Explainable and Adaptive Intrusion Detection in Digital Twin Environments

Alharbi, Ohood, Shaikh, Riaz Ahmed ORCID: https://orcid.org/0000-0001-6666-0253, Hassan, Raheel and Asif, Rameez (2026) Explainable and Adaptive Intrusion Detection in Digital Twin Environments. In: Proceedings - 2026 13th International Conference on Future Internet of Things and Cloud, FiCloud 2026. Proceedings - 2026 13th International Conference on Future Internet of Things and Cloud, FiCloud 2026 . The Institute of Electrical and Electronics Engineers (IEEE), ESP, pp. 59-66. ISBN 9798319547392

[thumbnail of advanced-programme-2026]
Preview
PDF (advanced-programme-2026) - Published Version
Available under License Unspecified licence.

Download (598kB) | Preview

Abstract

This paper presents an Intrusion Detection System (IDS) grounded in Explainable Artificial Intelligence (XAI) to enhance transparency, reliability, and user trust in IoT security. To make detection decisions interpretable and accountable, the system employs ensemble machine learning for real-time anomaly detection and integrates two complementary explainability methods: SHapley Additive exPlanations (SHAP), and Local Interpretable Model-agnostic Explanations (LIME). A Digital Twin (DT) module continuously mirrors device behaviour, supporting predictive threat analysis and early anomaly identification by detecting deviations from expected operational baselines. The framework is evaluated on the TON_IoT benchmark dataset using accuracy, precision, recall, F1-score, ROC-AUC, and the Matthews Correlation Coefficient (MCC). Experimental results demonstrate that Random Forest and XGBoost achieve the highest accuracy of 0.996. In the XAI comparison, SHAP outperforms LIME across all metrics F1=0.995, ROC-AUC=0.998 vs. 0.993 for LIME), confirming its stronger explanatory and predictive effectiveness. While the current framework focuses on XAIdriven detection and digital twin integration, the architecture is designed to accommodate future extensions, including blockchain with zero-knowledge proof (ZKP) protocols for tamper.

Item Type: Book Section
Uncontrolled Keywords: digital twin,intrusion detection system,iot security,lime,shap,ton_iot,xai,computer networks and communications,computer science applications,information systems ,/dk/atira/pure/subjectarea/asjc/1700/1705
Faculty \ School: Faculty of Science > School of Computing Sciences
Faculty of Science
UEA Research Groups: Faculty of Science > Research Groups > Cyber Intelligence and Networks
Related URLs:
Depositing User: LivePure Connector
Date Deposited: 13 Aug 2026 09:01
Last Modified: 16 Sep 2026 14:41
URI: https://ueaeprints.uea.ac.uk/id/eprint/104106
DOI: 10.1109/FiCloud70576.2026.00016

Downloads

Downloads per month over past year

Actions (login required)

View Item View Item