Submitted:
30 August 2026
Posted:
01 September 2026
You are already at the latest version
Abstract
Intrusion detection systems often operate with incomplete information. Rule bases may contain gaps, attack types may be rare or previously unseen, labels may arrive late, sensors may capture only part of an event, and some observations may be poorly represented in the training data. However, many studies still use static closed-world evaluations and assume that providing an explanation makes a system trustworthy. This structured narrative survey examines explainable intrusion detection using the concept of incomplete information, defined as a lack of evidence needed to justify a label, score, abstention, escalation, or response. It distinguishes incomplete information from uncertainty, class imbalance, concept drift, privacy, federated learning, and adaptation. The review covers fuzzy rule interpolation, network and device evidence, post hoc explainable artificial intelligence, adversarial robustness and recovery, distributed and adaptive learning, and edge/fog/cloud deployment. Three main findings emerge. First, no single method addresses every information gap. Fuzzy rule interpola-tion directly addresses missing coverage in sparse fuzzy rule bases, while other methods are relevant only when they target a clearly defined information problem and are tested under matching conditions. Second, an explanation is credible only when its fidelity, stability, semantic validity, computational cost, and disclosure of information limits are evaluated for the intended task. Third, deployment design and governance determine whether an output can support operational action. The survey proposes a six-axis taxonomy, seven evidence streams, a tiered deployment architecture, an integrated evaluation and benchmarking protocol, design and reporting templates, and a research agenda. The framework links each conclusion to the tested information condition, stress model, computational tier, and authority boundary.
Keywords:
intrusion detection systems
; incomplete information
; explainable artificial intelli-gence
; fuzzy rule interpolation
; sparse rule bases
; network traffic analysis
; adversarial robustness
; edge/fog/cloud deployment
; IoT security
; adaptive cyber defense
; critical infrastructure
; analyst-centered evaluation
1. Introduction
Operational intrusion detection is more appropriately understood as decision support under asymmetric costs and incomplete visibility than as classification alone. When attack prevalence is low, even modest false-positive rates can dominate analyst workload [1]. Closed-world training may ob-scure rare, evolving, or previously unseen attacks [2,3,4], while benchmark partitions may not reproduce the temporal, device, family, site, and deployment boundaries that shape field performance [5,6]. These limitations are particularly consequential in cloud, IoT, mobile, operational-technology, smart-grid, and software-supply-chain environments, where sensing is selective, telemetry is distributed, and labels are frequently delayed or noisy. Consequently, a detector may achieve strong test accuracy while offering insufficient support for triage, escalation, or response.
The central analytical issue is decision-relative sufficiency. An IDS may be required to classify, score, explain, abstain, escalate, or recommend an action despite sparse rule coverage, rare attack examples, missing labels, partial observability, or an input located in a region that is weakly supported by the training distribution. This survey denotes such circumstances as incomplete information. The concept is narrower than uncertainty, class imbalance, privacy preservation, federated learning, reinforcement learning, or concept drift. Fuzzy rule interpolation (FRI) directly addresses one instance of this broader set—missing coverage in a sparse fuzzy rule base—because it was developed for observations for which no exact rule is available [7,8,9]. Other mechanisms are included only when they create, expose, or reduce a clearly specified information deficit.
Explainability requires equivalent conceptual precision. Rule traces, membership degrees, feature attributions, local surrogates, counterfactuals, prototypes, and saliency maps address different ques-tions and serve different users. Post hoc methods can render an opaque detector more inspectable, but the presence of an explanation does not establish its fidelity, stability, semantic validity, or use-fulness to analysts [10,11,12,13,14]. Similarly, federated and adaptive architectures can support data locality, privacy-preserving collaboration, or sequential action without demonstrating dependable reasoning under incomplete information or operational readiness [15,16,17,18,19]. The analysis therefore distinguishes mechanism from warrant: architecture specifies how a system operates, whereas reported evidence determines which conclusions are justified.
This survey makes four contributions. First, it defines incomplete information as a decision condition and distinguishes it from adjacent constructs. Second, it organizes the literature through a six-axis study profile and seven interconnected evidence streams. Third, it relates explanation, robustness, and model updating to a tiered device–gateway–fog–cloud/SOC–governance architecture. Fourth, it develops evaluation, reporting, design, and governance criteria intended to keep conclusions proportional to the conditions actually tested. Recent studies of explainable random-forest IDS and high-dimensional zero-day detection illustrate why interpretability and generalization must be evaluated independently rather than inferred from predictive performance [20,21]. Table 1 translates these contributions into the research questions that guide the review.
Figure 1.
Analytical architecture of the survey. Decision-relevant information gaps are mapped to a study profile, evidence synthesis, operational placement, and matched evaluation; the final conclusion is bounded by the least-supported link.
Figure 1.
Analytical architecture of the survey. Decision-relevant information gaps are mapped to a study profile, evidence synthesis, operational placement, and matched evaluation; the final conclusion is bounded by the least-supported link.

The remainder of the paper progresses from conceptual scope to operational guidance. Section 2 describes the review design and evidence-appraisal logic, while Section 3 defines the focal construct and its boundaries. Section 4 and Section 5 introduce the study profile and synthesize the principal evidence streams. Section 6, Section 7 and Section 8 examine explanation, deployment placement, and benchmarking. The subse-quent sections translate the synthesis into failure modes, design patterns, domain-transfer boundaries, reporting protocols, governance controls, method-family comparisons, and a research agenda, after which Section 16 presents the principal conclusions.
2. Review Design, Scope, and Evidence Normalization
2.1. Review Design and Unit of Analysis
This article adopts a structured narrative design rather than a PRISMA-style systematic review or quantitative meta-analysis. It therefore makes no claim of exhaustive retrieval, formal screening counts, or pooled effect estimation. This choice reflects the methodological breadth of explainable IDS under incomplete information, which spans fuzzy rule interpolation, sparse rule bases, benchmark datasets, feature-level traffic analysis, post hoc XAI, adversarial machine learning, federated and adaptive learning, edge/fog/cloud placement, and operational governance [5,7,8,10,11,17,18,22,23,24,25,26]. Because these literatures employ different units of analysis and report outcomes that are not directly comparable, the review assesses what each source can substantiate rather than ranking methods by headline accuracy.
The unit of analysis is the claim associated with a study or method family. Sources are normal-ized according to five questions: which information is unavailable or weakly supported; how IDS observations are represented; what form of reasoning or explanation is produced; which evaluation protocol bears on the claim; and which deployment assumptions are imposed. This approach enables comparison without implying methodological equivalence. For example, an FRI study may directly support inference claims concerning incomplete rule coverage, whereas a post hoc XAI study may explain a trained model but cannot, on that basis alone, demonstrate reliable reasoning under limited information. Likewise, a federated IDS supports distributed learning under local data ownership; it becomes relevant to the present framework only when client heterogeneity, partial observation, delayed labels, or weak local support is explicit in the formulation [15,17,18,19].
2.2. Source Roles and Evidence Appraisal
The evidence base is organized into six source roles. Foundational studies provide the conceptual vocabulary of fuzzy sets, rule interpolation, open-set recognition, interpretability, reinforcement learning, and adversarial machine learning. IDS surveys and dataset papers establish benchmark practices, closed-world limitations, and the semantics of network, IoT, mobile, and cyber-physical observations. Applied studies demonstrate how sparse rules, selected features, traffic counters, URL properties, device telemetry, or synthetic attacks are incorporated into concrete detectors. XAI research contributes methods for assessing fidelity, stability, fragility, plausibility, and analyst relevance, whereas federated- and adaptive-learning sources clarify when distributed or sequential learning changes the information available for a decision. Finally, operational and governance sources delimit claims concerning safety, auditability, deployment, and analyst-facing use [1,2,3,12,13,14,26,27,28,29,30,31,32].
Table 2 specifies the scope boundaries. Designating a source as peripheral does not imply low quality; rather, it indicates that the source does not substantiate the particular claim under examination. Generic feature-selection research, for instance, may explain evidence compression but cannot establish IDS deployability unless feature availability, runtime, and operational semantics are reported. Similarly, an adversarial-perturbation study contributes evidence about IDS robustness only when its manipulations are feasible under the relevant traffic, protocol, device, application, or process constraints.
Figure 2 summarizes this normalization procedure. Conceptual sources establish terminology; empirical IDS and dataset studies anchor observable behavior; XAI and adversarial research define validation requirements; and deployment or governance sources constrain claims of practical use. This layered mode of interpretation is applied consistently to the taxonomy, evidence synthesis, architecture, evaluation framework, reporting templates, and operational guidance developed in the following sections.
The normalization strategy retains, rather than suppresses, evidentiary heterogeneity. Concep-tual, empirical, explanatory, adversarial, deployment, and governance sources may inform the same argument while supporting different forms of inference. Dataset and threat taxonomies characterize recurrent benchmark limitations; XAI syntheses explain why the availability of an explanation is not equivalent to explanation validity; federated-IDS reviews identify assumptions concerning communi-cation, heterogeneity, and update security; and contemporary threat reports supply operational context rather than detector validation [5,6,33,34,35].
3. Incomplete Information as a Decision Condition
3.1. Decision-Relative Definition
Incomplete information is defined here relative to a specific decision. It arises when an IDS must assign a label or risk score, provide an explanation, abstain, escalate, or recommend a response without sufficient information to justify that output. The deficit may result from sparse rule coverage, rare or unseen attacks, delayed or missing labels, partial observation, or feature combinations that are weakly supported by the training distribution. This is an evidentiary definition: it concerns whether the available information warrants the decision, rather than whether the model merely reports uncertainty. The umbrella term incomplete information expresses this decision problem more directly than alternatives that could be confused with sparse matrices, sparse features, small samples, or knowledge graphs. The adjective sparse is retained where it is technically precise—most notably in sparse fuzzy rule bases, sparse rule coverage, and weakly populated support regions. This distinction preserves the formal FRI setting while extending the framework to rare or unseen attacks, delayed labels, partial observations, and weak distributional support.
3.2. Boundary to Adjacent Concepts
Several adjacent concepts can generate incomplete information, but none is synonymous with it. Open-set recognition and out-of-distribution detection concern inputs outside known classes or training support [3,4]. Class imbalance and low attack base rates affect reliability and operational cost, particularly when false alarms dominate analyst workload [1]. Concept drift denotes temporal change in the data-generating process [36], whereas privacy constraints and federated learning concern data locality, update exchange, and decentralized ownership [15,17,18,19]. Fuzzy-set semantics likewise distinguish graded membership, similarity, and incomplete knowledge rather than collapsing them into a single notion of uncertainty [37,38]. These phenomena enter the present framework only when they leave the detector without sufficient information for the decision under consideration.
