Adaptive Diffusion Markov-Enhanced GCN with LLM Explanations for IoT Attack Detection
Safa Ben Atitallah, Maha Driss, Arwa Alsehibani, Wadii Boulila · Procedia Computer Science · 2025
The increasing complexity and connectivity of Internet of Things (IoT) environments have made them targets for advanced cyber-attacks. Recently, Deep Learning (DL)-based intrusion detection systems have shown remarkable success in identifying malicious activities within IoT traffic. In particular, Graph Neural Networks (GNNs) have emerged as effective solutions. However, GNNs come with inherent challenges, including high computational complexity and a black-box nature, which limit their transparency and interoperability. In this paper, we introduce a hybrid framework that combines a GNN model, named AD-MGCN, with a Large Language Model (LLM) to address these limitations. The proposed AD-MGCN leverages a Markov-based multi-step diffusion process to enhance feature propagation, reduce noisy edges, and improve classification performance across both frequent and rare attack types. In addition, a fine-tuned instruction-based LLM (Falcon-7B Instruct) generates natural language explanations that translate model predictions into human-understandable insights. We evaluated our framework on the Edge-IIoTset dataset, which includes diverse IoT attack scenarios. The experimental results show that AD-MGCN achieves an accuracy of 97.38%, significantly outperforming the baseline GCN models. Furthermore, the LLM explanations achieve an average clarity score of 4.2/5 in expert evaluations, improving the transparency of the model for cybersecurity analysts. These results demonstrate the potential of AD-MGCN as a reliable, efficient, and interpretable solution for securing modern IoT ecosystems.