Jul 2026· IEEE Power & Energy Society General Meeting· pp. 1-5· 1 citation· 20 references
Computer Science
TL;DR
An XAI-based anomaly detection framework tailored for DER networks (ExCYDER) that distinguished between coherent and inconsistent alerts without compromising detection accuracy, demonstrating that integrated verification within XAI-based ADS enhances interpretability, auditability, and operational robustness for DER-focused SOCs.
Abstract
The rapid growth of Distributed Energy Resources (DERs) has significantly expanded the cyber-attack surface of modern power grids. Furthermore, increasing sophistication in attack techniques demands anomaly detection systems (ADS) that are accurate, interpretable, and reliable to support DER cybersecurity. While ML-based ADS provide strong detection capabilities, their "black-box" nature reduces operator trust and limits Security Operation Center’s (SOC) ability to effectively interpret alerts and respond, highlighting the need for explainable Artificial Intelligence (XAI) to ensure transparency and operational confidence. This paper presents an XAI-based anomaly detection framework tailored for DER networks (ExCYDER). The proposed framework uses a self-verifying mechanism that validates ADS alerts to ensure trustworthy decision-making. ExCYDER combines LightGBM with SHAP to check whether each model decision aligns with its feature-attribution evidence, allowing the system to confirm that its internal reasoning is consistent and reliable. Experiments on a realistic DNP3 dataset achieved over 98% detection accuracy, an average rule–SHAP consistency of 44.6%, a SHAP latency of 14.5 ms per alert, and a confidence deviation within ±5%, demonstrating stable verification behavior with minimal computational overhead. The framework distinguished between coherent and inconsistent alerts without compromising detection accuracy, demonstrating that integrated verification within XAI-based ADS enhances interpretability, auditability, and operational robustness for DER-focused SOCs.
An explainable machine learning-based framework for accurate, transparent, and reliable DDoS attack detection in an SDN environment that combines reliable DDoS detection with transparent, analyst-oriented decision support for SDN security monitoring is developed.
J. Malik, N. Naz, Muhammad Saleem et al.· Italian National Conference...· 0 citations
The study demonstrates that integrating deep learning with stable explainable AI offers a practical and trustworthy solution for zero-day intrusion detection, contributing validated evidence to an area where explanation reliability is rarely examined.
Sumayyamol Mukkil Muhammed Ismail, M. Ahmed, S. Begum· Applied Informatics· 0 citations
A conceptual framework is proposed that combines detection, explanation, and orchestrated response in a continuous feedback loop that is suitable for zero trust and IoT-enabled critical-infrastructure environments that will allow for continuous retraining of the model.
Jayesh Dalmet· Journal of Digital Security...· 0 citations
The increase in the number and complexity of interconnected systems requires new methods to identify potential threats in today’s hyperconnected world. This trend affects systems ranging from smart homes and Internet of Things (IoT) devices to critical infrastructure which must be equipped with the corresponding cyber...
P. Vezeteu, Nicolae-Daniel Boboc, D. Năstac· Algorithms· 0 citations
This paper discusses how explanation outputs can be operationalized in cybersecurity training labs through auditable “rationale artifacts,” while clarifying that any observed reduction in false positives should be interpreted as the outcome of explanation-guided interventions (e.g., threshold tuning and triage rule adj...
Ahmad Almufarreh, Ashfaq Ahmad, Muhammad Arshad et al.· Frontiers of Computer Scienc...· 0 citations
A hybrid multi-layered intrusion detection framework combining traditional machine learning, Deep Neural Architectures (DenseNN), and ensemble methods to evaluate zero-day resilience within cloud-level backend connectivity interfacing EV and V2X management ecosystems is proposed.
H. Sakr, Ahmed A. El-Douh, M. Lapina et al.· Computers· 0 citations
Exploring how generative AI could make machine vision more accessible to businesses. The post GenEye in a Box: Making Machine Vision Something You Can Just Ask For appeared first on GPT-Lab.
Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.
MIT News · Artificial Intelligence· news.mit.eduOct 6, 2026
With $2.1 million funding from Google.org, the open-source Public Transit Intelligence Hub will unify public transit monitoring, operations, and passenger communication.
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.