingly, the selective-fallback set is defined as
<disp-formula id="eqn-38"><label>(38)</label><mml:math id="mml-eqn-38" display="block"><mml:msub><mml:mrow><mml:mi>&#x211B;</mml:mi></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>TopK</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mrow><mml:mi>&#x1D49E;</mml:mi></mml:mrow><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>s</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>k</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula id="ieqn-129"><mml:math id="mml-ieqn-129"><mml:mi>TopK</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> selects the top <inline-formula id="ieqn-130"><mml:math id="mml-ieqn-130"><mml:msub><mml:mi>k</mml:mi><mml:mi>t</mml:mi></mml:msub></mml:math></inline-formula> samples in descending order of <inline-formula id="ieqn-131"><mml:math id="mml-ieqn-131"><mml:msub><mml:mi>s</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>.</p>
<p>Under the protection mechanism, the final attack risk is defined as
<disp-formula id="eqn-39"><label>(39)</label><mml:math id="mml-eqn-39" display="block"><mml:msub><mml:mrow><mml:mover><mml:mi>r</mml:mi><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mtable columnalign="left left" rowspacing=".2em" columnspacing="1em" displaystyle="false"><mml:mtr><mml:mtd><mml:msub><mml:mi>r</mml:mi><mml:mrow><mml:mrow><mml:mtext>anc</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo></mml:mtd><mml:mtd><mml:mi>x</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mi>&#x1D4AA;</mml:mi></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo>&#x222A;</mml:mo><mml:msub><mml:mrow><mml:mi>&#x211B;</mml:mi></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo>,</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:msub><mml:mi>r</mml:mi><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo></mml:mtd><mml:mtd><mml:mrow><mml:mtext>otherwise</mml:mtext></mml:mrow><mml:mo>,</mml:mo></mml:mtd></mml:mtr></mml:mtable><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo></mml:mrow></mml:math></disp-formula>and the protected task-level trust score and class output are written as
<disp-formula id="eqn-40"><label>(40)</label><mml:math id="mml-eqn-40" display="block"><mml:msub><mml:mrow><mml:mover><mml:mi>T</mml:mi><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mi>r</mml:mi><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mspace width="2em" /><mml:msub><mml:mrow><mml:mover><mml:mi>y</mml:mi><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">I</mml:mi></mml:mrow><mml:mrow><mml:mo>[</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mi>r</mml:mi><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2265;</mml:mo><mml:mn>0.5</mml:mn><mml:mo>]</mml:mo></mml:mrow><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>Here, <inline-formula id="ieqn-132"><mml:math id="mml-ieqn-132"><mml:mrow><mml:mi mathvariant="double-struck">I</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is the indicator function. In the binary setting considered in this paper, <inline-formula id="ieqn-133"><mml:math id="mml-ieqn-133"><mml:msub><mml:mrow><mml:mover><mml:mi>y</mml:mi><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> denotes attack, while <inline-formula id="ieqn-134"><mml:math id="mml-ieqn-134"><mml:msub><mml:mrow><mml:mover><mml:mi>y</mml:mi><mml:mo>&#x007E;</mml:mo></mml:mover></mml:mrow><mml:mi>t</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula> denotes normal.</p>
<p>This mechanism ensures that strongly anomalous samples are preferentially protected by the anchor model, while only a limited number of high-risk samples with model disagreement are selectively corrected under a fixed budget. In this way, the spread of erroneous self-adaptation can be suppressed while the online model still retains its capability to recognize anomalous behavior. For ease of implementation, the startup-window calibration, entropy-shift detection, risk judgment, and constrained maintenance procedures are summarized in Algorithm 1.</p>
<fig id="fig-7">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_82704-fig-7.tif"/>
</fig>
</sec>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Experiments and Results Analysis</title>
<sec id="s4_1">
<label>4.1</label>
<title>Experimental Environment and Datasets</title>
<sec id="s4_1_1">
<label>4.1.1</label>
<title>Experimental Scenario and Cross-Domain Task</title>
<p>The experiments are conducted on the <monospace>DNN-EdgeIIoT-dataset.csv</monospace> file from the Edge-IIoTset benchmark proposed by Ferrag et al. [<xref ref-type="bibr" rid="ref-21">21</xref>]. This dataset is collected from network traffic in IIoT environments and contains both normal-behavior samples and multiple categories of attack samples, thereby providing a rich set of traffic features for edge-side security evaluation. In this study, the binary label <monospace>Attack_label</monospace> provided by the dataset is adopted as the supervision signal, where <monospace>Normal</monospace> is encoded as 0 and <monospace>Attack</monospace> is encoded as 1. The attack-type label <monospace>Attack_type</monospace> is used only for cross-domain task construction, statistical analysis, and result presentation, and is not involved in model input or online parameter updates. The overall statistics of the dataset are summarized in <xref ref-type="table" rid="table-2">Table 2</xref>.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Statistical summary of the dataset.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Category</th>
<th>Value</th>
</tr>
</thead>
<tbody>
<tr>
<td>Total number of samples</td>
<td>2,219,201</td>
</tr>
<tr>
<td>Feature dimension</td>
<td>63</td>
</tr>
<tr>
<td>Number of normal samples</td>
<td>1,615,643</td>
</tr>
<tr>
<td>Number of attack samples</td>
<td>603,558</td>
</tr>
<tr>
<td>Number of attack categories</td>
<td>14</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>This paper focuses on the cross-domain behavior distribution shift problem faced by IIoT edge nodes under continuous online streaming conditions. Unlike protocol-only domain definitions, this study defines the cross-domain task as a compound-shift scenario involving both device communication relationships and attack types. In this setting, the normal behavior patterns and attack compositions differ between the source and target domains. The specific data division, online stream construction, and feature configuration are respectively presented in <xref ref-type="sec" rid="s4_1_2">Sections 4.1.2</xref> and <xref ref-type="sec" rid="s4_1_3">4.1.3</xref>.</p>
</sec>
<sec id="s4_1_2">
<label>4.1.2</label>
<title>Data Construction and Streaming Evaluation Settings</title>
<p>To ensure fair comparisons among different methods, ablation experiments, and parameter sensitivity experiments, this paper uniformly completes data partitioning, independent startup-window construction, and three-phase online stream pre-generation under the condition of fixed random seeds. Except for the variables under investigation, all experiments reuse the same data partitioning and streaming sequences. The source-domain training set is composed of source-domain normal traffic and source-domain attack samples extracted according to a fixed attack ratio. The normal and attack traffic of the target domain are split at the group level and divided into validation and test sets in a 1:1 ratio to avoid instance-level leakage. The resulting dataset compositions are summarized in <xref ref-type="table" rid="table-3">Tables 3</xref> and <xref ref-type="table" rid="table-4">4</xref>.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Composition of the source-domain training dataset.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Item</th>
<th>Description</th>
<th>Count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Source-domain normal samples</td>
<td>Non-MQTT normal traffic from the communication pair <monospace>192.168.0.101</monospace> <inline-formula id="ieqn-183"><mml:math id="mml-ieqn-183"><mml:mo stretchy="false">&#x2194;</mml:mo></mml:math></inline-formula> <monospace>192.168.0.128</monospace></td>
<td>1,000,310</td>
</tr>
<tr>
<td>Source-domain attack pool</td>
<td>Total number of source-domain attack samples from 11 attack categories</td>
<td>315,492</td>
</tr>
<tr>
<td>Offline attack ratio <inline-formula id="ieqn-184"><mml:math id="mml-ieqn-184"><mml:msub><mml:mi>r</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>Fixed setting</td>
<td>0.2</td>
</tr>
<tr>
<td>Sampled attack instances</td>
<td>Drawn from the source-domain attack pool with <inline-formula id="ieqn-185"><mml:math id="mml-ieqn-185"><mml:msub><mml:mi>r</mml:mi><mml:mi>s</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mn>0.2</mml:mn></mml:math></inline-formula></td>
<td>250,077</td>
</tr>
<tr>
<td>Total size of source-domain training set</td>
<td>Sum of normal samples and sampled attack samples</td>
<td>1,250,387</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Composition of the validation and test sets in the target domain.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Subset</th>
<th>Source of Normal Samples</th>
<th>Source of Attack Samples</th>
<th># Normal Samples</th>
<th># Attack Samples</th>
</tr>
</thead>
<tbody>
<tr>
<td>Validation set</td>
<td>Group-wise split from the target-domain normal pool</td>
<td>Group-wise split from the target-domain attack pool</td>
<td>141,625</td>
<td>144,033</td>
</tr>
<tr>
<td>Test set</td>
<td>Group-wise split from the target-domain normal pool</td>
<td>Group-wise split from the target-domain attack pool</td>
<td>141,625</td>
<td>144,033</td>
</tr>
<tr>
<td>Total</td>
<td>Remaining non-MQTT normal traffic</td>
<td><monospace>DDoS_TCP</monospace>, <monospace>DDoS_UDP</monospace>,<break/> <monospace>DDoS_ICMP</monospace></td>
<td>283,250</td>
<td>288,066</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn id="table-4fn1" fn-type="other">
<p>Note: The source-domain attack samples, validation-set attack samples, and test-set attack samples are mutually exclusive. The normal samples in the validation set and the test set are also mutually exclusive.</p>
</fn>
</table-wrap-foot>
</table-wrap>
<p>Before online evaluation, an independent subset <inline-formula id="ieqn-186"><mml:math id="mml-ieqn-186"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> is drawn from the pool of target-domain normal samples to construct the deployment startup window, where <inline-formula id="ieqn-187"><mml:math id="mml-ieqn-187"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mn>1000</mml:mn></mml:math></inline-formula> in the main experiments. This startup window is used only for AdaBN anchor calibration, target-domain normal-reference statistics estimation, and threshold initialization, and does not participate in the subsequent three-phase online evaluation. The online stream consists of an initial normal phase (Phase 1), a perturbation phase (Phase 2), and a recovery phase (Phase 3). The main experiments are conducted on the target-domain test split with settings <inline-formula id="ieqn-188"><mml:math id="mml-ieqn-188"><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mn>8</mml:mn></mml:math></inline-formula>, <inline-formula id="ieqn-189"><mml:math id="mml-ieqn-189"><mml:mi>r</mml:mi><mml:mo>=</mml:mo><mml:mn>0.3</mml:mn></mml:math></inline-formula>, <inline-formula id="ieqn-190"><mml:math id="mml-ieqn-190"><mml:msub><mml:mi>&#x03C0;</mml:mi><mml:mi>a</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mn>0.1</mml:mn></mml:math></inline-formula>, and sample-level arbitration budget <inline-formula id="ieqn-191"><mml:math id="mml-ieqn-191"><mml:mi>&#x03C1;</mml:mi><mml:mo>=</mml:mo><mml:mn>0.01</mml:mn></mml:math></inline-formula>. The main comparison adopts the random-mixing stream with <inline-formula id="ieqn-192"><mml:math id="mml-ieqn-192"><mml:mi>r</mml:mi><mml:mo>=</mml:mo><mml:mn>0.3</mml:mn></mml:math></inline-formula>, while the extended attack-ratio and burst-injection settings in <xref ref-type="table" rid="table-5">Table 5</xref> are retained as robustness-oriented implementation settings. In the five-seed main comparison, different random seeds are used to construct or evaluate pre-built target streams; for the burst-injection robustness setting, the seed controls the attack-injection offset in Phase 2. The three-phase streaming settings are listed in <xref ref-type="table" rid="table-5">Table 5</xref>.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Experimental settings for three-phase streaming evaluation.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Phase/Item</th>
<th>Setting</th>
</tr>
</thead>
<tbody>
<tr>
<td>Deployment startup window <inline-formula id="ieqn-193"><mml:math id="mml-ieqn-193"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula></td>
<td>1000 target-domain normal samples, used only for deployment initialization and excluded from the three-phase online evaluation</td>
</tr>
<tr>
<td>Phase 1</td>
<td>5000 target-domain normal samples</td>
</tr>
<tr>
<td>Total length of Phase 2</td>
<td>3000 samples</td>
</tr>
<tr>
<td>Phase 3</td>
<td>5000 target-domain normal samples</td>
</tr>
<tr>
<td>Attack ratio <inline-formula id="ieqn-194"><mml:math id="mml-ieqn-194"><mml:mi>r</mml:mi></mml:math></inline-formula> in the main experiments</td>
<td>0.3</td>
</tr>
<tr>
<td>Composition of the perturbation phase in the main experiments</td>
<td>900 attack samples &#x002B; 2100 normal samples</td>
</tr>
<tr>
<td>Extended settings for attack ratio</td>
