Home / Journals / CMC / Online First / doi:10.32604/cmc.2026.084273
Special Issues
Table of Content

Open Access

ARTICLE

APENet: Advanced Cyber Security Attack Detection with Attentive Path-Encoding in IoT Networks Using SHAP Based Explainability

Muhammad Mujahid1, Fatima Alshannaq1, Shaha Al-Otaibi2, Tanzila Saba1,*
1 Artificial Intelligence & Data Analytics Lab, CCIS, Prince Sultan University, Riyadh, Saudi Arabia
2 Department of Information Systems, College of Computer and Information Sciences, Princess Nourah bint Abdulrahman University, Riyadh, Saudi Arabia
* Corresponding Author: Tanzila Saba. Email: email
(This article belongs to the Special Issue: Advances in Intrusion Detection and Prevention Systems)

Computers, Materials & Continua https://doi.org/10.32604/cmc.2026.084273

Received 19 April 2026; Accepted 03 June 2026; Published online 10 July 2026

Abstract

Cybersecurity threats in Internet of Things (IoT) networks have escalated, enabled by rapid advancements in wireless communication and edge computing technologies. These advancements expose networks to a wide range of sophisticated and evolving threats and increasingly complex research challenges. Traditional Intrusion Detection and Prevention Systems (IDS/IPS) often fail to provide reliable performance regarding the flexibility and scalability required to handle evolving attack patterns. This study proposes an APENet approach to detect cyberattacks from a real-world cybersecurity dataset, and incorporated a contextual dependency mechanism. The approach captures both local transition dependencies and global relational interactions within structural sequences using bidirectional contextual aggregation and global attention-based interaction modeling. Furthermore, a protocol-aware feature normalization and preprocessing pipeline is developed, including hex-to-integer protocol field normalization, timestamp rebasing, and derivation of traffic dynamics indicators. Severe imbalance in the IoT cybersecurity dataset is addressed with synthetic minority oversampling and TomekLinks techniques to ensure balanced and representative training data. The proposed approach’s generalization and robustness are evaluated using stratified 5-fold cross-validation to ensure reliable performance across heterogeneous IoT scenarios. We did several experiments, and the proposed approach achieved remarkable performance for attack detection and underscored the model’s flexibility in adapting to various IoT environments. Furthermore, SHapley Additive exPlanations (SHAP) are incorporated to provide explainability, enabling the identification of key features influencing attack predictions and improving trust in model decisions. Overall, this study contributes a robust and adaptive security solution for strengthening IoT ecosystems against evolving cyber threats.

Keywords

Intrusion detection; cybersecurity; explainability; imbalance data; IoT; artificial intelligence
  • 117

    View

  • 19

    Download

  • 0

    Like

Share Link