Detection Depth and Distributed Trust in AI-Based IoT Intrusion Detection: A Systematic Analysis

Blockchain-integrated deep learning intrusion detection systems for the Internet of Things have attracted growing research attention, yet the relationship between detection depth and blockchain trust scope in these architectures has not been examined systematically. This analysis codes 50 published studies against seven dimensions: protocol-awareness level (PA-LEVEL), blockchain role, blockchain integration depth, consensus mechanism, federated learning use, deployment domain, and study quality. A three-tier PA-LEVEL taxonomy distinguishes flow-level statistical detection (L1), protocol field awareness (L2), and protocol state and semantic awareness (L3). Forty-eight of the 50 included studies operate at L1 irrespective of blockchain integration depth or deployment domain, and 18 studies describe blockchain integration without evaluation. End-to-end detection-to-logging latency, the operationally critical trust metric, is reported in only four studies.

Three gap clusters are identified and mapped to an established gap taxonomy. The first is a methodological gap: the dominant evaluation datasets do not meet IoT representativeness criteria for device traffic, protocol coverage, or attack specificity. The second is an empirical gap: blockchain trust properties are asserted without benchmarking. The third is a knowledge gap with a practical-knowledge dimension: no study co-designs detection depth and trust scope as jointly constrained variables derived from a shared threat model. The three gaps form a dependency chain that constrains the order in which they can be resolved, and a research agenda addressing each cluster in sequence is proposed.

Keywords: Intrusion detection systems, Internet of Things, Deep learning, Blockchain, Protocol-awareness, Trust management, Systematic analysis.