<td><inline-formula id="ieqn-195"><mml:math id="mml-ieqn-195"><mml:mi>r</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0.1</mml:mn><mml:mo>,</mml:mo><mml:mn>0.3</mml:mn><mml:mo>,</mml:mo><mml:mn>0.5</mml:mn><mml:mo>,</mml:mo><mml:mn>1.0</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>Mode 1</td>
<td>Random mixing: attack samples are randomly inserted into the normal stream</td>
</tr>
<tr>
<td>Mode 2</td>
<td>Burst injection: attack samples are inserted into the normal stream in contiguous segments</td>
</tr>
<tr>
<td>Robustness setting for burst scenarios</td>
<td>Random seed of attack-injection offset: 0&#x2013;4</td>
</tr>
<tr>
<td>Total length of the online stream</td>
<td>13,000 samples</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4_1_3">
<label>4.1.3</label>
<title>Feature Preprocessing and Input Feature Configuration</title>
<p>After data construction, the raw traffic features are uniformly preprocessed and configured, and all methods share the same preprocessing pipeline and input feature space. For numerical features, the log-compression strategy described in <xref ref-type="sec" rid="s3_2_1">Section 3.2.1</xref> is applied. The standardization parameters are estimated only on the source-domain training set. They are then fixed and applied to the source-domain validation set, target-domain validation set, target-domain test set, the startup window <inline-formula id="ieqn-196"><mml:math id="mml-ieqn-196"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula>, and subsequent online evaluation streams to avoid leakage of target-domain statistical information.</p>
<p>To reduce the model dependence on protocol identifiers, explicit identity information, and protocol-specific fields, the experiments remove the label field, time field, communication-object identifier fields, and various protocol-specific fields, while retaining only general statistical features, behavioral features, and transport-layer-related features. On this basis, following the LoFT-IIoT feature-selection strategy, candidate features are screened on the source-domain training set and the final input dimensionality is determined. Unless otherwise specified, the main experiments adopt <inline-formula id="ieqn-197"><mml:math id="mml-ieqn-197"><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mn>8</mml:mn></mml:math></inline-formula> input features. The final retained features are listed in <xref ref-type="table" rid="table-6">Table 6</xref>.</p>
<table-wrap id="table-6">
<label>Table 6</label>
<caption>
<title>Final set of selected input features.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>No.</th>
<th>Feature Name</th>
<th>Feature Category</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>1</td>
<td><monospace>tcp.checksum</monospace></td>
<td>Transport-layer checksum feature</td>
<td>Characterizes TCP packet checksum behavior</td>
</tr>
<tr>
<td>2</td>
<td><monospace>tcp.dstport</monospace></td>
<td>Port and connection feature</td>
<td>Characterizes the distribution pattern of destination ports</td>
</tr>
<tr>
<td>3</td>
<td><monospace>tcp.flags</monospace></td>
<td>Packet-control feature</td>
<td>Characterizes the combination pattern of TCP flags</td>
</tr>
<tr>
<td>4</td>
<td><monospace>tcp.flags.ack</monospace></td>
<td>Packet-control feature</td>
<td>Characterizes ACK response behavior</td>
</tr>
<tr>
<td>5</td>
<td><monospace>tcp.len</monospace></td>
<td>Length-statistics feature</td>
<td>Characterizes variations in TCP packet length</td>
</tr>
<tr>
<td>6</td>
<td><monospace>udp.time_delta</monospace></td>
<td>Temporal-behavior feature</td>
<td>Characterizes changes in UDP packet inter-arrival time</td>
</tr>
<tr>
<td>7</td>
<td><monospace>tcp.connection.fin</monospace></td>
<td>Connection-state feature</td>
<td>Characterizes TCP connection termination behavior</td>
</tr>
<tr>
<td>8</td>
<td><monospace>udp.stream</monospace></td>
<td>Session-association feature</td>
<td>Characterizes UDP flow-level session association information</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The use of eight retained features is motivated by the trade-off among cross-domain robustness, lightweight edge-side deployment, and avoidance of shortcut learning, rather than by an assumption that eight features are universally sufficient for all IIoT scenarios. During feature construction, label fields, timestamps, communication-object identifiers, and protocol-specific application-layer fields are removed to reduce identity or protocol shortcuts. The retained features cover complementary low-level behavioral evidence, including transport-layer integrity, port and connection patterns, packet-control behavior, packet-length statistics, temporal behavior, connection-state information, and flow-level session association. These categories jointly characterize packet control, timing, length, and connection behavior that remain meaningful under heterogeneous service or protocol shifts. Therefore, the eight-dimensional representation provides sufficient behavioral evidence for the evaluated cross-domain robust dynamic trust task while keeping the TrustMLP model and online BN maintenance lightweight. We do not claim that the same eight features are universally optimal for every deployment; rather, they are selected as a conservative low-dimensional configuration for the studied cross-domain evaluation setting.</p>
</sec>
<sec id="s4_1_4">
<label>4.1.4</label>
<title>Evaluation Metrics and Experimental Environment</title>
<p>To comprehensively evaluate the proposed method under cross-domain continuous online streams, the evaluation criteria are organized into four aspects, namely, overall classification performance, phase-wise streaming behavior, trust-score calibration, and resource overhead. Specifically, the overall classification metrics are used to measure the general detection capability of the model; the phase-wise metrics are introduced to characterize the dynamic behavior of the model during the initial deployment stage, the perturbation stage, and the recovery stage; the calibration metrics are used to evaluate the probabilistic interpretability of the task-level trust score; and the resource-overhead metrics are adopted to assess the feasibility of the proposed method under edge-side deployment conditions. The definitions of all evaluation metrics are summarized in <xref ref-type="table" rid="table-7">Table 7</xref>, while the experimental environment and the main parameter settings are listed in <xref ref-type="table" rid="table-8">Table 8</xref>.</p>
<table-wrap id="table-7">
<label>Table 7</label>
<caption>
<title>Main evaluation metrics and their definitions.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Metric Category</th>
<th>Metric Name</th>
<th>Definition</th>
</tr>
</thead>
<tbody>
<tr>
<td align="center" rowspan="4">Overall classification performance</td>
<td>True Positive Rate (TPR)</td>
<td>Correctly identified attack samples</td>
</tr>
<tr>
<td>False Positive Rate (FPR)</td>
<td>Normal samples incorrectly classified as attacks</td>
</tr>
<tr>
<td>F1-score</td>
<td>Harmonic balance between precision and recall</td>
</tr>
<tr>
<td>Accuracy (Acc)</td>
<td>Correctly classified samples among all samples</td>
</tr>
<tr>
<td align="center" rowspan="6">Phase-wise streaming behavior</td>
<td>Phase-1 accuracy (P1_Acc)</td>
<td>Stability at the beginning of target-domain deployment</td>
</tr>
<tr>
<td>Phase-2 accuracy (P2_Acc)</td>
<td>Overall performance during the perturbation stage</td>
</tr>
<tr>
<td>Phase-2 true positive rate (P2_TPR)</td>
<td>Attack-detection ability during the perturbation stage</td>
</tr>
<tr>
<td>Phase-2 false positive rate (P2_FPR)</td>
<td>False-alarm level on normal samples during the perturbation stage</td>
</tr>
<tr>
<td>Phase-2 F1-score (P2_F1)</td>
<td>Overall classification balance during the perturbation stage</td>
</tr>
<tr>
<td>Phase-3 accuracy (P3_Acc)</td>
<td>Steady-state recovery performance after perturbation</td>
</tr>
<tr>
<td align="center" rowspan="3">Trust-score calibration</td>
<td>Expected Calibration Error (ECE)</td>
<td>Consistency between the trust score and empirical correctness</td>
</tr>
<tr>
<td>Brier score</td>
<td>Mean squared error of predicted probabilities</td>
</tr>
<tr>
<td>Negative Log-Likelihood (NLL)</td>
<td>Fit between predicted probabilities and true labels</td>
</tr>
<tr>
<td align="center" rowspan="5">Resource overhead</td>
<td>Total runtime</td>
<td>Total time required to process the complete online stream</td>
</tr>
<tr>
<td>Average batch latency</td>
<td>Online processing delay per batch</td>
</tr>
<tr>
<td>Throughput</td>
<td>Number of samples processed per unit time</td>
</tr>
<tr>
<td>Peak memory usage</td>
<td>Maximum memory overhead during execution</td>
</tr>
<tr>
<td>Number of online trainable parameters</td>
<td>Scale of model adjustment during online maintenance</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-8">
<label>Table 8</label>
<caption>
<title>Experimental environment and main parameter settings.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Category</th>
<th>Item</th>
<th>Setting</th>
</tr>
</thead>
<tbody>
<tr>
<td align="center" rowspan="3">Hardware environment</td>
<td>CPU</td>
<td>Intel i7-11800H</td>
</tr>
<tr>
<td>GPU</td>
<td>NVIDIA GeForce RTX 3080 Laptop GPU (16 GB)</td>
</tr>
<tr>
<td>Memory</td>
<td>64 GB</td>
</tr>
<tr>
<td align="center" rowspan="3">Software environment</td>
<td>Operating system</td>
<td>Windows 11</td>
</tr>
<tr>
<td>Python</td>
<td>3.7.4</td>
</tr>
<tr>
<td>PyTorch</td>
<td>1.13.1</td>
</tr>
<tr>
<td align="center" rowspan="6">Offline training</td>
<td>Optimizer</td>
<td>Adam</td>
</tr>
<tr>
<td>Learning rate</td>
<td><inline-formula id="ieqn-198"><mml:math id="mml-ieqn-198"><mml:mn>1</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>3</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula></td>
</tr>
<tr>
<td>Batch size</td>
<td>256</td>
</tr>
<tr>
<td>Input feature dimension <inline-formula id="ieqn-199"><mml:math id="mml-ieqn-199"><mml:mi>k</mml:mi></mml:math></inline-formula></td>
<td>8</td>
</tr>
<tr>
<td>Number of training epochs</td>
<td>20</td>
</tr>
<tr>
<td>Label-smoothing factor</td>
<td>0.05</td>
</tr>
<tr>
<td align="center" rowspan="14">Online stage</td>
<td>Online batch size</td>
<td>256</td>
</tr>
<tr>
<td>Startup-window size <inline-formula id="ieqn-200"><mml:math id="mml-ieqn-200"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula></td>
<td>1000 Target-domain normal samples in the main setting</td>
</tr>
<tr>
<td>Entropy-shift threshold <inline-formula id="ieqn-201"><mml:math id="mml-ieqn-201"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">S</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>0.25</td>
</tr>
<tr>
<td>Strong-outlier quantile <inline-formula id="ieqn-202"><mml:math id="mml-ieqn-202"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">t</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>0.99</td>
</tr>
<tr>
<td>Fallback score threshold <inline-formula id="ieqn-203"><mml:math id="mml-ieqn-203"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>0.80</td>
</tr>
<tr>
<td>Volatility coefficient <inline-formula id="ieqn-204"><mml:math id="mml-ieqn-204"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula></td>
<td>2.0</td>
</tr>
<tr>
<td>Prior attack ratio <inline-formula id="ieqn-205"><mml:math id="mml-ieqn-205"><mml:msub><mml:mi>&#x03C0;</mml:mi><mml:mi>a</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>0.1</td>
</tr>
<tr>
<td>Online adaptation learning rate <inline-formula id="ieqn-206"><mml:math id="mml-ieqn-206"><mml:mi>&#x03B7;</mml:mi></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-207"><mml:math id="mml-ieqn-207"><mml:mn>5</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>3</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula></td>
</tr>
<tr>
<td>Sample-level arbitration budget <inline-formula id="ieqn-208"><mml:math id="mml-ieqn-208"><mml:mi>&#x03C1;</mml:mi></mml:math></inline-formula></td>
<td>0.01</td>
</tr>
<tr>
<td>BN regularization weight</td>
<td><inline-formula id="ieqn-209"><mml:math id="mml-ieqn-209"><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>4</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula></td>
</tr>
<tr>
<td>Number of update steps per batch</td>
<td>3</td>
</tr>
<tr>
<td>Mahalanobis gating quantile threshold</td>
<td>0.90/0.99</td>
</tr>
<tr>
<td>AdaBN anchor calibration</td>
<td>Max. 20 startup mini-batches; capped by available <inline-formula id="ieqn-210"><mml:math id="mml-ieqn-210"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> samples; effective 4 in the main setting</td>
</tr>
<tr>
<td>AdaBN momentum</td>
<td>0.2</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4_1_5">
<label>4.1.5</label>
<title>External X-IIoTID Validation Protocol</title>
<p>To evaluate generalization beyond Edge-IIoTset, we additionally conduct external validation on the X-IIoTID dataset [<xref ref-type="bibr" rid="ref-22">22</xref>]. Unlike the Edge-IIoTset main experiment, the X-IIoTID experiment adopts a service-holdout cross-domain protocol. The source domain contains multiple source services, while the target domain consists of disjoint Modbus, MQTT, and WebSocket services. The target perturbation stage further includes multiple attack families, including false data injection, MQTT cloud broker subscription, Modbus register reading, scanning vulnerability, and fuzzing. This setting is used to evaluate whether RaL-TTA can maintain dynamic trust evaluation capability under external cross-service distribution shift.</p>
</sec>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Comparison of Cross-Domain Detection Performance</title>
