Abstract
This paper presents an interpretable and robust intrusion detection system that integrates a lightweight Convolutional Block Attention Module (CBAM) within a 1D Convolutional Neural Network (CNN) and employs explainable AI (XAI) techniques for post-hoc interpretation. The model enhances feature discrimination through channel and spatial attention with limited computational overhead. Evaluated on CIC-IDS 2017 and CIC-IoT 2023, it achieves 99% and 85% detection rate (recall), respectively. The findings suggest a practical trade-off between interpretability, detection performance, and efficiency across conventional and IoT network environments. To explain the predictions, SHAP and LIME are applied to produce global and local attributions, and SHAP-based descriptive accuracy and sparsity metrics quantify explanation quality. Overall, the approach combines strong detection performance with actionable explanations, supporting transparent intrusion detection in ever-evolving cyber environments.
| Original language | English |
|---|---|
| Article number | 111348 |
| Journal | Computers and Electrical Engineering |
| Volume | 138 |
| DOIs | |
| State | Published - Oct 2026 |
Bibliographical note
Publisher Copyright:© 2026 Elsevier Ltd.
Keywords
- Attention-based CNN
- Convolutional Block Attention Module (CBAM)
- Deep learning (DL)
- Explainable AI (XAI)
- Explainable AI performance evaluation
- Intrusion Detection Systems (IDS)
- Machine learning (ML)
ASJC Scopus subject areas
- Control and Systems Engineering
- General Computer Science
- Electrical and Electronic Engineering
Fingerprint
Dive into the research topics of 'Interpretable and robust intrusion detection: A hybrid CBAM-CNN model with XAI techniques'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver