Skip to content
#federated learning Open access

An Explainable AI-Driven Cyber Threat Intelligence Framework for Proactive and Adaptive Cyberattack Detection

Aug 2026 · Journal of Intelligent Decision Making and Information Science · 0 citations · 30 references

TL;DR

XAI-CTI is presented, a novel Explainable Artificial Intelligence (XAI)-driven Cyber Threat Intelligence (CTI) framework designed to enable proactive and adaptive cyberattack detection that achieves state-of-the-art detection accuracy and reduces analyst investigation time.

Abstract

The rapid proliferation of sophisticated cyberattacks poses an unprecedented challenge to existing intrusion detection and threat intelligence systems. Conventional machine learning (ML)-based detection approaches, while effective in controlled environments, suffer from opacity, limited adaptability, and an inability to proactively anticipate novel attack vectors. This paper presents XAI-CTI, a novel Explainable Artificial Intelligence (XAI)-driven Cyber Threat Intelligence (CTI) framework designed to enable proactive and adaptive cyberattack detection. The proposed framework integrates a multi-layered threat intelligence pipeline comprising real-time data ingestion, federated feature engineering, ensemble-based anomaly detection, and post-hoc explainability modules grounded in SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-agnostic Explanations). By coupling gradient-boosted ensemble models with attention-based deep neural architectures, XAI-CTI achieves state-of-the-art detection accuracy of 99.21% on the CIC-IDS2017 dataset, 98.87% on the UNSW-NB15 benchmark, and 97.94% on the NSL-KDD corpus, with average false positive rates below 0.31%. The adaptive learning module employs continual learning strategies to mitigate concept drift and maintain performance under evolving threat landscapes. Extensive evaluations demonstrate that the explainability layer reduces analyst investigation time by 43% compared to black-box baselines while maintaining detection fidelity.

Read PDF

Similar papers

Conference Jul 2026

XAI-HDRL: An Intelligent Framework for Cyber Threat Prediction and Automated Security Response

Cybersecurity systems face significant challenges in detecting sophisticated cyber threats, predicting future attacks, and executing rapid response actions in dynamic network environments. To address these limitations, this study proposes XAI-HDRL, an Explainable AI-Driven Hybrid Deep Reinforcement Learning Framework for Real-Time Cyber Threat Detection, Prediction, and Automated Response. The proposed framework integrates Artificial Protozoa Optimization (APO) for optimal feature selection, CNN-BiLSTM for accurate threat detection, LIME for model explainability and transparent decision-making, Proximal Policy Optimization (PPO)-based Deep Reinforcement Learning for automated response generation, and a Transformer-based Threat Prediction Module for proactive cyberattack forecasting. The framework was evaluated using the CICIDS2017 dataset and simulated in the NS-3 network simulator integrated with Python/TensorFlow. Experimental results were compared with SentinelAI-IDS, CNN-LSTM, and Explainable Deep Learning-based Threat Detection System (XDLTDS). The proposed XAI-HDRL achieved a Threat Prediction Accuracy of 98.84%, Attack Mitigation Rate of 97.52%, Resource Utilization of 91.37%, and Network Throughput of 978.45 Mbps, while reducing Detection Time to 18.63 ms and Response Time to 12.47 ms. Compared with the strongest baseline (XDLTDS), the proposed framework improved Threat Prediction Accuracy by 5.73%, Attack Mitigation Rate by 8.29%, Resource Utilization by 10.08%, and Network Throughput by 11.82%, while reducing Detection Time and Response Time by 41.72% and 47.94%, respectively. These findings demonstrate that XAI-HDRL provides a highly effective, explainable, and autonomous cybersecurity solution capable of enhancing real-time threat intelligence, predictive defense, and automated incident response for next-generation network security infrastructures.

A. Raj, Sasanko Sekhar Gantayat, K. Venkatesh et al. · 0 citations
Open access Jul 2026

Innovative AI-Driven Intelligent Attack Detection, Prediction, and Autonomous Response for Next-Generation Cyber Security

This chapter explores innovative AI technologies, including Machine Learning, Deep Learning, Reinforcement Learning, Explainable AI, and Generative AI, for intelligent attack detection, prediction, and mitigation and discusses current challenges, implementation limitations, and future research directions.

S. Mohanarangan, G. Shoba, D. Karthika et al. · 0 citations
Conference Jul 2026

AI-Enabled Cyber Warfare Defense: A Unified Hybrid Framework for Intelligent Threat Detection

The increasing sophistication of cyber threats poses serious challenges to national security (NS) and critical infrastructure (CI), requiring adaptive and intelligence-driven cyber defense mechanisms. While recent artificial intelligence (AI)-based methods have improved detection capabilities, many existing solutions focus on isolated threat categories or rely on single-layer detection models, limiting their robustness and deployment feasibility. This work presents a unified and adaptive artificial intelligence (AI)-enabled cyber threats detection framework that simultaneously addresses intrusion detection, malware detection and phishing detection within a cyber warfare context. The proposed framework integrates hybrid detection strategies with a threshold-based decision mechanism to balance detection effectiveness, false positive control and computational efficiency. A formal mathematical formulation supports feature representation, classification and evaluation. The framework is evaluated using multiple publicly available benchmark datasets under a consistent experimental setup. The experimental results demonstrate strong performance across threat categories, achieving detection accuracy above 96%, F1-scores exceeding 95% and false positive rates below 2%, highlighting the framework's effectiveness and deployment suitability for mission-critical cyber defense applications.

Krishan Berwal, D. Makhija, R. Bodade · 0 citations
Conference Jul 2026

Explainable AI and Machine Learning Framework for Cyber Threat Detection and Adaptive Defense Systems

Advanced persistent threats, zero-day exploits, encrypted command-and-control traffic, and botnet campaigns continue to reduce the reliability of conventional intrusion detection systems because static detectors provide limited transparency and weak adaptation under traffic drift. This paper presents an explainable and adaptive machine learning framework that integrates a LightGBM threat detector, SHAP-based decision explanations, density-aware concept drift detection, active incremental updating, and a contextual bandit defense policy. LightGBM is adopted because its leaf-wise gradient boosting structure provides high discrimination for heterogeneous flow features while maintaining low inference latency and native feature-importance support. The framework is evaluated on CIC-IDS2017, UNSW-NB15, and ToN_IoT using stratified train-validation-test splits, leakage prevention, five-run validation, and a 48-hour Kafka-based streaming simulation. The proposed model achieved 99.1% accuracy, 98.7% F1-score, 98.4% recall, and a 0.007 false alarm rate. During streaming evaluation, 14 adaptive model updates reduced mean detection latency from 27.4 s to 11.2 s, while SHAP explanations based on DNS entropy, JA3 rarity, packet interval, and flow-duration evidence reduced analyst triage time by 23%. Comparative results show that the proposed explainable adaptive pipeline improves detection reliability, reduces false alarms, and supports auditable mitigation decisions better than static and black-box IDS baselines.

P. A. Prakash, Salath Joseph A, A. M et al. · 0 citations
Open access Aug 2026

Artificial Intelligence-Based Cyber Threat Detection and Response for Critical Infrastructure Security

By minimizing false alarms, the proposed framework improves the efficiency of security operations, reduces alert fatigue among cybersecurity analysts, and enables security teams to prioritize genuine threats more effectively.

Reily Kaium, Lizi Alasa, K. Robert et al. · 0 citations

Related blog posts

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.