A Unified Generative and Explainable Artificial Intelligence Framework for Trustworthy Intrusion Detection in Cyber-Physical Networks
Mian Muhammad Kamal1,*, Tianjun Ma1,*, Mohammed K. Alzaylaee2, Husam S. Samkari3,4, Mohammed F. Allehyani3, Omar Almomani5, Heba G. Mohamed6,7
1 School of Electronics and Communication Engineering, Quanzhou University of Information Engineering, Quanzhou, 362000, China
2 Department of Computing, College of Engineering and Computing in Al-Qunfudhah, Umm AL-Qura University, Makkah, Saudi Arabia
3 Department of Electrical Engineering, University of Tabuk, Tabuk, 47713, Saudi Arabia
4 Artificial Intelligence and Sensing Technologies Research Center, University of Tabuk, Tabuk, 47713, Saudi Arabia
5 Department of Networks and Cybersecurity, Hourani Center for Applied Scientific Research, Al-Ahliyya Amman University, Amman, Jordan
6 Department of Electrical Engineering, College of Engineering, Princess Nourah bint Abdulrahman University, P.O. Box 84428, Riyadh, 11671, Saudi Arabia
7 Electrical Department, College of Engineering, Alexandria Higher Institute of Engineering and Technology, Alexandria, 21421, Egypt
* Corresponding Author: Mian Muhammad Kamal. Email:
; Tianjun Ma. Email:
Computers, Materials & Continua https://doi.org/10.32604/cmc.2026.085412
Received 11 May 2026; Accepted 24 June 2026; Published online 20 July 2026
Abstract
The cyber-physical network (CPS) combines sensing, communication, and control in physical processes, making them very susceptible to sophisticated cyber-attacks that may cause safety-critical effects. There are two core shortcomings to existing intrusion detection systems (IDS): generative-only models have little transparency of decision-making, while explainable-only models have low robustness in the presence of imbalanced and zero-day attacks. This paper presents a sequentially integrated trustworthy intrusion detection (ID) framework that combines generative learning and explainable AI (XAI) to boost robustness and transparency. The generative module enhances training data diversity, while the explainability module provides post-hoc interpretations during inference. The framework exploits a Generative Adversarial Network (GAN) to tackle the issue of class imbalance and boost generalization to untrained attacks, and SHAP, LIME, and attention-based approaches give instance-level and feature-level explanations. The proposed framework is proven to significantly improve the performance of the state-of-the-art methods through extensive evaluations on industrial CPS, industrial IoT-based CPS, and smart grid-based datasets. In terms of quantitative metrics, it achieves 97.4% accuracy, 96.1% F1-score, 3.1% false alarm rate, 0.983 AUC, and 91.2% zero-day attack detection (compared to 84.7% for GAN-only and 78.6% for XAI-only). The proposed framework provides a qualitative framework that enables the derivation of transparent, human-understandable decisions that are not compromised in terms of detection performance while maintaining an inference latency of 2.6 ms per sample, suitable for real-time CPS monitoring. The results validate the effectiveness of the integration of generative learning and explainable AI as a secure, transparent, and trusted solution to securing modern cyber–physical networks, where current generative-only and explainable-only IDS methods are unable to cover the essential needs.
Keywords
Cyber-physical systems; trustworthy intrusion detection; generative learning; explainable artificial intelligence (XAI); zero-day attack detection