Explainable Artificial Intelligence Framework for Real-Time Cybersecurity Risk Assessment and Intrusion Detection in Enterprise Networks
Rejwan Bin Sulaiman: School of Computer Science and Technology, Northumbria University, Newcastle Upon Tyne, UK, , GBR
Mohammed Amin Almaiah: King Abdullah the II IT School, The University of Jordan, Amman 11942, Jordan, JOR
Published: 2026/09/02
Pages: 60–87
Abstract
The study proposed an explainable framework for real-time intrusion detection and cybersecurity risk assessment in enterprise networks, XRisk-IDS. The model was an adaptive fusion of LightGBM and a CNN–BiGRU temporal branch. The decision process was enhanced by incorporating the concepts of probability calibration, predictive uncertainty, explanation fidelity, explanation stability, asset criticality, and network exposure. The test partition was the official UNSW-NB15 with 82,332 flows in 10 classes, which was used for evaluation. XRisk-IDS achieved 71.68% accuracy, 60.18% balanced accuracy, 48.03% macro-F1, and 95.63% macro-AUROC. It achieved an 18.59 percentage point increase in macro-F1 compared to the standalone CNN–BiGRU, while Random Forest was still better overall. The mean of the explanation quality was 0.7172, and the high-impact attack coverage was 99.45%. The framework was able to process ~26,274 flows/s and had a model footprint of 2.74 MB. XRisk-IDS offers an audit trail between detection and explanation reliability and operational risk. More research is needed to decrease benign false positives and improve multiclass calibration and test performance in real enterprise settings.
Keywords
Explainable Artificial Intelligence Framework for Real-Time Cybersecurity Risk Assessment and Intrusion Detection in Enterprise Networks is licensed under CC BY 4.0
References
- Shtayat, M. M., Hasan, M. K., Sulaiman, R., Islam, S., & Khan, A. U. R. (2023). An explainable ensemble deep learning approach for intrusion detection in Industrial Internet of Things. IEEE Access, 11, 115047–115061. https://doi.org/10.1109/ACCESS.2023.3323573
- Zha, C., Wang, Z., Fan, Y., Bai, B., Zhang, Y., Shi, S., & Zhang, R. (2025). DM-IDS—A network intrusion detection method based on dual-modal fusion. IEEE Transactions on Network and Service Management, 22(4), 3646-3661. https://doi.org/10.1109/TNSM.2025.3565614
- Luo, X., Yin, L., Yang, H., Liu, Z., Chen, W., Jia, S., ... & Xiang, H. (2025). SnifferDog: Comprehensively Learning Heterogeneous Features of Network Traffic to Identify Malicious Flows. IEEE Transactions on Information Forensics and Security. https://doi.org/10.1109/TIFS.2025.3620640
- Zhang, C., Jia, D., Wang, L., Wang, W., Liu, F., & Yang, A. (2022). Comparative research on network intrusion detection methods based on machine learning. Computers & Security, 121, 102861.
- Ali, B. (2025). On the fog's frontline: A federated machine learning approach for industrial network threat detection and intrusion prevention. Journal of Cybersecurity, 11(1), Article tyaf041. https://doi.org/10.1093/cybsec/tyaf041
- Sayem, I. M., Sayed, M. I., Saha, S., & Haque, A. (2024). ENIDS: A deep learning-based ensemble framework for network intrusion detection systems. IEEE Transactions on Network and Service Management, 21(5), 5809–5825. https://doi.org/10.1109/TNSM.2024.3414305
- Molina-Coronado, B., Mori, U., Mendiburu, A., & Miguel-Alonso, J. (2020). Survey of network intrusion detection methods from the perspective of the knowledge discovery in databases process. IEEE Transactions on Network and Service Management, 17(4), 2451-2479.