3.3. Direct and Conditional Relevance
FRI provides an unusually explicit case because its inference problem is incomplete antecedent coverage in a sparse fuzzy rule base. When no rule matches exactly, a conclusion is inferred from neighboring rules rather than derived from an unsupported crisp decision or an unexplained rejection [7,8,9,39,40,41]. This specificity does not make FRI a universal solution. Feature selection, federated learning, reinforcement learning, deep learning, and post hoc XAI address different primary problems; they are relevant here only when reduced features, local views, delayed feedback, unseen states, or opaque evidence use create an explicitly stated incomplete-information condition that is evaluated directly [10,11,16,17,18,42,43,44]. Recent zero-day studies further illustrate why both the condition and protocol must remain explicit: attention-based IoT explanations, hybrid multi-stage detection, and cross-dataset Siamese–reinforcement learning systems address different forms of unseen or weakly represented traffic and cannot be compared without reference to their split and transfer assumptions [45,46,47].
Table 3 operationalizes the definition as an evaluation checklist by linking each incomplete-information condition to a characteristic IDS manifestation and the evidence required to examine it. Compact features, distributed training, or the presence of an explanation layer do not, by themselves, justify a claim that a detector handles incomplete information. The relevant information gap must be identified, instantiated or observed in the study design, and evaluated with metrics that reveal system behavior under that condition.
The same distinction can be expressed at the level of mechanisms. Some methods, including FRI in a sparse rule base, formulate their inference problem around missing coverage. Other methods become relevant only when they create, reveal, or reduce a particular information gap. Table 4 summarizes these relationships and specifies the evidence required before each mechanism can support a claim concerning incomplete information.
Figure 3.
Boundary between direct and conditional relevance. FRI directly addresses sparse fuzzy-rule coverage; adjacent mechanisms support an incomplete-information claim only when a specific gap and matched test are explicit.
Figure 3.
Boundary between direct and conditional relevance. FRI directly addresses sparse fuzzy-rule coverage; adjacent mechanisms support an incomplete-information claim only when a specific gap and matched test are explicit.

The definition is therefore decision relative. A dataset may provide sufficient evidence for one output but insufficient evidence for another; accordingly, the information condition and intended action must be reported together.
4. Analytical Taxonomy for Explainable IDS under Incomplete Information
4.1. Study Profile and Classification Logic
The taxonomy is designed to prevent category errors rather than merely classify papers by al-gorithm. Prior IDS taxonomies, data-mining surveys, and dataset studies demonstrate why model class alone is insufficient: the same paradigm may support closed-world classification, rare-class detection, open-set recognition, online adaptation, adversarial testing, or deployment-constrained triage [5,6,22,48]. Conversely, a single information condition may be addressed through rules, sup-port estimation, abstention, post hoc explanation, federated aggregation, or adaptive control. The appropriate unit of classification is therefore the complete study profile: claim, information condition, observable data, method, test design, and operational output.
Table 5 defines six interdependent axes. The operating environment constrains visibility, latency, safety, and privacy; the evidence representation determines whether explanations possess operational meaning; and the reasoning paradigm shapes both plausible explanation forms and likely failure modes. The incomplete-information axis identifies the decision-level deficit, whereas the adversarial assumption bounds robustness claims. The final axis records the operational output—classification, triage, abstention, escalation, or response—and thereby determines which outcomes require evaluation. The fourth axis, incomplete-information condition, prevents method labels from substituting for problem definitions. A small feature set, federated protocol, reinforcement-learning policy, or post hoc explanation does not establish competence under incomplete information. Such a claim becomes supportable only when the study specifies and tests incomplete rule coverage, rare or unseen attacks, delayed or missing labels, partial observation, weak support, open-set behavior, or another explicit information gap. This axis links the taxonomy to the evaluation framework in Section 8 and the reporting templates in Section 12.
4.2. Applying the Taxonomy
Recent studies illustrate the analytical value of reporting these axes jointly. MuZero-based SDN de-fense and explainable reinforcement-learning incident response primarily propose policy architectures [49,50]. By contrast, heartbeat-aware 5G AMI self-healing evaluates availability-oriented intervention, whereas tamper-evident RPL telemetry evaluates provenance cost rather than classification quality [51,52]. Federated IoT botnet detection and family-held-out DQN ransomware detection address local evidence and unseen-family behavior under different protocols [53,54]; recent causal federated learning and PPO-based network detection introduce still different explanation and sequential-control assumptions [55,56]. The bilingual phishing framework adds language coverage and data sovereignty to the environment and evidence dimensions [57]. Grouping these studies under the broad label “AI-based IDS” would obscure the information gap, operational output, and validation burden associated with each.
Figure 4 represents the taxonomy as a study profile rather than a hierarchy. A complete profile specifies the observations available to the system, the information gap under investigation, the expla-nation produced, the assumed failure or attacker model, and the downstream decision supported by the output. These dimensions organize the evidence streams, explanation requirements, deployment placement, and evaluation criteria developed in subsequent sections.
The taxonomy should therefore be applied as an integrated study profile rather than as a menu of independent labels. Omitting any axis typically leaves an assumption about transfer, robustness, or deployment unstated.
5. Evidence Synthesis across IDS Contexts
The evidence base cannot be reduced to a single algorithm family or dataset lineage. It encom-passes sparse fuzzy-rule reasoning, traffic and network-management variables, phishing and mobile detection, IoT and edge security, cyber-physical and OT monitoring, adversarial testing, and adaptive learning. These streams intersect in deployed systems: an IoT botnet detector, for example, may com-bine partial gateway visibility, non-IID device behavior, resource constraints, post hoc explanation, and adversarial risk. The synthesis therefore examines what each stream contributes, which information deficit it exposes, and the point at which its conclusions cease to transfer.
Each stream is interpreted through the taxonomy introduced in Section 4: what the detector can observe, what remains unavailable or weakly supported, which form of explanation is meaningful, and which evaluation risk must be controlled. Table 6 summarizes these relationships, while Figure 5 highlights their interdependence.
5.1. FRI and Sparse Fuzzy-Rule Reasoning
FRI offers the clearest formal illustration of one incomplete-information condition: absent coverage in a sparse fuzzy rule base. Classical fuzzy inference is grounded in fuzzy sets and antecedent–consequent rules [58,59,60]; FRI extends this setting to observations that lie between or beyond directly matching rules [7,8,9,40]. The conclusion is consequently inferred from neighboring rules rather than forced through a nearest match, returned as an unsupported crisp label, or rejected without an interpretable rationale.
FRI is most valuable for IDS when the features retain stable operational meaning and sparse rule coverage is the actual limitation. Studies using SNMP-MIB counters and network-abnormality features illustrate how interpolation can support decisions when exact rules are unavailable [39,61]. The broader FRI literature also demonstrates that outcomes depend on antecedent geometry, distance measures, scale-and-move transformations, and rule-base construction [40,41,62,63,64]. Evaluation should therefore document rule coverage, membership functions, distance or similarity assumptions, interpolation frequency, and representative successes and failures. Readability is an explanatory affordance, not evidence that an interpolated conclusion is correct.
5.2. Traffic, SNMP-MIB, and Feature-Level Evidence
Traffic and network-management features remain important because they can preserve opera-tional meaning when payload inspection is unavailable, encrypted, or computationally prohibitive. Flow counts, packet rates, protocol summaries, and windowed statistics can be related to infrastruc-ture behavior [65,66,67]; SNMP-MIB counters provide an additional management-layer source used in FRI-based abnormality detection [61]. Although such features do not reveal the complete attack, they can identify the observable rates, counters, or flow properties that contributed to an alert.
Their utility is nevertheless deployment dependent. Offline datasets may include features that a constrained gateway cannot collect, and apparently predictive variables may encode capture artifacts rather than attack behavior. Feature-selection research is pertinent only when the retained variables remain semantically meaningful and stable across splits, datasets, and rare or weak-support cases [42,43]. Reports should specify the observation point, feature definitions, collection window, handling of missing variables, manipulation risk, and persistence of explanatory meaning under chronological, device-holdout, rare-class, or weak-support tests.
Recent traffic studies introduce two additional practical dimensions. One-hot encoding of categor-ical flow variables has been evaluated for DDoS subattack classification, while streaming architectures combine message-broker ingestion with deep and incremental learners [68,69]. Separately, high-dimensional and multi-stage zero-day frameworks use feature compression, latent-space distance, clustering, and staged classification to distinguish known from previously unseen traffic [21,45]. These results bear on feature semantics, subattack confusion, false-positive behavior, throughput, update latency, and generalization. Neither encoding, streaming, nor staged detection constitutes a solution to incomplete information in itself; each becomes relevant when rare subattacks, delayed labels, changing traffic, or weakly supported feature combinations constrain the decision.
5.3. Phishing, Web, and Mobile Attack Evidence
Phishing and web detection frequently operate at an early stage of a campaign. Before user interaction, a detector may observe only a URL, registration pattern, redirect chain, certificate attribute, page fragment, or lexical cue. Fuzzy and rule-based systems can express these observations as analyst-readable reasons, while machine-learning studies demonstrate both the utility of compact URL representations and their susceptibility to leakage [70,71,72,73]. The incomplete-information problem arises when a pre-click decision must be made from this partial and potentially short-lived evidence.
Mobile malware poses a related but distinct observation problem. Application metadata, permis-sions, API use, network behavior, and brief execution traces may be available, yet platform policy and privacy constraints restrict collection. DREBIN is notable for linking Android malware decisions to explanation-oriented features [74]; broader cybersecurity data-science surveys provide useful general context but do not constitute mobile-specific validation [75]. Credible evaluation in web and mobile settings therefore requires chronological, campaign, family, or application holdouts, together with checks for duplicate URLs, related domains, near-duplicate applications, and collection artifacts.
Generative AI further increases variability through synthetic impersonation, code-switched phishing, polymorphic behavior, and rapidly changing campaign artifacts [76,77,78]. A proposed bilingual LLM phishing framework adds low-resource language coverage, redaction, and sovereign or on-premise deployment constraints [57]. These sources motivate language-, campaign-, chronology-, and family-stratified testing. The bilingual design, however, remains an architectural and evaluative proposal until comparative experiments establish detector performance.
