Submitted:
28 May 2026
Posted:
29 May 2026
You are already at the latest version
Abstract
Keywords:
1. Introduction
- A cyber-physical cross layer explainable intrusion detection framework is proposed for operator-oriented microgrid systems via cross-modal evidence reasoning.
- A structured cross-modal evidence representation is designed to integrate network flows, SDN states, system calls, and power measurements within a unified reasoning framework. This design enables the model to capture correlations across cyber and physical layers, rather than relying on isolated indicators.
- An evidence explanation mechanism is utilized to bridge model reasoning and physical system evidence. By aligning sample importance with structured evidence, the proposed method reveals how heterogeneous evidence contributes to intrusion decisions.
- A novel explanation pipeline is proposed, which transforms heatmap-based representations into structured features and surrogate decision models. This design enables the extraction of decision paths and their conversion into interpretable reasoning processes, providing system explanations grounded in physical evidence.
- The proposed framework enables explanation-guided attack localization and impact minimization by linking decision path explanations to raw artefacts and topology, as demonstrated in SubSection 5.6.
- Experiments are carried out on realistic microgrid IDS datasets to assess both detection performance and explanation ability. We also compare the proposed framework with a text-based QA baseline to show that the proposed framework is different from traditional numerical IDS methods.
2. Related Work
3. Preliminaries
3.1. Intrusion Detection in Microgrid Systems
3.2. LLM Fine-Tuning
3.3. Model Explanation Techniques
4. Proposed Method
4.1. Framework Overview
4.2. Structured QA Formulation
| Algorithm 1 QA Dataset Construction for Microgrid Intrusion Detection |
|
4.3. Model Fine-Tuning
| Algorithm 2 Model Fine-Tuning Process |
|
4.4. Model Explanation and Reasoning
| Algorithm 3 Explanation and Reasoning via Heatmap and Decision Tree |
|
5. Experimental Design and Results
5.1. Datasets
5.1.1. UNSW-MG24 Dataset
5.1.2. SDN-MG25 Dataset
5.2. Experimental Setup
5.3. Intrusion Detection Evaluation
5.4. Heatmap Explanation
5.5. Decision Tree Explanation
5.6. Decision Path-based Explanations and Examples
6. Analysis and Discussion
7. Conclusions
Acknowledgments
References
- Sarker, P.S.; Venkataramanan, V.; Cardenas, D.S.; Srivastava, A.; Hahn, A.; Miller, B. Cyber-physical security and resiliency analysis testbed for critical microgrids with ieee 2030.5. In Proceedings of the 2020 8th workshop on modeling and simulation of cyber-physical energy systems. IEEE, 2020; pp. 1–6. [Google Scholar]
- Solat, A.; Gharehpetian, G.B.; Naderi, M.S.; Anvari-Moghaddam, A. On the control of microgrids against cyber-attacks: A review of methods and applications. Appl. Energy 2024, 353, 122037. [Google Scholar] [CrossRef]
- Singh, M.P.; Bhandari, A. New-flow based DDoS attacks in SDN: Taxonomy, rationales, and research challenges. Comput. Commun. 2020, 154, 509–527. [Google Scholar] [CrossRef]
- McKeown, N.; Anderson, T.; Balakrishnan, H.; Parulkar, G.; Peterson, L.; Rexford, J.; Shenker, S.; Turner, J. OpenFlow: enabling innovation in campus networks. ACM SIGCOMM Comput. Commun. Rev. 2008, 38, 69–74. [Google Scholar] [CrossRef]
- Zhong, J.; Chen, C.; Bie, Z.; Shahidehpour, M. Strategic SDN-Based Microgrid Formation for Managing Communication Failures in Distribution System Restoration. IEEE Trans. Power Syst. 2025, 40, 2506–2518. [Google Scholar] [CrossRef]