- Ullah, F., Srivastava, G., Mostarda, L., & Raza, U. (2025). ZTID-IoV: Zero-trust intrusion detection in IoV using neurosymbolic AI approach with federated meta-learning. IEEE Transactions on Consumer Electronics, 71(4), 12037–12046. https://doi.org/10.1109/TCE.2025.3625081
- Barik, K., Misra, S., & Fernandez-Sanz, L. (2024). Adversarial attack detection framework based on optimized weighted conditional stepwise adversarial network. International Journal of Information Security, 23, 2353–2376. https://doi.org/10.1007/s10207-024-00844-w
- Wu, Z., Wang, J., Hu, L., Zhang, Z., & Wu, H. (2020). A network intrusion detection method based on semantic re-encoding and deep learning. Journal of Network and Computer Applications, 164, 102688.
- Munna, M. M. I., Rahman, M. M., Frnda, J., Anwar, M. S., & Kutlimuratov, A. (2025). Elevating intrusion detection and security fortification in intelligent networks through cutting-edge machine learning paradigms. Scientific Reports, 15(1), 39989. https://doi.org/10.1038/s41598-025-23754-w
- Li, J., Wang, Y., Jia, Y., Zeng, L., Feng, W., Jing, X., ... & Fang, B. (2025). IL-IDS: an incremental learning approach with confined data streams for intrusion detection. Cybersecurity, 8(1), 80. https://doi.org/10.1186/s42400-025-00359-4
- Farrukh, Y. A., Wali, S., Khan, I., & Bastian, N. D. (2024). AIS-NIDS: An intelligent and self-sustaining network intrusion detection system. Computers & Security, 144, Article 103982. https://doi.org/10.1016/j.cose.2024.103982
- Sánchez-Zas, C., Larriva-Novo, X., Villagrá, V. A., Solera-Cotanilla, S., & Sanz-Rodrigo, M. (2026). Dynamic characterisation of cyberattacks based on the MITRE ATT&CK framework applied to the optimisation of a mitigation selection process. Future Generation Computer Systems, 177, Article 108272. https://doi.org/10.1016/j.future.2025.108272
- Polónio, J., Moura, J., & Marinheiro, R. N. (2025). Toward automatic detection and mitigation of high-risk cybersecurity vulnerabilities at networked systems. IEEE Access, 13, 181957–181976. https://doi.org/10.1109/ACCESS.2025.3622497
- Alam, K., Kifayat, K., Sampedro, G. A., Karovič, V., & Naeem, T. (2024). SXAD: Shapely explainable AI-based anomaly detection using log data. IEEE Access, 12, 95659–95672. https://doi.org/10.1109/ACCESS.2024.3425472
- Long, Z., Yan, H., Shen, G., Zhang, X., He, H., & Cheng, L. (2024). A Transformer-based network intrusion detection approach for cloud security. Journal of Cloud Computing, 13(1), 5.
- Dai, W., Li, X., Ji, W., & He, S. (2024). Network intrusion detection method based on CNN-BiLSTM-attention model. IEEE access, 12, 53099-53111.
- Schmitt, M. (2023). Securing the digital world: Protecting smart infrastructures and digital industries with artificial intelligence (AI)-enabled malware and intrusion detection. Journal of Industrial Information Integration, 36, Article 100520. https://doi.org/10.1016/j.jii.2023.100520
- Arreche, O., Guntur, T. R., Roberts, J. W., & Abdallah, M. (2024). E-XAI: Evaluating black-box explainable AI frameworks for network intrusion detection. IEEE Access, 12, 23954–23988. https://doi.org/10.1109/ACCESS.2024.3365140
- Zhou, H., Zou, H., Li, W., Li, D., & Kuang, Y. (2025). HiViT-IDS: an efficient network intrusion detection method based on vision transformer. Sensors, 25(6), 1752.
