Skip to content

Author

Samia Tasnim

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Conference Jul 2026

CriticIDS: LLM-Augmented Intrusion Detection with AutoML and Explainability for IoT Networks

The rapid growth of Internet of Things (IoT) deployments has intensified the need for accurate and deployable network intrusion detection systems. Although machine learning based IDS models achieve high benchmark accuracy, most prioritize predictive performance without providing transparency or analyst-oriented validation mechanisms, limiting practical deployment in heterogeneous IoT environments. This paper presents CriticIDS, an automated and explanation-aware intrusion detection framework that integrates AutoML-driven model selection, SHapley Additive exPlanations (SHAP)–based feature attribution, and a decoupled large language model critique layer. The AutoML backbone adaptively selects and optimizes the most suitable learner for a given feature regime, while SHAP produces structured feature-level explanations. The language model analyzes prediction-attribution consistency and generates concise natural language rationales without participating in realtime inference, preserving CPU-efficient deployment. Across two public IoT intrusion detection datasets from the Canadian Institute for Cybersecurity, CriticIDS achieves up to 99.97% accuracy and 99.96% macro-averaged F1 under reproducible CPU-only evaluation. Comparative analysis against recent state-of-the-art methods demonstrates competitive or superior performance while uniquely combining automated model selection with semantic validation, indicating a practical pathway toward IDS systems that balance accuracy and interpretability.

Tasnimul Hasan, Samia Tasnim · 0 citations