- Taherian-Fard, E.; Niknam, T.; Sahebi, R.; Javidsharifi, M.; Kavousi-Fard, A.; Aghaei, J. A Software Defined Networking Architecture for DDoS-Attack in the Storage of Multimicrogrids. IEEE Access 2022, 10, 83802–83812. [Google Scholar] [CrossRef]
- Pota, H.R. Droop control for islanded microgrids. In Proceedings of the 2013 IEEE Power & Energy Society General Meeting; IEEE, 2013; pp. 1–4. [Google Scholar]
- Zhang, Z.; Turnbull, B.; Kermanshahi, S.K.; Pota, H.; Damiani, E.; Yeun, C.Y.; Hu, J. A survey on resilient microgrid system from cybersecurity perspective. Appl. Soft Comput. 2025, 113088. [Google Scholar] [CrossRef]
- Tan, S.; Wu, Y.; Xie, P.; Guerrero, J.M.; Vasquez, J.C.; Abusorrah, A. New challenges in the design of microgrid systems: Communication networks, cyberattacks, and resilience. IEEE Electrif. Mag. 2020, 8, 98–106. [Google Scholar] [CrossRef]
- Nand, K.; Zhang, Z.; Hu, J. A Comprehensive Survey on the Usage of Machine Learning to Detect False Data Injection Attacks in Smart Grids. IEEE Open J. Comput. Soc. 2025, 6, 1121–1132. [Google Scholar] [CrossRef]
- Zou, H.; Zhao, Q.; Tian, Y.; Bariah, L.; Bader, F.; Lestable, T.; Debbah, M. TelecomGPT: A Framework to Build Telecom-Specific Large Language Models. IEEE Trans. Mach. Learn. Commun. Netw. 2025, 3, 948–975. [Google Scholar] [CrossRef]
- Kalafatidis, S.; Papageorgopoulos, N.; Kartakoullis, A.; Ledakis, G. LLM-Enhanced Intrusion Detection for Containerized Applications: A Two-Tier Strategy for SDN and Kubernetes Environments. In Proceedings of the International Conference on Availability, Reliability and Security, 2025; Springer; pp. 55–73. [Google Scholar]
- Karunanayake, B.; Khalil, I.; Yi, X.; Lam, K.Y. Toward LLM-Driven Adaptive Policy Orchestration for Host-Based Intrusion Detection Systems in IoT Environments. IEEE Netw. 2025, 39, 66–73. [Google Scholar] [CrossRef]
- Houssel, P.R.; Layeghy, S.; Singh, P.; Portmann, M. ex-nids: A framework for explainable network intrusion detection leveraging large language models. Comput. Electr. Eng. 2026, 129, 110826. [Google Scholar] [CrossRef]
- Adjewa, F.; Esseghir, M.; Merghem-Boulahia, L.; Kacfah, C. LLM-based Continuous Intrusion Detection Framework for Next-Gen Networks. Proc. 2025 Int. Wirel. Commun. Mob. Comput. (IWCMC) 2025, 1198–1203. [Google Scholar] [CrossRef]
- Zhao, H.; Chen, H.; Yang, F.; Liu, N.; Deng, H.; Cai, H.; Wang, S.; Yin, D.; Du, M. Explainability for large language models: A survey. ACM Trans. Intell. Syst. Technol. 2024, 15, 1–38. [Google Scholar] [CrossRef]
- Zhang, L.; Hu, L.; Wang, D. Mechanistic Unveiling of Transformer Circuits: Self-Influence as a Key to Model Reasoning. Proc. Find. Assoc. Comput. Linguist. NAACL 2025, 2025, 1387–1404. [Google Scholar]
- Vig, J. A multiscale visualization of attention in the transformer model. In Proceedings of the Proceedings of the 57th annual meeting of the association for computational linguistics: system demonstrations, 2019; pp. 37–42. [Google Scholar]
- Seo, S.; Yoo, S.; Lee, H.; Jang, Y.; Park, J.H.; Kim, J.N. A Sentence-Level Visualization of Attention in Large Language Models. Proceedings of the Proceedings of the 2025 Conference of the Nations of the Americas Chapter of the Association for Computational Linguistics: Human Language Technologies (System Demonstrations) 2025, 313–320. [Google Scholar]
- Xu, H.; Wang, S.; Li, N.; Wang, K.; Zhao, Y.; Chen, K.; Yu, T.; Liu, Y.; Wang, H. Large language models for cyber security: A systematic literature review. ACM Transactions on Software Engineering and Methodology, 2024. [Google Scholar]
