Journal of Cybersecurity in AI and Quantum Computing

ISSN: Pending Request (Online)Peer ReviewedOpen AccessOpen Access
open accessOpen Access

research

👁️0views

Explainable Artificial Intelligence Framework for Real-Time Cybersecurity Risk Assessment and Intrusion Detection in Enterprise Networks

Volume 2026, Issue 1ISSN: Pending Request (Online)Journal: Journal of Cybersecurity in AI and Quantum Computing
by 

Rejwan Bin Sulaiman ORCID profile ;

Mohammed Amin Almaiah ORCID profile

Rejwan Bin Sulaiman: School of Computer Science and Technology, Northumbria University, Newcastle Upon Tyne, UK, , GBR

Mohammed Amin Almaiah: King Abdullah the II IT School, The University of Jordan, Amman 11942, Jordan, JOR

PDF logoPDF

Published: 2026/09/02

Pages: 6087

Abstract

The study proposed an explainable framework for real-time intrusion detection and cybersecurity risk assessment in enterprise networks, XRisk-IDS. The model was an adaptive fusion of LightGBM and a CNN–BiGRU temporal branch. The decision process was enhanced by incorporating the concepts of probability calibration, predictive uncertainty, explanation fidelity, explanation stability, asset criticality, and network exposure. The test partition was the official UNSW-NB15 with 82,332 flows in 10 classes, which was used for evaluation. XRisk-IDS achieved 71.68% accuracy, 60.18% balanced accuracy, 48.03% macro-F1, and 95.63% macro-AUROC. It achieved an 18.59 percentage point increase in macro-F1 compared to the standalone CNN–BiGRU, while Random Forest was still better overall. The mean of the explanation quality was 0.7172, and the high-impact attack coverage was 99.45%. The framework was able to process ~26,274 flows/s and had a model footprint of 2.74 MB. XRisk-IDS offers an audit trail between detection and explanation reliability and operational risk. More research is needed to decrease benign false positives and improve multiclass calibration and test performance in real enterprise settings.

Keywords

Explainable artificial intelligenceIntrusion detectionCybersecurity risk assessmentEnterprise networksReal-time threat detection

