AccScience Publishing / IJOSI / Online First / DOI: 10.6977/IJoSI.202607_10(4).026160059
ARTICLE

Explainable deep learning intrusion detection system for robust and interpretable security in smart city networks

Vijayakumari Rodda1* Anurag Shrivastava2 Aditya Rautaray3 Sundaram K. Meenakshi4 G. Shailaja5 S. Prabagar6 S. B. G. Tilak Babu7
Show Less
1 Department of Computer Science, Faculty of Engineering and Technology, Krishna University, Machilipatnam, Krishna District, Andhra Pradesh, India
2 Department of Information Technology, Indiana Wesleyan University, Merrillville, Indiana, United States of America
3 Independent Research Scholar, Independent Research Scholar
4 Department of Computer Science and Engineering, Saveetha School of Engineering, Saveetha Institute of Medical and Technical Sciences, Chennai, Tamil Nadu, India
5 Department of IT, CVR College of Engineering, Hyderabad, Telangana, India
6 Department of Computer Science & Engineering (Data Science), School of Computing, Vel Tech Rangarajan Dr. Sagunthala R&D Institute of Science and Technology, Chennai, Tamil Nadu, India
7 Department of Electronics and Communication Engineering, Faculty of Engineering and Technology, Aditya University, Surampalem, Andhra Pradesh, India
Received: 17 April 2026 | Revised: 22 June 2026 | Accepted: 1 July 2026 | Published online: 3 August 2026
© 2026 by the Author(s). This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution -Noncommercial 4.0 International License (CC-by the license) ( https://creativecommons.org/licenses/by-nc/4.0/ )
Abstract

Smart urban systems are based on interconnected software-defined networking and Internet of Things platforms that face critical threats from advanced Layer 2 and zero-day attacks. Although deep learning provides powerful detection capabilities, the available models tend to be black boxes that do not meet security-forensics requirements and have high latency when redundant features are learned. The present research fills these gaps by proposing a powerful, explainable intrusion detection system based on a hybrid convolutional neural network and a bidirectional long short-term memory architecture, aided by an attention-based fusion mechanism. The framework combines domain-constrained feature selection with dual-layer explainability, using Shapley additive explanations and local interpretable model-agnostic explanations to provide both global and attack-specific model transparency. The experimental findings from the intrusion detection dataset for software-defined networking and the extended industrial Internet of Things intrusion detection dataset show that detection of known threats is 99.85%, and the detection of unknown zero-day vectors is also significant at 71.09%. The method reduces feature dimensionality by 77%, resulting in 4.1 ms of inference latency. Such a combination of high-performance classification and actionable interpretability enhances forensic reliability in urban infrastructure that is highly important to the mission.

Keywords
Explainable artificial intelligence
Software-defined networking
Zero-day attack detection
Hybrid deep learning
Funding
This research received no specific grant from any funding agency in the public, commercial, or not-for-profit sectors.
Conflict of interest
The authors declare no conflicts of interest.
References

Admass, W. S., Munaye, Y. Y., & Diro, A. A. (2024). Cyber security: State of the art, challenges and future directions. Cyber Security and Applications, 2, 100031. https://doi.org/10.1016/j.csa.2023.100031

 

Afraji, D. M. A. A., Lloret, J., & Peñalver, L. (2025). An integrated hybrid deep learning framework for intrusion detection in IoT and IIoT networks using CNN-LSTM-GRU architecture. Computation, 13(9), 222. https://doi.org/10.3390/computation13090222

 

Agbor, B. A., Stephen, B. U. A., Asuquo, P., Luke, U. O., & Anaga, V. (2025). Hybrid CNN–BiLSTM–DNN approach for detecting cybersecurity threats in IoT networks. Computers, 14(2), 58. https://doi.org/10.3390/computers14020058

 

Ahmad, J., Latif, S., Khan, I. U., Alshehri, M. S., Khan, M. S., Alasbali, N., & Jiang, W. (2025). An interpretable deep learning framework for intrusion detection in industrial Internet of Things. Internet of Things, 33, 101681. https://doi.org/10.1016/j.iot.2025.101681

 

Ahmed, M., Islam, S. R., Anwar, A., Moustafa, N., & Pathan, A.-S. K. (Eds.). (2022). Explainable artificial intelligence for cyber security (Studies in Computational Intelligence, Vol. 1025). Springer Nature Switzerland, Cham, Switzerland. https://doi.org/10.1007/978-3-030-96630-0

 

Al Lail, M., Garcia, A., & Olivo, S. (2023). Machine learning for network intrusion detection—A comparative study. Future Internet, 15(7), 243. https://doi.org/10.3390/fi15070243

 