<p>To compare the detection performance of different online adaptation strategies under cross-domain distribution shifts, we evaluate Source-Only, AdaBN-only [<xref ref-type="bibr" rid="ref-13">13</xref>], TENT [<xref ref-type="bibr" rid="ref-16">16</xref>], POEM [<xref ref-type="bibr" rid="ref-18">18</xref>], POEM&#x002B;SafeBrake, and RaL-TTA under the unified experimental protocol described above. The results are reported as mean <inline-formula id="ieqn-211"><mml:math id="mml-ieqn-211"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> standard deviation over multiple pre-built target streams. The main Edge-IIoTset results are listed in <xref ref-type="table" rid="table-9">Table 9</xref>. The RaL-TTA configuration uses the validation-selected hyperparameters described in <xref ref-type="sec" rid="s4_5">Section 4.5</xref>.</p>
<table-wrap id="table-9">
<label>Table 9</label>
<caption>
<title>Comparison of different online adaptation strategies in the Edge-IIoTset perturbation and recovery stages.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Method</th>
<th>P2_TPR</th>
<th>P2_FPR</th>
<th>P2_F1</th>
<th>P2_Acc</th>
<th>P3_FPR</th>
<th>P3_Acc</th>
</tr>
</thead>
<tbody>
<tr>
<td>Source-Only</td>
<td>1.0000 <inline-formula id="ieqn-212"><mml:math id="mml-ieqn-212"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.9000 <inline-formula id="ieqn-213"><mml:math id="mml-ieqn-213"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0054</td>
<td>0.4878 <inline-formula id="ieqn-214"><mml:math id="mml-ieqn-214"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0015</td>
<td>0.3700 <inline-formula id="ieqn-215"><mml:math id="mml-ieqn-215"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0037</td>
<td>0.8990 <inline-formula id="ieqn-216"><mml:math id="mml-ieqn-216"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.1010 <inline-formula id="ieqn-217"><mml:math id="mml-ieqn-217"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td>AdaBN-only</td>
<td>1.0000 <inline-formula id="ieqn-218"><mml:math id="mml-ieqn-218"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.6016 <inline-formula id="ieqn-219"><mml:math id="mml-ieqn-219"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0135</td>
<td>0.5876 <inline-formula id="ieqn-220"><mml:math id="mml-ieqn-220"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0054</td>
<td>0.5789 <inline-formula id="ieqn-221"><mml:math id="mml-ieqn-221"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0094</td>
<td>0.6080 <inline-formula id="ieqn-222"><mml:math id="mml-ieqn-222"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.3920 <inline-formula id="ieqn-223"><mml:math id="mml-ieqn-223"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td>TENT</td>
<td>0.2193 <inline-formula id="ieqn-224"><mml:math id="mml-ieqn-224"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0269</td>
<td>0.6774 <inline-formula id="ieqn-225"><mml:math id="mml-ieqn-225"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0124</td>
<td>0.1565 <inline-formula id="ieqn-226"><mml:math id="mml-ieqn-226"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0178</td>
<td>0.2916 <inline-formula id="ieqn-227"><mml:math id="mml-ieqn-227"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0120</td>
<td>0.6418 <inline-formula id="ieqn-228"><mml:math id="mml-ieqn-228"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0463</td>
<td>0.3582 <inline-formula id="ieqn-229"><mml:math id="mml-ieqn-229"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0463</td>
</tr>
<tr>
<td>POEM</td>
<td>0.9087 <inline-formula id="ieqn-230"><mml:math id="mml-ieqn-230"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0287</td>
<td>0.6884 <inline-formula id="ieqn-231"><mml:math id="mml-ieqn-231"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0391</td>
<td>0.5172 <inline-formula id="ieqn-232"><mml:math id="mml-ieqn-232"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0166</td>
<td>0.4907 <inline-formula id="ieqn-233"><mml:math id="mml-ieqn-233"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0272</td>
<td>0.7067 <inline-formula id="ieqn-234"><mml:math id="mml-ieqn-234"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0565</td>
<td>0.2933 <inline-formula id="ieqn-235"><mml:math id="mml-ieqn-235"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0565</td>
</tr>
<tr>
<td>POEM&#x002B;SafeBrake</td>
<td>0.9993 <inline-formula id="ieqn-236"><mml:math id="mml-ieqn-236"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0006</td>
<td>0.0309 <inline-formula id="ieqn-237"><mml:math id="mml-ieqn-237"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0028</td>
<td>0.9649 <inline-formula id="ieqn-238"><mml:math id="mml-ieqn-238"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0032</td>
<td>0.9782 <inline-formula id="ieqn-239"><mml:math id="mml-ieqn-239"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0021</td>
<td>0.0332 <inline-formula id="ieqn-240"><mml:math id="mml-ieqn-240"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.9668 <inline-formula id="ieqn-241"><mml:math id="mml-ieqn-241"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td>RaL-TTA</td>
<td>1.0000 <inline-formula id="ieqn-242"><mml:math id="mml-ieqn-242"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0410 <inline-formula id="ieqn-243"><mml:math id="mml-ieqn-243"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0016</td>
<td>0.9544 <inline-formula id="ieqn-244"><mml:math id="mml-ieqn-244"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0017</td>
<td>0.9713 <inline-formula id="ieqn-245"><mml:math id="mml-ieqn-245"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0012</td>
<td>0.0352 <inline-formula id="ieqn-246"><mml:math id="mml-ieqn-246"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.9648 <inline-formula id="ieqn-247"><mml:math id="mml-ieqn-247"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>As shown in <xref ref-type="table" rid="table-9">Table 9</xref>, Source-Only and AdaBN-only still suffer from high false-positive rates in the target domain, indicating that merely relying on the source-domain model or simple BN-statistics recalibration is insufficient to mitigate cross-domain mismatch. TENT and POEM behave unstably under continuous unlabeled streams, suggesting that online updates without explicit risk constraints are vulnerable to attack-contaminated drift. In contrast, RaL-TTA achieves a strong perturbation-stage trade-off against the external TTA baselines: it maintains a P2_TPR of 1.0000, reduces P2_FPR to 0.0410, and achieves a P2_F1 of 0.9544. The internal POEM&#x002B;SafeBrake control obtains slightly lower P2_FPR and higher P2_F1 in this controlled stream, but it does not include the full task-level trust-score formulation and budgeted sample-level safeguard used by RaL-TTA. Therefore, the results should be interpreted as showing that risk-aware gating is essential for safe online maintenance, while the full RaL-TTA framework provides a conservative trust-evaluation design with only a small raw-performance cost relative to the strongest internal control.</p>

<p><xref ref-type="fig" rid="fig-4">Fig. 4</xref> further visualizes the online behavior of different methods. Source-Only, TENT, and POEM show unstable or low rolling accuracy under the target-domain stream, whereas the risk-protected POEM-based variants maintain more stable trajectories. RaL-TTA preserves high rolling accuracy during the perturbation and recovery phases, which is consistent with the phase-wise metrics in <xref ref-type="table" rid="table-9">Table 9</xref>. These trajectories further support the role of risk-aware gating and protection in stabilizing online trust evaluation under attack-contaminated target streams.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Sliding-window accuracy trajectories of different online adaptation methods in the three-phase continuous online stream. Each curve reports the mean accuracy over five pre-built target streams with a rolling window of 256 samples, and the shaded region indicates one standard deviation. The vertical dashed lines mark the transitions from the P1 normal phase to the P2 mixed-perturbation phase and from the P2 phase to the P3 normal recovery phase.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_82704-fig-4.tif"/>
</fig>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>External Validation on X-IIoTID</title>
<p>To evaluate generalization beyond Edge-IIoTset, we further conduct external validation on X-IIoTID under the service-holdout protocol described in <xref ref-type="sec" rid="s4_1_5">Section 4.1.5</xref>. <xref ref-type="table" rid="table-10">Table 10</xref> reports the overall representative results under the strong perturbation setting. Compared with Source-Only, RaL-TTA reduces P2_FPR and P3_FPR while maintaining meaningful attack recall. The external setting is more challenging than the Edge-IIoTset main setting because the target services and attack families are held out from the source domain.</p>
<table-wrap id="table-10">
<label>Table 10</label>
<caption>
<title>External X-IIoTID validation under the service-holdout strong perturbation setting.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Method</th>
<th>P1_Acc</th>
<th>P2_TPR</th>
<th>P2_FPR</th>
<th>P2_F1</th>
<th>P2_Acc</th>
<th>P3_FPR</th>
</tr>
</thead>
<tbody>
<tr>
<td>Source-Only</td>
<td>0.7094</td>
<td>0.4144</td>
<td>0.3243</td>
<td>0.3818</td>
<td>0.5973</td>
<td>0.2938</td>
</tr>
<tr>
<td>AdaBN-only</td>
<td>0.8208</td>
<td>0.2944</td>
<td>0.0686</td>
<td>0.4049</td>
<td>0.7403</td>
<td>0.1798</td>
</tr>
<tr>
<td>TENT</td>
<td>0.8594</td>
<td>0.0222</td>
<td>0.0052</td>
<td>0.0430</td>
<td>0.7030</td>
<td>0.0156</td>
</tr>
<tr>
<td>POEM</td>
<td>0.8156</td>
<td>0.4011</td>
<td>0.1324</td>
<td>0.4691</td>
<td>0.7277</td>
<td>0.1516</td>
</tr>
<tr>
<td>POEM&#x002B;SafeBrake</td>
<td>0.8184</td>
<td>0.3789</td>
<td>0.0986</td>
<td>0.4710</td>
<td>0.7447</td>
<td>0.1214</td>
</tr>
<tr>
<td>RaL-TTA</td>
<td>0.8388</td>
<td>0.3633</td>
<td>0.0952</td>
<td>0.4583</td>
<td>0.7423</td>
<td>0.1128</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The X-IIoTID results show that general cross-domain TTA methods may produce very different trade-offs. For example, TENT obtains very low false-positive rates but almost loses attack recall in Phase 2. POEM-based variants achieve competitive P2_F1, whereas RaL-TTA provides lower post-perturbation false positives. Therefore, RaL-TTA should be understood as a risk-aware trust-maintenance framework that emphasizes the balance among attack detection, false-alarm suppression, and post-perturbation recovery rather than a method that maximizes every single metric.</p>
<p><xref ref-type="table" rid="table-11">Table 11</xref> further reveals that the X-IIoTID service-holdout setting is challenging. RaL-TTA shows relatively stable behavior on MQTT-related target traffic, while Modbus exhibits larger seed-level variance and WebSocket remains difficult due to the mixture of normal and attack samples. These findings provide a fine-grained view of cross-service generalization and suggest that service-specific calibration remains an important direction for future work. <xref ref-type="table" rid="table-12">Table 12</xref> reports the per-attack-family recall of RaL-TTA under the X-IIoTID service-holdout setting.</p>
<table-wrap id="table-11">
<label>Table 11</label>
<caption>
<title>Fine-grained X-IIoTID per-service results of RaL-TTA in the target perturbation stage.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Target Service</th>
<th>Samples</th>
<th>Attack Samples</th>
<th>Normal Samples</th>
<th>P2_TPR</th>
<th>P2_F1</th>
</tr>
</thead>
<tbody>
<tr>
<td>MQTT</td>
<td>360</td>
<td>360</td>
<td>0</td>
<td>0.4028 <inline-formula id="ieqn-248"><mml:math id="mml-ieqn-248"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0419</td>
<td>0.5734 <inline-formula id="ieqn-249"><mml:math id="mml-ieqn-249"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0429</td>
</tr>
<tr>
<td>Modbus</td>
<td>180</td>
<td>180</td>
<td>0</td>
<td>0.5426 <inline-formula id="ieqn-250"><mml:math id="mml-ieqn-250"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.4651</td>
<td>0.6008 <inline-formula id="ieqn-251"><mml:math id="mml-ieqn-251"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.5108</td>
</tr>
<tr>
<td>WebSocket</td>
<td>2460</td>
<td>360</td>
<td>2100</td>
<td>0.1806 <inline-formula id="ieqn-252"><mml:math id="mml-ieqn-252"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.2152</td>
<td>0.1685 <inline-formula id="ieqn-253"><mml:math id="mml-ieqn-253"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.1764</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-12">
<label>Table 12</label>
<caption>
<title>-IIoTID per-attack-family recall of RaL-TTA.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Attack Family</th>
<th>Samples</th>
<th>Recall/TPR</th>
</tr>
</thead>
<tbody>
<tr>
<td>False data injection</td>
<td>180</td>
<td>0.0926 <inline-formula id="ieqn-254"><mml:math id="mml-ieqn-254"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0463</td>
</tr>
<tr>
<td>MQTT cloud broker subscription</td>
<td>180</td>
<td>0.7130 <inline-formula id="ieqn-255"><mml:math id="mml-ieqn-255"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.1297</td>
</tr>
<tr>
<td>Modbus register reading</td>
<td>180</td>
<td>0.5426 <inline-formula id="ieqn-256"><mml:math id="mml-ieqn-256"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.4651</td>
</tr>
<tr>
<td>Scanning vulnerability</td>
<td>180</td>
<td>0.2111 <inline-formula id="ieqn-257"><mml:math id="mml-ieqn-257"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.3368</td>
</tr>
<tr>