References

  1. Shtayat, M. M., Hasan, M. K., Sulaiman, R., Islam, S., & Khan, A. U. R. (2023). An explainable ensemble deep learning approach for intrusion detection in Industrial Internet of Things. IEEE Access, 11, 115047–115061. https://doi.org/10.1109/ACCESS.2023.3323573
  2. Zha, C., Wang, Z., Fan, Y., Bai, B., Zhang, Y., Shi, S., & Zhang, R. (2025). DM-IDS—A network intrusion detection method based on dual-modal fusion. IEEE Transactions on Network and Service Management, 22(4), 3646-3661. https://doi.org/10.1109/TNSM.2025.3565614
  3. Luo, X., Yin, L., Yang, H., Liu, Z., Chen, W., Jia, S., ... & Xiang, H. (2025). SnifferDog: Comprehensively Learning Heterogeneous Features of Network Traffic to Identify Malicious Flows. IEEE Transactions on Information Forensics and Security. https://doi.org/10.1109/TIFS.2025.3620640
  4. Zhang, C., Jia, D., Wang, L., Wang, W., Liu, F., & Yang, A. (2022). Comparative research on network intrusion detection methods based on machine learning. Computers & Security, 121, 102861.
  5. Ali, B. (2025). On the fog's frontline: A federated machine learning approach for industrial network threat detection and intrusion prevention. Journal of Cybersecurity, 11(1), Article tyaf041. https://doi.org/10.1093/cybsec/tyaf041
  6. Sayem, I. M., Sayed, M. I., Saha, S., & Haque, A. (2024). ENIDS: A deep learning-based ensemble framework for network intrusion detection systems. IEEE Transactions on Network and Service Management, 21(5), 5809–5825. https://doi.org/10.1109/TNSM.2024.3414305
  7. Molina-Coronado, B., Mori, U., Mendiburu, A., & Miguel-Alonso, J. (2020). Survey of network intrusion detection methods from the perspective of the knowledge discovery in databases process. IEEE Transactions on Network and Service Management, 17(4), 2451-2479.
  8. Ullah, F., Srivastava, G., Mostarda, L., & Raza, U. (2025). ZTID-IoV: Zero-trust intrusion detection in IoV using neurosymbolic AI approach with federated meta-learning. IEEE Transactions on Consumer Electronics, 71(4), 12037–12046. https://doi.org/10.1109/TCE.2025.3625081
  9. Barik, K., Misra, S., & Fernandez-Sanz, L. (2024). Adversarial attack detection framework based on optimized weighted conditional stepwise adversarial network. International Journal of Information Security, 23, 2353–2376. https://doi.org/10.1007/s10207-024-00844-w
  10. Wu, Z., Wang, J., Hu, L., Zhang, Z., & Wu, H. (2020). A network intrusion detection method based on semantic re-encoding and deep learning. Journal of Network and Computer Applications, 164, 102688.
  11. Munna, M. M. I., Rahman, M. M., Frnda, J., Anwar, M. S., & Kutlimuratov, A. (2025). Elevating intrusion detection and security fortification in intelligent networks through cutting-edge machine learning paradigms. Scientific Reports, 15(1), 39989. https://doi.org/10.1038/s41598-025-23754-w
  12. Li, J., Wang, Y., Jia, Y., Zeng, L., Feng, W., Jing, X., ... & Fang, B. (2025). IL-IDS: an incremental learning approach with confined data streams for intrusion detection. Cybersecurity, 8(1), 80. https://doi.org/10.1186/s42400-025-00359-4
  13. Farrukh, Y. A., Wali, S., Khan, I., & Bastian, N. D. (2024). AIS-NIDS: An intelligent and self-sustaining network intrusion detection system. Computers & Security, 144, Article 103982. https://doi.org/10.1016/j.cose.2024.103982
  14. Sánchez-Zas, C., Larriva-Novo, X., Villagrá, V. A., Solera-Cotanilla, S., & Sanz-Rodrigo, M. (2026). Dynamic characterisation of cyberattacks based on the MITRE ATT&CK framework applied to the optimisation of a mitigation selection process. Future Generation Computer Systems, 177, Article 108272. https://doi.org/10.1016/j.future.2025.108272
  15. Polónio, J., Moura, J., & Marinheiro, R. N. (2025). Toward automatic detection and mitigation of high-risk cybersecurity vulnerabilities at networked systems. IEEE Access, 13, 181957–181976. https://doi.org/10.1109/ACCESS.2025.3622497
  16. Alam, K., Kifayat, K., Sampedro, G. A., Karovič, V., & Naeem, T. (2024). SXAD: Shapely explainable AI-based anomaly detection using log data. IEEE Access, 12, 95659–95672. https://doi.org/10.1109/ACCESS.2024.3425472
