[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-86612-en":3,"doc-seo-86612-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},86612,34359740700684,"Finn","https://ap-avatar.wpscdn.com/avatar/1f400023980c374ae676?_k=1777273430885731487",8,"Research & Report","IoT-based Intrusion Detection System Using Explainable Multi-class Deep Learning Approaches","With the surge in Internet of Things (IoT) across domains and escalating security threats, intrusion detection remains essential for identifying and classifying cyber-attacks. Deep learning models deliver strong detection performance but operate as black boxes, limiting transparency and trust in cybersecurity settings. This study proposes DL-based IDS models trained on NSL-KDD, UNSW-NB15, TON-IoT, and X-IIoTID and applies SHAP explainability to interpret model behavior. Best models are selected per dataset, and 15 most influential features are extracted, improving efficiency while maintaining high accuracy across datasets.","Computers and Electrical Engineering 123 (2025) 110256  \nContents lists available at ScienceDirect  \nComputers and Electrical Engineering  \njournal [homepage: www.elsevier.com/locate/compeleceng](homepage: www.elsevier.com/locate/compeleceng)  \n| IoT-based intrusion detection system using explainable multi-class\u003Cbr>deep learning approaches\u003Cbr>Sapna Sadhwani, Ameya Navare, Alan Mohan, Raja Muthalagu *, Pranav M. Pawar Department of Computer Science and Engineering, Birla Institute of Technology and Science Pilani, Dubai Campus, Dubai, United Arab Emirates |  |  |\n| --- | --- | --- |\n| A R T I C L E I N F O\u003Cbr>Keywords:\u003Cbr>Internet of Things (IoT)\u003Cbr>Intrusion Detection Systems (IDS)\u003Cbr>Artificial Intelligence (AI)\u003Cbr>Explainable AI (XAI)\u003Cbr>Long Short-Term Memory (LSTM)\u003Cbr>Shapley Additive Explanations (SHAP) Local Interpretable Model-agnostic Explanations (LIME) | A B S T R A C T\u003Cbr>With the surge in Internet of Things (IoT) across various domains and the rise in security threats, researchers have developed Intrusion Detection Systems (IDS) attacks in networks. These Machine Learning (ML) and Deep Learning (DL) models are powerful in detecting and classifying attacks; however, they have a black-box nature and lack interpretability. Explainable Artificial Intelligence (XAI) works towards this and improves the model’s transparency and trustworthiness with research in XAI increasing significantly. However, its application within cybersecurity and IoT Intrusion Detection, particularly, requires more work to interpret various IDS models and provide explanations on how various cyber-attacks occur. This work proposes various DL-based IDS trained on four datasets: NSL-KDD, UNSW-NB15, TON-IoT and X-IIoTID and applies XAI using Shapely Additive Explanations (SHAP) to interpret these models. Utilizing four datasets captures diverse network environments to thoroughly evaluate and interpret the model. Convolutional Neural Networks (CNN), Long Short-Term Memory (LSTM) and Bidirectional LSTM (Bi-LSTM) based models were trained for multi-class classification. The best model (based on performance and training time) was chosen for each dataset and SHAP was applied to it. Furthermore, a novel set of 15 features, which impacted the model’s decisions the most, were extracted using explanations generated from SHAP. The models trained on these reduced features required less training time without significant impact on training time and achieving a higher performance in comparison to peer models. This work achieves model accuracies of 98.21 % in NSL-KDD, 97.80 % in TON-IoT, 92.9 % in UNSW-NB15 and 98.09 % in X-IIoTID dataset using a CNN-based model, CNN-X and using a subset of only 15 features in each dataset. This work\u003Cbr>achieves high model performances, while improving the efficiency and interpretability of IDS.© 2017 Elsevier Inc. All rights reserved. |  |\n\n1. Introduction  \nIoT revolutionizes the way devices communicate by connecting everyday objects to the internet thus, enabling a seamless data exchange and automation across diverse environments [1]. However, this connectivity also introduces a variety of unknown security vulnerabilities, as each connected device can become an entry point for malicious actors [2]. Intrusion Detection Systems (IDS) play a crucial role in safeguarding IoT ecosystems by actively monitoring network traffic, identifying suspicious activities, and triggering  \n* Corresponding author.  \nE-mail addresses: [sapna@dubai.bits-pilani.ac.in](sapna@dubai.bits-pilani.ac.in) (S. Sadhwani), [f20210254@dubai.bits-pilani.ac.in](f20210254@dubai.bits-pilani.ac.in) (A. Navare), [f20210224@dubai.bits-pilani.ac](f20210224@dubai.bits-pilani.ac).  \nin (A. Mohan), [raja.m@dubai.bits-pilani.ac.in](raja.m@dubai.bits-pilani.ac.in) (R. Muthalagu), [pranav@dubai.bits-pilani.ac.in](pranav@dubai.bits-pilani.ac.in) (P.M. Pawar).  \n[https://doi.org/10.1016/j.compeleceng.2025.110256](https://doi.org/10.1016/j.compeleceng.2025.110256)  \nReceived 29","cbCaijsJfGtWpQCy","https://ap.wps.com/l/cbCaijsJfGtWpQCy","pdf",5006350,7,1,20,"English","en",105,"# Introduction\n## Intrusion detection in IoT and security motivation\n## ML and deep learning approaches for IDS\n## Black-box limitations and the role of XAI\n## LIME and SHAP for model interpretability","[{\"question\":\"Why is explainable AI important for IoT intrusion detection?\",\"answer\":\"Deep learning IDS models achieve high accuracy but behave as black boxes, making it difficult to trust and validate predictions. XAI provides insight into the reasoning behind model outputs, improving transparency and confidence for cybersecurity use.\"},{\"question\":\"Which datasets and model types are used in this work?\",\"answer\":\"The study trains DL-based IDS models on four datasets: NSL-KDD, UNSW-NB15, TON-IoT, and X-IIoTID. Multi-class classification models are built using CNN, LSTM, and Bi-LSTM architectures.\"},{\"question\":\"How does SHAP contribute to the proposed intrusion detection framework?\",\"answer\":\"SHAP is applied to interpret trained models and identify which inputs most influence decisions. Using SHAP-generated explanations, the work extracts a reduced set of 15 impactful features per dataset to improve training efficiency without significant performance loss.\"}]",1784236198,50,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"iot-based-intrusion-detection-system-using-explainable-multi-class-deep-learning-approaches","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/iot-based-intrusion-detection-system-using-explainable-multi-class-deep-learning-approaches/86612/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-29","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"Why is explainable AI important for IoT intrusion detection?","Question",{"text":76,"@type":77},"Deep learning IDS models achieve high accuracy but behave as black boxes, making it difficult to trust and validate predictions. XAI provides insight into the reasoning behind model outputs, improving transparency and confidence for cybersecurity use.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"Which datasets and model types are used in this work?",{"text":81,"@type":77},"The study trains DL-based IDS models on four datasets: NSL-KDD, UNSW-NB15, TON-IoT, and X-IIoTID. Multi-class classification models are built using CNN, LSTM, and Bi-LSTM architectures.",{"name":83,"@type":74,"acceptedAnswer":84},"How does SHAP contribute to the proposed intrusion detection framework?",{"text":85,"@type":77},"SHAP is applied to interpret trained models and identify which inputs most influence decisions. Using SHAP-generated explanations, the work extracts a reduced set of 15 impactful features per dataset to improve training efficiency without significant performance loss.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,115,119,122,126,129,133],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":46,"category_name":113,"show_sort_weight":29,"slug":114},6,"Technology","technology",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":22,"slug":125},9,"Religion & Spirituality","religion-spirituality",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":127,"show_sort_weight":22,"slug":128},"World Cup","world-cup",{"id":130,"doc_module":4,"doc_module_name":46,"category_name":131,"show_sort_weight":130,"slug":132},10,"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":46,"category_name":135,"show_sort_weight":107,"slug":136},19,"General","general"]