- Hassan, A., Rauf, A., Shafqat, N., Latif, R., & Khan, H. (2025). ZenGuard a machine learning based zero trust framework for context aware threat mitigation using SIEM SOAR and UEBA. Scientific Reports, 15(1), 35871. https://doi.org/10.1038/s41598-025-20998-4
- Yang, H., & Wang, F. (2019). Wireless network intrusion detection based on improved convolutional neural network. Ieee Access, 7, 64366-64374.
- Liang, W., Li, K. C., Long, J., Kui, X., & Zomaya, A. Y. (2019). An industrial network intrusion detection algorithm based on multifeature data clustering optimization model. IEEE Transactions on Industrial Informatics, 16(3), 2063-2071.
- Ghanbarzadeh, R., Hosseinalipour, A., & Ghaffari, A. (2023). A novel network intrusion detection method based on metaheuristic optimisation algorithms: R. Ghanbarzadeh et al. Journal of ambient intelligence and humanized computing, 14(6), 7575-7592.
- Ozdem, M. (2025). A novel approach for real-time anomaly detection in dynamic computer networks using temporal graph networks and explainable artificial intelligence. Alexandria Engineering Journal, 132, 369–382. https://doi.org/10.1016/j.aej.2025.11.001
- Zhang, Y., Zhang, Y., Zhang, N., & Xiao, M. (2020). A network intrusion detection method based on deep learning with higher accuracy. Procedia Computer Science, 174, 50-54.
- Wang, X., Yin, S., Li, H., Wang, J., & Teng, L. (2020). A network intrusion detection method based on deep multi-scale convolutional neural network. International Journal of Wireless Information Networks, 27(4), 503-517.
- Javeed, D., Gao, T., Kumar, P., & Jolfaei, A. (2024). An explainable and resilient intrusion detection system for Industry 5.0. IEEE Transactions on Consumer Electronics, 70(1), 1342–1350. https://doi.org/10.1109/TCE.2023.3283704
- Mary, D. S., Dhas, L. J. S., Deepa, A. R., Chaurasia, M. A., & Sheela, C. J. J. (2024). Network intrusion detection: An optimized deep learning approach using big data analytics. Expert Systems with Applications, 251, Article 123919. https://doi.org/10.1016/j.eswa.2024.123919
- Karn, A. L., Ghanimi, H. M., Iyengar, V., Siddiqui, M. S., Alharbi, M. G., Alroobaea, R., ... & Sengan, S. (2025). Applying the defense model to strengthen information security with artificial intelligence in computer networks of the financial services sector. Scientific Reports, 15(1), 30292. https://doi.org/10.1038/s41598-025-15034-4
- Ebrahimi, F., Javidan, R., Akbari, R., & Hosseini, Y. (2025). Intrusion detection in the internet of things using convolutional neural networks: an explainable AI approach. Cybersecurity, 8(1), 66. https://doi.org/10.1186/s42400-025-00369-2
- Tserenkhuu, M., Hossain, M. D., Taenaka, Y., & Kadobayashi, Y. (2025). Intrusion detection system framework for SDN-based IoT networks using deep learning approaches with XAI-based feature selection techniques and domain-constrained features. IEEE Access, 13, 136864–136880. https://doi.org/10.1109/ACCESS.2025.3595595
- Hore, S., Ghadermazi, J., Shah, A., & Bastian, N. D. (2024). A sequential deep learning framework for a robust and resilient network intrusion detection system. Computers & Security, 144, Article 103928. https://doi.org/10.1016/j.cose.2024.103928
- Lee, H.-W., Han, T.-H., & Lee, T.-J. (2023). Reference-based AI decision support for cybersecurity. IEEE Access, 11, 143324–143339. https://doi.org/10.1109/ACCESS.2023.3342868
- Arya, K., Siddhant, S., & Upadhyay, L. (2025). An explainable hybrid deep learning framework for network intrusion detection using feature-guided CNN models. IEEE Access, 13, 204954–204977. https://doi.org/10.1109/ACCESS.2025.3637857
