Generative AI and synthetic media generation tools have enabled widespread media manipulation tools and raised important privacy concerns with misinformation, identity fraud and the verification of authenticity of media. Most of the current convolution-based deepfake detection methods are hard to be deployed in real scenarios and hard to be interpretable, especially because they have limited ability to capture long-range spatial dependency. It introduces an explainable deepfake face image detection framework based on a vision transformer network for performing powerful binary classification of manipulated and real facial images and an explainable face image localization framework for localizing deepfake image faces. The proposed system involves a transformer-encoder backbone for extracting features through a patches-wise process, which proves suitable for modeling the subtle changes of features when the processes of manipulating the image are designed. To make the network more interpretable, and aid the understanding of the transformer attention distribution as well as localization of manipulated facial regions, a dedicated attention rollout mechanism is embedded. A dedicated rollout mechanism for attention distribution of the transformer and heatmap generating and attention spatial localization are incorporated to improve the interpretability of the network. The framework comprises an end-to-end inference pipeline, such as image preprocessing, estimation of confidence scores, fake-real classification, generation of explainable visualization and storage of prediction history using an integrated database system. An experimental evaluation shows the system can effectively detect deepfakes while also providing accurate local information as justification for classification decisions, contributing to transparency, reliability and trust towards automated synthetic media detection systems.
K. Phani, Shaik Mahaboob, Jailan PG Student et al.· 2026 International Conferenc...· 0 citations
The escalation of security attacks has led to a growing complexity and posed serious challenges for traditional IDS paradigms to securing and sustaining a resilient network infrastructure. Current solutions are generally inefficient at optimizing detection parameters, cannot detect attacks that have previously not been encountered and do not offer clear decision making processes. In this work, a framework for optimization of secure data protection using quantum computing is proposed which combines machine learning, anomaly detection, explainable AI and quantum computing inspired optimization techniques in a single cybersecurity framework to overcome these limitations. Selected network traffic from CICIDS2017 data set is used in the system to detect various types of attacks such as Denial-of-Service (DoS), Distributed Denial-of-Service (DDoS), PortScan and WebAttack. The multi-class intrusion detection uses an XGBoost (Extreme Gradient Boosted) Classifier to learn discriminative patterns from network flow features. The Quantum Approximate Optimization Algorithm (QAOA) is integrated to optimize certain model parameters (learning rate, tree depth and decision thresholds) that can enhance detection performance. Moreover, an Isolation Forest model is run concurrently to detect zero day and unknown anomalies not found in the training set. To enhance the interpretability, SHAP-based explainability is incorporated to measure the network's contribution to each prediction by its features. All the framework is deployed via Flask and is displayed on an interactive dashboard that shows attack classifications, threat risk scores, optimized configurations and explanatory insights. The hybrid architecture proposed shows a novel combination of classical artificial intelligence and quantum optimization techniques to create an adaptive, explainable, and intelligent cybersecurity solution.
M. Anusha, M. Neha, PG Student et al.· 2026 International Conferenc...· 0 citations
Phishing websites still pose a threat to internet users by using well-known domain names and confusing URL formats to trick them into divulging confidential information. This research proposes a phishing website detection system and a cyberattack prevention system based on a deep learning model designed to detect whether raw URLs are phishing or legitimate, leveraging a transformer model. The system analyzes URL sequences to identify patterns, domain name irregularities, suspicious tokens, unusual lengths, special character usage, and deceptive subdomains. A web interface enables the user to input URLs, and the Flask backend performs pre-processing, tokenization, model inference, and suspicious feature identification. The proposed method fuses the transformer-based semantic representation of the URL and lexical feature analysis to reliably detect phishing and provide explainable warning features. The system creates a prediction label, confidence score, and suspicious features in real time to support the decision-making process. This work provides a practical and scalable solution for phishing identification, user protection, and web-based cyberattack prevention.
Dr. N. Ramadevi, Dr. K. Uday, Kumar et al.· 2026 International Conferenc...· 0 citations
Large-scale DDoS attacks remain a serious threat to today's networked systems, which aim to make services unavailable by sending a massive amount of traffic. The traditional detection methods are mostly about attack categorization and are not that context-aware or actionable in providing support to security analysts. We propose SentinelsGuard AI, a self-learning DDoS classification and mitigation system that is built from a combination of machine learning, retrieval-augmented knowledge, and LLM-based reasoning in one platform. The proposed system is realized as a Flask-based web application, which processes the network flow statistics data, extracted from incoming traffic, and transforms the data to generate representative features of the network flows, before detecting the attacks using the XGBoost classifier. After classification, the framework accesses domain-specific attack intelligence from a structured Retrieval-Augmented Generation (RAG) knowledge base with profiles of multiple categories of DDoS attacks. This contextual information is used with LLM-enabled reasoning to derive comprehensible security explanations, determine the severity of the attack, and suggest the firewall mitigation rules that can be applied. The framework stores analysis data in a SQLite database for operational monitoring, and displays security events in an interactive dashboard that includes traffic visualization, attack logs, and threat summaries. The architecture proposed brings statistical learning together with contextual knowledge of cybersecurity and attempts to bridge the gap between automatic attack detection and explainable incident response. It integrates all the key features of a classification-based network security decision support platform into a single stream, enabling a classification-based approach to network security to become more interpretable and usable in reality: persistent logging, visualization, knowledge retrieval, reasoning, and system recommendation of mitigations.
K. Phani, P. Karthik, PG Student et al.· 2026 International Conferenc...· 0 citations