Skip to content
Open access

XP-IDS: an explainable hybrid CNN–XGBoost framework for IoT intrusion detection

Aug 2026 · Scientific Reports · 0 citations

TL;DR

The proposed accurate and interpretable framework shows strong potential as an edge-deployable security solution for safeguarding IoT devices and improving cyber resilience.

Abstract

The rapid growth of IoT-enabled technologies and interconnected smart devices has significantly increased security risks associated with poorly protected and resource-constrained IoT environments. Efficient anomaly detection mechanisms can help mitigate these threats by analyzing network traffic and identifying abnormal activities. However, such mechanisms must also preserve user privacy and maintain scalability for deployment on low-power edge devices. This paper presents XP-IDS : a hybrid deep gradient boosting framework for intrusion detection in IoT networks. Using the CIC IoT-DIAD 2024 dataset, XP-IDS learns from three categories of handcrafted features: (i) strategic-based features that capture high-level protocol semantics and flow behavior, (ii) time-based features that represent sequential relationships and traffic evolution over time, and (iii) IP-based features that characterize packet-flow communication among IoT endpoints. Feature representations extracted through stacked Convolutional Neural Networks are subsequently forwarded to an Extreme Gradient Boosting classifier for final prediction. In addition, SHapley Additive exPlanation (SHAP) is utilized to provide interpretability for model decisions and to identify overall feature importance, thereby enhancing transparency and privacy-aware analysis. Extensive experimental evaluation demonstrates that the proposed framework achieves strong detection accuracy across several common attack categories while outperforming multiple baseline approaches. The proposed accurate and interpretable framework shows strong potential as an edge-deployable security solution for safeguarding IoT devices and improving cyber resilience.

Read PDF

Similar papers

Open access Jul 2026

Hybrid CNN–LSTM Intrusion Detection Framework for Industrial IoT Security

The results indicate that the proposed CNN–LSTM framework is suitable for near-real-time IIoT intrusion detection where low false alarms, calibrated confidence, temporal stability, and lightweight deployment are critical.

Mushtaq Ali, Imad Ullah · 3 citations · ⚡1
Open access Aug 2026

A hybrid CNN-BiLSTM edge-cloud intrusion detection system with online incremental learning and SHAP explainability for smart city IoT

MI-IDS is presented, a hybrid Convolutional Neural Network–Bidirectional Long Short-Term Memory (CNN-BiLSTM) ensemble deployed on a two-tier edge-cloud framework that integrates reservoir-sampling-based incremental learning and SHAP explainability under a single experimentally validated pipeline.

Manjot Kaur, Kedar Nath Singh, Alpana Suman et al. · 0 citations
Open access Aug 2026

Explainable Deep Learning Intrusion Detection Framework for Securing IoT Environment

A new explainable hybrid IDS architecture for IoT environments named XABiL-IDS (Explainable Attention-based Bi LSTM-Intrusion Detection System) in response to this challenge, which uses a robust hybrid architecture to detect attacks effectively.

Ravi Patni, Gurvinder Singh · 0 citations
Conference Aug 2026

An Intelligent Deep Learning-Based Intrusion Detection System for IoT Nodes using CNN- BiLSTM and Grasshopper Optimization

Recent networks have a remote larger attack surface owing to the quick spread of Internet of Things (IoT) strategies, which for effective and instantaneous Intrusion Detection Systems (IDS). Deep-IDS, a real-time Deep Learning (DL) IDS intended for IoT nodes with limited resources, is presented in this work. The raw ne...

D. Sameera, M. Sreenivasu, Aruna Kommu · 0 citations
Open access Aug 2026

HybridML CyberShield for explainable proactive intrusion detection in enterprise and IoT networks

The framework introduces CNN–BiLSTM deep learning networks to represent traffic in a spatiotemporal manner and adopts ensemble machine learning classifiers to enhance the robustness of traffic detection and its interpretability, to enhance the robustness of traffic detection and its interpretability.

Ramesh N. S. V. S. C. Sripada, A. Bhavani, Kiran B. Malagi et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.