<td>Fuzzing</td>
<td>180</td>
<td>0.1500 <inline-formula id="ieqn-258"><mml:math id="mml-ieqn-258"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.1164</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The per-attack-family results indicate that different attack types have different degrees of cross-domain difficulty. MQTT cloud broker subscription attacks are detected more reliably, whereas false data injection, fuzzing, and scanning-related attacks remain more challenging. This observation is consistent with the difficulty of unlabeled external cross-service adaptation and is acknowledged as a limitation of the current framework.</p>
</sec>
<sec id="s4_4">
<label>4.4</label>
<title>Analysis of Key Mechanisms</title>
<sec id="s4_4_1">
<label>4.4.1</label>
<title>Ablation Study of Key Modules</title>
<p>To analyze the main sources of performance improvement during the perturbation stage, this paper constructs three representative ablation settings: removing anchor protection (RaL-TTA w/o Anchor), removing budgeted sample-level safeguard/rollback (BSR; RaL-TTA w/o BSR), and always freezing updates (AlwaysFreeze). The results are summarized in <xref ref-type="table" rid="table-13">Table 13</xref>.</p>
<table-wrap id="table-13">
<label>Table 13</label>
<caption>
<title>Ablation results of key modules in the perturbation stage.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Method</th>
<th>P2_TPR</th>
<th>P2_FPR</th>
<th>P2_F1</th>
<th>P2_Acc</th>
<th>P3_Acc</th>
</tr>
</thead>
<tbody>
<tr>
<td>AlwaysFreeze</td>
<td>1.0000 <inline-formula id="ieqn-259"><mml:math id="mml-ieqn-259"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.6016 <inline-formula id="ieqn-260"><mml:math id="mml-ieqn-260"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0121</td>
<td>0.5876 <inline-formula id="ieqn-261"><mml:math id="mml-ieqn-261"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0049</td>
<td>0.5789 <inline-formula id="ieqn-262"><mml:math id="mml-ieqn-262"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0084</td>
<td>0.3920 <inline-formula id="ieqn-263"><mml:math id="mml-ieqn-263"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td>RaL-TTA w/o Anchor</td>
<td>0.9993 <inline-formula id="ieqn-264"><mml:math id="mml-ieqn-264"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0005</td>
<td>0.0309 <inline-formula id="ieqn-265"><mml:math id="mml-ieqn-265"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0025</td>
<td>0.9649 <inline-formula id="ieqn-266"><mml:math id="mml-ieqn-266"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0029</td>
<td>0.9782 <inline-formula id="ieqn-267"><mml:math id="mml-ieqn-267"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0019</td>
<td>0.9668 <inline-formula id="ieqn-268"><mml:math id="mml-ieqn-268"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td>RaL-TTA w/o BSR</td>
<td>1.0000 <inline-formula id="ieqn-269"><mml:math id="mml-ieqn-269"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0430 <inline-formula id="ieqn-270"><mml:math id="mml-ieqn-270"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0029</td>
<td>0.9522 <inline-formula id="ieqn-271"><mml:math id="mml-ieqn-271"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0031</td>
<td>0.9699 <inline-formula id="ieqn-272"><mml:math id="mml-ieqn-272"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0021</td>
<td>0.9648 <inline-formula id="ieqn-273"><mml:math id="mml-ieqn-273"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td>RaL-TTA</td>
<td>1.0000 <inline-formula id="ieqn-274"><mml:math id="mml-ieqn-274"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0410 <inline-formula id="ieqn-275"><mml:math id="mml-ieqn-275"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0015</td>
<td>0.9544 <inline-formula id="ieqn-276"><mml:math id="mml-ieqn-276"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0016</td>
<td>0.9713 <inline-formula id="ieqn-277"><mml:math id="mml-ieqn-277"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0010</td>
<td>0.9648 <inline-formula id="ieqn-278"><mml:math id="mml-ieqn-278"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="table" rid="table-13">Table 13</xref> shows that simply freezing updates cannot effectively handle cross-domain abnormal perturbations because AlwaysFreeze preserves attack recall but causes a high false-positive rate and poor recovery. The variant without anchor protection is close to the POEM&#x002B;SafeBrake control, indicating that SafeBrake-style risk gating is the dominant source of false-positive control in the Edge-IIoTset stream. The comparison between RaL-TTA and RaL-TTA w/o BSR further shows that budgeted sample-level rollback has only a limited numerical effect under the main setting. Thus, the ablation study supports a conservative interpretation: risk gating is the primary stabilization mechanism, whereas AdaBN anchor protection and budgeted rollback provide additional safety boundaries for the full trust-evaluation framework rather than serving as the sole source of raw metric gains.</p>

</sec>
<sec id="s4_4_2">
<label>4.4.2</label>
<title>Analysis of Online Maintenance Behavior</title>
<p>To further illustrate how RaL-TTA operates in the main experiments, <xref ref-type="table" rid="table-14">Table 14</xref> summarizes the numbers of batches under different risk states and the corresponding maintenance actions across the three-phase online stream.</p>
<table-wrap id="table-14">
<label>Table 14</label>
<caption>
<title>Statistics of online maintenance states in the main experiment.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Phase</th>
<th>Total</th>
<th>No-Shift</th>
<th>Low-Risk</th>
<th>High-Risk</th>
<th>Update</th>
<th>Protect</th>
<th>Anchor</th>
<th>Rollback</th>
<th>Backup</th>
</tr>
</thead>
<tbody>
<tr>
<td>Phase 1</td>
<td>20.0 <inline-formula id="ieqn-279"><mml:math id="mml-ieqn-279"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>1.0 <inline-formula id="ieqn-280"><mml:math id="mml-ieqn-280"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>15.0 <inline-formula id="ieqn-281"><mml:math id="mml-ieqn-281"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>4.0 <inline-formula id="ieqn-282"><mml:math id="mml-ieqn-282"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>12.0 <inline-formula id="ieqn-283"><mml:math id="mml-ieqn-283"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>4.0 <inline-formula id="ieqn-284"><mml:math id="mml-ieqn-284"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>4.0 <inline-formula id="ieqn-285"><mml:math id="mml-ieqn-285"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>0.0 <inline-formula id="ieqn-286"><mml:math id="mml-ieqn-286"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>0.0 <inline-formula id="ieqn-287"><mml:math id="mml-ieqn-287"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
</tr>
<tr>
<td>Phase 2</td>
<td>12.0 <inline-formula id="ieqn-288"><mml:math id="mml-ieqn-288"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>0.0 <inline-formula id="ieqn-289"><mml:math id="mml-ieqn-289"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>0.0 <inline-formula id="ieqn-290"><mml:math id="mml-ieqn-290"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>12.0 <inline-formula id="ieqn-291"><mml:math id="mml-ieqn-291"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>0.0 <inline-formula id="ieqn-292"><mml:math id="mml-ieqn-292"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>12.0 <inline-formula id="ieqn-293"><mml:math id="mml-ieqn-293"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>12.0 <inline-formula id="ieqn-294"><mml:math id="mml-ieqn-294"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>0.2 <inline-formula id="ieqn-295"><mml:math id="mml-ieqn-295"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.4</td>
<td>0.0 <inline-formula id="ieqn-296"><mml:math id="mml-ieqn-296"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
</tr>
<tr>
<td>Phase 3</td>
<td>20.0 <inline-formula id="ieqn-297"><mml:math id="mml-ieqn-297"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>11.0 <inline-formula id="ieqn-298"><mml:math id="mml-ieqn-298"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>8.0 <inline-formula id="ieqn-299"><mml:math id="mml-ieqn-299"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>1.0 <inline-formula id="ieqn-300"><mml:math id="mml-ieqn-300"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>8.0 <inline-formula id="ieqn-301"><mml:math id="mml-ieqn-301"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>1.0 <inline-formula id="ieqn-302"><mml:math id="mml-ieqn-302"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>1.0 <inline-formula id="ieqn-303"><mml:math id="mml-ieqn-303"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>0.0 <inline-formula id="ieqn-304"><mml:math id="mml-ieqn-304"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
<td>0.0 <inline-formula id="ieqn-305"><mml:math id="mml-ieqn-305"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn id="table-14fn1" fn-type="other">
<p>Note: Update, Protect, Anchor, Rollback, and Backup denote update-executed, protection-mode, anchor-protected, rollback-covered, and backup-anchor actions, respectively.</p>
</fn>
</table-wrap-foot>
</table-wrap>
<p><xref ref-type="table" rid="table-14">Table 14</xref> shows that all 12 batches in the perturbation stage are judged as high-risk and therefore enter the protection mode, with no online updates being executed. This indicates that the proposed method prioritizes freezing unreliable adaptation when attack traffic is mixed into the stream. In contrast, updates occur mainly in low-risk batches during the initial normal phase and the recovery phase, showing that RaL-TTA follows a selective online strategy of freezing at high risk and maintaining at low risk.</p>

</sec>
<sec id="s4_4_3">
<label>4.4.3</label>
<title>Analysis of Trust-Score Calibration Ability</title>
<p>To verify that the task-level trust scores output in this paper have probabilistic interpretability, we further assess calibration using expected calibration error (ECE), Brier score, and negative log-likelihood (NLL). <xref ref-type="table" rid="table-15">Table 15</xref> compares the trust-score reliability of RaL-TTA and representative baselines on the target-domain online stream.</p>
<table-wrap id="table-15">
<label>Table 15</label>
<caption>
<title>Trust-score calibration results for different methods.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Evaluation Scope</th>
<th>Method</th>
<th>ECE</th>
<th>Brier Score</th>
<th>NLL</th>
</tr>
</thead>
<tbody>
<tr>
<td>Perturbation stage</td>
<td>Source-Only</td>
<td>0.6000 <inline-formula id="ieqn-306"><mml:math id="mml-ieqn-306"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.5751 <inline-formula id="ieqn-307"><mml:math id="mml-ieqn-307"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0027</td>
<td>2.1230 <inline-formula id="ieqn-308"><mml:math id="mml-ieqn-308"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0145</td>
</tr>
<tr>
<td>Perturbation stage</td>
<td>POEM&#x002B;SafeBrake</td>
<td>0.0483 <inline-formula id="ieqn-309"><mml:math id="mml-ieqn-309"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0248 <inline-formula id="ieqn-310"><mml:math id="mml-ieqn-310"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0018</td>
<td>0.1217 <inline-formula id="ieqn-311"><mml:math id="mml-ieqn-311"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0061</td>
</tr>
<tr>
<td>Perturbation stage</td>
<td>RaL-TTA</td>
<td>0.0543 <inline-formula id="ieqn-312"><mml:math id="mml-ieqn-312"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0016</td>
<td>0.0298 <inline-formula id="ieqn-313"><mml:math id="mml-ieqn-313"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0011</td>
<td>0.1421 <inline-formula id="ieqn-314"><mml:math id="mml-ieqn-314"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0049</td>
</tr>
<tr>
<td>Full stream</td>
<td>Source-Only</td>
<td>0.8141 <inline-formula id="ieqn-315"><mml:math id="mml-ieqn-315"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0006</td>
<td>0.7649 <inline-formula id="ieqn-316"><mml:math id="mml-ieqn-316"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0006</td>
<td>2.8016 <inline-formula id="ieqn-317"><mml:math id="mml-ieqn-317"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0034</td>
</tr>
<tr>
<td>Full stream</td>
<td>POEM&#x002B;SafeBrake</td>
<td>0.2354 <inline-formula id="ieqn-318"><mml:math id="mml-ieqn-318"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0004</td>
<td>0.1752 <inline-formula id="ieqn-319"><mml:math id="mml-ieqn-319"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0004</td>
<td>0.6213 <inline-formula id="ieqn-320"><mml:math id="mml-ieqn-320"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0014</td>
</tr>
<tr>
<td>Full stream</td>
<td>RaL-TTA</td>
<td>0.1896 <inline-formula id="ieqn-321"><mml:math id="mml-ieqn-321"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0003</td>
<td>0.1270 <inline-formula id="ieqn-322"><mml:math id="mml-ieqn-322"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0003</td>
<td>0.4161 <inline-formula id="ieqn-323"><mml:math id="mml-ieqn-323"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0011</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="table" rid="table-15">Table 15</xref> indicates that Source-Only suffers from large calibration errors after direct transfer to the target domain. During the perturbation stage, RaL-TTA and POEM&#x002B;SafeBrake both provide substantially better calibration than Source-Only, with POEM&#x002B;SafeBrake slightly lower on the three calibration metrics. Over the full stream, however, RaL-TTA obtains lower ECE, Brier score, and NLL, suggesting that the full protection-oriented trust-score output improves overall probabilistic reliability across deployment, perturbation, and recovery.</p>