5.4. IoT, Edge, and Botnet Evidence
IoT and edge environments make information constraints especially visible. A device or gateway observes only a local segment of behavior, whereas a botnet campaign may extend across numerous devices, networks, and time periods; sensing, storage, explanation, and communication are also resource constrained. Bot-IoT, TON-IoT, IoT-23, Kitsune, Edge-IIoTset, SVELTE, and N-BaIoT illustrate the diversity of traffic representations, device baselines, online anomaly detectors, edge evaluations, and botnet traces in this literature [79,80,81,82,83,84,85].
In this stream, partial observation is generally more consequential than sparse rule coverage. A lo-cal model may learn benign device behavior while lacking examples of a new botnet family; a federated client may represent only a narrow device population; and a gateway may be limited to a lightweight anomaly proxy. Local explanations must therefore be distinguished from campaign-level attribution. Evaluation should include device or site holdouts, non-IID partitions where applicable, communication cost, latency, memory, energy, and susceptibility to poisoning or client-side manipulation [17,18,19,86].
Recent IoT research also distinguishes mechanisms that are often collapsed into a single security claim. Federated IDS coordinates learning while retaining local, potentially non-IID data; tamper-evident telemetry protects provenance; and moving-target defense or cyberdeception modifies the environment in response to observed behavior [52,53,87,88,89]. Other federated studies introduce causal explanation, hybrid convolutional–recurrent modeling, and broader analyses of confidentiality, hetero-geneity, and attack surfaces [34,55,90]. Differential privacy and IoT trust research further demonstrate that data locality, privacy, and system security are distinct properties requiring separate evidence [91,92]. Edge-computing reviews add constraints related to placement, latency, and communication [93]. Federated systems therefore require client, communication, privacy, and poisoning analyses; telemetry assurance requires storage and proof-cost measurements; and adaptive deception requires tests of state, action, reward, safety, and rollback. None of these properties, in isolation, demonstrates explainable detection or dependable operation under incomplete information.
5.5. Smart Grid, OT, and Advanced Threat Evidence
Smart-grid and operational-technology monitoring is constrained by the physical process as well as by the cyber model. Meter readings, process variables, control commands, topology assumptions, timing, and physical-consistency checks may all contribute to a decision [94,95,96,97,98]. Because alerts can affect service availability and safety, OT guidance treats segmentation, monitoring, response authority, and human control as design constraints rather than post-deployment additions [26].
Information deficits in this stream arise from limited instrumentation, restricted public data, incomplete topology knowledge, and labels that may become available only after investigation. A cyber alert may be statistically plausible yet physically inconsistent, or operationally concerning despite weak cyber support. Explanations should therefore connect model evidence to process plausibility and response risk. MITRE ATT&CK can organize adversary behavior and campaign context, but it cannot substitute for dataset evidence or empirical detector validation [30]. Safety envelopes, latency constraints, approval boundaries, and false positives capable of triggering harmful actions must be included in the evaluation.
Recent smart-grid and ICS studies provide complementary rather than commensurate evidence. They examine integrity-attack classification, fog-based energy-theft detection, heartbeat-aware self-healing in sliced 5G AMI, lightweight multivariate anomaly detection on WADI, and optimized Sunburst detection [51,99,100,101,102]. Because their outputs range from class labels and family-held-out alerts to attack-byte suppression, intervention cost, and anomaly reconstruction, detection quality, availability, latency, model footprint, explanation, and safety must remain separate dimensions. Re-views and conceptual frameworks contribute additional perspectives on modernization, zero-trust access, blockchain-assisted AMI assurance, 5G threat context, and autonomous critical-infrastructure design [103,104,105,106,107,108]. These mechanisms may strengthen assurance and auditability, but they do not replace empirical IDS evaluation.
5.6. Adversarial Robustness and Explanation Integrity
Adversarial machine learning recasts IDS evaluation as a contested decision problem. High clean accuracy may coexist with fragility under crafted perturbations, black-box transfer, poisoning, or defenses that depend on obfuscated gradients [24,25,28,109,110,111,112,113,114,115,116]. Network- and IoT-specific studies further indicate that attackers can manipulate features, target weak-support regions, or use generative models to probe decision boundaries [117,118,119].
The central analytical question is whether an attacker can exploit the system’s information limits. A perturbation is operationally meaningful only when it respects the relevant protocol, timing, device, traffic, application, or physical constraints. Detection robustness and explanation integrity should be evaluated jointly: the label may remain unchanged while the rationale becomes unstable, or successful evasion may be accompanied by a plausible but false explanation. General GAN research establishes the modeling concept, whereas IDS-specific claims require checks of sample realism, diversity, leakage, and semantic feasibility [118,120,121]. Reports should specify attacker knowledge, objective, budget, feasible manipulations, degradation, recovery, and explanation stability.
Recent GAN-based IDS research extends analysis beyond a binary clean-versus-attacked compari-son by examining transferability, feature-selection effects, generated-sample realism, and post-attack recovery [122,123]. A separate 2026 study evaluates recurrent IDS models under FGSM and PGD and uses SHAP drift as an auxiliary adversarial signal [124]. Appropriate reporting therefore includes attack success, performance degradation, recovery time or recovered performance, diversity and leakage checks, and explanation stability. Restoration of the original label distribution is insufficient if the system continues to provide unstable or misleading reasons.
5.7. Adaptive Learning and Online Response
Adaptive learning becomes relevant when security decisions evolve over time. Concept drift, moving-target defense, feedback-enabled resilience, and reinforcement learning address changing conditions, sequential action, or delayed feedback [16,36,44,125,126]. They enter the incomplete-information framework when action precedes labeling, the state is only partially observed, a new attack state was absent from training, or analyst feedback is delayed and uncertain.
The principal risk lies in equating adaptation with safe autonomy. An adaptive detector or response policy requires an explicit state representation, action space, reward structure, exploration boundary, safety constraint, and rollback procedure [16,26,98,126]. Reward ablations are essential because a policy that appears successful may nevertheless increase false alarms, analyst burden, service disruption, or attacker leverage. Evaluation should address delayed labels, pre- and post-drift behav-ior, escalation thresholds, approval requirements, and model or policy versioning. Where decision information is limited and consequences are substantial, abstention or a bounded recommendation may be preferable to autonomous containment.
Recent studies reinforce this distinction. Reward-function choice alters APT detection trade-offs; a ransomware-family holdout provides stronger evidence of unseen-family behavior than a random split; and streaming learners expose requirements related to update latency and delayed labels [54,69,127]. PPO-based adaptive network detection offers a recent example of sequential optimization whose contribution remains contingent on reward, state, and evaluation design [56]; foundational work on deep reinforcement learning likewise does not remove the need for security-specific safety evidence [128]. Moving-target defense, MuZero-style agents, 5G AMI self-healing, and proposed explainable-response architectures introduce pre-authorized actions, safety shields, operator override, and rollback boundaries [49,50,51,87,108,129]. Their claims should be framed as bounded adaptation under stated controls rather than as evidence that adaptation alone produces safe response.
Across these evidence streams, information quality, explanation quality, robustness, and place-ment are mutually dependent. Observable data shape the explanation, domain constraints determine feasible attacks, and the deployment tier limits both computation and attribution.
6. Explanation Mechanisms and Validation
6.1. Explanation Purpose and Model Class
Explanation quality depends on both the decision function and the user it is intended to serve. Analysts may require triage support, developers may need failure diagnosis, governance teams may require an auditable update record, and responders may need a defensible basis for escalation or containment. These tasks demand different forms of evidence. An attribution plot may assist debugging yet remain inadequate for response approval; a readable rule trace may be based on poor coverage; and a mathematically minimal counterfactual may violate feasible traffic or device behavior. The relevant question is therefore not whether an IDS emits an explanation, but whether the explanation is faithful, stable, semantically valid, feasible at the intended tier, and useful for the specified task [10,11,12,13,14,130,131,132].
Interpretable-by-design models expose part of their reasoning through their structure. FRI is particularly informative when sparse rule coverage is the problem because it can reveal neighboring rules, membership degrees, antecedent distances, and the interpolated conclusion [7,8,9,39,40,41,61]. Tree paths, rule lists, and compact feature models can provide other transparent traces when their variables retain stable operational semantics. Structural interpretability, however, does not guarantee correctness: readable rules may encode artifacts, poorly covered regions, unstable thresholds, or unsafe actions. Validation must still address coverage, path stability, class support, membership sensitivity, and failure behavior in weak-support or otherwise incomplete-information cases.
Post hoc methods explain a model after it has been trained. LIME constructs a local surrogate; SHAP assigns additive feature contributions; saliency identifies influential neural inputs; prototypes retrieve similar cases; and counterfactuals describe changes that would alter a decision [10,11,131,133,134,135]. These methods can improve the inspectability of high-capacity traffic, malware, IoT, and cyber-physical models, but plausibility should not be conflated with fidelity. Recent IDS-specific frameworks combine random forests or deep models with LIME, SHAP, decision-tree summaries, and multi-class explanations [20,35,136,137]. Saliency and attribution methods in particular require sanity checks and perturbation analyses because visually convincing outputs may be insensitive to model parameters or unstable under small input changes [13,14,132]. Explicit evaluation criteria for threat-intelligence use therefore remain necessary [138].
6.2. Validation under Information Limits
Under incomplete information, an explanation must also disclose the boundary of the decision. An interpolated FRI result should be identified as interpolated; a label assigned in a weak-support region should include a support or calibration warning; and an alert generated by a local edge or federated model should not be presented as global campaign attribution. When labels are delayed, the explanation should distinguish provisional evidence from analyst feedback or a confirmed forensic label. Such disclosure is operationally important because analysts need both the evidence supporting an alert and a clear account of what the system has not observed.
Five validation dimensions emerge from research on fidelity, sanity checks, fragility, responsible explanation, and human-centered evaluation [10,11,13,14,130,131,132,139,140]. Fidelity concerns corre-spondence with the model’s actual decision process; stability concerns consistency across nearby inputs, random seeds, or repeated runs; and semantic validity asks whether features and counterfactual changes are meaningful in the security domain. Cost and placement address latency, memory, bandwidth, and energy at the intended tier. Analyst usefulness concerns the human task itself, including triage, prioritization, escalation, and reconstruction. Taken together, these dimensions connect explanation to the architecture in Section 7 and the evaluation framework in Section 8.
