Scalable Explainable AI with a Cloud-Native Approach for Cybersecurity Threat Detection

Thiyagarajan Mani Chettier, Venkata Ashok Kumar Boyina, Sunil Jorepalli, Charanjit Singh, Neha Gupta · 2025

The growing complexity and number of cyber threats call for sophisticated detection approaches that provide both high performance and interpretability. The proposed hybrid AI approach (AE-RF-CNN-LSTM) is a promising hybrid up-to-date improving SEO framework for cybersecurity. All these models play a steady role in performance improvement. Autoencoders are trained to sense patterns from normal data to assist in anomaly detection, random forests help with the robustness of the model with overfitting reduction, and CNN-LSTMs assist greatly in recognizing the complex temporal dependencies in network traffic data. Experimental results show that this approach achieves substantially improved accuracy nearest neighbor anomaly detection and surpasses every single model in terms of accuracy. This hybrid framework, thus, helps to detect known and unknown cyber threats, leading to a huge decrease in false positive and false negative rates. Furthermore, integrating explainable AI (XAI) methods, including SHAP (SHapley Additive explanations) and LIME (Local Interpretable Model-Agnostic Explanations), to enhance decision interpretability. The methods enable security analysts to comprehend the most relevant features of making predictions and, therefore, trust the model and correct further cybersecurity actions. This not only allows for the improvement of defense mechanisms against cyberattacks but also builds confidence in AI-driven security solutions by providing interpretability and assurance of performance.

Read the paper · More papers on PaperTik