Skip to content
#explainable ai Open access

Explainable AI-driven edge–cloud framework for cluster-based predictive cyber threat detection in IIoT-enabled internet of vehicles

Sep 2026 · Discover Artificial Intelligence · Vol 6 · 0 citations · 31 references

TL;DR

A robust and explainable cybersecurity framework for IoV in IIoT Cyber-Physical Systems (CPS) is proposed, in which implementation and validation using the RT-IoT2022 (Real-Time Internet of Things) dataset is performed.

Abstract

Industrial Internet of Things (IIoT) networks have greatly expanded with emerging environments, including Internet of Vehicles (IoV), and the need to ensure real-time cybersecurity has become much more complex. We propose a robust and explainable cybersecurity framework for IoV in IIoT Cyber-Physical Systems (CPS), in which we perform implementation and validation using the RT-IoT2022 (Real-Time Internet of Things) dataset. The framework includes clustering techniques for pattern discovery, predictive modeling for threat detection, Explainable Artificial Intelligence (XAI) for interpretability enhancement, and a cloud–edge integration concept for efficient and scalable processing. The behavior patterns in the network traffic were discovered to be clustered, which helped in early anomalous behavior detection. Gaussian Mixture Modeling (GMM) achieved a Silhouette Score of 0.53 and an ARI of 0.75, indicating better alignment with the true labels. Decision Tree (DT), K-Nearest Neighbors (KNN), and Light Gradient Boosting Machine (LightGBM), as well as Multi-Layer Perceptron (MLP) classifiers, were used to carry out predictive analysis. Among these, DT attained the highest classification accuracy of 99.43%, followed by KNN (99.25%), MLP (98.90%), and LightGBM (81.03%). The DT, KNN, and MLP models achieved consistently high precision, recall, and F1-scores across most attack classes, whereas LightGBM exhibited comparatively lower performance for several classes. In order to maintain transparency in decision-making, LIME (Local Interpretable Model-agnostic Explanations) was used to get feature-level insights into the predictions of each model. The LIME analysis shows that each model relied on several features and decision-making logic, such as threshold-based splits in DT, feature similarity in KNN, volume-based patterns in LightGBM, and non-linear interactions in MLP. The proposed framework combines cloud–edge processing, high detection accuracy, early threat identification, and explainability, and thus is a powerful solution for real-time IIoT cybersecurity applications.

Read PDF

Similar papers

Open access 2026

A Lightweight Language-Model-Driven Agentic Framework for Intrusion Prediction, Detection, and Mitigation in 6G-Enabled IoT Networks

A role-based multi-agent cybersecurity framework for 6G-enabled IoT networks that enables proactive intrusion prediction, real-time detection, and knowledge-driven threat mitigation and a promising step toward scalable and intelligent cybersecurity management in 6G-enabled IoT networks is proposed.

Alaeddine Diaf, A. A. Korba, W. Jaafar et al. · 0 citations
Open access 2026

XEAD-AgriSec: An Explainable Edge Anomaly Detection Framework for Cybersecurity in AI-Powered Agricultural IoT Systems

The convergence of generative artificial intelligence (GAI), large language models, and automated vulnerability discovery tools has fundamentally altered the cyber-threat landscape for Internet of Things (IoT) infrastructures in precision agriculture. Adversaries now leverage AI-powered attack generators to craft sophi...

Yassine Boukhali, S. Drǎguşin, N. Bizon et al. · 0 citations
Conference 2026

Causal Inference-Based Network Anomaly Detection for Internet of Vehicles

5G-V2X technology and connected and autonomous vehicles are deeply in-tegrated. The Internet of Vehicles (IoV) has become the core support of an intelligent transportation system. Its heterogeneous architecture and high-dynamic characteristics bring serious cybersecurity risks. Traditional anoma-ly detection methods re...

Äo Ë · 0 citations
Conference Aug 2026

Framework for Intrusion Detection in IoT Networks: A Lightweight Soft-Voting Ensemble of XGBoost and LightGBM with Explainable AI

The rapid propagation of Internet of Things (IoT) devices has significantly expanded the cyber-attack surface, particularly in essential infrastructure sectors such as energy, water, and healthcare. Machine learning (ML) based intrusion detection systems (IDS) offer a promising defense, but their real-world deployment...

Nooruddine F. Assarwie, F. Alqasemi, Tasnim M. Al-Khawlani et al. · 0 citations

Related blog posts

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.