- Chen, Y.; Cui, M.; Wang, D.; Cao, Y.; Yang, P.; Jiang, B.; Lu, Z.; Liu, B. A survey of large language models for cyber threat detection. Comput. Secur. 2024, 145, 104016. [Google Scholar] [CrossRef]
- Zhang, Z.; Turnbull, B.; Kermanshahi, S.K.; Pota, H.; Hu, J. UNSW-MG24: A Heterogeneous Dataset for Cybersecurity Analysis in Realistic Microgrid Systems. IEEE Open J. Comput. Soc. 2025, 6, 543–553. [Google Scholar] [CrossRef]
- Zhibo, Z.; Turnbull, B.; Kermanshahi, S.K.; Pota, H.; Hu, J. SDN-MG25: A Comprehensive Dataset for Cybersecurity Analysis in Software Defined Networking-Enabled Microgrid Systems. IEEE Open J. Comput. Soc. 2026, 7, 26–36. [Google Scholar] [CrossRef]
- Yang, Y.; Guo, L.; Li, X.; Li, J.; Liu, W.; He, H. A data-driven detection strategy of false data in cooperative DC microgrids. In Proceedings of the IECON 2021–47th Annual Conference of the IEEE Industrial Electronics Society. IEEE, 2021; pp. 1–6. [Google Scholar]
- Panthi, M. Anomaly detection in smart grids using machine learning techniques. In Proceedings of the 2020 First International Conference on Power, Control and Computing Technologies (ICPC2T); IEEE, 2020; pp. 220–222. [Google Scholar]
- Safari, A.; Hashemzadeh, F.; Zare, K. DeepEMS: Multimodal optimal energy management of microgrid systems based on a hybrid multi-stage machine learning model. J. Eng. 2024, 2024, e70012. [Google Scholar] [CrossRef]
- Jena, S.; Padhy, N.P.; Guerrero, J.M. Multi-Layered Coordinated Countermeasures for DC Microgrid Clusters Under Man in the Middle Attack. IEEE Trans. Ind. Appl. 2024, 60, 2127–2141. [Google Scholar] [CrossRef]
- Zhang, J.; Bu, H.; Wen, H.; Liu, Y.; Fei, H.; Xi, R.; Li, L.; Yang, Y.; Zhu, H.; Meng, D. When llms meet cybersecurity: A systematic literature review. Cybersecurity 2025, 8, 55. [Google Scholar] [CrossRef]
- Shafee, S.; Bessani, A.; Ferreira, P.M. Evaluation of LLM-based chatbots for OSINT-based Cyber Threat Awareness. Expert Syst. With Appl. 2025, 261, 125509. [Google Scholar] [CrossRef]
- Ghimire, A.; Ghajari, G.; Gurung, K.; Sah, L.K.; Amsaad, F. Enhancing Cybersecurity in Critical Infrastructure with LLM-Assisted Explainable IoT Systems. Proceedings of the 2025 1st International Conference on Secure IoT, Assured and Trusted Computing (SATC) 2025, 1–5. [Google Scholar] [CrossRef]
- Keltek, M.; Hu, R.; Sani, M.F.; Li, Z. LSAST: Enhancing cybersecurity through LLM-supported static application security testing. In Proceedings of the IFIP International Conference on ICT Systems Security and Privacy Protection, 2025; Springer; pp. 166–179. [Google Scholar]
- Liu, C.; Wang, Y.; Yan, Z.; Konstantinou, C.; Xie, K. Operator-in-the-Loop Multi-Objective Scheduling of Multi-Energy Microgrids via LLM-Guided Reinforcement Learning. IEEE Trans. Ind. Appl. 2025, 1–13. [Google Scholar] [CrossRef]
- Yang, H.; Li, Z.; Liu, Y.; Xiang, Y.; Li, L.; Yang, J.; Tan, L.; Wang, S.; Ma, H.; Xi, Z.; et al. LLM-Powered Distributed Optimal Scheduling for Industrial Heat-Electricity Micro-Grids. IEEE Trans. Ind. Appl. 2026, 62, 1874–1885. [Google Scholar] [CrossRef]
- Wang, H.; Li, J.; Liu, X. Large Language Model Compatibility With Reinforcement Learning for Networked Microgrids Considering Device and System-Level Missing Measurements. IEEE Trans. Ind. Appl. 2026, 62, 3746–3759. [Google Scholar] [CrossRef]
- Tian, S.; Zhang, T.; Zhang, R.; Tang, X.; Liu, Z.; Kang, J.; Liu, J.; Niyato, D.; Kim, D.I. Reasoning Techniques Meet GraphRAG: Advancing LLM for Wireless Network Cyber Defense. IEEE Wirel. Commun. 2026, 1–8. [Google Scholar] [CrossRef]