6.3. Policy-Level Explanation
Adaptive response introduces a policy-level explanation problem. The explanation should identify the state information available at the decision tier, the selected action or value target, the reward or cost components, any intervention by a safety shield, the status of operator override, and the approval or rollback boundary [50,51,52]. Unlike a classifier attribution, a policy explanation must clarify why an action was selected, which information was unavailable, and which control prevented an unsafe transition.
The synthesis supports a two-part standard: an explanation should account for the model’s decision and disclose the information boundary within which that decision was made. Neither requirement alone is sufficient for high-impact analyst use.
Table 7.
Explanation forms, validation requirements, and information-limit disclosures.
| Explanation form | Use under incomplete Output Validation tests information |
||
|---|---|---|---|
| FRI / fuzzy trace | Rule semantics, rule-base coverage, Neighboring rules, membership interpolation distance, Direct when sparse rule coverage degrees, antecedent distances, membership-function sensitivity, is the incomplete-information interpolated conclusion, and and examples of correct and condition. rule-coverage status. incorrect interpolations. |
||
| Tree path / rule list | Path stability, pruning effects, split Sequence of feature tests, rule Conditional when paths expose leakage, feature semantics, and clauses, class support, and weak support, rare-class evidence, class support in weakly supported terminal decision path. or partial observation. leaves. |
||
| Feature attribution | Ranked feature contributions, local weights, additive attributions, or feature-importance profiles. | Fidelity to the model, stability across perturbations and seeds, runtime cost, and security-domain semantics. | Indirect; reveals evidence used by an opaque model but does not itself provide reasoning under incomplete information. |
| Counterfactual explanation | Feature changes that would alter the label, risk score, abstention, or escalation decision. | Feasibility, actionability, protocol constraints, monotonicity, and resistance to misleading evasion guidance. | Useful for probing decision boundaries, weak-support regions and adversarial feasibility. |
| Prototype / example-based explanation | Similar records, representative clusters, nearest cases, or family exemplars. | Distance metric, representativeness, leakage, duplicate handling, and chronology or family separation. | Useful for rare classes, weak support, and analyst comparison, but only when examples are valid and non-leaking. |
| Saliency / neural influence | Highlighted input regions, time steps, packets, bytes, or learned features. | Sanity checks, parameter sensitivity, perturbation stability, and domain interpretability. | Limited unless the highlighted evidence can be mapped to meaningful IDS features or analyst tasks. |
| Governance-oriented explanation | Evidence summary, information-gap statement, confidence, limitation statement, model version, and recommended action boundary. |
Completeness, auditability, version Essential when limited information traceability, escalation policy, and affects operational response or analyst feedback handling. human approval. | |
| XRL / policy explanation | State evidence, selected action or value target, reward or cost components, safety-shield intervention, override status, and rollback boundary. |
Relevant when partial states, Policy fidelity, reward sensitivity, unseen states, or delayed rewards shield trace, action stability, leave policy decisions incompletely operator comprehension, runtime, supported; proposed architectures and rollback reproducibility. require separate empirical validation. | |
Figure 6.
Explanation-validation pipeline. A useful explanation must match its intended purpose, disclose the information limit, pass fidelity and stability tests, respect domain semantics, fit the deployment tier, and improve the stated task.
Figure 6.
Explanation-validation pipeline. A useful explanation must match its intended purpose, disclose the information limit, pass fidelity and stability tests, respect domain semantics, fit the deployment tier, and improve the stated task.

7. Deployment Architecture and Operational Placement
7.1. Tier-Specific Information and Computation
Operational design should distinguish observation, inference, explanation, model updating, and response approval. These functions operate under different information scopes, resource budgets, and authority structures. Devices provide narrow local signals; gateways aggregate short traffic or telemetry windows; fog or site-edge nodes add local correlation and cached context; cloud or SOC backends support cross-site training and computationally intensive analysis; and analysts or governance processes authorize consequential actions and validate feedback. Conflating these roles obscures feasibility, failure behavior, and accountability.
The architecture proposed here is a deployment-aware synthesis rather than a universal or empirically validated reference design. Its purpose is to align computation with information scope and operational constraints. Evidence from edge systems, federated-learning studies, IoT datasets, IoT trust analysis, 5G security research, and OT guidance collectively motivates explicit reporting of locality, latency, bandwidth, energy, memory, privacy, and safety [15,17,18,19,26,80,83,86,92,141]. Recent fog, federated, and causal-explanation systems further illustrate how placement alters the information and explanations available at each tier [55,90,100]. A constrained gateway, for example, should not be assumed to perform full post hoc explanation, poisoning audits, high-frequency aggregation, long-horizon drift analysis, and cross-site reconstruction for every event. These tasks may be feasible at fog, cloud, or SOC tiers, but only under explicit data-movement and latency assumptions.
The form of incomplete information changes across the stack. Devices have local, low-dimensional views that are often limited to counters, health states, or brief telemetry windows. Gateways observe a broader yet still partial context and typically lack campaign-wide evidence or final forensic labels. Site-edge correlation can reduce these deficits by combining devices, cached baselines, compact models, and local rules. Cloud and SOC systems add cross-site history, federated updates, computationally intensive attribution, poisoning analysis, and threat intelligence. At the analyst and governance tier, the residual gap is contextual: technical evidence must be interpreted in relation to mission criticality, safety, acceptable risk, and response authority.
Explanation depth should follow the same tiered logic. Devices and gateways can provide sensor state, threshold violations, rule hits, local anomaly proxies, confidence or support warnings, and escalation flags. These outputs are bounded local reasons rather than complete explanations of a global model. SHAP profiles, counterfactuals, cross-site prototypes, poisoning diagnostics, model-health reports, and drift summaries generally require the context and computational resources of fog, cloud, or SOC infrastructure. Even when FRI or compact rule models are deployed locally, they should disclose coverage and interpolation status rather than return only a final label.
7.2. Placement Evidence and Failure Behavior
Table 8 maps these functions to deployment tiers. The mapping is deliberately falsifiable rather than prescriptive: a study that locates explanation or update logic on a device, gateway, or edge node should measure latency, memory, energy, bandwidth, and failure behavior at that location. When analysis is offloaded, the report should also specify the local proxy, fallback, or escalation path that remains available during delay, disconnection, or backend failure.
Recent literature provides concrete but non-equivalent evidence about placement. Smart-grid theft detection compares fog and cloud execution; 5G AMI self-healing is evaluated in a dual-fog simulation; lightweight ICS research reports parameter count and per-sample benchmark time; federated IoT detection retains training data locally but introduces client and communication requirements; and Merkle-tree telemetry quantifies proof and storage costs [51,52,53,100,101]. Proposed SDN, bilingual phishing, and 5G architectures add controller, sovereignty, and slice-level constraints [49,57,107]. These studies support only tier-specific feasibility claims. Inference time, proof time, or simulation latency should not be interpreted as end-to-end operational latency unless sensing, transport, queuing, explanation, and response are also measured.
A deployment report should therefore state where each function executes, which information is visible at that location, what explanation is produced, what resources it consumes, and how the system behaves when communication or backend analysis fails. Federated learning may avoid centralizing raw data, but it still requires descriptions of non-IID clients, communication overhead, update security, privacy assumptions, and poisoning risk. Adaptive learning likewise requires procedures for delayed labels, safety constraints, version control, and rollback. These details transform an architectural diagram into a testable systems claim.
Figure 7.
Deployment-aware allocation of information and authority. Context and explanation increase toward fog and SOC tiers, while approved policies, constraints, and rollback propagate toward local execution tiers.
Figure 7.
Deployment-aware allocation of information and authority. Context and explanation increase toward fog and SOC tiers, while approved policies, constraints, and rollback propagate toward local execution tiers.

The architectural implication is not that every system requires five physical layers. Rather, information scope, computational placement, and response authority should be distinguished and measured.
8. Evaluation and Benchmarking Framework
8.1. Evaluation from the Claim–Condition Pair
Evaluation should proceed backward from the claim. Closed-world prediction requires docu-mented data, justified baselines, and appropriate predictive metrics. Operation under incomplete information requires a test that instantiates the specified deficit. Explainability requires evidence con-cerning the explanation itself; adversarial robustness requires an explicit attacker model and feasible manipulations; and deployment readiness requires measured execution of inference, explanation, update, and response functions at the proposed tier. The fundamental unit of evaluation is therefore the claim–condition pair, supplemented by the resource and authority assumptions under which the claim is expected to hold.
Random-split accuracy generally supports only a narrow benchmark claim. Low attack base rates can make false positives operationally costly even when aggregate accuracy is high [1], while dataset-specific or closed-world splits can conceal failures across time, devices, families, sites, or unseen attacks [2,5,6,27]. Predictive metrics remain necessary, but they should be aligned with operational use and include per-class precision and recall, precision–recall behavior for rare attacks, false positives per hour or asset, detection delay, calibration, and abstention rate.
Tests of incomplete information must render the relevant condition observable. Sparse rule coverage requires reporting of coverage, interpolation frequency, distance design, and interpolation error. Rare or unseen attacks call for family, chronology, open-set, or cross-dataset holdouts rather than random partitioning. Partial observation requires an explicit map of visible and hidden sensors, clients, devices, gateways, features, or time windows. Delayed labels and online adaptation require assumptions about label latency, escalation, rollback, and pre/post-update performance. Weak support requires support-distance or density estimates, calibration, abstention, and error analysis in low-support regions.
Predictive and explanatory evaluation should remain analytically separate. An accurate model may yield unstable, unfaithful, or semantically empty explanations, while a readable rule set may reflect poor coverage or dataset artifacts. Relevant measures include fidelity, stability, domain validity, runtime and placement cost, and usefulness for the analyst task [10,11,13,14,130,131,132]. In incomplete-information settings, the output should additionally disclose interpolation, weak support, missing labels, partial visibility, or the basis for abstention.
Adversarial evaluation should address both label degradation and explanation integrity. The attacker model must specify knowledge, objective, capability, budget, and constraints; for IDS, these constraints should correspond to feasible traffic, protocol, timing, device, application, or physical behavior. Reports should include clean and attacked performance, degradation curves where feasible, recovery, update-security or poisoning effects, and the stability and semantic validity of explanations under attack [24,25,28,109,110,111,117,118,119,132].
