Explainable Artificial Intelligence for Cyberattack Detection in Industrial IoT Environments
DOI:
https://doi.org/10.71229/zwvq5m76Keywords:
Explainable Ai , SHAP, Cyberattack Detection, Industrial Iot, , XGBoost,, Cyberattack DetectionAbstract
The growth of Industrial Internet of Things (IIoT) has greatly increased the attack surface against critical infrastructure such as manufacturing, energy and transportation systems. While machine learning (ML) intrusion detection systems (IDS) are accurate, they are opaque and thus difficult for operators to trust or comply with regulations. So In this paper, an Explainable AI (XAI) enhanced framework for cyberattack detection in IIoT networks is proposed. We perform ensemble learning models: Random Forest (RF) and Extreme Gradient Boosting (XGBoost) and apply SHapley Additive exPlanations (SHAP) and Local Interpretable Model-Agnostic Explanations (LIME) as post-hoc explainability techniques for two publicly available benchmark datasets: Edge-IIoTset and CICIoT2023. Experimental results shows that XGBoost model is capable of 98.9% detection accuracy and 99.2% F1 score in 14 attack categories. SHAP selects the most discriminative traffic features for each attack class, and LIME generates instance-level explanations of the decisions to be made by a non-expert operator. Finally, by closing the transparency gap in the security of the IIoT, the proposed XAI-IDS framework will allow for threat intelligence that is both actionable and human-readable, while no compromising the detection performance. The results serve as a repeatable reference point for future studies in industrial cybersecurity that can be trusted.
References
[1] Alotaibi B. A Survey on Industrial Internet of Things Security: Requirements, Attacks, AI-Based Solutions, and Edge Computing Opportunities. Sensors. 2023 Aug 28;23(17):7470. doi: 10.3390/s23177470. PMID: 37687922; PMCID: PMC10490764.
[2] Alnajim AM, Habib S, Islam M, Thwin SM, Alotaibi F. A Comprehensive Survey of Cybersecurity Threats, Attacks, and Effective Countermeasures in Industrial Internet of Things. Technologies. 2023 Nov;11(6):161. doi: 10.3390/technologies11060161.
[3] Al-Garadi MA, Mohamed A, Al-Ali AK, Du X, Ali I, Guizani M. A Survey of Machine and Deep Learning Methods for Internet of Things (IoT) Security. IEEE Commun Surv Tutor. 2020;22(3):1646-85. doi: 10.1109/COMST.2020.2988293.
[4] Rjoub G, Bentahar J, Abdel Wahab O, Mizouni R, Song A, Cohen R, et al. A Survey on Explainable Artificial Intelligence for Cybersecurity. IEEE Trans Netw Serv Manag. 2023 Dec;20(4):5115-40. doi: 10.1109/TNSM.2023.3282740.
[5] Capuano N, Fenza G, Loia V, Stanzione C. Explainable Artificial Intelligence in Cybersecurity: A Survey. IEEE Access. 2022;10:93575-93600. doi: 10.1109/ACCESS.2022.3204171.
[6] Ferrag MA, Friha O, Hamouda D, Maglaras L, Janicke H. Edge-IIoTset: A New Comprehensive Realistic Cyber Security Dataset of IoT and IIoT Applications for Centralized and Federated Learning. IEEE Access. 2022 Apr;10:40281-306. doi: 10.1109/ACCESS.2022.3165809.
[7] Neto EC, Dadkhah S, Ferreira R, Zohourian A, Lu R, Ghorbani AA. CICIoT2023: A Real-Time Dataset and Benchmark for Large-Scale Attacks in IoT Environment. Sensors. 2023 Jun;23(13):5941. doi: 10.3390/s23135941.
[8] Lundberg SM, Lee SI. A Unified Approach to Interpreting Model Predictions. In: Advances in Neural Information Processing Systems (NeurIPS). 2017;30:4765-74. arXiv: 1705.07874.
[9] Ribeiro MT, Singh S, Guestrin C. "Why Should I Trust You?": Explaining the Predictions of Any Classifier. In: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD 2016); 2016 Aug 13-17; San Francisco, CA, USA. New York: ACM; 2016. p. 1135-44. doi: 10.1145/2939672.2939778.
[10] Ben Ncir CE, Ben HajKacem MA, Alattas M. Enhancing Intrusion Detection Performance using Explainable Ensemble Deep Learning. PeerJ Comput Sci. 2024 Sep 13;10:e2289. doi: 10.7717/peerj-cs.2289. PMCID: PMC11419647.
[11] Gaspar D, Silva P, Silva C. Explainable AI for Intrusion Detection Systems: LIME and SHAP Applicability on Multi-Layer Perceptron. IEEE Access. 2024;12:30164-75. doi: 10.1109/ACCESS.2024.3368377.
[12] Abdulhammed R, Musafer H, Alessa A, Faezipour M, Abuzneid A. Intrusion Detection Framework for Internet of Things with Rule Induction for Model Explanation. Sensors. 2025 Mar;25(6):1845. doi: 10.3390/s25061845.
[13] Sivamohan S, Sridhar SS. An Optimized Model for Network Intrusion Detection Systems in Industry 4.0 using XAI based Bi-LSTM Framework. Neural Comput Appl. 2023 Aug;35(15):11459-75. doi: 10.1007/s00521-023-08319-0.
[14] Djenouri Y, Belhadi A, Srivastava G, Lin JCW. When Explainable AI Meets IoT Applications for Supervised Learning. Cluster Comput. 2023;26(4):2313-23. doi: 10.1007/s10586-022-03656-2.
[15] Mishra S, Sharma A, Saha S. An Intrusion Detection System over the IoT Data Streams Using eXplainable Artificial Intelligence (XAI). Appl Sci. 2025 Feb;15(4):1834. doi: 10.3390/app15041834. PMCID: PMC11820747.
[16] Capuano N, Fenza G, Loia V, Stanzione C. Explainable Artificial Intelligence in Cybersecurity: A Survey. IEEE Access. 2022;10:93575-93600. doi: 10.1109/ACCESS.2022.3204171.
[17] Breiman L. Random Forests. Mach Learn. 2001 Oct;45(1):5-32. doi: 10.1023/A:1010933404324.
[18] Chen T, Guestrin C. XGBoost: A Scalable Tree Boosting System. In: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining; 2016 Aug 13-17; San Francisco, CA, USA. New York: ACM; 2016. p. 785-94. doi: 10.1145/2939672.2939785.
[19] Abosata N, Al-Rubaye S, Inalhan G, Emmanouilidis C. Internet of Things for System Integrity: A Comprehensive Survey on Security, Attacks and Countermeasures for Industrial Applications. Sensors. 2021 May 24;21(11):3654. doi: 10.3390/s21113654. PMCID: PMC8197321.
[20] Liashchynskyi P, Liashchynskyi P. Grid Search, Random Search, Genetic Algorithm: A Big Comparison for NAS. arXiv. 2019;1912.06059. doi: 10.48550/arXiv.1912.06059
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Al-Noor Journal of Engineering Management and Computer Science

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.





