Aug 2026· International journal of computer information systems and industrial management applications· 0 citations
TL;DR
A new explainable hybrid IDS architecture for IoT environments named XABiL-IDS (Explainable Attention-based Bi LSTM-Intrusion Detection System) in response to this challenge, which uses a robust hybrid architecture to detect attacks effectively.
Abstract
In the fast-growing world of Internet of Things (IoT), devices have exploded that are not only efficient but also expose serious security vulnerabilities that can be used as vectors for more advanced cyber-attacks. Traditional IDS has the challenge of false positive rate, which could cause critical operations to be disrupted in various domains from smart medical devices (SMDs) to municipal infrastructure. Machine Learning (ML) and Deep Learning (DL) models are state-of-the art solutions to detect complex, high-dimensional and temporal network anomalies in terms of accuracy but their deployment is still hampered severely due to the fact that they lack interpretability. This paper introduces a new explainable hybrid IDS architecture for IoT environments named XABiL-IDS (Explainable Attention-based Bi LSTM-Intrusion Detection System) in response to this challenge. This study uses a robust hybrid architecture to detect attacks effectively. Global analysis using the SHAP method for determining the most relevant traffic attributes affecting the classification process in the dataset on the other hand local analysis done by LIME for providing explanation at the instance level on the prediction made regarding network flows. The key differentiating feature of this approach compared to earlier methods is the incorporation of both global and local explainability in single pipeline.
LSTM had good detection for frequent attacks and slow-changing patterns, which shows its capacity in learning long-lasting dependencies, which shows its capacity in learning long-lasting dependencies.
Jawad Hussain Awan, Misbah Safdar, Muhammad Ayaz Shirazi et al.· Italian National Conference...· 0 citations
The framework introduces CNN–BiLSTM deep learning networks to represent traffic in a spatiotemporal manner and adopts ensemble machine learning classifiers to enhance the robustness of traffic detection and its interpretability, to enhance the robustness of traffic detection and its interpretability.
Ramesh N. S. V. S. C. Sripada, A. Bhavani, Kiran B. Malagi et al.· Discover Computing· 0 citations
An intelligent cyberattack detection system that applies machine learning and deep learning techniques to classify network traffic as either normal or malicious, and demonstrates the potential of machine learningbased intrusion detection systems in improving network security and supporting the protection of modern smart environments.
KADADHARAPU ANUPRIYA, Dr.S.SWATHI RAO· International Journal of Eng...· 0 citations
A lightweight, explainable IDS that combines a 1D-CNN for spatial feature analysis with SHAP for model interpretation, yielding streamlined models that preserve over 93% F1-score and reduce computational overhead by more than 38%, facilitating millisecond-level inference on edge hardware.
Miracle Udurume, Vladimir V. Shakhov, Insoo Koo· Scientific Reports· 0 citations
The swift deployment of IoT-based smart home appliances has increased the attack surface for the smart environment and exposed it to attacks like botnet command-and-control communications, brute force attacks, denial-of-service attacks, and web-based attacks. Even though the Intrusion Detection Systems (IDSs) that use Machine Learning (ML) algorithms achieve a very high detection rate, most existing solutions focus on predictive performance but lack the ability to link detected attacks to the corresponding vulnerabilities in the Internet of Things (IoT). In this paper, an interpretable vulnerability-aware ML-based approach is presented to solve this problem through the integration of vulnerability classes of IoT, attack classes, network flow attributes, and ML features into one interpretation model. The proposed method uses leakage-aware pre-processing, addressing class imbalance, and compares Random Forest, XGBoost, and soft voting ensemble ML techniques using the CSE-CIC-IDS2018 dataset. Experimental outcomes indicate that XGBoost outperforms the other approaches in terms of performance, with an accuracy of 98.22%, precision of 99.69%, F1-score of 95.36%, ROC-AUC of 99.07%, and only 760 false alarms, which is approximately 19× lower number of false positives compared to Random Forest while keeping a similar level of detection efficiency. In addition to numeric assessment of the approach performance, the suggested model provides the vulnerability-oriented interpretation module that establishes mapping between prominent network flow attributes and possible IoT vulnerability states and attacks. Therefore, the integration of an interpretable vulnerability reasoning component into a high-performing tree-based machine learning algorithm proves to be effective for smart home IoT intrusion detection.
Huda Aldawghan, Mounir Frikha· International Journal of Adv...· 0 citations
A machine learning-based framework to tackle issues in traditional systems in traditional systems is introduced by combining large language models (LLMs) and is effective in identifying possible threats as well as filling the semantic gap.
Mamoon M. Saeed, Rashid A. Saeed, Salah Hagahmoodi et al.· Baghdad Science Journal· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.