Skip to content

Self-Verifying Anomaly Detection using Explainable AI for Cybersecurity of DER Networks

Jul 2026 · IEEE Power & Energy Society General Meeting · pp. 1-5 · 1 citation · 20 references
Computer Science

TL;DR

An XAI-based anomaly detection framework tailored for DER networks (ExCYDER) that distinguished between coherent and inconsistent alerts without compromising detection accuracy, demonstrating that integrated verification within XAI-based ADS enhances interpretability, auditability, and operational robustness for DER-focused SOCs.

Abstract

The rapid growth of Distributed Energy Resources (DERs) has significantly expanded the cyber-attack surface of modern power grids. Furthermore, increasing sophistication in attack techniques demands anomaly detection systems (ADS) that are accurate, interpretable, and reliable to support DER cybersecurity. While ML-based ADS provide strong detection capabilities, their "black-box" nature reduces operator trust and limits Security Operation Center’s (SOC) ability to effectively interpret alerts and respond, highlighting the need for explainable Artificial Intelligence (XAI) to ensure transparency and operational confidence. This paper presents an XAI-based anomaly detection framework tailored for DER networks (ExCYDER). The proposed framework uses a self-verifying mechanism that validates ADS alerts to ensure trustworthy decision-making. ExCYDER combines LightGBM with SHAP to check whether each model decision aligns with its feature-attribution evidence, allowing the system to confirm that its internal reasoning is consistent and reliable. Experiments on a realistic DNP3 dataset achieved over 98% detection accuracy, an average rule–SHAP consistency of 44.6%, a SHAP latency of 14.5 ms per alert, and a confidence deviation within ±5%, demonstrating stable verification behavior with minimal computational overhead. The framework distinguished between coherent and inconsistent alerts without compromising detection accuracy, demonstrating that integrated verification within XAI-based ADS enhances interpretability, auditability, and operational robustness for DER-focused SOCs.

Read PDF

Similar papers

#software testing Open access Sep 2026

Intelligent DDoS Attack Detection in Software-Defined Networks Using Explainable Machine Learning

An explainable machine learning-based framework for accurate, transparent, and reliable DDoS attack detection in an SDN environment that combines reliable DDoS detection with transparent, analyst-oriented decision support for SDN security monitoring is developed.

J. Malik, N. Naz, Muhammad Saleem et al. · 0 citations
#explainable ai Open access Sep 2026

Evaluating Explainable Hybrid Intrusion Detection Models Under Zero-Day Conditions

The study demonstrates that integrating deep learning with stable explainable AI offers a practical and trustworthy solution for zero-day intrusion detection, contributing validated evidence to an area where explanation reliability is rarely examined.

Sumayyamol Mukkil Muhammed Ismail, M. Ahmed, S. Begum · 0 citations
Review Open access Aug 2026

AI-DRIVEN THREAT DETECTION AND AUTOMATED RESPONSE IN MODERN CYBERSECURITY SYSTEMS: A SYSTEMATIC REVIEW AND FRAMEWORK

A conceptual framework is proposed that combines detection, explanation, and orchestrated response in a continuous feedback loop that is suitable for zero trust and IoT-enabled critical-infrastructure environments that will allow for continuous retraining of the model.

Jayesh Dalmet · 0 citations
#explainable ai Review Open access Sep 2026

Artificial Intelligence for Anomaly Detection in Cyber Defense: A Critical Review of Methodological Trends, Datasets, and Explainability

The increase in the number and complexity of interconnected systems requires new methods to identify potential threats in today’s hyperconnected world. This trend affects systems ranging from smart homes and Internet of Things (IoT) devices to critical infrastructure which must be equipped with the corresponding cyber...

P. Vezeteu, Nicolae-Daniel Boboc, D. Năstac · 0 citations
Open access Aug 2026

Enhancing cybersecurity with Explainable Artificial Intelligence: technical framework and applications in training labs

This paper discusses how explanation outputs can be operationalized in cybersecurity training labs through auditable “rationale artifacts,” while clarifying that any observed reduction in false positives should be interpreted as the outcome of explanation-guided interventions (e.g., threshold tuning and triage rule adj...

Ahmad Almufarreh, Ashfaq Ahmad, Muhammad Arshad et al. · 0 citations
Open access Sep 2026

Explainable and Deployment-Aware Zero-Day Intrusion Detection for Cloud-Level Backend and Management Ecosystems in EV/V2X Cyber–Physical Systems

A hybrid multi-layered intrusion detection framework combining traditional machine learning, Deep Neural Architectures (DenseNN), and ensemble methods to evaluate zero-day resilience within cloud-level backend connectivity interfacing EV and V2X management ecosystems is proposed.

H. Sakr, Ahmed A. El-Douh, M. Lapina et al. · 0 citations

Related blog posts

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.