AN EXPLAINABLE FEDERATED DEEP LEARNING FRAMEWORK FOR REAL-TIME INTRUSION DETECTION IN CRITICAL INFRASTRUCTURE IOT NETWORKS

Authors

  • Muhammad Umar
  • Azhar Ali Khan
  • Ayesha Batool
  • Mustajib Ur Rehman
  • Imran Khursheed
  • Muhammad Abrar

Keywords:

Federated learning, Explainable artificial intelligence, Intrusion detection, Internet of Things, Critical infrastructure, Deep learning, Convolutional neural networks, Cybersecurity, Real-time systems, Edge computing.

Abstract

The paper introduces a novel Explainable Federated Deep Learning Framework for real-time Intrusion Detection in Critical Infrastructure IoT Networks, to offer secure, scalable, privacy-preserving, and interpretable cybersecurity. With the rapid growth of IoT infrastructures, conventional centralized intrusion detection systems (IDSs) have obvious limitations in privacy, latency, and scalability. While federated learning can achieve distributed model training without sharing data, deep learning can enhance detection accuracy, the current methods are not necessarily interpretable, and in the case of heterogeneous environments with limited resources, they are unable to meet real-time operation requirements. The proposed framework is based on a federated learning architecture that incorporates a Decision Tree (DT), Isolation Forest (IF), k-Nearest Neighbours (KNN), Logistic Regression (LR), and a Convolutional Neural Network (CNN) to enable distributed intelligence, while maintaining data privacy. Further, it enhances the transparency and trustworthiness of intrusion detection decisions thanks to Explanation-Based Artificial Intelligence (XAI) techniques. Experimental results show that CNN gives superior performance than others with accuracy, F1 score, AUC, recall, and precision of 95.00%, 93.59%, 98.37%, 90.68%, and 96.69% respectively. The novelty of this research is the design of a unified Explainable Federated Deep Learning Framework which combines privacy-preserving Federated Learning (FL), explainable AI (XAI), and deep learning (DL) to accomplish real-time intrusion detection (ID) in multi-type heterogeneous critical infrastructure IoT (CIIoT) environments. The proposed framework realizes explainability, distributed intelligence and scalable deep learning in a single architecture, enhancing trust, transparency and operation efficiency, different from existing approaches focusing on either detection accuracy or privacy. Future research will concentrate on lightweight model optimisation, adaptive learning, and increased explainability in order to continue improve the deployment in the dynamic IoT context.

Downloads

Published

2026-03-12

How to Cite

Muhammad Umar, Azhar Ali Khan, Ayesha Batool, Mustajib Ur Rehman, Imran Khursheed, & Muhammad Abrar. (2026). AN EXPLAINABLE FEDERATED DEEP LEARNING FRAMEWORK FOR REAL-TIME INTRUSION DETECTION IN CRITICAL INFRASTRUCTURE IOT NETWORKS. Spectrum of Engineering Sciences, 4(3), 4990–5014. Retrieved from https://www.thesesjournal.com.medicalsciencereview.com/index.php/1/article/view/3703