  17. Long, Z., Yan, H., Shen, G., Zhang, X., He, H., & Cheng, L. (2024). A Transformer-based network intrusion detection approach for cloud security. Journal of Cloud Computing, 13(1), 5.
  18. Dai, W., Li, X., Ji, W., & He, S. (2024). Network intrusion detection method based on CNN-BiLSTM-attention model. IEEE access, 12, 53099-53111.
  19. Schmitt, M. (2023). Securing the digital world: Protecting smart infrastructures and digital industries with artificial intelligence (AI)-enabled malware and intrusion detection. Journal of Industrial Information Integration, 36, Article 100520. https://doi.org/10.1016/j.jii.2023.100520
  20. Arreche, O., Guntur, T. R., Roberts, J. W., & Abdallah, M. (2024). E-XAI: Evaluating black-box explainable AI frameworks for network intrusion detection. IEEE Access, 12, 23954–23988. https://doi.org/10.1109/ACCESS.2024.3365140
  21. Zhou, H., Zou, H., Li, W., Li, D., & Kuang, Y. (2025). HiViT-IDS: an efficient network intrusion detection method based on vision transformer. Sensors, 25(6), 1752.
  22. Hassan, A., Rauf, A., Shafqat, N., Latif, R., & Khan, H. (2025). ZenGuard a machine learning based zero trust framework for context aware threat mitigation using SIEM SOAR and UEBA. Scientific Reports, 15(1), 35871. https://doi.org/10.1038/s41598-025-20998-4
  23. Yang, H., & Wang, F. (2019). Wireless network intrusion detection based on improved convolutional neural network. Ieee Access, 7, 64366-64374.
  24. Liang, W., Li, K. C., Long, J., Kui, X., & Zomaya, A. Y. (2019). An industrial network intrusion detection algorithm based on multifeature data clustering optimization model. IEEE Transactions on Industrial Informatics, 16(3), 2063-2071.
  25. Ghanbarzadeh, R., Hosseinalipour, A., & Ghaffari, A. (2023). A novel network intrusion detection method based on metaheuristic optimisation algorithms: R. Ghanbarzadeh et al. Journal of ambient intelligence and humanized computing, 14(6), 7575-7592.
  26. Ozdem, M. (2025). A novel approach for real-time anomaly detection in dynamic computer networks using temporal graph networks and explainable artificial intelligence. Alexandria Engineering Journal, 132, 369–382. https://doi.org/10.1016/j.aej.2025.11.001
  27. Zhang, Y., Zhang, Y., Zhang, N., & Xiao, M. (2020). A network intrusion detection method based on deep learning with higher accuracy. Procedia Computer Science, 174, 50-54.
  28. Wang, X., Yin, S., Li, H., Wang, J., & Teng, L. (2020). A network intrusion detection method based on deep multi-scale convolutional neural network. International Journal of Wireless Information Networks, 27(4), 503-517.
  29. Javeed, D., Gao, T., Kumar, P., & Jolfaei, A. (2024). An explainable and resilient intrusion detection system for Industry 5.0. IEEE Transactions on Consumer Electronics, 70(1), 1342–1350. https://doi.org/10.1109/TCE.2023.3283704
  30. Mary, D. S., Dhas, L. J. S., Deepa, A. R., Chaurasia, M. A., & Sheela, C. J. J. (2024). Network intrusion detection: An optimized deep learning approach using big data analytics. Expert Systems with Applications, 251, Article 123919. https://doi.org/10.1016/j.eswa.2024.123919
  31. Karn, A. L., Ghanimi, H. M., Iyengar, V., Siddiqui, M. S., Alharbi, M. G., Alroobaea, R., ... & Sengan, S. (2025). Applying the defense model to strengthen information security with artificial intelligence in computer networks of the financial services sector. Scientific Reports, 15(1), 30292. https://doi.org/10.1038/s41598-025-15034-4
  32. Ebrahimi, F., Javidan, R., Akbari, R., & Hosseini, Y. (2025). Intrusion detection in the internet of things using convolutional neural networks: an explainable AI approach. Cybersecurity, 8(1), 66. https://doi.org/10.1186/s42400-025-00369-2
  33. Tserenkhuu, M., Hossain, M. D., Taenaka, Y., & Kadobayashi, Y. (2025). Intrusion detection system framework for SDN-based IoT networks using deep learning approaches with XAI-based feature selection techniques and domain-constrained features. IEEE Access, 13, 136864–136880. https://doi.org/10.1109/ACCESS.2025.3595595
