Aug 2026· Journal of Intelligent Decision Making and Information Science· 0 citations· 30 references
TL;DR
XAI-CTI is presented, a novel Explainable Artificial Intelligence (XAI)-driven Cyber Threat Intelligence (CTI) framework designed to enable proactive and adaptive cyberattack detection that achieves state-of-the-art detection accuracy and reduces analyst investigation time.
Abstract
The rapid proliferation of sophisticated cyberattacks poses an unprecedented challenge to existing intrusion detection and threat intelligence systems. Conventional machine learning (ML)-based detection approaches, while effective in controlled environments, suffer from opacity, limited adaptability, and an inability to proactively anticipate novel attack vectors. This paper presents XAI-CTI, a novel Explainable Artificial Intelligence (XAI)-driven Cyber Threat Intelligence (CTI) framework designed to enable proactive and adaptive cyberattack detection. The proposed framework integrates a multi-layered threat intelligence pipeline comprising real-time data ingestion, federated feature engineering, ensemble-based anomaly detection, and post-hoc explainability modules grounded in SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-agnostic Explanations). By coupling gradient-boosted ensemble models with attention-based deep neural architectures, XAI-CTI achieves state-of-the-art detection accuracy of 99.21% on the CIC-IDS2017 dataset, 98.87% on the UNSW-NB15 benchmark, and 97.94% on the NSL-KDD corpus, with average false positive rates below 0.31%. The adaptive learning module employs continual learning strategies to mitigate concept drift and maintain performance under evolving threat landscapes. Extensive evaluations demonstrate that the explainability layer reduces analyst investigation time by 43% compared to black-box baselines while maintaining detection fidelity.
Cybersecurity systems face significant challenges in detecting sophisticated cyber threats, predicting future attacks, and executing rapid response actions in dynamic network environments. To address these limitations, this study proposes XAI-HDRL, an Explainable AI-Driven Hybrid Deep Reinforcement Learning Framework for Real-Time Cyber Threat Detection, Prediction, and Automated Response. The proposed framework integrates Artificial Protozoa Optimization (APO) for optimal feature selection, CNN-BiLSTM for accurate threat detection, LIME for model explainability and transparent decision-making, Proximal Policy Optimization (PPO)-based Deep Reinforcement Learning for automated response generation, and a Transformer-based Threat Prediction Module for proactive cyberattack forecasting. The framework was evaluated using the CICIDS2017 dataset and simulated in the NS-3 network simulator integrated with Python/TensorFlow. Experimental results were compared with SentinelAI-IDS, CNN-LSTM, and Explainable Deep Learning-based Threat Detection System (XDLTDS). The proposed XAI-HDRL achieved a Threat Prediction Accuracy of 98.84%, Attack Mitigation Rate of 97.52%, Resource Utilization of 91.37%, and Network Throughput of 978.45 Mbps, while reducing Detection Time to 18.63 ms and Response Time to 12.47 ms. Compared with the strongest baseline (XDLTDS), the proposed framework improved Threat Prediction Accuracy by 5.73%, Attack Mitigation Rate by 8.29%, Resource Utilization by 10.08%, and Network Throughput by 11.82%, while reducing Detection Time and Response Time by 41.72% and 47.94%, respectively. These findings demonstrate that XAI-HDRL provides a highly effective, explainable, and autonomous cybersecurity solution capable of enhancing real-time threat intelligence, predictive defense, and automated incident response for next-generation network security infrastructures.
A. Raj, Sasanko Sekhar Gantayat, K. Venkatesh et al.· 2026 7th International Confe...· 0 citations
This chapter explores innovative AI technologies, including Machine Learning, Deep Learning, Reinforcement Learning, Explainable AI, and Generative AI, for intelligent attack detection, prediction, and mitigation and discusses current challenges, implementation limitations, and future research directions.
S. Mohanarangan, G. Shoba, D. Karthika et al.· International Journal of Com...· 0 citations
The increasing sophistication of cyber threats poses serious challenges to national security (NS) and critical infrastructure (CI), requiring adaptive and intelligence-driven cyber defense mechanisms. While recent artificial intelligence (AI)-based methods have improved detection capabilities, many existing solutions focus on isolated threat categories or rely on single-layer detection models, limiting their robustness and deployment feasibility. This work presents a unified and adaptive artificial intelligence (AI)-enabled cyber threats detection framework that simultaneously addresses intrusion detection, malware detection and phishing detection within a cyber warfare context. The proposed framework integrates hybrid detection strategies with a threshold-based decision mechanism to balance detection effectiveness, false positive control and computational efficiency. A formal mathematical formulation supports feature representation, classification and evaluation. The framework is evaluated using multiple publicly available benchmark datasets under a consistent experimental setup. The experimental results demonstrate strong performance across threat categories, achieving detection accuracy above 96%, F1-scores exceeding 95% and false positive rates below 2%, highlighting the framework's effectiveness and deployment suitability for mission-critical cyber defense applications.
Krishan Berwal, D. Makhija, R. Bodade· 2026 6th International Confe...· 0 citations
The rapid advancement of digital communication and networking technologies has resulted in a significant increase in the frequency and sophistication of cyber threats, creating new challenges for securing modern computer networks. Traditional intrusion detection approaches mainly depend on signature-based techniques and predefined security rules, making them less effective against newly emerging and continuously evolving cyber attacks. To address these limitations, this study presents an Explainable Artificial Intelligence (XAI)-based cyber threat detection framework that combines Long Short-Term Memory (LSTM) and Autoencoder models for accurate and transparent threat detection. The LSTM model captures sequential network traffic patterns to identify temporal attack behaviours, whereas the Autoencoder detects anomalous activities by learning the characteristics of normal network traffic. The integration of Explainable AI enables users to understand prediction outcomes by highlighting the factors influencing each detection decision. Furthermore, the framework performs quantitative risk assessment, categorizes threats into multiple severity levels, and generates suitable mitigation recommendations through an interactive web-based dashboard. Experimental results demonstrate that the proposed framework provides reliable, interpretable, and effective cyber threat detection, thereby supporting security professionals in making timely and well-informed decisions.
Indu Asitha, M. N.· International Journal of Com...· 0 citations
Advanced persistent threats, zero-day exploits, encrypted command-and-control traffic, and botnet campaigns continue to reduce the reliability of conventional intrusion detection systems because static detectors provide limited transparency and weak adaptation under traffic drift. This paper presents an explainable and adaptive machine learning framework that integrates a LightGBM threat detector, SHAP-based decision explanations, density-aware concept drift detection, active incremental updating, and a contextual bandit defense policy. LightGBM is adopted because its leaf-wise gradient boosting structure provides high discrimination for heterogeneous flow features while maintaining low inference latency and native feature-importance support. The framework is evaluated on CIC-IDS2017, UNSW-NB15, and ToN_IoT using stratified train-validation-test splits, leakage prevention, five-run validation, and a 48-hour Kafka-based streaming simulation. The proposed model achieved 99.1% accuracy, 98.7% F1-score, 98.4% recall, and a 0.007 false alarm rate. During streaming evaluation, 14 adaptive model updates reduced mean detection latency from 27.4 s to 11.2 s, while SHAP explanations based on DNS entropy, JA3 rarity, packet interval, and flow-duration evidence reduced analyst triage time by 23%. Comparative results show that the proposed explainable adaptive pipeline improves detection reliability, reduces false alarms, and supports auditable mitigation decisions better than static and black-box IDS baselines.
P. A. Prakash, Salath Joseph A, A. M et al.· 2026 7th International Confe...· 0 citations
The rapid digital transformation of critical infrastructure has significantly increased its exposure to complex and continuously evolving cyber threats, creating an urgent need for intelligent and adaptive cybersecurity solutions. Conventional security mechanisms, such as signature-based and rule-based intrusion detection systems, often struggle to identify novel attack patterns and provide timely responses to emerging threats. To address these limitations, this study proposes an artificial intelligence (AI)-driven framework for cyber threat detection and automated response that strengthens the security, resilience, and operational reliability of critical infrastructure environments. The experimental evaluation demonstrates that AI-based techniques substantially outperform traditional cybersecurity methods in terms of detection performance. Conventional rule-based systems achieve an average detection accuracy of approximately 68%, whereas machine learning and deep learning models improve the accuracy to nearly 80% and 88%, respectively. The proposed AI-driven framework delivers the highest performance, achieving an overall detection accuracy of approximately 94%. This superior performance highlights its capability to accurately identify both previously known attacks and sophisticated zero-day threats. Beyond detection accuracy, the study evaluates response time, which plays a crucial role in limiting the impact of cyber incidents. The findings reveal that the proposed AI-enabled response mechanism reduces the average response time to approximately 35 seconds, compared with around 150 seconds for manual response processes and 90 seconds for conventional rule-based automation. Such improvements enable faster threat containment, minimize operational disruption, and enhance the resilience of critical infrastructure systems. The framework also demonstrates notable improvements in reducing false positive alerts. The AI-driven approach achieves a false positive rate of approximately 5%, significantly lower than the 20% observed in signature-based systems and the 12% reported for anomaly-based detection methods. By minimizing false alarms, the proposed framework improves the efficiency of security operations, reduces alert fatigue among cybersecurity analysts, and enables security teams to prioritize genuine threats more effectively.
Reily Kaium, Lizi Alasa, K. Robert et al.· The Eastasouth Journal of In...· 0 citations