Deployment evaluation completes the framework. Studies should locate inference, explanation, aggregation, updating, audit, and response approval across device, gateway, fog, cloud, SOC, and analyst tiers, and then measure latency, memory, energy, bandwidth, update size, explanation time, failure handling, and fallback behavior. Federated or edge studies additionally require client partitions, non-IID severity, communication overhead, privacy assumptions, update-leakage risk, and poisoning resistance [15,17,18,19,26,80,83,86].
8.2. Recent Empirical Anchors
Table 9 presents recent empirical studies used as anchors in the synthesis. Because these studies differ in dataset, attack model, output, split policy, and deployment setting, the table does not rank them. Instead, each reported result is paired with the limited claim that it can support.
Table 9.
Recent empirical anchors and the bounded interpretations they support.
| Study | Setting or condition | Evidence reported by the study | Permitted use and claim boundary |
|---|---|---|---|
| GAN attack and recovery [122] | 5G IDS adversarial testing and post-adversarial recovery. | Reports degradation under GAN-based attacks and evaluates recovery; exact attack-success and recovery values depend on the evaluated detector and attack configuration. | Supports adversarial-degradation and recovery methodology, not universal robustness. |
| Smart-grid integrity attacks [99] | Deep models for data-integrity attacks with class-balancing procedures. |
Compares CNN, LSTM, and DQN configurations; the abstract identifies stronger CNN behavior and limitations in the DQN configuration. |
Supports method-comparison discussion within the reported dataset and preprocessing, not a general ranking of deep or reinforcement learners. |
| RL reward functions [127] |
APT detection in industrial IoT. | Shows that reward selection changes precision, recall, false-positive, and false-negative trade-offs. | Supports reward-ablation and cost-sensitive evaluation; no reward is universally optimal. |
| Categorical DDoS features [68] | CSE-CICIDS2018 DDoS subattack classification. | Reports a 99.7% F-measure and a 5.2% false-positive rate for the evaluated one-hot feature pipeline. | Supports feature-representation and subattack-level evaluation only for the documented dataset and split. |
| 5G AMI self-healing [51] |
ns-3 dual-fog, sliced and non-sliced 5G/mmWave AMI scenarios. | Reports approximately 87% attack-byte suppression in sliced heartbeat-aware operation and 90.2% in non-sliced operation, with no benign or collateral intervention reported in the stated setting; classifier precision spans the study’s evaluated range. | Supports a combined detection–response–explanation case under the simulated testbed; suppression is not classification accuracy and safety requires external validation. |
| Fog smart-grid detection [100] | Theft and zero-day attack Reports 98% accuracy and recall, 99% F1, detection at fog versus cloud and approximately 85% lower detection tiers. time than the cloud configuration. | Supports fog-placement evidence within the reported data and system assumptions; the zero-day protocol and generated-data assumptions require full-text verification. |
|
Table 9.
Recent empirical anchors and the bounded interpretations they support (continued).
| Study | Setting or condition | Evidence reported by the study Permitted use and claim boundary | |
|---|---|---|---|
| Tamper-evident RPL telemetry [52] | Merkle-root and proof generation for IoT telemetry. | Reports 320 bytes of root storage, less than Supports evidence-integrity and 0.15 ms tree construction, and less than 1.7 proof-cost claims; it is not evidence of ms proof generation in the evaluated intrusion-detection effectiveness. implementation. |
|
| GAN review and cases [123] |
Systematic review, meta-analysis, and IDS case studies. | Synthesizes GAN-enabled attack effectiveness and evaluates realism, feature-selection, transfer, and recovery issues. | Supports adversarial-evaluation design and research-gap claims; individual effect sizes remain conditional on study comparability. |
| BiPAM for ICS [101] | WADI multivariate anomaly detection using 127 sensors. | Reports 96.73% F1, 95.45% precision, 98.03% recall, 289K parameters, and 0.019 ms per sample in the benchmark setting. | Supports ICS anomaly-detection and model-efficiency evidence; benchmark throughput is not end-to-end field latency or explanation quality. |
| Streaming IDS [69] | Kafka-based processing and incremental online learning. | Reports 98.1% accuracy for the Kafka/deep-learning configuration and 98.45% F1 for the incremental VFDT configuration. |
Supports streaming and online-update evidence under the reported workload it does not automatically establish zero-day generalization. |
| Federated IoT IDS [53] | N-BaIoT clients trained with FedAvg. | Reports 92% precision and 0.89 F1 in the evaluated federated configuration. | Supports collaborative local-data IDS evidence; data locality does not by itself prove privacy, poisoning resistance, or fairness across clients. |
| DQN zero-day IDS [54] | UGRansome family-held-out ransomware evaluation. | Reports 95.9% binary accuracy with 0.96 F1 and 92.0% multiclass accuracy in the stated holdout protocol. | Supports the tested ransomware-family holdout, not all zero-day, open-set, or cross-domain conditions. |
8.3. Integrated Evaluation Dimensions and Benchmark Protocol
Table 11 translates the metric groups into a staged benchmark protocol. The core column identifies the reporting required to interpret a result, whereas the extended column identifies the additional evidence needed for stronger claims about incomplete information, explanation, robustness, or deploy-ment. A study need not complete every stage; however, it must provide the evidence associated with each claim that it advances.
Table 10.
Evaluation dimensions, measures, test designs, and bounded claims.
| Evaluation dimension | Measures | Required test design Bounded claim | |
|---|---|---|---|
| Detection quality | Precision, recall, F1-score, ROC-AUC, precision–recall behavior, false positives per hour, detection delay, confusion matrix. | Documented dataset, justified split, baseline comparison, and operationally meaningful class distribution. | Basic classification or anomaly-detection competence. |
| Sparse-rule behavior | Rule-base coverage, interpolation rate, nearest-rule distance, membership sensitivity, interpolation error, trace examples. | Sparse fuzzy rule base with documented missing or weakly covered antecedent regions. | FRI or sparse-rule reasoning under incomplete rule coverage. |
| Rare or unseen attack behavior | Per-class recall, rare-class precision, family-holdout performance, zero-day or open-set behavior, calibration, abstention. | Rare-class split, family holdout, chronological holdout, open-set split, or cross-dataset test. | Detection under underrepresented unseen, or weakly supported attack evidence. |
| Partial-observation behavior | Client-level performance, sensor-ablation result, missing-feature sensitivity, tier comparison, local/global disagreement. | Explicitly limited sensor, client, gateway, device, time-window, or feature visibility. | Decision support from partial local views at edge, fog, or federated tiers. |
| Delayed-label and adaptive behavior | Pre/post-update performance, label-latency sensitivity, reward ablation, rollback success, escalation rate. | Streaming, delayed-label, drift, or sequential-response scenario. | Safe adaptation under incomplete feedback or unseen states. |
| Explanation quality | Fidelity, stability, sparsity, semantic validity, explanation runtime, analyst-task usefulness, misleading-explanation rate. | Explanation method matched to a model and analyst task, with perturbation, repetition, or task-based validation. |
Reliable and usable explanation rather than decorative XAI. |
| Adversarial robustness | Attack success rate, robust F1-score, poisoning impact, degradation curve, recovery time, explanation stability under attack. | Attacker knowledge, objective, budget, and domain-constrained perturbation or poisoning scenario. | Robustness and explanation integrity under deliberate manipulation. |
| Deployment cost and placement | Latency, memory, energy, bandwidth, update size, explanation runtime, offloading rate, fallback behavior. | Declared device, gateway, fog, cloud, SOC, or analyst tier with measured resource constraints. | Operational feasibility at the claimed deployment tier. |
Table 11.
Staged benchmark protocol linking core evidence to stronger claims.
| Stage | Core evidence | Stronger evidence | Failure controlled |
|---|---|---|---|
| Dataset documentation | Report source, label semantics, feature list, collection context, preprocessing, and train–test split. | Provide a dataset card, leakage analysis, duplicate handling, chronology, device/site/family partitions, and known unsupported classes. |
Irreproducibility, leakage, benchmark saturation, and unsupported transfer claims. |
| Baseline comparison | Compare against appropriate conventional ML, deep-learning, rule-based, or anomaly-detection baselines. | Include interpretable, post hoc XAI, sparse-rule, federated, or adaptive baselines when those claims are made. | Overclaiming from weak or mismatched baselines. |
| Incomplete-information test | Report class imbalance, rule coverage, missing labels, partial observation, or weak-support assumptions. | Use family-holdout, weak-support probing, delayed-label evaluation, partial-observation tests, open-set tests, or interpolation-error analysis. | Treating incomplete information as a label rather than an evaluated condition. |
| Explanation validation | Provide representative explanations for correct and incorrect decisions. | Measure fidelity, stability, semantic validity, explanation cost, incomplete-information disclosure, and analyst-task usefulness. | Plausible but unfaithful, unstable, or unusable explanations. |
| Adversarial test | Report clean performance and at least one relevant evasion, poisoning, or stress scenario if robustness is claimed. |
State attacker knowledge, objective, budget, semantic constraints, degradation curve, recovery behavior, and explanation-integrity result. | Invalid perturbations, incomplete robustness evidence, and manipulated explanations. |
| Deployment test | Report inference runtime and claimed deployment tier. | Report latency, memory, energy, bandwidth, update cost, explanation runtime, offloading design, failure handling, and fallback mode. | Physically infeasible or under-specified deployment claims. |
| Analyst and governance test | State the intended analyst or response use of the output. | Evaluate triage time, escalation quality, false-alarm handling, feedback quality, action boundary, auditability, and rollback. | Confusing model explanation with operational decision support. |
No single composite score can represent these dimensions without obscuring important trade-offs. A defensible evaluation therefore reports a vector of claim-specific results and identifies the conclusions that remain unsupported.
Figure 8.
Iterative evaluation workflow. The claim is paired with a concrete c ondition, measured, stressed, qualified, and revised until the conclusion is no broader than the reported evidence.
Figure 8.
Iterative evaluation workflow. The claim is paired with a concrete c ondition, measured, stressed, qualified, and revised until the conclusion is no broader than the reported evidence.