</sec>
</sec>
<sec id="s4_5">
<label>4.5</label>
<title>Hyperparameter Selection and Sensitivity Analysis</title>
<p>To clarify how the key thresholds and online-adaptation parameters are selected, <xref ref-type="table" rid="table-16">Table 16</xref> summarizes the candidate values, selected values, and selection rules. The parameters are selected through a combination of validation-based tuning, startup-window quantile calibration, and conservative security-budget constraints.</p>
<table-wrap id="table-16">
<label>Table 16</label>
<caption>
<title>Hyperparameter and threshold selection procedure.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Parameter</th>
<th>Candidate Values/Range</th>
<th>Selected Value and Rule</th>
</tr>
</thead>
<tbody>
<tr>
<td><inline-formula id="ieqn-324"><mml:math id="mml-ieqn-324"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">S</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>0.15, 0.20, 0.25, 0.30, 0.35</td>
<td>0.25; Validation trade-off between drift sensitivity and false positives</td>
</tr>
<tr>
<td><inline-formula id="ieqn-325"><mml:math id="mml-ieqn-325"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">t</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>0.95, 0.97, 0.99, 0.995</td>
<td>0.99; Normal-window distance quantile for conservative outlier gating</td>
</tr>
<tr>
<td><inline-formula id="ieqn-326"><mml:math id="mml-ieqn-326"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:math></inline-formula>/Selective-fallback score threshold</td>
<td>0.70, 0.75, 0.80, 0.85, 0.90</td>
<td>0.80; Validation low-FPR preference and startup-window score calibration</td>
</tr>
<tr>
<td><inline-formula id="ieqn-327"><mml:math id="mml-ieqn-327"><mml:mi>&#x03B7;</mml:mi></mml:math></inline-formula>/Online adaptation learning rate</td>
<td><inline-formula id="ieqn-328"><mml:math id="mml-ieqn-328"><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>3</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula>, <inline-formula id="ieqn-329"><mml:math id="mml-ieqn-329"><mml:mn>2</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>3</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula>, <inline-formula id="ieqn-330"><mml:math id="mml-ieqn-330"><mml:mn>5</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>3</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula>, <inline-formula id="ieqn-331"><mml:math id="mml-ieqn-331"><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-332"><mml:math id="mml-ieqn-332"><mml:mn>5</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>3</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula>; Stable online adaptation</td>
</tr>
<tr>
<td><inline-formula id="ieqn-333"><mml:math id="mml-ieqn-333"><mml:mi>&#x03C1;</mml:mi></mml:math></inline-formula>/Arbitration budget</td>
<td>0, 0.005, 0.01, 0.02</td>
<td>0.01; Minimal nonzero conservative rollback budget</td>
</tr>
<tr>
<td><inline-formula id="ieqn-334"><mml:math id="mml-ieqn-334"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula>/SafeBrake multiplier</td>
<td>1.5, 2.0, 2.5</td>
<td>2.0; Validation stability of SafeBrake activation</td>
</tr>
<tr>
<td><inline-formula id="ieqn-335"><mml:math id="mml-ieqn-335"><mml:msub><mml:mi>&#x03C0;</mml:mi><mml:mi>a</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>0.1, 0.2, 0.3, 0.5</td>
<td>0.1; Dev-set selection with P2_F1 and low-FPR preference</td>
</tr>
<tr>
<td>AdaBN calibration cap</td>
<td>5, 10, 20, all</td>
<td>Maximum 20 mini-batches; early stop when <inline-formula id="ieqn-336"><mml:math id="mml-ieqn-336"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> is exhausted; effective main setting: all 4 <inline-formula id="ieqn-337"><mml:math id="mml-ieqn-337"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> mini-batches</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="table" rid="table-17">Table 17</xref> shows that RaL-TTA remains stable under moderate variations of <inline-formula id="ieqn-338"><mml:math id="mml-ieqn-338"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">S</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-339"><mml:math id="mml-ieqn-339"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">t</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-340"><mml:math id="mml-ieqn-340"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:math></inline-formula>, and the SafeBrake multiplier. The learning-rate analysis shows that an excessively small learning rate, such as <inline-formula id="ieqn-341"><mml:math id="mml-ieqn-341"><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>3</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula>, fails to adapt sufficiently and leads to high false positives, whereas learning rates from <inline-formula id="ieqn-342"><mml:math id="mml-ieqn-342"><mml:mn>2</mml:mn><mml:mo>&#x00D7;</mml:mo><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>3</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula> to <inline-formula id="ieqn-343"><mml:math id="mml-ieqn-343"><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula> provide stable performance. The sensitivity analysis of <inline-formula id="ieqn-344"><mml:math id="mml-ieqn-344"><mml:mi>&#x03C1;</mml:mi></mml:math></inline-formula> shows that rollback is not the dominant source of performance improvement under the main setting. A zero budget yields slightly lower FPR in this controlled stream, while a small nonzero budget such as 0.01 retains the conservative safeguard mechanism with only minor performance cost. The identical results for the AdaBN calibration caps of 5, 10, 20, and all are expected under the main startup-window setting. Since <inline-formula id="ieqn-345"><mml:math id="mml-ieqn-345"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mn>1000</mml:mn></mml:math></inline-formula> and the online batch size is 256, only four startup mini-batches are available. Therefore, any calibration cap no smaller than 5 is effectively equivalent to using all available startup samples.</p>
<table-wrap id="table-17">
<label>Table 17</label>
<caption>
<title>One-factor sensitivity analysis of major hyperparameters.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Parameter</th>
<th>Value</th>
<th>P2_TPR</th>
<th>P2_FPR</th>
<th>P2_F1</th>
<th>P3_FPR</th>
</tr>
</thead>
<tbody>
<tr>
<td><inline-formula id="ieqn-346"><mml:math id="mml-ieqn-346"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">S</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>0.15</td>
<td>1.0000 <inline-formula id="ieqn-347"><mml:math id="mml-ieqn-347"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-348"><mml:math id="mml-ieqn-348"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-349"><mml:math id="mml-ieqn-349"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0352 <inline-formula id="ieqn-350"><mml:math id="mml-ieqn-350"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-351"><mml:math id="mml-ieqn-351"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">S</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>0.20</td>
<td>1.0000 <inline-formula id="ieqn-352"><mml:math id="mml-ieqn-352"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-353"><mml:math id="mml-ieqn-353"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-354"><mml:math id="mml-ieqn-354"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0352 <inline-formula id="ieqn-355"><mml:math id="mml-ieqn-355"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-356"><mml:math id="mml-ieqn-356"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">S</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>0.25</td>
<td>1.0000 <inline-formula id="ieqn-357"><mml:math id="mml-ieqn-357"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-358"><mml:math id="mml-ieqn-358"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-359"><mml:math id="mml-ieqn-359"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0346 <inline-formula id="ieqn-360"><mml:math id="mml-ieqn-360"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-361"><mml:math id="mml-ieqn-361"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">S</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>0.30</td>
<td>1.0000 <inline-formula id="ieqn-362"><mml:math id="mml-ieqn-362"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-363"><mml:math id="mml-ieqn-363"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-364"><mml:math id="mml-ieqn-364"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0338 <inline-formula id="ieqn-365"><mml:math id="mml-ieqn-365"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-366"><mml:math id="mml-ieqn-366"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">K</mml:mi><mml:mi mathvariant="normal">S</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>0.35</td>
<td>1.0000 <inline-formula id="ieqn-367"><mml:math id="mml-ieqn-367"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0440 <inline-formula id="ieqn-368"><mml:math id="mml-ieqn-368"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0028</td>
<td>0.9512 <inline-formula id="ieqn-369"><mml:math id="mml-ieqn-369"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0029</td>
<td>0.0350 <inline-formula id="ieqn-370"><mml:math id="mml-ieqn-370"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-371"><mml:math id="mml-ieqn-371"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">t</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>0.95</td>
<td>1.0000 <inline-formula id="ieqn-372"><mml:math id="mml-ieqn-372"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0457 <inline-formula id="ieqn-373"><mml:math id="mml-ieqn-373"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0022</td>
<td>0.9494 <inline-formula id="ieqn-374"><mml:math id="mml-ieqn-374"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.0350 <inline-formula id="ieqn-375"><mml:math id="mml-ieqn-375"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-376"><mml:math id="mml-ieqn-376"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">t</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>0.97</td>
<td>1.0000 <inline-formula id="ieqn-377"><mml:math id="mml-ieqn-377"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-378"><mml:math id="mml-ieqn-378"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-379"><mml:math id="mml-ieqn-379"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0346 <inline-formula id="ieqn-380"><mml:math id="mml-ieqn-380"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-381"><mml:math id="mml-ieqn-381"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">t</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>0.99</td>
<td>1.0000 <inline-formula id="ieqn-382"><mml:math id="mml-ieqn-382"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-383"><mml:math id="mml-ieqn-383"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-384"><mml:math id="mml-ieqn-384"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0346 <inline-formula id="ieqn-385"><mml:math id="mml-ieqn-385"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-386"><mml:math id="mml-ieqn-386"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">o</mml:mi><mml:mi mathvariant="normal">u</mml:mi><mml:mi mathvariant="normal">t</mml:mi></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>0.995</td>
<td>1.0000 <inline-formula id="ieqn-387"><mml:math id="mml-ieqn-387"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0406 <inline-formula id="ieqn-388"><mml:math id="mml-ieqn-388"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0028</td>
<td>0.9547 <inline-formula id="ieqn-389"><mml:math id="mml-ieqn-389"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0030</td>
<td>0.0344 <inline-formula id="ieqn-390"><mml:math id="mml-ieqn-390"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-391"><mml:math id="mml-ieqn-391"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>0.70</td>
<td>1.0000 <inline-formula id="ieqn-392"><mml:math id="mml-ieqn-392"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-393"><mml:math id="mml-ieqn-393"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-394"><mml:math id="mml-ieqn-394"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0346 <inline-formula id="ieqn-395"><mml:math id="mml-ieqn-395"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-396"><mml:math id="mml-ieqn-396"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>0.75</td>
<td>1.0000 <inline-formula id="ieqn-397"><mml:math id="mml-ieqn-397"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-398"><mml:math id="mml-ieqn-398"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-399"><mml:math id="mml-ieqn-399"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0346 <inline-formula id="ieqn-400"><mml:math id="mml-ieqn-400"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-401"><mml:math id="mml-ieqn-401"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>0.80</td>
<td>1.0000 <inline-formula id="ieqn-402"><mml:math id="mml-ieqn-402"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-403"><mml:math id="mml-ieqn-403"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-404"><mml:math id="mml-ieqn-404"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0346 <inline-formula id="ieqn-405"><mml:math id="mml-ieqn-405"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-406"><mml:math id="mml-ieqn-406"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>0.85</td>