  34. Hore, S., Ghadermazi, J., Shah, A., & Bastian, N. D. (2024). A sequential deep learning framework for a robust and resilient network intrusion detection system. Computers & Security, 144, Article 103928. https://doi.org/10.1016/j.cose.2024.103928
  35. Lee, H.-W., Han, T.-H., & Lee, T.-J. (2023). Reference-based AI decision support for cybersecurity. IEEE Access, 11, 143324–143339. https://doi.org/10.1109/ACCESS.2023.3342868
  36. Arya, K., Siddhant, S., & Upadhyay, L. (2025). An explainable hybrid deep learning framework for network intrusion detection using feature-guided CNN models. IEEE Access, 13, 204954–204977. https://doi.org/10.1109/ACCESS.2025.3637857
  37. Ghadermazi, J., Shah, A., & Bastian, N. D. (2025). Towards real-time network intrusion detection with image-based sequential packets representation. IEEE Transactions on Big Data, 11(1), 157–173. https://doi.org/10.1109/TBDATA.2024.3403394
  38. Volpe, G., Fiore, M., La Grasta, A., Albano, F., Stefanizzi, S., Mongiello, M., & Mangini, A. M. (2024). A Petri net and LSTM hybrid approach for intrusion detection systems in enterprise networks. Sensors, 24, Article 7924. https://doi.org/10.3390/s24247924
  39. Alamro, H., Alahmari, S., Nemri, N., Aljebreen, M., Alhashmi, A. A., Alamro, S., ... & Al Duhayyim, M. (2025). Enhanced intrusion detection in cybersecurity through dimensionality reduction and explainable artificial intelligence. Scientific Reports, 15(1), 33848. https://doi.org/10.1038/s41598-025-06761-9
  40. Sivamohan, S., & Sridhar, S. S. (2023). An optimized model for network intrusion detection systems in Industry 4.0 using XAI-based Bi-LSTM framework. Neural Computing and Applications, 35, 11459–11475. https://doi.org/10.1007/s00521-023-08319-0
  41. Yang, L., Rajab, M. E., Shami, A., & Muhaidat, S. (2024). Enabling AutoML for zero-touch network security: Use-case driven analysis. IEEE Transactions on Network and Service Management, 21(3), 3555–3582. https://doi.org/10.1109/TNSM.2024.3376631
  42. He, K., Kim, D. D., & Asghar, M. R. (2025). MTD-AD: Moving target defense as adversarial defense. IEEE Transactions on Dependable and Secure Computing, 22(5), 5047–5059. https://doi.org/10.1109/TDSC.2025.3560246
  43. Kim, Y., Kim, J., & Kim, D. (2024). Hi-MLIC: Hierarchical multilayer lightweight intrusion classification for various intrusion scenarios. IEEE Access, 12, 120098–120115. https://doi.org/10.1109/ACCESS.2024.3450671
  44. Gong, S., Cho, J., & Choi, K. K. (2025). Detection of multi-stage attacks through attack pattern segmentation. IEEE Access, 13, 204155–204167. https://doi.org/10.1109/ACCESS.2025.3635053
  45. Janati Idrissi, M., Alami, H., El Mahdaouy, A., El Mekki, A., Oualil, S., Yartaoui, Z., & Berrada, I. (2023). Fed-ANIDS: Federated learning for anomaly-based network intrusion detection systems. Expert Systems with Applications, 234, Article 121000. https://doi.org/10.1016/j.eswa.2023.121000
  46. Kim, H., Lee, J., & Park, J.-G. (2024). SITRAN: Self-supervised IDS with transferable techniques for 5G industrial environments. IEEE Internet of Things Journal, 11(21), 35465–35476. https://doi.org/10.1109/JIOT.2024.3437448
  47. Zhou, Y., Mazzuchi, T. A., & Sarkani, S. (2020). M-AdaBoost-A based ensemble system for network intrusion detection. Expert Systems with Applications, 162, 113864. Wardana, A. A., Kołaczek, G., Warzyński, A., Sukarno, P., & Adiwijaya. (2026). SNI-CIDS: Collaborative intrusion detection using modified ensemble stacking deep neural networks for new network integration in heterogeneous networks. Future Generation Computer Systems, 177, Article 108252. https://doi.org/10.1016/j.future.2025.108252
  48. Sharafaldin, I., Lashkari, A. H., & Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. In Proceedings of the 4th International Conference on Information Systems Security and Privacy (ICISSP) (pp. 108–116). https://doi.org/10.5220/0006639801080116
  49. Moustafa, N., & Slay, J. (2015). UNSW-NB15: A comprehensive data set for network intrusion detection systems. In Proceedings of the Military Communications and Information Systems Conference (MilCIS) (pp. 1–6). https://doi.org/10.1109/MilCIS.2015.7348942.