Explainable AI-Driven Threat Detection and Response for Industrial IoT
Shokooh Khandan, Deniz Beyazgul, Olamide Jogunola, Yakubu Tsado, Tooska Dargahi · 2025
The growing complexity and volume of cyber attacks to Cyber-Physical Systems (CPS) and Industrial Internet of Things (IIoT) have outpaced traditional detection methods, requiring more intelligent and explainable security solutions. While Artificial Intelligence (AI)-based anomaly detection solutions have been proposed in the literature, they either focus on a single type of attack, or their decisions are restricted based on a single dataset, or they lack transparency. To address these challenges, this paper presents an explainable attack detection framework for IIoT, combining advanced machine learning (ML) models and AI-driven interpretability. The framework employs mid-level and late data fusion techniques on two IIoT datasets, using Autoencoders (AE) and Manifold Alignment (MA) techniques to generate a unified feature space. A Random Forest (RF) classifier is trained on the fused dataset to detect four attack types, achieving a 97% accuracy. The model's decision-making is made transparent through Explainable AI (XAI) tools, providing both global and local interpretability. Furthermore, a Large Language Model (LLM)-powered AI assistant is developed to provide automated, context-aware mitigation strategies based on MITRE D3FEND framework. This integrated approach enhances the detection, interpretability, and response to threats in IIoT environments, promoting greater trust and operational resilience.