Aug 2026· Journal of Intelligent Decision Making and Information Science· 0 citations· 30 references
TL;DR
XAI-CTI is presented, a novel Explainable Artificial Intelligence (XAI)-driven Cyber Threat Intelligence (CTI) framework designed to enable proactive and adaptive cyberattack detection that achieves state-of-the-art detection accuracy and reduces analyst investigation time.
Abstract
The rapid proliferation of sophisticated cyberattacks poses an unprecedented challenge to existing intrusion detection and threat intelligence systems. Conventional machine learning (ML)-based detection approaches, while effective in controlled environments, suffer from opacity, limited adaptability, and an inability to proactively anticipate novel attack vectors. This paper presents XAI-CTI, a novel Explainable Artificial Intelligence (XAI)-driven Cyber Threat Intelligence (CTI) framework designed to enable proactive and adaptive cyberattack detection. The proposed framework integrates a multi-layered threat intelligence pipeline comprising real-time data ingestion, federated feature engineering, ensemble-based anomaly detection, and post-hoc explainability modules grounded in SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-agnostic Explanations). By coupling gradient-boosted ensemble models with attention-based deep neural architectures, XAI-CTI achieves state-of-the-art detection accuracy of 99.21% on the CIC-IDS2017 dataset, 98.87% on the UNSW-NB15 benchmark, and 97.94% on the NSL-KDD corpus, with average false positive rates below 0.31%. The adaptive learning module employs continual learning strategies to mitigate concept drift and maintain performance under evolving threat landscapes. Extensive evaluations demonstrate that the explainability layer reduces analyst investigation time by 43% compared to black-box baselines while maintaining detection fidelity.
Cybersecurity systems face significant challenges in detecting sophisticated cyber threats, predicting future attacks, and executing rapid response actions in dynamic network environments. To address these limitations, this study proposes XAI-HDRL, an Explainable AI-Driven Hybrid Deep Reinforcement Learning Framework for Real-Time Cyber Threat Detection, Prediction, and Automated Response. The proposed framework integrates Artificial Protozoa Optimization (APO) for optimal feature selection, CNN-BiLSTM for accurate threat detection, LIME for model explainability and transparent decision-making, Proximal Policy Optimization (PPO)-based Deep Reinforcement Learning for automated response generation, and a Transformer-based Threat Prediction Module for proactive cyberattack forecasting. The framework was evaluated using the CICIDS2017 dataset and simulated in the NS-3 network simulator integrated with Python/TensorFlow. Experimental results were compared with SentinelAI-IDS, CNN-LSTM, and Explainable Deep Learning-based Threat Detection System (XDLTDS). The proposed XAI-HDRL achieved a Threat Prediction Accuracy of 98.84%, Attack Mitigation Rate of 97.52%, Resource Utilization of 91.37%, and Network Throughput of 978.45 Mbps, while reducing Detection Time to 18.63 ms and Response Time to 12.47 ms. Compared with the strongest baseline (XDLTDS), the proposed framework improved Threat Prediction Accuracy by 5.73%, Attack Mitigation Rate by 8.29%, Resource Utilization by 10.08%, and Network Throughput by 11.82%, while reducing Detection Time and Response Time by 41.72% and 47.94%, respectively. These findings demonstrate that XAI-HDRL provides a highly effective, explainable, and autonomous cybersecurity solution capable of enhancing real-time threat intelligence, predictive defense, and automated incident response for next-generation network security infrastructures.
A. Raj, Sasanko Sekhar Gantayat, K. Venkatesh et al.· 2026 7th International Confe...· 0 citations
This chapter explores innovative AI technologies, including Machine Learning, Deep Learning, Reinforcement Learning, Explainable AI, and Generative AI, for intelligent attack detection, prediction, and mitigation and discusses current challenges, implementation limitations, and future research directions.
S. Mohanarangan, G. Shoba, D. Karthika et al.· International Journal of Com...· 0 citations
The increasing sophistication of cyber threats poses serious challenges to national security (NS) and critical infrastructure (CI), requiring adaptive and intelligence-driven cyber defense mechanisms. While recent artificial intelligence (AI)-based methods have improved detection capabilities, many existing solutions focus on isolated threat categories or rely on single-layer detection models, limiting their robustness and deployment feasibility. This work presents a unified and adaptive artificial intelligence (AI)-enabled cyber threats detection framework that simultaneously addresses intrusion detection, malware detection and phishing detection within a cyber warfare context. The proposed framework integrates hybrid detection strategies with a threshold-based decision mechanism to balance detection effectiveness, false positive control and computational efficiency. A formal mathematical formulation supports feature representation, classification and evaluation. The framework is evaluated using multiple publicly available benchmark datasets under a consistent experimental setup. The experimental results demonstrate strong performance across threat categories, achieving detection accuracy above 96%, F1-scores exceeding 95% and false positive rates below 2%, highlighting the framework's effectiveness and deployment suitability for mission-critical cyber defense applications.
Krishan Berwal, D. Makhija, R. Bodade· 2026 6th International Confe...· 0 citations
This study presents an Explainable Artificial Intelligence (XAI)-based cyber threat detection framework that combines Long Short-Term Memory (LSTM) and Autoencoder models for accurate and transparent threat detection.
Indu Asitha, M. N.· International Journal of Com...· 0 citations
Advanced persistent threats, zero-day exploits, encrypted command-and-control traffic, and botnet campaigns continue to reduce the reliability of conventional intrusion detection systems because static detectors provide limited transparency and weak adaptation under traffic drift. This paper presents an explainable and adaptive machine learning framework that integrates a LightGBM threat detector, SHAP-based decision explanations, density-aware concept drift detection, active incremental updating, and a contextual bandit defense policy. LightGBM is adopted because its leaf-wise gradient boosting structure provides high discrimination for heterogeneous flow features while maintaining low inference latency and native feature-importance support. The framework is evaluated on CIC-IDS2017, UNSW-NB15, and ToN_IoT using stratified train-validation-test splits, leakage prevention, five-run validation, and a 48-hour Kafka-based streaming simulation. The proposed model achieved 99.1% accuracy, 98.7% F1-score, 98.4% recall, and a 0.007 false alarm rate. During streaming evaluation, 14 adaptive model updates reduced mean detection latency from 27.4 s to 11.2 s, while SHAP explanations based on DNS entropy, JA3 rarity, packet interval, and flow-duration evidence reduced analyst triage time by 23%. Comparative results show that the proposed explainable adaptive pipeline improves detection reliability, reduces false alarms, and supports auditable mitigation decisions better than static and black-box IDS baselines.
P. A. Prakash, Salath Joseph A, A. M et al.· 2026 7th International Confe...· 0 citations
By minimizing false alarms, the proposed framework improves the efficiency of security operations, reduces alert fatigue among cybersecurity analysts, and enables security teams to prioritize genuine threats more effectively.
Reily Kaium, Lizi Alasa, K. Robert et al.· The Eastasouth Journal of In...· 0 citations
A weeklong summer workshop brought higher education faculty to campus to explore how AI and machine learning materials can be adapted for their classrooms.