Skip to content
Conference

LLM-Based Explainable Intrusion Detection System for IoT Networks

Jul 2026 · International Conference on Smart Communications and Networking · pp. 1-8 · 0 citations · 33 references

Abstract

The rapid proliferation of the Internet of Things (IoT) has increased network complexity and exposed IoT infrastructures to diverse and evolving cyber threats. Traditional intrusion detection systems (IDSs), whether signature based or machine learning based, often struggle to adapt to emerging attack patterns and frequently operate as “black boxes” with limited interpretability. To address these challenges, this paper proposes a novel Large Language Model-based Explainable IDS for IoT networks. The system fine-tunes an open-source large language model, LLaMA 3.3, to jointly perform intrusion detection and natural-language explanation generation. The model is trained on multiple IoT security datasets, namely CIC-IoT-2023 [1], BoT-IoT [2], and ToN_IoT [3] to recognize various attack types, including distributed denial-of-service (DDoS), botnet activity, man-in-the-middle (MITM), and data exfiltration. Experimental results show that the fine-tuned LLM outperforms both zero-shot LLM baselines and traditional machine learning classifiers, achieving competitive accuracy while delivering concise, human-readable explanations for each prediction. By integrating detection and explainability within a single model, the proposed framework enhances transparency, interpretability, and usability.

View source

Similar papers

Open access Aug 2026

Explainable Deep Learning Intrusion Detection Framework for Securing IoT Environment

A new explainable hybrid IDS architecture for IoT environments named XABiL-IDS (Explainable Attention-based Bi LSTM-Intrusion Detection System) in response to this challenge, which uses a robust hybrid architecture to detect attacks effectively.

Ravi Patni, Gurvinder Singh · 0 citations
#explainable ai Review Open access Sep 2026

Explainable AI-Based Intrusion Detection Systems for IoT Environments: A Systematic Literature Review

This paper aims to provide a foundational resource to guide future research on reliable, explainable, and practical IoT intrusion detection systems by identifying the problems addressed in current research and highlighting the limitations in the literature.

Murat Varol, Aykut Karakaya · 0 citations
Open access Aug 2026

HybridML CyberShield for explainable proactive intrusion detection in enterprise and IoT networks

The framework introduces CNN–BiLSTM deep learning networks to represent traffic in a spatiotemporal manner and adopts ensemble machine learning classifiers to enhance the robustness of traffic detection and its interpretability, to enhance the robustness of traffic detection and its interpretability.

Ramesh N. S. V. S. C. Sripada, A. Bhavani, Kiran B. Malagi et al. · 0 citations
Open access 2026

From IoT Vulnerabilities to Intrusion Detection: An Explainable Vulnerability-Aware Machine Learning Framework for Smart Home IoT Security

The swift deployment of IoT-based smart home appliances has increased the attack surface for the smart environment and exposed it to attacks like botnet command-and-control communications, brute force attacks, denial-of-service attacks, and web-based attacks. Even though the Intrusion Detection Systems (IDSs) that use...

Huda Aldawghan, Mounir Frikha · 0 citations
Open access Aug 2026

LLM-Integrated Anomaly Detection for IoT Networks: Framework Structure

A machine learning-based framework to tackle issues in traditional systems in traditional systems is introduced by combining large language models (LLMs) and is effective in identifying possible threats as well as filling the semantic gap.

Mamoon M. Saeed, Rashid A. Saeed, Salah Hagahmoodi et al. · 0 citations
Open access 2026

Tiny-IDS: A Pruned Ensemble Distillation Pipeline for Lightweight and Explainable IoT Intrusion Detection

The results demonstrate the effectiveness of the proposed Tiny-IDS in accurately identifying Mirai botnet attacks on IoT devices along with a minimal memory footprint and low inference time, while also emphasizing the need for IoT-specific evaluation frameworks to support the development of robust and lightweight IDS.

Shyam Bahadur, Sudhanshu Kumar Jha, Rajkumar Singh Rathore et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.