- Ghadermazi, J., Shah, A., & Bastian, N. D. (2025). Towards real-time network intrusion detection with image-based sequential packets representation. IEEE Transactions on Big Data, 11(1), 157–173. https://doi.org/10.1109/TBDATA.2024.3403394
- Volpe, G., Fiore, M., La Grasta, A., Albano, F., Stefanizzi, S., Mongiello, M., & Mangini, A. M. (2024). A Petri net and LSTM hybrid approach for intrusion detection systems in enterprise networks. Sensors, 24, Article 7924. https://doi.org/10.3390/s24247924
- Alamro, H., Alahmari, S., Nemri, N., Aljebreen, M., Alhashmi, A. A., Alamro, S., ... & Al Duhayyim, M. (2025). Enhanced intrusion detection in cybersecurity through dimensionality reduction and explainable artificial intelligence. Scientific Reports, 15(1), 33848. https://doi.org/10.1038/s41598-025-06761-9
- Sivamohan, S., & Sridhar, S. S. (2023). An optimized model for network intrusion detection systems in Industry 4.0 using XAI-based Bi-LSTM framework. Neural Computing and Applications, 35, 11459–11475. https://doi.org/10.1007/s00521-023-08319-0
- Yang, L., Rajab, M. E., Shami, A., & Muhaidat, S. (2024). Enabling AutoML for zero-touch network security: Use-case driven analysis. IEEE Transactions on Network and Service Management, 21(3), 3555–3582. https://doi.org/10.1109/TNSM.2024.3376631
- He, K., Kim, D. D., & Asghar, M. R. (2025). MTD-AD: Moving target defense as adversarial defense. IEEE Transactions on Dependable and Secure Computing, 22(5), 5047–5059. https://doi.org/10.1109/TDSC.2025.3560246
- Kim, Y., Kim, J., & Kim, D. (2024). Hi-MLIC: Hierarchical multilayer lightweight intrusion classification for various intrusion scenarios. IEEE Access, 12, 120098–120115. https://doi.org/10.1109/ACCESS.2024.3450671
- Gong, S., Cho, J., & Choi, K. K. (2025). Detection of multi-stage attacks through attack pattern segmentation. IEEE Access, 13, 204155–204167. https://doi.org/10.1109/ACCESS.2025.3635053
- Janati Idrissi, M., Alami, H., El Mahdaouy, A., El Mekki, A., Oualil, S., Yartaoui, Z., & Berrada, I. (2023). Fed-ANIDS: Federated learning for anomaly-based network intrusion detection systems. Expert Systems with Applications, 234, Article 121000. https://doi.org/10.1016/j.eswa.2023.121000
- Kim, H., Lee, J., & Park, J.-G. (2024). SITRAN: Self-supervised IDS with transferable techniques for 5G industrial environments. IEEE Internet of Things Journal, 11(21), 35465–35476. https://doi.org/10.1109/JIOT.2024.3437448
- Zhou, Y., Mazzuchi, T. A., & Sarkani, S. (2020). M-AdaBoost-A based ensemble system for network intrusion detection. Expert Systems with Applications, 162, 113864. Wardana, A. A., Kołaczek, G., Warzyński, A., Sukarno, P., & Adiwijaya. (2026). SNI-CIDS: Collaborative intrusion detection using modified ensemble stacking deep neural networks for new network integration in heterogeneous networks. Future Generation Computer Systems, 177, Article 108252. https://doi.org/10.1016/j.future.2025.108252
- Sharafaldin, I., Lashkari, A. H., & Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. In Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP) (pp. 108–116). https://doi.org/10.5220/0006639801080116
- Moustafa, N., & Slay, J. (2015). UNSW-NB15: A comprehensive data set for network intrusion detection systems. In Proceedings of the Military Communications and Information Systems Conference (MilCIS) (pp. 1–6). https://doi.org/10.1109/MilCIS.2015.7348942.