<td>1.0000 <inline-formula id="ieqn-407"><mml:math id="mml-ieqn-407"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-408"><mml:math id="mml-ieqn-408"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-409"><mml:math id="mml-ieqn-409"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0346 <inline-formula id="ieqn-410"><mml:math id="mml-ieqn-410"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-411"><mml:math id="mml-ieqn-411"><mml:msub><mml:mi>&#x03C4;</mml:mi><mml:mi>s</mml:mi></mml:msub></mml:math></inline-formula></td>
<td>0.90</td>
<td>1.0000 <inline-formula id="ieqn-412"><mml:math id="mml-ieqn-412"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-413"><mml:math id="mml-ieqn-413"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-414"><mml:math id="mml-ieqn-414"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0346 <inline-formula id="ieqn-415"><mml:math id="mml-ieqn-415"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-416"><mml:math id="mml-ieqn-416"><mml:mi>&#x03B7;</mml:mi></mml:math></inline-formula></td>
<td>0.001</td>
<td>1.0000 <inline-formula id="ieqn-417"><mml:math id="mml-ieqn-417"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.5403 <inline-formula id="ieqn-418"><mml:math id="mml-ieqn-418"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0077</td>
<td>0.6134 <inline-formula id="ieqn-419"><mml:math id="mml-ieqn-419"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0034</td>
<td>0.3600 <inline-formula id="ieqn-420"><mml:math id="mml-ieqn-420"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-421"><mml:math id="mml-ieqn-421"><mml:mi>&#x03B7;</mml:mi></mml:math></inline-formula></td>
<td>0.002</td>
<td>1.0000 <inline-formula id="ieqn-422"><mml:math id="mml-ieqn-422"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0340 <inline-formula id="ieqn-423"><mml:math id="mml-ieqn-423"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.9619 <inline-formula id="ieqn-424"><mml:math id="mml-ieqn-424"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0026</td>
<td>0.0350 <inline-formula id="ieqn-425"><mml:math id="mml-ieqn-425"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-426"><mml:math id="mml-ieqn-426"><mml:mi>&#x03B7;</mml:mi></mml:math></inline-formula></td>
<td>0.005</td>
<td>1.0000 <inline-formula id="ieqn-427"><mml:math id="mml-ieqn-427"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-428"><mml:math id="mml-ieqn-428"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-429"><mml:math id="mml-ieqn-429"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0346 <inline-formula id="ieqn-430"><mml:math id="mml-ieqn-430"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-431"><mml:math id="mml-ieqn-431"><mml:mi>&#x03B7;</mml:mi></mml:math></inline-formula></td>
<td>0.010</td>
<td>1.0000 <inline-formula id="ieqn-432"><mml:math id="mml-ieqn-432"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-433"><mml:math id="mml-ieqn-433"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-434"><mml:math id="mml-ieqn-434"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0344 <inline-formula id="ieqn-435"><mml:math id="mml-ieqn-435"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td>AdaBN cap</td>
<td>5</td>
<td>1.0000 <inline-formula id="ieqn-436"><mml:math id="mml-ieqn-436"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-437"><mml:math id="mml-ieqn-437"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-438"><mml:math id="mml-ieqn-438"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0346 <inline-formula id="ieqn-439"><mml:math id="mml-ieqn-439"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td>AdaBN cap</td>
<td>10</td>
<td>1.0000 <inline-formula id="ieqn-440"><mml:math id="mml-ieqn-440"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-441"><mml:math id="mml-ieqn-441"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-442"><mml:math id="mml-ieqn-442"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0346 <inline-formula id="ieqn-443"><mml:math id="mml-ieqn-443"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td>AdaBN cap</td>
<td>20</td>
<td>1.0000 <inline-formula id="ieqn-444"><mml:math id="mml-ieqn-444"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-445"><mml:math id="mml-ieqn-445"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-446"><mml:math id="mml-ieqn-446"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0346 <inline-formula id="ieqn-447"><mml:math id="mml-ieqn-447"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td>AdaBN cap</td>
<td>all</td>
<td>1.0000 <inline-formula id="ieqn-448"><mml:math id="mml-ieqn-448"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-449"><mml:math id="mml-ieqn-449"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-450"><mml:math id="mml-ieqn-450"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0346 <inline-formula id="ieqn-451"><mml:math id="mml-ieqn-451"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-452"><mml:math id="mml-ieqn-452"><mml:mi>&#x03C1;</mml:mi></mml:math></inline-formula></td>
<td>0</td>
<td>1.0000 <inline-formula id="ieqn-453"><mml:math id="mml-ieqn-453"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0325 <inline-formula id="ieqn-454"><mml:math id="mml-ieqn-454"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0028</td>
<td>0.9634 <inline-formula id="ieqn-455"><mml:math id="mml-ieqn-455"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0030</td>
<td>0.0334 <inline-formula id="ieqn-456"><mml:math id="mml-ieqn-456"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-457"><mml:math id="mml-ieqn-457"><mml:mi>&#x03C1;</mml:mi></mml:math></inline-formula></td>
<td>0.005</td>
<td>1.0000 <inline-formula id="ieqn-458"><mml:math id="mml-ieqn-458"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0378 <inline-formula id="ieqn-459"><mml:math id="mml-ieqn-459"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0028</td>
<td>0.9578 <inline-formula id="ieqn-460"><mml:math id="mml-ieqn-460"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0030</td>
<td>0.0342 <inline-formula id="ieqn-461"><mml:math id="mml-ieqn-461"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-462"><mml:math id="mml-ieqn-462"><mml:mi>&#x03C1;</mml:mi></mml:math></inline-formula></td>
<td>0.010</td>
<td>1.0000 <inline-formula id="ieqn-463"><mml:math id="mml-ieqn-463"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-464"><mml:math id="mml-ieqn-464"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-465"><mml:math id="mml-ieqn-465"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0346 <inline-formula id="ieqn-466"><mml:math id="mml-ieqn-466"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-467"><mml:math id="mml-ieqn-467"><mml:mi>&#x03C1;</mml:mi></mml:math></inline-formula></td>
<td>0.020</td>
<td>1.0000 <inline-formula id="ieqn-468"><mml:math id="mml-ieqn-468"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0432 <inline-formula id="ieqn-469"><mml:math id="mml-ieqn-469"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9520 <inline-formula id="ieqn-470"><mml:math id="mml-ieqn-470"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0354 <inline-formula id="ieqn-471"><mml:math id="mml-ieqn-471"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-472"><mml:math id="mml-ieqn-472"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula></td>
<td>1.5</td>
<td>1.0000 <inline-formula id="ieqn-473"><mml:math id="mml-ieqn-473"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-474"><mml:math id="mml-ieqn-474"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-475"><mml:math id="mml-ieqn-475"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0346 <inline-formula id="ieqn-476"><mml:math id="mml-ieqn-476"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-477"><mml:math id="mml-ieqn-477"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula></td>
<td>2.0</td>
<td>1.0000 <inline-formula id="ieqn-478"><mml:math id="mml-ieqn-478"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-479"><mml:math id="mml-ieqn-479"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-480"><mml:math id="mml-ieqn-480"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0346 <inline-formula id="ieqn-481"><mml:math id="mml-ieqn-481"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td><inline-formula id="ieqn-482"><mml:math id="mml-ieqn-482"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula></td>
<td>2.5</td>
<td>1.0000 <inline-formula id="ieqn-483"><mml:math id="mml-ieqn-483"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0413 <inline-formula id="ieqn-484"><mml:math id="mml-ieqn-484"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.9541 <inline-formula id="ieqn-485"><mml:math id="mml-ieqn-485"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
<td>0.0340 <inline-formula id="ieqn-486"><mml:math id="mml-ieqn-486"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4_6">
<label>4.6</label>
<title>Computational Overhead Analysis</title>
<p>To compare the relative runtime cost of different methods, we conduct an overhead evaluation on a unified platform with a pre-built online stream. This subsection uses the test split under the pure-attack pressure setting <inline-formula id="ieqn-487"><mml:math id="mml-ieqn-487"><mml:mi>r</mml:mi><mml:mo>=</mml:mo><mml:mn>1.0</mml:mn></mml:math></inline-formula> solely to compare the relative computational cost of different methods. For each online batch with batch size <inline-formula id="ieqn-488"><mml:math id="mml-ieqn-488"><mml:mi>b</mml:mi></mml:math></inline-formula> and retained feature dimension <inline-formula id="ieqn-489"><mml:math id="mml-ieqn-489"><mml:mi>m</mml:mi></mml:math></inline-formula>, the fixed MLP forward pass has linear cost in the batch size up to the constant hidden-layer widths. KS-based entropy comparison is performed on one-dimensional entropy values and costs <inline-formula id="ieqn-490"><mml:math id="mml-ieqn-490"><mml:mi>O</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>b</mml:mi><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mi>b</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> if sorting is required. The Mahalanobis distance is computed in the selected low-dimensional feature space, where the inverse covariance matrix is precomputed from <inline-formula id="ieqn-491"><mml:math id="mml-ieqn-491"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula>, leading to <inline-formula id="ieqn-492"><mml:math id="mml-ieqn-492"><mml:mi>O</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>b</mml:mi><mml:msup><mml:mi>m</mml:mi><mml:mn>2</mml:mn></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> per batch. Since only BN affine parameters are updated, the number of online trainable parameters is 192 and the online update cost is independent of the full model size. The empirical overhead results are shown in <xref ref-type="table" rid="table-18">Table 18</xref> and <xref ref-type="fig" rid="fig-5">Fig. 5</xref>.</p>
<table-wrap id="table-18">
<label>Table 18</label>
<caption>
<title>Relative overhead comparison of different methods under a unified platform and a pre-built online stream.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th>Method</th>
<th>Runtime (s)</th>
<th>Latency (ms/Batch)</th>
<th>Throughput (Samples/s)</th>
<th>Memory (MB)</th>
<th>Trainable Params</th>
</tr>
</thead>
<tbody>
<tr>
<td>Source-Only</td>
<td>2.7787 <inline-formula id="ieqn-493"><mml:math id="mml-ieqn-493"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0231</td>
<td>53.44 <inline-formula id="ieqn-494"><mml:math id="mml-ieqn-494"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.44</td>
<td>4678.71 <inline-formula id="ieqn-495"><mml:math id="mml-ieqn-495"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 38.70</td>
<td>270.34 <inline-formula id="ieqn-496"><mml:math id="mml-ieqn-496"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.20</td>
<td>0</td>
</tr>
<tr>
<td>AdaBN-only</td>
<td>2.8368 <inline-formula id="ieqn-497"><mml:math id="mml-ieqn-497"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0424</td>
<td>54.55 <inline-formula id="ieqn-498"><mml:math id="mml-ieqn-498"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.82</td>
<td>4583.61 <inline-formula id="ieqn-499"><mml:math id="mml-ieqn-499"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 68.96</td>
<td>253.49 <inline-formula id="ieqn-500"><mml:math id="mml-ieqn-500"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 3.57</td>
<td>0</td>
</tr>
<tr>
<td>TENT</td>
<td>2.9986 <inline-formula id="ieqn-501"><mml:math id="mml-ieqn-501"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0211</td>
<td>57.67 <inline-formula id="ieqn-502"><mml:math id="mml-ieqn-502"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.41</td>
<td>4335.56 <inline-formula id="ieqn-503"><mml:math id="mml-ieqn-503"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 30.43</td>
<td>271.57 <inline-formula id="ieqn-504"><mml:math id="mml-ieqn-504"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.13</td>
<td>192</td>
</tr>
<tr>
<td>POEM</td>
<td>3.0167 <inline-formula id="ieqn-505"><mml:math id="mml-ieqn-505"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0165</td>
<td>58.01 <inline-formula id="ieqn-506"><mml:math id="mml-ieqn-506"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.32</td>
<td>4309.47 <inline-formula id="ieqn-507"><mml:math id="mml-ieqn-507"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 23.68</td>
<td>272.91 <inline-formula id="ieqn-508"><mml:math id="mml-ieqn-508"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.22</td>
<td>192</td>
</tr>
<tr>
<td>POEM&#x002B;SafeBrake</td>
<td>3.0666 <inline-formula id="ieqn-509"><mml:math id="mml-ieqn-509"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0254</td>