Al-Hawawreh, M., Sitnikova, E., & Aboutorab, N. (2022). X-IIoTID: A connectivity-agnostic and device-agnostic intrusion data set for industrial Internet of Things. IEEE Internet of Things Journal, 9(5), 3962–3977. https://doi.org/10.1109/JIOT.2021.3102056

 

Altulaihan, E., Almaiah, M. A., & Aljughaiman, A. (2022). Cybersecurity threats, countermeasures and mitigation techniques on the IoT: Future research directions. Electronics, 11(20), 3330. https://doi.org/10.3390/electronics11203330

 

Altunay, H. C., & Albayrak, Z. (2023). A hybrid CNN+LSTM-based intrusion detection system for industrial IoT networks. Engineering Science and Technology, an International Journal, 38, 101322. https://doi.org/10.1016/j.jestch.2022.101322

 

Arreche, O., Guntur, T., & Abdallah, M. (2024). XAI-IDS: Toward proposing an explainable artificial intelligence framework for enhancing network intrusion detection systems. Applied Sciences, 14(10), 4170. https://doi.org/10.3390/app14104170

 

Chaganti, R., Suliman, W., Ravi, V., & Dua, A. (2023). Deep learning approach for SDN-enabled intrusion detection system in IoT networks. Information, 14(1), 41. https://doi.org/10.3390/info14010041

 

Elsaid, S. A., & Binbusayyis, A. (2024). An optimized isolation forest based intrusion detection system for heterogeneous and streaming data in the industrial Internet of Things (IIoT) networks. Discover Applied Sciences, 6(9), 483. https://doi.org/10.1007/s42452-024-06165-w

 

Guo, Y. (2023). A review of machine learning-based zero-day attack detection: Challenges and future directions. Computer Communications, 198, 175–185. https://doi.org/10.1016/j.comcom.2022.11.001

 

Hakak, S., Khan, W. Z., Gilkar, G. A., Imran, M., & Guizani, N. (2020). Securing smart cities through blockchain technology: Architecture, requirements, and challenges. IEEE Network, 34(1), 8–14. https://doi.org/10.1109/MNET.001.1900178

 

Hasan, M. A. M., Nasser, M., Pal, B., & Ahmad, S. (2014). Support vector machine and random forest modeling for intrusion detection system (IDS). Journal of Intelligent Learning Systems and Applications, 06(01), 45–52. https://doi.org/10.4236/jilsa.2014.61005

 

Hasnain, M., Javaid, N., Saudagar, A. K. J., & Kumar, N. (2026). An intelligent and explainable intrusion detection framework for Internet of Sensor Things using generalizable optimized active machine learning. Journal of Network and Computer Applications, 245, 104358. https://doi.org/10.1016/j.jnca.2025.104358

 

Houda, Z. A. El, Brik, B., & Khoukhi, L. (2022). "Why should I trust your IDS?": An explainable deep learning framework for intrusion detection systems in Internet of Things networks. IEEE Open Journal of the Communications Society, 3, 1164–1176. https://doi.org/10.1109/OJCOMS.2022.3188750

 

Iftikhar, A., Hussain, F. B., Qureshi, K. N., Shiraz, M., & Sookhak, M. (2025). Securing edge based smart city networks with software defined networking and zero trust architecture. Journal of Network and Computer Applications, 244, 104341. https://doi.org/10.1016/j.jnca.2025.104341

 

Imtiaz, N., Wahid, A., Ul Abideen, S. Z., Muhammad Kamal, M., Sehito, N., Khan, S., Virdee, B. S., Kouhalvandi, L., & Alibakhshikenari, M. (2025). A deep learning-based approach for the detection of various Internet of Things intrusion attacks through optical networks. Photonics, 12(1), 35. https://doi.org/10.3390/photonics12010035

 

Ioannou, C., & Vassiliou, V. (2021). Network attack classification in IoT using support vector machines. Journal of Sensor and Actuator Networks, 10(3), 58. https://doi.org/10.3390/jsan10030058

 

Kampourakis, K. E., Gkioulos, V., & Katsikas, S. (2026). Cybersecurity digital twins for industrial systems: From literature synthesis to framework design. Information, 17(3), 286. https://doi.org/10.3390/info17030286

 

Kampourakis, K. E., Gkioulos, V., Kavallieratos, G., & Lin, J. C. (2025). Digital twin-enabled incident detection and response: A systematic review of critical infrastructures applications. International Journal of Information Security, 24(5), 194. https://doi.org/10.1007/s10207-025-01113-0

 

Keshk, M., Koroniotis, N., Pham, N., Moustafa, N., Turnbull, B., & Zomaya, A. Y. (2023). An explainable deep learning-enabled intrusion detection framework in IoT networks. Information Sciences, 639, 119000. https://doi.org/10.1016/j.ins.2023.119000

