Skip to content
Open access

TAE-IDS: a trust-aware explainable intrusion detection framework using attention-based meta-ensemble learning with blockchain validation

Aug 2026 · Frontiers in Artificial Intelligence · Vol 9 · 0 citations · 35 references
Medicine

TL;DR

TAE-IDS, a Trust-Aware Explainable Intrusion Detection Framework that integrates attention-based meta-ensemble learning, SHapley Additive exPlanations (SHAP)-driven explainability, and blockchain-inspired tamper-evident validation within a unified cybersecurity architecture, is proposed.

Abstract

Recent intrusion detection systems (IDS) increasingly rely on machine learning (ML) and deep learning techniques to detect sophisticated cyberattacks. However, many existing frameworks still suffer from limited explainability, black-box decision-making, and the absence of secure trust verification mechanisms for intrusion records. To address these challenges, this paper proposes TAE-IDS, a Trust-Aware Explainable Intrusion Detection Framework that integrates attention-based meta-ensemble learning, SHapley Additive exPlanations (SHAP)-driven explainability, and blockchain-inspired tamper-evident validation within a unified cybersecurity architecture. The proposed framework employs heterogeneous base classifiers, namely Logistic Regression (LR), Extra Trees (ET), and XGBoost (XGB), to capture diverse network traffic characteristics. Uncertainty-aware meta-features, including logits, confidence scores, and entropy representations, are extracted from the base learners and processed by an adaptive Bidirectional Long Short-Term Memory (BiLSTM) attention-based meta-classifier for contextual intrusion reasoning and adaptive ensemble aggregation. To enhance transparency and analyst trust, SHAP-based explainability is incorporated to provide both global and local interpretations of intrusion predictions. Furthermore, a blockchain-inspired tamper-evident validation mechanism based on SHA-256 cryptographic hashing is integrated to enable tamper-proof intrusion logging, immutable auditing, and secure forensic verification of IDS outputs. The proposed framework was evaluated on the UNSW-NB15 and CICIDS2017 benchmark datasets under both binary and multiclass intrusion detection settings. Experimental results demonstrate that TAE-IDS achieves strong intrusion detection performance, interpretable intrusion reasoning, and effective blockchain-assisted tamper-evident validation on the evaluated benchmark datasets. The integration of explainable artificial intelligence (XAI) and blockchain-assisted validation enhances transparency, forensic traceability, and the integrity of intrusion records while providing a foundation for future validation in operational network environments.

Read PDF

Similar papers

Open access Sep 2026

Explainable and Deployment-Aware Zero-Day Intrusion Detection for Cloud-Level Backend and Management Ecosystems in EV/V2X Cyber–Physical Systems

A hybrid multi-layered intrusion detection framework combining traditional machine learning, Deep Neural Architectures (DenseNN), and ensemble methods to evaluate zero-day resilience within cloud-level backend connectivity interfacing EV and V2X management ecosystems is proposed.

H. Sakr, Ahmed A. El-Douh, M. Lapina et al. · 0 citations
Review Open access 2026

Explaining the Black Box: An XAI-Driven Trustworthiness Audit of ML-Based IoT Intrusion Detection Across Attack Categories

Machine learning classifiers for Internet of Things (IoT) intrusion detection routinely report accuracy above 99%, yet this conceals systematic failures on operationally important minority categories such as BruteForce and Web-based attacks, and the global explainability analyses usually applied to these models say not...

Khalid Alalawi · 0 citations
Open access 2026

Explainable Artificial Intelligence-Based Intrusion Detection for Zero-Day Cyber Attacks: A Hybrid Transformer–Long Short-Term Memory Framework with SHapley Additive exPlanations and Local Interpretable Model-Agnostic Explanations Interpretability

The findings indicate that embedding explainability directly into the zero-day detection pipeline, rather than treating it as an auxiliary diagnostic layer, materially improves both detection robustness and analyst-facing transparency without incurring prohibitive computational overhead.

Samuel Okechukwu Nnaji, Christabel Linda Uchenwa, Anyalebechi Felicia Nneamaka · 0 citations
Sep 2026

SA-IDS: a self-supervised and adaptive intrusion detection system for edge-based IIoT security with label-free drift resilience

SA-IDS is proposed, a self-supervised and adaptive intrusion detection framework designed for resource-constrained IIoT edge devices that leverages contrastive self-supervised learning to learn robust representations of benign telemetry data without requiring labeled attacks.

Mahdi Ajdani, Maziar Asmani · 0 citations
Open access Sep 2026

A lightweight blockchain-inspired hybrid intrusion detection system with ensemble learning for tamper-proof auditing

The rapid expansion of digital systems has intensified the complexity of cyber threats, rendering traditional intrusion detection systems (IDS) inadequate against evolving attacks. This study proposes a hybrid IDS (H-IDS) that integrates supervised (SVM, Random Forest, CatBoost, DNN) and unsupervised (Isolation Forest,...

Shailendra Mishra, Reem Alshenaifi, Ruba Ahmed Alfahidah · 0 citations
Conference Aug 2026

TwinSentinel-X: A Trust-Aware Digital Twin and SHAP-based Explainable Framework for Real-Time IoT Anomaly Detection

The proliferation of IoT devices has made it imperative to develop intelligent cybersecurity systems which can detect new and evolving threats. Rule-based IDS-Intrusion detection Systems are not always able to identify sophisticated and emerging attacks in highly dynamic IoT environments. This work proposes TwinSentine...

Bolishetty Hemasri Varma, Chittela Tej Avinash Reddy, K. Geetha · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.