<td>58.97 <inline-formula id="ieqn-510"><mml:math id="mml-ieqn-510"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.49</td>
<td>4239.50 <inline-formula id="ieqn-511"><mml:math id="mml-ieqn-511"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 34.97</td>
<td>271.64 <inline-formula id="ieqn-512"><mml:math id="mml-ieqn-512"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 2.11</td>
<td>192</td>
</tr>
<tr>
<td>RaL-TTA</td>
<td>3.1044 <inline-formula id="ieqn-513"><mml:math id="mml-ieqn-513"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0404</td>
<td>59.70 <inline-formula id="ieqn-514"><mml:math id="mml-ieqn-514"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.78</td>
<td>4188.37 <inline-formula id="ieqn-515"><mml:math id="mml-ieqn-515"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 54.22</td>
<td>274.84 <inline-formula id="ieqn-516"><mml:math id="mml-ieqn-516"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.34</td>
<td>192</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn id="table-18fn1" fn-type="other">
<p>Note: Runtime, Latency, Memory, and Trainable params denote total runtime, average batch latency, peak memory usage, and the number of online trainable parameters, respectively.</p>
</fn>
</table-wrap-foot>
</table-wrap><fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Overhead comparison of different online adaptation methods under a unified hardware and software platform with a pre-built online stream. The figure reports average batch latency, throughput, peak memory usage, and the number of online trainable parameters. Error bars indicate one standard deviation over three repeated measurements.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_82704-fig-5.tif"/>
</fig>
<p>From <xref ref-type="table" rid="table-18">Table 18</xref> and <xref ref-type="fig" rid="fig-5">Fig. 5</xref>, RaL-TTA uses 192 online-trainable parameters, with a total runtime of 3.1044 s, an average batch latency of 59.70 ms/batch, a throughput of 4188.37 samples/s, and a peak memory usage of 274.84 MB. Its overhead is higher than Source-Only and basic TTA baselines because it performs risk gating and protected inference, but the cost remains bounded and the number of online trainable parameters is unchanged at 192. These results support the feasibility of lightweight edge-side deployment while also clarifying that the additional safety mechanisms introduce a modest runtime and memory cost.</p>

</sec>
<sec id="s4_7">
<label>4.7</label>
<title>Startup-Window Robustness</title>
<p>The target-domain normal startup window is important for AdaBN calibration, target-domain normal-reference estimation, and sample-level threshold initialization. To evaluate the feasibility and limitation of this assumption, we test RaL-TTA under different startup-window sizes and contamination rates. This robustness experiment uses three seeds and independently resampled startup windows; therefore, the clean <inline-formula id="ieqn-517"><mml:math id="mml-ieqn-517"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mn>1000</mml:mn></mml:math></inline-formula> setting is intended to evaluate robustness trends rather than exactly duplicate the five-seed main protocol in <xref ref-type="table" rid="table-9">Table 9</xref>. The results are shown in <xref ref-type="table" rid="table-19">Table 19</xref> and <xref ref-type="fig" rid="fig-6">Fig. 6</xref>.</p>
<table-wrap id="table-19">
<label>Table 19</label>
<caption>
<title>Robustness under limited and contaminated startup windows.</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/> </colgroup>
<thead>
<tr>
<th><inline-formula id="ieqn-520"><mml:math id="mml-ieqn-520"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> Size</th>
<th>Contamination</th>
<th>P2_TPR</th>
<th>P2_FPR</th>
<th>P2_F1</th>
<th>P3_FPR</th>
</tr>
</thead>
<tbody>
<tr>
<td>256</td>
<td>0%</td>
<td>1.0000 <inline-formula id="ieqn-521"><mml:math id="mml-ieqn-521"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
<td>0.0349 <inline-formula id="ieqn-522"><mml:math id="mml-ieqn-522"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0040</td>
<td>0.9609 <inline-formula id="ieqn-523"><mml:math id="mml-ieqn-523"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0043</td>
<td>0.0344 <inline-formula id="ieqn-524"><mml:math id="mml-ieqn-524"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td>256</td>
<td>5%</td>
<td>0.6567 <inline-formula id="ieqn-525"><mml:math id="mml-ieqn-525"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.3132</td>
<td>0.0265 <inline-formula id="ieqn-526"><mml:math id="mml-ieqn-526"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0167</td>
<td>0.7362 <inline-formula id="ieqn-527"><mml:math id="mml-ieqn-527"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.2059</td>
<td>0.0225 <inline-formula id="ieqn-528"><mml:math id="mml-ieqn-528"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0125</td>
</tr>
<tr>
<td>256</td>
<td>10%</td>
<td>0.3700 <inline-formula id="ieqn-529"><mml:math id="mml-ieqn-529"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0068</td>
<td>0.0113 <inline-formula id="ieqn-530"><mml:math id="mml-ieqn-530"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0029</td>
<td>0.5300 <inline-formula id="ieqn-531"><mml:math id="mml-ieqn-531"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0093</td>
<td>0.0252 <inline-formula id="ieqn-532"><mml:math id="mml-ieqn-532"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0078</td>
</tr>
<tr>
<td>1000</td>
<td>0%</td>
<td>0.9881 <inline-formula id="ieqn-533"><mml:math id="mml-ieqn-533"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0023</td>
<td>0.0349 <inline-formula id="ieqn-534"><mml:math id="mml-ieqn-534"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0019</td>
<td>0.9549 <inline-formula id="ieqn-535"><mml:math id="mml-ieqn-535"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0032</td>
<td>0.0332 <inline-formula id="ieqn-536"><mml:math id="mml-ieqn-536"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td>1000</td>
<td>5%</td>
<td>0.9870 <inline-formula id="ieqn-537"><mml:math id="mml-ieqn-537"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0034</td>
<td>0.0405 <inline-formula id="ieqn-538"><mml:math id="mml-ieqn-538"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0075</td>
<td>0.9484 <inline-formula id="ieqn-539"><mml:math id="mml-ieqn-539"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0093</td>
<td>0.0332 <inline-formula id="ieqn-540"><mml:math id="mml-ieqn-540"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0000</td>
</tr>
<tr>
<td>1000</td>
<td>10%</td>
<td>0.5526 <inline-formula id="ieqn-541"><mml:math id="mml-ieqn-541"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.3148</td>
<td>0.0546 <inline-formula id="ieqn-542"><mml:math id="mml-ieqn-542"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0190</td>
<td>0.6308 <inline-formula id="ieqn-543"><mml:math id="mml-ieqn-543"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.2523</td>
<td>0.0358 <inline-formula id="ieqn-544"><mml:math id="mml-ieqn-544"><mml:mo>&#x00B1;</mml:mo></mml:math></inline-formula> 0.0024</td>
</tr>
</tbody>
</table>
</table-wrap><fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Startup-window robustness under contaminated startup windows. Curves report the perturbation-stage F1-score under different startup contamination rates for <inline-formula id="ieqn-518"><mml:math id="mml-ieqn-518"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mn>256</mml:mn></mml:math></inline-formula> and <inline-formula id="ieqn-519"><mml:math id="mml-ieqn-519"><mml:msub><mml:mi>W</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mn>1000</mml:mn></mml:math></inline-formula>. Error bars indicate one standard deviation over three random seeds.</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_82704-fig-6.tif"/>
</fig>
<p>The results in <xref ref-type="table" rid="table-19">Table 19</xref> and <xref ref-type="fig" rid="fig-6">Fig. 6</xref> show that RaL-TTA performs reliably when the startup window is clean, even with 256 normal samples. With a sufficiently large startup window, the method also tolerates mild contamination. However, small contaminated windows or heavily contaminated startup data degrade calibration reliability. This indicates that the normal startup window is a practical but nontrivial deployment assumption, and further robust initialization under contaminated startup conditions remains future work.</p>

</sec>
<sec id="s4_8">
<label>4.8</label>
<title>Discussion and Limitations</title>
<p>First, the trust score in this work is defined from a security-risk perspective. It is suitable for real-time edge-side security monitoring, but does not cover all dimensions of general trust management, such as long-term reputation, social interaction history, resource reliability, or quality-of-service evaluation. Second, RaL-TTA assumes that a short normal startup window is available for unsupervised calibration. Although this assumption is realistic during commissioning, maintenance restart, or trusted initialization, heavily contaminated startup data may weaken anchor construction and threshold estimation. Third, although this study includes external validation on X-IIoTID, both Edge-IIoTset and X-IIoTID are still public benchmark datasets. Real long-term industrial deployments may involve more complex temporal drift, device heterogeneity, and unseen attack behaviors. Fourth, false-positive control remains important for practical edge security systems. Although the main Edge-IIoTset setting reduces the perturbation-stage FPR to 0.0410, deployment-time alert fatigue still needs to be considered. In deployment, the trust score can be combined with multi-window smoothing, alert aggregation, or operator-confirmed escalation to reduce unnecessary alarms. Finally, the ablation results indicate that the conservative rollback branch has limited numerical effect under the main stream, and therefore more adaptive criteria for when to activate sample-level protection deserve further study.</p>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Conclusion</title>
<p>This paper has proposed RaL-TTA, a risk-aware lightweight test-time adaptation (TTA) framework for security-oriented dynamic trust evaluation of IIoT edge nodes under cross-domain online streams. By combining a low-dimensional source-domain trust baseline, KS-based entropy-shift detection, SafeBrake risk gating, AdaBN anchor protection, and budgeted sample-level safeguards, RaL-TTA selectively maintains the online model under low-risk conditions and freezes unsafe adaptation under high-risk attack-contaminated streams. Experiments on Edge-IIoTset demonstrate that RaL-TTA improves perturbation-stage attack detection over general TTA baselines while substantially reducing false positives and maintaining post-perturbation stability. External validation on X-IIoTID further evaluates cross-service generalization across Modbus, MQTT, and WebSocket target services. Additional ablation, sensitivity, startup-window robustness, calibration, and overhead analyses show that the proposed method achieves a favorable balance among detection performance, trust-score reliability, adaptation safety, and edge-side efficiency. Future work will focus on more robust initialization under heavily contaminated startup windows, real edge-hardware deployment, and broader validation across long-term industrial traffic streams.</p>
</sec>
</body>
<back>
<ack>
<p>Not applicable.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>This work was supported by the National Natural Science Foundation of China [Grant No. 62102449] and the Science and Technology Research Project of Henan Province [Grant No. 252102211080].</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>The authors confirm contribution to the paper as follows: conceptualization, Qiuguo Guan and Zhiyu Ren; methodology, Qiuguo Guan; software and validation, Qiuguo Guan; formal analysis, Qiuguo Guan and Zhiyu Ren; writing&#x2014;original draft preparation, Qiuguo Guan; writing&#x2014;review and editing, Qiuguo Guan and Zhiyu Ren; supervision, Zhiyu Ren. All authors reviewed and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>The datasets used in this study are publicly available. Edge-IIoTset and X-IIoTID are available from their public dataset sources cited in the manuscript. The experimental code and processed scripts can be made available from the corresponding author upon reasonable request.</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable. This study does not involve human participants, human data, or animal experiments.