TwinSentinel-X: A Trust-Aware Digital Twin and SHAP-based Explainable Framework for Real-Time IoT Anomaly Detection
Abstract
The proliferation of IoT devices has made it imperative to develop intelligent cybersecurity systems which can detect new and evolving threats. Rule-based IDS-Intrusion detection Systems are not always able to identify sophisticated and emerging attacks in highly dynamic IoT environments. This work proposes TwinSentinel-X, which is a lightweight hybrid anomaly detection framework combining machine learning, digital twin, and XAI using SHAP for real-time cybersecurity monitoring in IoT devices. In the proposed framework, the sensor data is continuously collected, analyzed using machine learning models, and system behavior is validated through a lightweight digital twin. A hybrid fusion technique uses the output of the ML anomaly score, DT deviation score, and SHAP explainability information to improve accuracy and minimize false positives. Additionally, SHAP helps to provide explanations at the level of features. Evaluation is done on an internally created IoT dataset and standard benchmark datasets such as IoT-23 and N-BaIoT. Experimental results show that the performance is excellent with 99.63% accuracy, 97.76% F1-Score, and 100% recall with low computational overhead.