Skip to content

Explainable Artificial Intelligence for Industrial Cybersecurity: A Review of Methods, Operational Integration, and Research Challenges

Aug 2026 · 0 citations · 203 references
Computer Science Engineering

TL;DR

A comprehensive review of XAI techniques in industrial cybersecurity, focusing on industrial SOC environments and operational security workflows, and identifies open research directions and opportunities for developing trustworthy, operationally viable, and domain-specific XAI-enabled cybersecurity solutions for industrial environments.

Abstract

The increasing digitalization of industrial infrastructure and the convergence of information technology (IT) and operational technology (OT) have expanded the cyberattack surface of industrial systems. To address the growing complexity of cyber threats, artificial intelligence (AI) and machine learning (ML) techniques are increasingly deployed within industrial cybersecurity operations, particularly in Security Operations Centers (SOCs). While these approaches improve anomaly detection, threat analysis, and automated response, their opaque decision-making presents challenges for operational trust, regulatory compliance, and incident response. EXplainable Artificial Intelligence (XAI) has emerged as a promising paradigm to improve the transparency and interpretability of AI-driven cybersecurity systems and decisions. This paper provides a comprehensive review of XAI techniques in industrial cybersecurity, focusing on industrial SOC environments and operational security workflows. We examine the role of AI in industrial SOC workflows, the types of operational data leveraged in industrial environments, and the benefits and limitations of AI-based threat detection. We then review major families of XAI approaches, including feature attribution methods, surrogate models, rule-based explanations, and visualization techniques, and analyze their applicability to industrial use cases. We further discuss the operational, regulatory, and safety requirements that distinguish industrial systems from traditional IT environments. Key challenges are examined, including limited labeled datasets, model reliability, explainability-performance tradeoffs, and the integration of XAI tools into SOC workflows. Finally, we identify open research directions and opportunities for developing trustworthy, operationally viable, and domain-specific XAI-enabled cybersecurity solutions for industrial environments.

View source

Similar papers

#explainable ai Review Open access Sep 2026

Artificial Intelligence for Anomaly Detection in Cyber Defense: A Critical Review of Methodological Trends, Datasets, and Explainability

The increase in the number and complexity of interconnected systems requires new methods to identify potential threats in today’s hyperconnected world. This trend affects systems ranging from smart homes and Internet of Things (IoT) devices to critical infrastructure which must be equipped with the corresponding cyber...

P. Vezeteu, Nicolae-Daniel Boboc, D. Năstac · 0 citations
Preprint Aug 2026

A Roadmap to Available ICS Datasets and Testbeds for Cybersecurity Research

The main objective of this paper is to provide the roadmap of existing ICS cybersecurity datasets, testbeds and digital twins, and provide the identification of research gaps and recommendations on creation of new tools.

Ebtesam S. Alqahtani, Mohammad Hammoudeh · 0 citations
#graph neural networks Review Open access Sep 2026

AI Approaches for Industrial Control System Cybersecurity: A Comprehensive Review of Methodological Contexts

A re-view is systematic, analyzing the use of artificial intelligence (AI) methodologies in ICS cybersecurity from the year 2018 to 2024, suggesting that graph-based and hybrid methods yield the best detection accuracy, whereas classical methods still seem to be the most suitable for resource-constrained applications.

Olujoke Mubo Oni, J. E. Efiong, Abiodun Akinwale et al. · 0 citations
#federated learning Review Open access Sep 2026

AI-driven cybersecurity for industrial internet of things: architectures, challenges, datasets, and future research directions

This review critically analyzes the cybersecurity research published over the past few years on cyber threats across the various layers of the IIoT architecture, publicly available cybersecurity datasets, evaluation practices, and AI-based intrusion detection methods to provide a pathway toward resilient, adaptive, and...

Siddhartha Singhal, Kakelli Anil Kumar · 0 citations
Open access Sep 2026

Cybersecurity and AI: A Comprehensive Implementation of Advanced Large Language Models for Threat Detection, Digital Forensics, SOC Automation, and Security Vulnerability Mitigation

This report encompasses the cutting-edge implementation of advanced Large Language Models (LLMs) for cybersecurity and digital forensics applications at the intersection of cybersecurity and AI. The project brings together innovative research on AI-based security solutions in four major areas: threat detection and inte...

Harsh Dankhara · 0 citations

Related blog posts

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.