9. Open Challenges and Failure Modes
9.1. Conceptual and Empirical Failure Modes
The literature contains no shortage of algorithms; its recurring weakness is that claims frequently exceed the evidence reported. High-capacity models, compact features, post hoc explanations, feder-ated updates, adaptive policies, and adversarial tests are often combined in ways that imply broader competence than the experiment demonstrates. Method labels are especially poor substitutes for validation: fuzzy rules do not guarantee sound interpolation, XAI does not guarantee faithful explana-tion, federation does not guarantee privacy or robustness, adaptation does not guarantee safety, and random-split accuracy does not establish deployability.
Four interacting forms of error recur. Conceptual errors conflate incomplete information with uncertainty, privacy, adaptation, or explanation. Evaluation errors test a condition different from the one claimed. Architectural errors assign computation to tiers whose latency, memory, energy, or bandwidth cannot support it. Governance errors permit model outputs to influence response without explicit action limits, approval rules, versioning, feedback control, or rollback. When the information gap is poorly specified, weak benchmarking, overclaimed explanation, and unsupported deployment conclusions tend to follow.
Conceptual overextension begins when incomplete information is treated as synonymous with uncertainty, class imbalance, privacy, federated learning, reinforcement learning, or concept drift. Any of these phenomena may create an information gap, but only within a defined decision setting. The problem should therefore be stated before the method: incomplete rule coverage, rare or unseen attacks, partial observation, delayed labels, weak support, non-IID local views, or unseen states. FRI directly addresses sparse rule coverage; federated and adaptive systems are relevant only insofar as client partitions, label timing, observation scope, or state representation create the gap [7,8,9,15,16,17,18,19].
A second recurring failure is explanation without validation. Rule traces, attribution plots, counterfactuals, prototypes, and saliency maps may facilitate inspection, but none independently establishes fidelity, stability, semantic validity, or analyst utility. When information is incomplete, the explanation should also disclose whether the decision was interpolated, weakly supported, based on local observations, issued before labels became available, or escalated because confidence was inadequate. Predictive and explanatory evaluation should therefore remain separate, and both routine and failure cases should be examined [10,11,13,14,130,131,132,134].
Benchmark overconfidence is equally consequential. Random splits and aggregate accuracy may conceal leakage, duplicates, chronological violations, family or device overlap, and saturated datasets. These weaknesses directly undermine claims concerning rare attacks, zero-day behavior, incomplete rule coverage, cross-site robustness, or deployment. The evaluation must instantiate the asserted condition: family holdout for unseen attacks, chronology-aware splitting for campaign change, device or site holdout for IoT, partial-view tests for local detectors, delayed-label tests for adaptation, and support-distance or abstention analysis for weakly represented regions [1,2,5,6,27].
Adversarial claims are under-specified when they consist only of added noise and clean-performance reporting. A credible attacker model identifies knowledge, objective, capability, budget, and feasible constraints. Manipulations in network, IoT, mobile, and cyber-physical settings must preserve the semantics of traffic, protocols, devices, timing, applications, or processes. Explanation integrity belongs in the same analysis because an attacker may change the rationale presented to an analyst even when the predicted label remains unchanged [24,25,28,109,110,111,117,118,119,132].
9.2. Architecture, Assurance, and Autonomy Risks
Architectures may also be overburdened. Constrained devices and gateways cannot reasonably be assumed to perform full attribution, global training, high-frequency federated aggregation, poisoning analysis, long-horizon drift monitoring, and analyst-grade explanation for every event. A deployment claim should identify local and offloaded functions, the proxy information available when offloading fails, and system behavior under communication delay or backend loss. Without such measurements and failure analyses, the design remains conceptual rather than deployable [15,17,18,19,26,80,83,86].
Adaptation introduces a distinct set of risks. Reinforcement learning, streaming updates, and moving-target defense may respond to changing evidence [16,36,44,125,126], but misaligned rewards, delayed labels, uncontrolled exploration, or irreversible updates can produce unsafe behavior. Process-control research further demonstrates that detection and response must respect physical safety [98]. Adaptive studies therefore require explicit definitions of state, action, reward, feedback timing, safety constraints, escalation, versioning, and rollback. In high-consequence settings, human escalation or abstention may be the appropriate output.
The recent literature reveals three additional forms of overstatement. Proposed MuZero and explainable-RL architectures inform state, action, safety, and evaluation design but should not be represented as completed operational validation [49,50]. Federated, blockchain, zero-trust, and tamper-evident mechanisms support locality, provenance, or access assurance, whereas detector performance remains a separate empirical question [52,89,104,106]. Finally, adaptive policies cannot be described as safe without evidence concerning reward sensitivity, safety-shield behavior, operator override, version control, and rollback [51,108,127,129,142].
The governing principle is direct: state the claim, specify the information or operational condition, select a test that bears directly on that condition, and restrict the conclusion to the evaluated setting. Figure 9 summarizes this gate. The following section reformulates the same logic as reusable design patterns rather than as a catalogue of failures.
These pitfalls are mutually reinforcing. The most effective correction occurs early—during problem formulation and split design—before explanation, deployment, and governance claims are built on an unsuitable experimental foundation.
10. Design Patterns for Explainable IDS under Incomplete Information
10.1. Pattern Selection Principle
The preceding pitfalls can be reformulated as design patterns that align five elements: the incomplete-information condition, observable data, reasoning or explanation mechanism, validation protocol, and deployment tier. A pattern is not an algorithm label; it is a compact contract between a problem and the evidence required to support a solution. FRI, feature selection, post hoc XAI, federated learning, reinforcement learning, and GAN-assisted testing become defensible only when their role is linked to a stated condition and evaluated accordingly.
Patterns may be combined when the operational problem requires it. An IoT system, for example, may use compact features at a gateway, federated learning across partial client views, and richer post hoc analysis at the SOC. A phishing detector may combine sparse-rule interpolation with chronological campaign holdouts, whereas an adaptive response system may integrate delayed-feedback control with explanation, approval, and rollback. In each case, the selected pattern defines the boundary of the resulting claim.
10.2. Pattern Catalogue
Rule-first reasoning under incomplete information applies when missing antecedent coverage is the formal problem and the available features can be expressed as meaningful rules. FRI is the clearest instance because it infers from sparse fuzzy rule bases when no exact rule matches [7,8,9,39,40,41,61,143]. The pattern supports interpretable inference only when coverage, membership design, interpolation distance, representative traces, and sensitivity to rule or feature choices are reported.
Feature-compression reasoning is appropriate when a compact set of traffic, URL, device, or process variables preserves operational meaning while reducing sensing, storage, runtime, or explanation cost. Feature selection and wrapper optimization can serve this aim, but compactness alone does not improve interpretation [42,43,71,72]. Reports must establish feature semantics and availability, stability across splits, sensitivity to rare classes, and behavior when selected variables are absent or manipulated.
Black-box detection with validated post hoc explanation addresses settings in which ensembles, deep models, autoencoders, or other high-capacity detectors are needed but inspection, debugging, triage, or audit remains necessary. Here, the explanation is a separate empirical claim. LIME, SHAP, counterfactu-als, prototypes, and saliency may be useful, yet they require tests of fidelity, stability, semantic validity, runtime, misleading cases, and analyst relevance rather than a few illustrative plots [10,11,13,14,131,132,133,134].
Distributed partial-evidence reasoning covers clients, devices, sites, gateways, or administrative domains whose raw observations cannot be centralized because of privacy, bandwidth, ownership, or governance constraints. Federated and edge approaches belong here only when local views, non-IID data, delayed labels, or partial client evidence create the stated information condition [15,17,18,19,86]. Required evidence includes client partitions, non-IID severity, local and global results, communication cost, secure-aggregation or privacy assumptions, leakage risk, poisoning resistance, and fallback during disconnection; Byzantine robustness addresses malicious updates, not the rationale for data locality [144].
Adaptive control under incomplete feedback applies to streaming decisions, concept drift, delayed feedback, unseen states, and moving-target operation. Reinforcement learning, online updates, cyberdecep-tion, and moving-target defense can implement the pattern [16,36,44,125,126], while process-control research motivates explicit safety and recovery constraints [98]. State, action, reward, label timing, approval, and rollback must be specified. The pattern should support bounded action, escalation, or abstention rather than being presented as autonomous security by default.
Adversarial weak-support probing uses evasion, poisoning, generative samples, or other stress tests to examine poorly supported decision regions. Such methods can reveal fragility only when generated or perturbed records satisfy domain constraints [24,25,28,109,110,117,118,119,120,121]. The evaluation should define attacker knowledge, objective, budget, feasible feature changes, diversity, leakage, degradation, recovery, and explanation integrity.
Governance-oriented incomplete-information decision support applies when IDS outputs affect triage, escalation, response approval, exceptions, model updates, or rollback. Explanation is treated as part of an accountable decision process, so the alert must identify observed information, the relevant gap, explanation type, confidence or support limitation, action boundary, model version, and feedback path. Operational and responsible-AI guidance can bound these uses [26,29,31,32,130], and threat sources may provide context [30,33]; neither replaces empirical detector validation.
Table 12.
Recurring design pitfalls, corrective controls, and protected claims.
| Design pitfall | Consequence Corrective control Claim protected |
|
|---|---|---|
| Incomplete information is treated as all uncertainty. | Define the exact incomplete-information condition: The term becomes unfalsifiable incomplete rule coverage, rare Reasoning under incomplete and hides the specific evidence class, partial observation, delayed information. gap. label, weak support, or unseen state. |
|
| Method name is treated as evidence. | FRI, FL, RL, XAI, GANs, or feature Separate mechanism from claim selection may be present without and report the condition under Conceptual validity. supporting the claimed property. which the mechanism is relevant. | |
| Readable rules are treated as valid rules. | A rule can be interpretable but Report rule coverage, membership Interpretable IDS under unsupported, biased by coverage, design, interpolation trace, incomplete rule coverage. or sensitive to membership design. sensitivity, and failure cases. |
|
| Explanation is shown but not validated. | Report fidelity, stability, semantic Plausible explanations may be validity, runtime cost, unfaithful, unstable, semantically Explainable IDS. incomplete-information disclosure, invalid, or unusable for triage. and analyst usefulness. |
|
| Feature reduction is treated as explanation. | Fewer features may remove Report feature semantics, evidence, amplify artifacts, or deployment availability, split Feature-level reasoning. obscure rare-class behavior. stability, and rare-class sensitivity. | |
| Federated learning is assumed private and robust. | Report client partition, non-IID Model updates can leak severity, communication cost, Distributed IDS under incomplete information, inherit non-IID bias, privacy mechanism, update information. or be poisoned. leakage risk, and poisoning defense. |
|
| Report state/action/reward | ||
| Reward misalignment, delayed Reinforcement learning is assumed design, reward ablations, safety feedback, and unseen states can Adaptive IDS or response. safe. constraints, escalation policy, and produce unsafe responses. rollback. Generated or perturbed records Report attacker model, semantic Synthetic or adversarial samples may violate protocol, device, constraints, diversity, leakage Adversarial robustness. are treated as realistic by default. traffic, or process semantics. checks, and degradation curves. Use lightweight local proxies, state Resource-constrained tiers may not Gateway-side heavy XAI and audit offloading policy, and report support expensive explanation, Deployment readiness. are assumed feasible. latency, memory, energy, aggregation, or poisoning analysis. bandwidth, and fallback behavior. Use chronological, family-holdout, Leakage, chronology violations, Random-split accuracy is treated device-holdout, site-holdout, and family or device overlap can External validity. as deployment evidence. cross-dataset, open-set, and inflate performance. weak-support tests where relevant. Provide action boundaries, human An explanation does not define approval rules, model versioning, Governance is reduced to a model response authority, auditability, feedback controls, limitation Responsible deployment. explanation. feedback quality, or rollback. statements, and rollback procedures. | ||
Table 13.