 

Kikissagbe, B. R., & Adda, M. (2024). Machine learning-based intrusion detection methods in IoT systems: A comprehensive review. Electronics, 13(18), 3601. https://doi.org/10.3390/electronics13183601

 

Kilincer, I. F. (2025). Explainable AI supported hybrid deep learning method for layer 2 intrusion detection. Egyptian Informatics Journal, 30, 100669. https://doi.org/10.1016/j.eij.2025.100669

 

Kumpf, K., Cajic, M., Zeljkovic, V., Mravik, M., Zivkovic, M., Mani, J., Simic, V., & Bacanin, N. (2025). Tackling smart city security: Deep learning approach utilizing feature selection and two-level cooperative framework optimized by adapted metaheuristics algorithm. International Journal of Information Security, 24(6), 221. https://doi.org/10.1007/s10207-025-01137-6

 

Lakshan Yasarathna, T., & Le-Khac, N. A. (2026). ASEADOS-SDN-IoT: A novel SDN-IoT network intrusion detection dataset and framework. Internet of Things, 36, 101891. https://doi.org/10.1016/j.iot.2026.101891

 

Mishra, S. R., Shanmugam, B., Yeo, K. C., & Thennadil, S. (2025). SDN-enabled IoT security frameworks—A review of existing challenges. Technologies, 13(3), 121. https://doi.org/10.3390/technologies13030121

 

Moustafa, N., Adi, E., Turnbull, B., & Hu, J. (2018). A new threat intelligence scheme for safeguarding Industry 4.0 systems. IEEE Access, 6, 32910–32924. https://doi.org/10.1109/ACCESS.2018.2844794

 

Oseni, A., Moustafa, N., Creech, G., Sohrabi, N., Strelzoff, A., Tari, Z., & Linkov, I. (2023). An explainable deep learning framework for resilient intrusion detection in IoT-enabled transportation networks. IEEE Transactions on Intelligent Transportation Systems, 24(1), 1000–1014. https://doi.org/10.1109/TITS.2022.3188671

 

Rachakonda, L. P., Siddula, M., & Sathya, V. (2024). A comprehensive study on IoT privacy and security challenges with focus on spectrum sharing in next-generation networks (5G/6G/beyond). High-Confidence Computing, 4(2), 100220. https://doi.org/10.1016/j.hcc.2024.100220

 

Rahman, M. A., Asyhari, A. T., Leong, L. S., Satrya, G. B., Hai Tao, M., & Zolkipli, M. F. (2020). Scalable machine learning-based intrusion detection system for IoT-enabled smart cities. Sustainable Cities and Society, 61, 102324. https://doi.org/10.1016/j.scs.2020.102324

 

Shoukat, S., Gao, T., Javeed, D., Saeed, M. S., & Adil, M. (2025). Trust my IDS: An explainable AI integrated deep learning-based transparent threat detection system for industrial networks. Computers and Security, 149, 104191. https://doi.org/10.1016/j.cose.2024.104191

 

Siddiqi, M. A., & Pak, W. (2020). Optimizing filter-based feature selection method flow for intrusion detection system. Electronics, 9(12), 2114. https://doi.org/10.3390/electronics9122114

 

Singh, C., & Jain, A. K. (2024). A comprehensive survey on DDoS attacks detection & mitigation in SDN-IoT network. E-Prime - Advances in Electrical Engineering, Electronics and Energy, 8, 100543. https://doi.org/10.1016/j.prime.2024.100543

 

Susilo, B., Muis, A., & Sari, R. F. (2025). Intelligent intrusion detection system against various attacks based on a hybrid deep learning algorithm. Sensors, 25(2), 580. https://doi.org/10.3390/s25020580

 

Tserenkhuu, M., Hossain, M. D., Taenaka, Y., & Kadobayashi, Y. (2025). Intrusion detection system framework for SDN-based IoT networks using deep learning approaches with XAI-based feature selection techniques and domain-constrained features. IEEE Access, 13, 136864–136880. https://doi.org/10.1109/ACCESS.2025.3595595

 

Vishwakarma, R., & Jain, A. K. (2019). A survey of DDoS attacking techniques and defence mechanisms in the IoT network. Telecommunication Systems, 73(1), 3–25. https://doi.org/10.1007/s11235-019-00599-z

 

Wahab, F., Shah, A., Khan, I., Ali, B., & Adnan, M. (2024). An SDN-based hybrid-DL-driven cognitive intrusion detection system for IoT ecosystem. Computers and Electrical Engineering, 119, 109545. https://doi.org/10.1016/j.compeleceng.2024.109545

Share
Back to top
International Journal of Systematic Innovation, Electronic ISSN: 2077-8767 Print ISSN: 2077-7973, Published by AccScience Publishing