XAI-HDRL: An Intelligent Framework for Cyber Threat Prediction and Automated Security Response
Abstract
Cybersecurity systems face significant challenges in detecting sophisticated cyber threats, predicting future attacks, and executing rapid response actions in dynamic network environments. To address these limitations, this study proposes XAI-HDRL, an Explainable AI-Driven Hybrid Deep Reinforcement Learning Framework for Real-Time Cyber Threat Detection, Prediction, and Automated Response. The proposed framework integrates Artificial Protozoa Optimization (APO) for optimal feature selection, CNN-BiLSTM for accurate threat detection, LIME for model explainability and transparent decision-making, Proximal Policy Optimization (PPO)-based Deep Reinforcement Learning for automated response generation, and a Transformer-based Threat Prediction Module for proactive cyberattack forecasting. The framework was evaluated using the CICIDS2017 dataset and simulated in the NS-3 network simulator integrated with Python/TensorFlow. Experimental results were compared with SentinelAI-IDS, CNN-LSTM, and Explainable Deep Learning-based Threat Detection System (XDLTDS). The proposed XAI-HDRL achieved a Threat Prediction Accuracy of 98.84%, Attack Mitigation Rate of 97.52%, Resource Utilization of 91.37%, and Network Throughput of 978.45 Mbps, while reducing Detection Time to 18.63 ms and Response Time to 12.47 ms. Compared with the strongest baseline (XDLTDS), the proposed framework improved Threat Prediction Accuracy by 5.73%, Attack Mitigation Rate by 8.29%, Resource Utilization by 10.08%, and Network Throughput by 11.82%, while reducing Detection Time and Response Time by 41.72% and 47.94%, respectively. These findings demonstrate that XAI-HDRL provides a highly effective, explainable, and autonomous cybersecurity solution capable of enhancing real-time threat intelligence, predictive defense, and automated incident response for next-generation network security infrastructures.