Claim-control checks for proposed architectures, assurance mechanisms, and adaptive policies.
Table 13.
Claim-control checks for proposed architectures, assurance mechanisms, and adaptive policies.
| Risk | Required control | Bounded claim |
|---|---|---|
| Proposed architecture is presented as validated. | State whether the contribution is a design, protocol, simulation, prototype, or completed field evaluation; report only evidence actually produced. | Architecture or evaluation-plan claim, not demonstrated operational effectiveness. |
| Assurance mechanism is presented as detection. | Separate telemetry integrity, access control, privacy, and audit metrics from precision, recall, delay, and unseen-attack behavior. | Trust or provenance claim, not detector competence. |
| Adaptive policy is presented as safe autonomy. | Report reward ablation, safety-shield interventions, operator override, action cost, versioning, and rollback. | Bounded adaptation under the evaluated safety assumptions. |
Table 14 consolidates the patterns and the evidence required to support each. The final column records the recurrent overclaim and thereby indicates how the conclusion should be narrowed when the requisite evidence is absent.
Table 14.
Design patterns linking information conditions, outputs, evidence, and common overclaims.
| Pattern | Best-fit condition | Operational output Required evidence Common overclaim | ||
|---|---|---|---|---|
| Rule-first reasoning under incomplete coverage | Sparse fuzzy rules, incomplete antecedent coverage, compact expert knowledge. | Rule coverage, Rule trace, membership interpolation trace, distance Treating readable rules as degrees, interpolation metric, membership design, automatically valid or status, neighboring-rule sensitivity, and failure complete. rationale. cases. |
||
| Feature-compression reasoning | Compact IDS, feature selection, low-cost traffic or URL reasoning. | Feature semantics, split Stable feature reason, Treating fewer features as stability, deployment selected-feature profile, inherently more availability, missing-feature deployment-available interpretable or more sensitivity, and rare-class evidence summary. robust. behavior. |
||
| Black-box with validated post hoc XAI | Deep models, ensembles, autoencoders, high-dimensional traffic or malware evidence. | Attribution, local surrogate, counterfactual, prototype, saliency, or explanation report. | Fidelity, stability, semantic validity, runtime cost, misleading-example analysis, and analyst usefulness. | Treating an explanation plot as a validated explanation. |
| Distributed partial-evidence reasoning | Federated IDS, edge IDS, IoT gateways, cross-site learning. | Local proxy reason, client evidence summary, global update note, support or uncertainty flag. | Client partition, non-IID severity, communication cost, privacy assumptions, update leakage risk, poisoning resistance, and fallback behavior. |
Treating federated learning as automatically private, robust, or capable of handling incomplete information. |
| Adaptive control under incomplete feedback | Streaming IDS, delayed labels, concept drift, moving-target defense, response policy learning. | Policy rationale, reward component, drift signal, escalation or rollback recommendation. | State/action/reward definition, delayed-feedback test, reward ablation, safety constraints, human approval, and rollback. | Treating adaptation as safe autonomous response. |
| Adversarial weak-support probing | Evasion, poisoning, weak-support testing, GAN-assisted stress testing. | Robustness report, degradation curve, feasible perturbation trace, explanation-integrity result. |
Attacker model, semantic constraints, budget, diversity, leakage check, recovery behavior, and explanation stability. | Treating arbitrary numerical perturbations or synthetic samples as realistic attacks. |
| Governance-oriented decision support | Analyst triage, escalation, audit, update approval, responsible deployment. | Alert rationale, Governance workflow, information-limit human-feedback controls, statement, action boundary, versioning, audit trail, model version, limitation approval boundary, and statement. rollback procedure. | Treating model explanation as sufficient for operational trust. | |
Recent studies provide examples without altering these evidentiary boundaries. Federated IoT detection and tamper-evident telemetry illustrate distributed learning and provenance controls [52,53]; reward-function analysis, streaming learning, and family-held-out DQN detection illustrate adaptive tests under incomplete feedback [54,69,127]; GAN attack-and-recovery research illustrates weak-support probing [122,123]; and SOC playbooks, zero-trust architectures, and autonomous-infrastructure frameworks illustrate governed decision support [104,108,142]. Each example is used only to the extent justified by its empirical or architectural status.
Figure 10 begins with the information or operational condition rather than with a preferred algorithm. Method family, explanation form, validation depth, and deployment tier are then selected so that the resulting claim remains proportional to the available evidence.
The patterns function as composable design contracts. Combining them may increase capa-bility, but it also accumulates evidence requirements at the interfaces through which information, explanations, updates, or authority move across tiers.
11. Domain-Specific Implications and Transfer Boundaries
Incomplete information is inseparable from domain. A partial view in enterprise monitoring is not equivalent to a partial view at an IoT gateway, in a phishing pre-click classifier, or within an industrial control loop. Enterprise, web, mobile, IoT, smart-grid, OT, 5G/SDN, vehicular, and smart-city environments expose different sensors, timing constraints, attack semantics, and action costs. Domain therefore determines which absence is consequential, which explanation is meaningful, which benchmark split is credible, and which deployment or governance boundary constrains the conclusion.
11.1. Enterprise, Web, and Mobile Environments
Enterprise monitoring may combine flows, logs, counters, and alert correlations while lacking payloads, complete attack-stage context, reliable labels, or stable base rates. The information deficit often concerns partial campaign visibility: scanning, lateral-movement indicators, or abnormal rates are observed without the complete intrusion chain. Explanations should remain at the level of these observations and temporal associations rather than imply causal reconstruction. Relevant evaluation includes false positives per time window or asset, detection delay, low-base-rate behavior, chronology-aware splits, and sensitivity to missing logs or features [1,65,66,67,145].
Phishing and web detectors frequently act before a campaign is fully visible. URLs, lexical cues, domain and certificate attributes, redirects, or page fragments may be available before a click or before the underlying infrastructure changes. These variables can support analyst-readable explanations [70,71,72,73]; fuzzy rules are useful when they form meaningful antecedents [70,73], and FRI has been applied where rule coverage is incomplete [143]. Evaluation should control chronology, campaign overlap, near-duplicate URLs, collection artifacts, and string leakage, because random splitting can place related campaign instances in both training and test sets.
Mobile malware and spyware impose constraints associated with the stage of analysis. Permis-sions, API calls, metadata, network traces, and brief dynamic windows may be observable, while privacy, platform policy, and instrumentation restrict collection. Explanations should specify whether a feature is available before installation, during execution, or only through subsequent forensic analysis. DREBIN-style reporting links Android malware decisions to interpretable application properties and examines known and unknown families [74]. Family holdouts, observation-window assumptions, feature availability, and temporal stability are therefore essential; privacy-aware release remains a separate claim.
11.2. IoT, Edge, and Critical Infrastructure
In IoT and edge deployments, partial observation is compounded by resource constraints. Devices and gateways observe local traffic or short telemetry windows even when a campaign extends across many devices and sites. Bot-IoT, TON-IoT, IoT-23, Kitsune, Edge-IIoTset, SVELTE, and N-BaIoT illustrate the range of traffic, device, online-detection, and botnet evidence used in this domain [79,80,81,82,83,84,85]. A local rationale should be presented as a proxy rather than as global botnet attribution. Device or site holdouts, latency, memory, energy, communication cost, non-IID partitions, and poisoning resistance are central evaluation requirements [17,18,19,86].
Smart-grid and OT monitoring raises the stakes because detection and explanation interact with physical processes and safety. Meter readings, control commands, topology, timing, and consistency constraints may all bear on a decision [94,95,96,98]. Public data may be limited, instrumentation incom-plete, topology only partly known, and labels delayed until investigation. An explanation should therefore relate cyber evidence to physical plausibility and response risk; identifying anomalous telemetry is insufficient when the proposed action could affect availability or safety. OT and secure-by-design guidance informs segmentation, approval, audit, and rollback, but it does not validate the detector itself [26,29].
11.3. Cross-Domain Adversarial Transfer
Adversarial evaluation spans all domains, but feasible manipulation is domain specific. Attackers may target weak support, alter features, poison updates, evade local models, or manipulate the explanation presented to an analyst. A URL modification, IoT traffic perturbation, enterprise-log edit, and cyber-physical process change are governed by different constraints. Results must therefore be interpreted in relation to the stated attacker model, feasible feature space, and operating environment [24,25,28,109,117,118,119,132]. Explanation integrity is important because a misleading rationale may be operationally harmful even when the predicted label is unchanged.
Table 15 summarizes these domain-specific implications. Transfer across domains is itself an empirical claim: differences in observation point, feature semantics, label timing, resources, attacker capability, or analyst task may invalidate an otherwise strong result.
Table 15.