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Alotaibi</surname> <given-names>B</given-names></string-name></person-group>. <article-title>A survey on industrial Internet of Things security: requirements, attacks, AI-based solutions, and edge computing opportunities</article-title>. <source>Sensors</source>. <year>2023</year>;<volume>23</volume>(<issue>17</issue>):<fpage>7470</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s23177470</pub-id>; <pub-id pub-id-type="pmid">37687926</pub-id></mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>DQ</given-names></string-name>, <string-name><surname>Liang</surname> <given-names>HL</given-names></string-name>, <string-name><surname>Zeng</surname> <given-names>XJ</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>ZD</given-names></string-name>, <string-name><surname>Li</surname> <given-names>MH</given-names></string-name></person-group>. <article-title>Edge computing application, architecture, and challenges in ubiquitous power Internet of Things</article-title>. <source>Front Energy Res</source>. <year>2022</year>;<volume>10</volume>:<fpage>850252</fpage>. doi:<pub-id pub-id-type="doi">10.3389/fenrg.2022.850252</pub-id>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>China Academy of Information and Communications Technology</collab></person-group>. <article-title>White paper on Internet of Things (2020) [Internet]. Beijing, China: China Academy of Information and Communications Technology</article-title>; <comment>2020 [cited 2026 Mar 19]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="http://www.caict.ac.cn/">http://www.caict.ac.cn/</ext-link>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ferraris</surname> <given-names>D</given-names></string-name>, <string-name><surname>Fernandez-Gago</surname> <given-names>C</given-names></string-name>, <string-name><surname>Roman</surname> <given-names>R</given-names></string-name>, <string-name><surname>Lopez</surname> <given-names>J</given-names></string-name></person-group>. <article-title>A survey on IoT trust model frameworks</article-title>. <source>J Supercomput</source>. <year>2024</year>;<volume>80</volume>(<issue>6</issue>):<fpage>8259</fpage>&#x2013;<lpage>96</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s11227-023-05765-4</pub-id>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Garagad</surname> <given-names>V</given-names></string-name>, <string-name><surname>Iyer</surname> <given-names>N</given-names></string-name></person-group>. <article-title>Dynamic trust-based device legitimacy assessment towards secure IoT interactions</article-title>. <source>J Commun Softw Syst</source>. <year>2022</year>;<volume>18</volume>(<issue>3</issue>):<fpage>269</fpage>&#x2013;<lpage>76</lpage>. doi:<pub-id pub-id-type="doi">10.24138/jcomss-2021-0189</pub-id>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Motmi</surname> <given-names>A</given-names></string-name>, <string-name><surname>Alhazmi</surname> <given-names>S</given-names></string-name>, <string-name><surname>Abu-Khadrah</surname> <given-names>A</given-names></string-name>, <string-name><surname>Al-Akhras</surname> <given-names>M</given-names></string-name>, <string-name><surname>Alhosban</surname> <given-names>F</given-names></string-name></person-group>. <article-title>Trust management in industrial Internet of Things using a trusted E-Lithe protocol</article-title>. <source>Int J Adv Comput Sci Appl</source>. <year>2022</year>;<volume>13</volume>(<issue>2</issue>):<fpage>334</fpage>&#x2013;<lpage>45</lpage>. doi:<pub-id pub-id-type="doi">10.14569/ijacsa.2022.0130239</pub-id>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jayasinghe</surname> <given-names>U</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>GM</given-names></string-name>, <string-name><surname>Um</surname> <given-names>TW</given-names></string-name>, <string-name><surname>Shi</surname> <given-names>Q</given-names></string-name></person-group>. <article-title>Machine learning based trust computational model for IoT services</article-title>. <source>IEEE Trans Sustain Comput</source>. <year>2019</year>;<volume>4</volume>(<issue>1</issue>):<fpage>39</fpage>&#x2013;<lpage>52</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tsusc.2018.2839623</pub-id>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Duque Anton</surname> <given-names>SD</given-names></string-name>, <string-name><surname>Sinha</surname> <given-names>S</given-names></string-name>, <string-name><surname>Schotten</surname> <given-names>HD</given-names></string-name></person-group>. <article-title>Anomaly-based intrusion detection in industrial data with SVM and random forests</article-title>. In: <conf-name>Proceedings of the 27th International Conference on Software, Telecommunications and Computer Networks (SoftCOM); 2019 Sep 19&#x2013;21; Split, Croatia</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2019</year>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Rabanser</surname> <given-names>S</given-names></string-name>, <string-name><surname>G&#x00FC;nnemann</surname> <given-names>S</given-names></string-name>, <string-name><surname>Lipton</surname> <given-names>ZC</given-names></string-name></person-group>. <article-title>Failing loudly: an empirical study of methods for detecting dataset shift</article-title>. In: <conf-name>Proceedings of the Advances in Neural Information Processing Systems 32 (NeurIPS 2019); 2019 Dec 8&#x2013;14; Vancouver, Canada</conf-name>. <publisher-loc>Red Hook, NY, USA</publisher-loc>: <publisher-name>Curran Associates, Inc.</publisher-name>; <year>2019</year>. p. <fpage>1396</fpage>&#x2013;<lpage>408</lpage>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Niu</surname> <given-names>SC</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>JX</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>YF</given-names></string-name>, <string-name><surname>Wen</surname> <given-names>ZQ</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>YF</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>PL</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Towards stable test-time adaptation in dynamic wild world</article-title>. In: <conf-name>Proceedings of the Eleventh International Conference on Learning Representations (ICLR 2023); 2023 May 1&#x2013;5</conf-name>; <publisher-loc>Kigali, Rwanda</publisher-loc>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Chen</surname> <given-names>J</given-names></string-name>, <string-name><surname>Mao</surname> <given-names>FJ</given-names></string-name>, <string-name><surname>Lv</surname> <given-names>ZH</given-names></string-name>, <string-name><surname>Tang</surname> <given-names>JH</given-names></string-name></person-group>. <article-title>EdgeFD: an edge-friendly drift-aware fault diagnosis system for industrial IoT</article-title>. In: <conf-name>Proceedings of the 2023 IEEE 23rd International Conference on Communication Technology (ICCT); 2023 Oct 13&#x2013;16; Wuxi, China</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2023</year>. p. <fpage>390</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Fink</surname> <given-names>O</given-names></string-name>, <string-name><surname>Van Gool</surname> <given-names>L</given-names></string-name>, <string-name><surname>Dai</surname> <given-names>DX</given-names></string-name></person-group>. <article-title>Continual test-time domain adaptation</article-title>. In: <conf-name>Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR); 2022 Jun 18&#x2013;24; New Orleans, LA, USA</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2022</year>. p. <fpage>7201</fpage>&#x2013;<lpage>11</lpage>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>YH</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>NY</given-names></string-name>, <string-name><surname>Shi</surname> <given-names>JP</given-names></string-name>, <string-name><surname>Hou</surname> <given-names>XD</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>JY</given-names></string-name></person-group>. <article-title>Adaptive batch normalization for practical domain adaptation</article-title>. <source>Pattern Recognit</source>. <year>2018</year>;<volume>80</volume>(<issue>3</issue>):<fpage>109</fpage>&#x2013;<lpage>17</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.patcog.2018.03.005</pub-id>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Liang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Hu</surname> <given-names>DP</given-names></string-name>, <string-name><surname>Feng</surname> <given-names>JS</given-names></string-name></person-group>. <article-title>Do we really need to access the source data? Source hypothesis transfer for unsupervised domain adaptation</article-title>. In: <conf-name>Proceedings of the 37th International Conference on Machine Learning (ICML); 2020 Jul 13&#x2013;18; Virtual Event</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>PMLR</publisher-name>; <year>2020</year>. p. <fpage>6028</fpage>&#x2013;<lpage>39</lpage>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liang</surname> <given-names>J</given-names></string-name>, <string-name><surname>He</surname> <given-names>R</given-names></string-name>, <string-name><surname>Tan</surname> <given-names>T</given-names></string-name></person-group>. <article-title>A comprehensive survey on test-time adaptation under distribution shifts</article-title>. <source>Int J Comput Vis</source>. <year>2025</year>;<volume>133</volume>(<issue>1</issue>):<fpage>31</fpage>&#x2013;<lpage>64</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s11263-024-02181-w</pub-id>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>DQ</given-names></string-name>, <string-name><surname>Shelhamer</surname> <given-names>E</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>ST</given-names></string-name>, <string-name><surname>Olshausen</surname> <given-names>BA</given-names></string-name>, <string-name><surname>Darrell</surname> <given-names>T</given-names></string-name></person-group>. <article-title>TENT: fully test-time adaptation by entropy minimization</article-title>. In: <conf-name>Proceedings of the 9th International Conference on Learning Representations (ICLR 2021); 2021 May 3&#x2013;7; Virtual Event</conf-name>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Yuan</surname> <given-names>YG</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>BB</given-names></string-name>, <string-name><surname>Hou</surname> <given-names>L</given-names></string-name>, <string-name><surname>Sun</surname> <given-names>F</given-names></string-name>, <string-name><surname>Shen</surname> <given-names>HW</given-names></string-name>, <string-name><surname>Cheng</surname> <given-names>XQ</given-names></string-name></person-group>. <article-title>TEA: test-time energy adaptation</article-title>. In: <conf-name>Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR); 2024 Jun 17&#x2013;21; Seattle, WA, USA</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2024</year>. p. <fpage>23901</fpage>&#x2013;<lpage>11</lpage>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Bar</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Shaer</surname> <given-names>S</given-names></string-name>, <string-name><surname>Romano</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Protected test-time adaptation via online entropy matching: a betting approach</article-title>. In: <conf-name>Proceedings of the Advances in Neural Information Processing Systems 37 (NeurIPS 2024); 2024 Dec 10&#x2013;15; Vancouver, Canada</conf-name>. <publisher-loc>Red Hook, NY, USA</publisher-loc>: <publisher-name>Curran Associates, Inc.</publisher-name>; <year>2024</year>. p. <fpage>85467</fpage>&#x2013;<lpage>99</lpage>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Guan</surname> <given-names>QG</given-names></string-name>, <string-name><surname>Ren</surname> <given-names>ZY</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>QL</given-names></string-name></person-group>. <article-title>LoFT-IIoT: a lightweight trust feature extraction method for industrial Internet of Things</article-title>. In: <conf-name>Proceedings of the 2025 IEEE 25th International Conference on Communication Technology (ICCT); 2025 Oct 16&#x2013;18; Shenyang, China</conf-name>. <publisher-loc>Piscataway, NJ, USA</publisher-loc>: <publisher-name>IEEE</publisher-name>; <year>2025</year>. p. <fpage>919</fpage>&#x2013;<lpage>23</lpage>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Guo</surname> <given-names>C</given-names></string-name>, <string-name><surname>Pleiss</surname> <given-names>G</given-names></string-name>, <string-name><surname>Sun</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Weinberger</surname> <given-names>KQ</given-names></string-name></person-group>. <article-title>On calibration of modern neural networks</article-title>. In: <conf-name>Proceedings of the 34th International Conference on Machine Learning (ICML); 2017 Aug 6&#x2013;11; Sydney, Australia</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>PMLR</publisher-name>; <year>2017</year>. p. <fpage>1321</fpage>&#x2013;<lpage>30</lpage>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ferrag</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Friha</surname> <given-names>O</given-names></string-name>, <string-name><surname>Hamouda</surname> <given-names>D</given-names></string-name>, <string-name><surname>Maglaras</surname> <given-names>L</given-names></string-name>, <string-name><surname>Janicke</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Edge-IIoTset: a new comprehensive realistic cyber security dataset of IoT and IIoT applications for centralized and federated learning</article-title>. <source>IEEE Access</source>. <year>2022</year>;<volume>10</volume>:<fpage>40281</fpage>&#x2013;<lpage>306</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2022.3165809</pub-id>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Al-Hawawreh</surname> <given-names>M</given-names></string-name>, <string-name><surname>Sitnikova</surname> <given-names>E</given-names></string-name>, <string-name><surname>Aboutorab</surname> <given-names>N</given-names></string-name></person-group>. <article-title>X-IIoTID: a connectivity- and device-agnostic intrusion dataset for industrial Internet of Things</article-title>. <source>IEEE Internet Things J</source>. <year>2022</year>;<volume>9</volume>(<issue>5</issue>):<fpage>3962</fpage>&#x2013;<lpage>77</lpage>. doi:<pub-id pub-id-type="doi">10.1109/jiot.2021.3102056</pub-id>.</mixed-citation></ref>
</ref-list>
</back></article>