- Yang, X.; Zhong, R.; Chen, Y.; Peng, G.; Yao, D.; Chen, C.; Wang, C.; Zhang, D.; Zhou, Y.; Yang, Z. CTI-Thinker: an LLM-driven system for CTI knowledge graph construction and attack reasoning. Cybersecurity 2026, 9, 106. [Google Scholar] [CrossRef]
- Suhail, S.; Iqbal, M.; Hussain, R.; Jurdak, R. ENIGMA: An explainable digital twin security solution for cyber–physical systems. Comput. Ind. 2023, 151, 103961. [Google Scholar] [CrossRef]
- Hoq, M.N.; Yao, J.W.; Majumdar, S.; Suárez, L.; Wang, L.; Boukhtouta, A.; Pourzandi, M.; Debbabi, M. Evaluating the security posture of 5G networks by combining state auditing and event monitoring. In Proceedings of the European Symposium on Research in Computer Security, 2023; Springer; pp. 123–144. [Google Scholar]
- Guo, F.; Xu, K.; Zhang, Z.; Zhou, H.; Chen, G.; Hu, J.; Zhang, J.; Mo, H. Battery SOH Prediction Under Different Conditions via MBLSTM and iTransformer With Anomaly Detection and Explainability. IEEE Open J. Comput. Soc. 2025, 6, 1847–1857. [Google Scholar] [CrossRef]
- Zhang, Z.; Hu, J.; Pota, H.; Kermanshahi, S.K.; Turnbull, B.; Damiani, E.; Yeun, C.Y. Experimental Demonstration of Risks and Influences of Cyber Attacks on Wireless Communication in Microgrids. Proceedings of the 2024 21st Annual International Conference on Privacy, Security and Trust (PST) 2024, 1–5. [Google Scholar] [CrossRef]
- Wu, X.K.; Chen, M.; Li, W.; Wang, R.; Lu, L.; Liu, J.; Hwang, K.; Hao, Y.; Pan, Y.; Meng, Q.; et al. LLM fine-tuning: Concepts, opportunities, and challenges. Big Data Cogn. Comput. 2025, 9, 87. [Google Scholar] [CrossRef]
- Zhang, B.; Wang, J.; Du, Q.; Zhang, J.; Tu, Z.; Chu, D. A survey on data selection for llm instruction tuning. J. Artif. Intell. Res. 2025, 83. [Google Scholar] [CrossRef]
- Che, C.; Wang, Z.; Yang, P.; Wang, C.; Ma, H.; Shi, Z. LoRA in LoRA: Towards parameter-efficient architecture expansion for continual visual instruction tuning. Proc. Proc. AAAI Conf. Artif. Intell. 2026, Vol. 40, 19978–19986. [Google Scholar] [CrossRef]
- Zhang, Z.; Hamadi, H.A.; Damiani, E.; Yeun, C.Y.; Taher, F. Explainable Artificial Intelligence Applications in Cyber Security: State-of-the-Art in Research. IEEE Access 2022, 10, 93104–93139. [Google Scholar] [CrossRef]
- Huang, X.; Zhang, Z.; Guo, F.; Wang, X.; Chi, K.; Wu, K. Research on older adults’ interaction with e-health interface based on explainable artificial intelligence. In Proceedings of the International Conference on Human-Computer Interaction, 2024; Springer; pp. 38–52. [Google Scholar]
- Ribeiro, M.T.; Singh, S.; Guestrin, C. Why should i trust you?" Explaining the predictions of any classifier. In Proceedings of the Proceedings of the 22nd ACM SIGKDD international conference on knowledge discovery and data mining, 2016; pp. 1135–1144. [Google Scholar]
- Li, H.; Kam-Kwai, W.; Luo, Y.; Chen, J.; Liu, C.; Zhang, Y.; Lau, A.K.H.; Qu, H.; Liu, D. Save It for the “Hot” Day: An LLM-Empowered Visual Analytics System for Heat Risk Management. IEEE Trans. Vis. Comput. Graph. 2025, 31, 8928–8943. [Google Scholar] [CrossRef] [PubMed]
- Ku, J.; Kim, S.; Lee, E.; Zaman, U.; Kim, K. Enhancing Autonomous Ship Communication: A Cost-Effective and High-Accuracy LLM Framework Using Decision Trees and RAG. Proceedings of the 2025 International Conference on Artificial Intelligence in Information and Communication (ICAIIC) 2025, 0420–0426. [Google Scholar] [CrossRef]
- Google DeepMind. Gemma 3 4B: Multimodal Large Language Model. 2026. Available online: https://ollama.com/library/gemma3:4b (accessed on 2026-04-17).
