← Back to VOLUME 15, ISSUE 8, AUGUST 2026
This work is licensed under a Creative Commons Attribution 4.0 International License.
XAI-IDS: Interpretable Machine Learning for Real-Time Multi-Class Intrusion Detection in Internet of Things Environments
Amith G M, Yoga Lakshmi M, Shailaja G S, Rihan Ahamed, Mrs. Roopa Patrimath
👁 12 views📥 8 downloads
Abstract: Existing IoT Intrusion Detection Systems (IDS) achieve competitive accuracy but are opaque black-box models, relying on single imbalanced datasets, centralising raw traffic, and incompatible with edge hardware. This paper presents XAI-IDS, a seven-layer federated explainable IDS resolving all four limitations simultaneously. The system trains LightGBM and a CNN-LSTM hybrid on CICIOT2023 (80/10/10 split, 5-fold CV) and evaluates without retraining on ToN-IoT and NSL-KDD across 33 attack types. LightGBM achieves macro-F1=0.9412/0.9138/0.9267 on CICIOT2023/ToN-IoT/NSL-KDD; CNN-LSTM achieves 0.9534. FPR=3.12% vs 8.92% (Extra Trees [4], p<0.001, - 5.80 p.p.). SMOTE-ENN recovers normal-class F1 from 0.6312 to 0.9134. TreeSHAP provides exact attribution in 4.3±0.4 ms; LIME cross-validates at 83.2% top-5 agreement; feature ablation confirms faithfulness (ΔAcc=19.3±1.7 p.p.). An LLM explanation layer raises non-technical comprehension from 31.2% to 84.3% (t(19)=14.23, p<0.001, n=20, ethics-approved). FedProx μ=0.01 achieves F1 within 1.32% of centralised baseline in 7 rounds under DP-SGD ε=5. ADWIN recovers from 93.7% of drift events in 47.3±4.8 s. The ONNX INT8 LightGBM (14.2 MB) achieves 1.83 ms inference and +0.4 W power draw on Raspberry Pi 4. All improvements: p<0.001, Bonferroni-corrected. Complete hyperparameters (Table IX), 78-feature schema (Table X), and edge metrics (Table XI) provided for full reproducibility.
Keywords: IoT Security, IDS, XAI, SHAP, LIME, LightGBM, CNN-LSTM, FedProx, Differential Privacy, SMOTE- ENN, ADWIN, Concept Drift, ONNX, LLM.
Keywords: IoT Security, IDS, XAI, SHAP, LIME, LightGBM, CNN-LSTM, FedProx, Differential Privacy, SMOTE- ENN, ADWIN, Concept Drift, ONNX, LLM.
How to Cite:
[1] Amith G M, Yoga Lakshmi M, Shailaja G S, Rihan Ahamed, Mrs. Roopa Patrimath, “XAI-IDS: Interpretable Machine Learning for Real-Time Multi-Class Intrusion Detection in Internet of Things Environments,” International Journal of Advanced Research in Computer and Communication Engineering (IJARCCE), DOI: 10.17148/IJARCCE.2026.15802
