Blockchain-anchored multi-discriminator GAN architecture for real-time zero-day attack detection in social IoT edge networks with explainable audit trails
Abstract
Social Internet of Things (SIoT) deployments, in which heterogeneous edge devices form long-lived peer-to-peer relationships governed by social-network primitives, have become prime targets for zero-day attackers that exploit local topology, abnormal behaviour of previously unknown devices, and resource-constrained gateways. Signature- and entropy-based intrusion detection systems (IDS) fail to generalise to unseen attack families, while most Generative Adversarial Network (GAN) based detectors rely on a single discriminator that fuses orthogonal evidence streams, ignore topological evidence from minority classes, and provide no externally auditable trail. We present BMG-Sentinel, a multi-discriminator GAN architecture that combines a synthetic edge-traffic generator; three complementary discriminators reasoning over signature, behavioural and topological evidence; a permissioned Hyperledger Fabric ledger that records threshold-signed on-chain detection digests while pinning off-chain evidence in IPFS; and an explainability layer that fuses SHAP attributions, DiCE counterfactuals and attention rollouts into regulator-ready forensic reports. We formalise the multi-discriminator min–max objective, derive a convex anomaly-fusion rule together with an explicit statement of the assumptions under which it is Bayes-consistent, and give an edge-gateway-friendly federated training schedule. On the zero-day subset of the BoT-IoT, ToN-IoT and CIC-IDS2018 benchmarks, augmented with two held-out zero-day classes, BMG-Sentinel attains an F1 of 0.942 and AUROC of 0.974, outperforming six baselines by 7.2-−24.2 F1 points and 4.4-−19.4 AUROC points. To rule out generator-induced construct-validity bias, we corroborate these results with a leave-one-attack-family-out protocol on natural unseen attacks and with strict cross-dataset transfer. The system runs at 9.8 ms inference latency on a Jetson Xavier NX and anchors 265 transactions per second on a 16-node PBFT cluster. Ablation, calibration, SMOTE-controlled baseline, and adversarial-robustness studies validate that the three discriminators, the federated channel and the audit trail each contribute meaningfully, and that detection-performance claims are cleanly separated from audit-integrity claims.