- Meta, A.I. LLaMA 3: Open Large Language Model Family. 2025. Available online: https://ollama.com/library/llama3 (accessed on 2026-04-17).
- Cloud, Alibaba. Qwen 3 4B: Large Language Model. 2025. Available online: https://ollama.com/library/qwen3:4b (accessed on 2026-04-17).
- Ollama. Ollama: Run Large Language Models Locally. 2026. Available online: https://github.com/ollama/ollama (accessed on 2026-04-17).
- Mintplex Labs. AnythingLLM: The All-in-One AI Application for LLM-Based Document Interaction. 2026. Available online: https://github.com/Mintplex-Labs/anything-llm (accessed on 2026-04-17).
- Rani, R.; Kumar, M.; Epiphaniou, G.; Maple, C. ICSThreatQA: A Knowledge-Graph Enhanced Question Answering Model for Industrial Control System Threat Intelligence. Expert Syst. With Appl. 2025, 130180. [Google Scholar] [CrossRef]
- Mohammadian, H.; Habibi Lashkari, A.; Ghorbani, A.A. Poisoning and Evasion: Deep Learning-Based NIDS under Adversarial Attacks. Proceedings of the 2024 21st Annual International Conference on Privacy, Security and Trust (PST) 2024, 1–9. [Google Scholar] [CrossRef]





| Work | A1 | A2 | A3 | A4 | A5 | A6 | A7 | A8 |
|---|---|---|---|---|---|---|---|---|
| [17] | × | × | ✓ | × | n/a | n/a | × | × |
| [18] | × | × | ✓ | ✓ | n/a | n/a | × | × |
| [19] | × | × | ✓ | ✓ | n/a | n/a | × | × |
| [25] | × | × | × | × | × | × | × | × |
| [26] | ✓ | × | × | × | × | × | × | ✓ |
| [27] | × | × | × | × | × | × | × | ✓ |
| [29] | × | × | ✓ | × | n/a | n/a | × | × |
| [30] | × | × | ✓ | × | ✓ | × | × | × |
| [31] | × | × | ✓ | × | n/a | n/a | × | × |
| [32] | × | × | ✓ | n/a | n/a | n/a | × | ✓ |
| [33] | × | × | ✓ | n/a | n/a | n/a | × | × |
| [34] | × | × | ✓ | n/a | n/a | n/a | × | ✓ |
| [35] | × | ✓ | ✓ | × | n/a | n/a | ✓ | ✓ |
| [36] | × | ✓ | ✓ | × | n/a | n/a | ✓ | ✓ |
| [38] | × | ✓ | × | n/a | n/a | n/a | × | × |
| [37] | × | × | × | × | ✓ | × | × | × |
| Proposed | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Setting | Dataset | Framework | QA Det. / Ans. Corr. (%) |
Atk. Type Acc. (%) |
Det. Gain (%) |
|---|---|---|---|---|---|
| QA Baseline and Cross-dataset Context | |||||
| Original result | ICSThreatQA | RAG only | 42.7–51.3 | – | – |
| Testing only | ICSThreatQA | Proposed framework | 43.1 | – | – |
| With tuning | ICSThreatQA | Proposed framework | 53.7 | – | – |
| No adaptation | Microgrid IDS QA | RAG only | 25.1–30.4 | – | – |
| Training adaptation | Microgrid IDS QA | RAG only | 35.8–42.4 | – | – |
| Without tuning | CICAug.24 IDS QA | Proposed framework | 42.1 | – | – |
| With tuning | CICAug.24 IDS QA | Proposed framework | 62.6 | – | – |
| Proposed Microgrid IDS QA Framework | |||||
| Untuned | Microgrid IDS QA | Gemma-3-4B | 42.2 | 36.0 | – |
| Tuned | Microgrid IDS QA | Gemma-3-4B | 62.8 | 57.2 | +48.8 |
| Untuned | Microgrid IDS QA | LLaMA-3-4B | 42.6 | 35.6 | – |
| Tuned | Microgrid IDS QA | LLaMA-3-4B | 59.4 | 56.4 | +39.4 |
| Untuned | Microgrid IDS QA | Qwen-3-4B | 46.2 | 35.2 | – |
| Tuned | Microgrid IDS QA | Qwen-3-4B | 71.4 | 64.0 | +54.5 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).