Open Access
ARTICLE
APENet: Advanced Cyber Security Attack Detection with Attentive Path-Encoding in IoT Networks Using SHAP Based Explainability
1 Artificial Intelligence & Data Analytics Lab, CCIS, Prince Sultan University, Riyadh, Saudi Arabia
2 Department of Information Systems, College of Computer and Information Sciences, Princess Nourah bint Abdulrahman University, Riyadh, Saudi Arabia
* Corresponding Author: Tanzila Saba. Email:
(This article belongs to the Special Issue: Advances in Intrusion Detection and Prevention Systems)
Computers, Materials & Continua 2026, 89(1), 29 https://doi.org/10.32604/cmc.2026.084273
Received 19 April 2026; Accepted 03 June 2026; Issue published 13 August 2026
Abstract
Cybersecurity threats in Internet of Things (IoT) networks have escalated, enabled by rapid advancements in wireless communication and edge computing technologies. These advancements expose networks to a wide range of sophisticated and evolving threats and increasingly complex research challenges. Traditional Intrusion Detection and Prevention Systems (IDS/IPS) often fail to provide reliable performance regarding the flexibility and scalability required to handle evolving attack patterns. This study proposes an APENet approach to detect cyberattacks from a real-world cybersecurity dataset, and incorporated a contextual dependency mechanism. The approach captures both local transition dependencies and global relational interactions within structural sequences using bidirectional contextual aggregation and global attention-based interaction modeling. Furthermore, a protocol-aware feature normalization and preprocessing pipeline is developed, including hex-to-integer protocol field normalization, timestamp rebasing, and derivation of traffic dynamics indicators. Severe imbalance in the IoT cybersecurity dataset is addressed with synthetic minority oversampling and TomekLinks techniques to ensure balanced and representative training data. The proposed approach’s generalization and robustness are evaluated using stratified 5-fold cross-validation to ensure reliable performance across heterogeneous IoT scenarios. We did several experiments, and the proposed approach achieved remarkable performance for attack detection and underscored the model’s flexibility in adapting to various IoT environments. Furthermore, SHapley Additive exPlanations (SHAP) are incorporated to provide explainability, enabling the identification of key features influencing attack predictions and improving trust in model decisions. Overall, this study contributes a robust and adaptive security solution for strengthening IoT ecosystems against evolving cyber threats.Keywords
Cite This Article
Copyright © 2026 The Author(s). Published by Tech Science Press.This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.


Submit a Paper
Propose a Special lssue
View Full Text
Download PDF
Downloads
Citation Tools