Skip to main navigation Skip to search Skip to main content

Interpretable and robust intrusion detection: A hybrid CBAM-CNN model with XAI techniques

Research output: Contribution to journalArticlepeer-review

Abstract

This paper presents an interpretable and robust intrusion detection system that integrates a lightweight Convolutional Block Attention Module (CBAM) within a 1D Convolutional Neural Network (CNN) and employs explainable AI (XAI) techniques for post-hoc interpretation. The model enhances feature discrimination through channel and spatial attention with limited computational overhead. Evaluated on CIC-IDS 2017 and CIC-IoT 2023, it achieves 99% and 85% detection rate (recall), respectively. The findings suggest a practical trade-off between interpretability, detection performance, and efficiency across conventional and IoT network environments. To explain the predictions, SHAP and LIME are applied to produce global and local attributions, and SHAP-based descriptive accuracy and sparsity metrics quantify explanation quality. Overall, the approach combines strong detection performance with actionable explanations, supporting transparent intrusion detection in ever-evolving cyber environments.

Original languageEnglish
Article number111348
JournalComputers and Electrical Engineering
Volume138
DOIs
StatePublished - Oct 2026

Bibliographical note

Publisher Copyright:
© 2026 Elsevier Ltd.

Keywords

  • Attention-based CNN
  • Convolutional Block Attention Module (CBAM)
  • Deep learning (DL)
  • Explainable AI (XAI)
  • Explainable AI performance evaluation
  • Intrusion Detection Systems (IDS)
  • Machine learning (ML)

ASJC Scopus subject areas

  • Control and Systems Engineering
  • General Computer Science
  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'Interpretable and robust intrusion detection: A hybrid CBAM-CNN model with XAI techniques'. Together they form a unique fingerprint.

Cite this