Domain-specific information gaps, explanations, tests, and transfer boundaries.
| Domain / setting | Information gap | Explanation focus | Critical test | Transfer boundary |
|---|---|---|---|---|
| Enterprise network | Partial attack stage, encrypted or summarized traffic, low attack base rate, delayed labels. | Flow reason, counter abnormality, temporal correlation, alert-context summary. | False positives per time window or asset, detection delay, chronology-aware split, missing-log sensitivity. |
Flow- or log-level evidence should not be presented as full campaign reconstruction without additional context. |
| Phishing / web | Limited pre-click evidence, changing campaigns, URL/domain/content fragments, sparse rule coverage. | URL, domain, certificate, content, or FRI rule trace with evidence-limit statement. |
Chronological split, campaign holdout, duplicate and near-duplicate control, leakage analysis. | Feature-level explanations are valid only if the features are observable and not artifacts of collection. |
| Mobile malware | Short observation windows, Permission, API, metadata, privacy-sensitive telemetry, app-behavior, traffic, or family diversity, platform family-context explanation. constraints. |
Family holdout, observation-window reporting, privacy-aware feature release, feature-availability check. | Static or dynamic features should not be generalized beyond the analysis stage in which they are observable. | |
| IoT / edge | Local client view, heterogeneous devices, non-IID behavior, limited compute, partial gateway visibility. | Lightweight local proxy plus fog/cloud explanation, support flag, or device-context rationale. | Device/site holdout, latency, memory, energy, communication, non-IID partition, poisoning resistance. |
Local explanations should not be treated as global botnet attribution without higher-tier evidence. |
| Smart grid / OT | Partial meter or process view, limited public attack data, safety constraints, incomplete topology. | Cyber-physical plausibility, process-consistency reason, response-risk statement. | Physical validation, safety envelope, latency requirement, human approval, rollback. | Classification evidence should not justify autonomous high-impact response without safety and governance controls. |
| Cross-domain adversarial setting | Weak support regions, feasible feature manipulation, poisoning, evasion, explanation manipulation. | Stable explanation under domain-constrained perturbation and attack-impact report. |
Attacker model, semantic Robustness claims transfer validity, degradation curve, only when attacker recovery behavior, capability and domain explanation integrity. constraints are comparable. | |
| 5G / SDN / vehicular / smart-city infrastructure |
Slice-, controller-, edge-, vehicle-, service-, or language-local evidence with cross-domain dependencies. |
Controller or slice rationale, local evidence summary, policy action trace, sovereignty statement, and escalation boundary. |
Slice/site/service/vehicle Local evidence should not holdout, controller failure, be presented as city-wide communication delay, or campaign-level language-stratified results, attribution without safety and rollback. cross-tier validation. |
|
A further cross-domain cluster includes 5G slices, software-defined controllers, vehicular net-works, business-intelligence services, and smart-city infrastructure. Information is distributed across slice monitors, controllers, edge nodes, vehicles, applications, and urban services, and no single observer necessarily possesses campaign-wide context [88,107,146,147,148,149]. Proposed bilingual phishing and critical-infrastructure designs add language coverage, data sovereignty, and response authority [57,108]; blockchain-oriented energy chapters contribute access, provenance, and governance context but remain secondary to empirical detection evidence [105]. Appropriate evaluation may require controller, slice, site, service, language, or vehicle holdouts and should distinguish local anomaly evidence from cross-service attribution.
Figure 11 expresses the resulting design sequence: begin with the operational domain and its observable information, identify the consequential gap, select an explanation grounded in domain semantics, construct a benchmark that tests the gap, and constrain transfer claims by deployment and governance conditions.
Domain specificity is part of the evidence rather than a nuisance variable. Transfer requires comparable observation points, attack semantics, timing constraints, resources, and consequences of error.
12. Reporting and Benchmark Protocols
12.1. Claim-Specific Reporting
A review becomes operationally useful when its analytical distinctions can be translated into reporting decisions. The templates in this section are intended for authors, reviewers, and benchmark designers who must assess whether claims about incomplete information, explanation, robustness, or deployment are adequately supported. They do not require every paper to perform every test; rather, they specify the evidence that becomes necessary once a particular claim is made.
Four elements anchor the templates: the information or operational condition, the observations available to the detector, the validation procedure, and the boundary of the conclusion. The same method may support different claims under different conditions. FRI substantiates sparse-rule rea-soning only when coverage gaps and interpolation are examined; federated learning substantiates distributed learning only when client partitions and update assumptions are explicit; and post hoc XAI substantiates an explanation claim only when fidelity, stability, semantics, and analyst relevance are evaluated.
Table 16 converts this logic into reporting statements. Its function is diagnostic: when the specified evidence is absent, the claim should contract accordingly. Performance on a documented closed-world split, for example, does not establish zero-day capability, dependable operation under incomplete information, adversarial robustness, or deployment readiness.
Table 16.
Reporting templates linking claims to required evidence and bounded conclusions.
| Claim type | Condition to state | Evidence to report | Bounded conclusion |
|---|---|---|---|
| Sparse-rule reasoning | The incomplete-information condition is incomplete rule coverage in a fuzzy or rule-based IDS. | Rule-base coverage, membership-function design, interpolation distance, interpolation frequency, representative traces, and interpolation error analysis. | Bounded to the evaluated rule base, feature space, and membership design. |
| Rare-class or unseen-family detection | The incomplete-information condition is underrepresented, unseen, or weakly supported attack evidence. | Per-class precision and recall, precision–recall behavior where rare attacks are central, family or chronology holdout, calibration, abstention, and error analysis. | Zero-day or open-set conclusions require explicit unseen-family or unknown-class tests. |
| Partial-observation IDS | The incomplete-information condition is limited visibility from a sensor, gateway, client, device, site, or time window. | Evidence map, observed and unobserved features, sensor or client ablation, tier comparison, local/global disagreement, and missing-feature sensitivity. | Bounded to the stated observation point; campaign attribution requires higher-tier evidence. |
| Federated IDS | The incomplete-information condition is partial, non-IID, privacy-constrained, or locally delayed client evidence, not federated learning itself. |
Client partition, non-IID severity, local and global metrics, communication cost, privacy or secure-aggregation assumptions, update leakage risk, and poisoning resistance. | Privacy, robustness, and incomplete-information competence require separate tests. |
| Adaptive IDS or response | The incomplete-information condition is delayed feedback, unseen state, temporal drift, or incomplete reward evidence. | State/action/reward definition, delayed-label test, reward ablation, Bounded to the evaluated safety constraint, escalation feedback, state, reward, and safety threshold, versioning, and rollback assumptions. procedure. |
|
| Post hoc XAI | The explanation supports a specified analyst, developer, audit, or response task. | Explanation method, fidelity, stability, semantic validity, runtime Illustrative explanations do not cost, examples for correct and establish fidelity, causality, or incorrect decisions, and actionability. analyst-task evidence where claimed. |
|
| Adversarial IDS | The attacker model is stated and constrained by the domain. | Attacker knowledge, objective, capability, budget, feasible feature Transfer is limited to attacks with constraints, clean and attacked comparable knowledge, budget, performance, degradation curve, and semantics. recovery behavior, and explanation integrity. |
|
| Deployment readiness | Tier placement, latency, memory, The proposed deployment tier can energy, bandwidth, update size, Deployment claims are bounded to run the required inference, explanation runtime, offloading the measured tier, workload, and explanation, update, and response policy, communication-failure failure model. functions. behavior, and fallback mode. |
||
| Governed analyst use | Alert rationale, information-limit statement, confidence or support High-impact automation requires The IDS output is part of an limitation, action boundary, independent safety, authority, and accountable decision process. approval rule, feedback record, rollback controls. model version, and rollback path. |
||
12.2. Benchmark Scenario Ladder
Benchmark scenarios apply the same discipline to experimental design. Historical datasets remain valuable for reproducibility, leakage analysis, and understanding benchmark limitations, but they do not independently establish contemporary deployment realism [150,151,152,153,154,155]. Dataset surveys and evaluation frameworks require documentation of source, feature semantics, split policy, and threat coverage before performance can be interpreted [5,6,27]. IoT and edge research adds heterogeneity, local observation, non-IID clients, and resource constraints [79,80,81,82,83,84,85]; adversarial guidance constrains attack scenarios [24,25,28,117,118,119]; and OT guidance constrains deployment and response [26,29].
Table 17 orders benchmark scenarios from basic classification to tests of information limits, expla-nation quality, adversarial robustness, multilingual and sovereign deployment, evidence provenance, and analyst use. Stopping at an earlier stage is acceptable when the conclusion remains correspond-ingly narrow. Stronger claims require the evidence associated with the relevant higher stage or an explicit qualification.
The ladder should be interpreted conservatively. A closed-world result is a baseline, not evidence of competence under incomplete information; a family holdout supports only the evaluated families and split; an adversarial result is bounded by its attacker model; and a deployment result is bounded by the measured tier and resource budget. Figure 12 depicts this progression from predictive performance to information-aware, explanatory, adversarial, systems, and governance evaluation.
Table 17.
Benchmark scenarios ordered by evidentiary strength, including multilingual, provenance, deployment, and governance tests.
Table 17.
Benchmark scenarios ordered by evidentiary strength, including multilingual, provenance, deployment, and governance tests.
| Scenario | Trigger | Question tested | Evidence produced | Bounded claim |
|---|---|---|---|---|
| Closed-world baseline | The paper claims ordinary classification or anomaly-detection performance. | Does the detector work on a documented and justified split? | Dataset description, feature list, preprocessing, split policy, baselines, standard metrics, and confusion matrix. | Basic predictive competence under the stated dataset and split assumptions. |
| Leakage and split audit | The dataset contains repeated records, related flows, chronological structure, device identities, campaigns, or families. | Could the train–test split inflate performance? | Duplicate and near-duplicate check, chronology policy, family/device/site separation, and leakage analysis. | More credible generalization within the dataset. |
| Sparse-rule coverage | The method uses FRI, fuzzy rules, sparse rule bases, or rule interpolation. | What happens when no exact rule covers the observed case? | Rule coverage, interpolation frequency, neighboring-rule traces, membership sensitivity, and interpolation errors. | Sparse-rule reasoning under incomplete antecedent coverage. |
| Rare-family, open-set, or multilingual holdout | The paper claims rare-class, zero-day, unseen-family, open-set, bilingual, or low-resource-language behavior. | Does the model detect, abstain, and explain consistently when attack or language evidence is underrepresented, unseen, or code-switched? | Family and chronology holdout, unknown-class protocol, language-stratified metrics, calibration, abstention, explanation fidelity, inference placement, and unsupported-language analysis. | Behavior under the evaluated rare, unseen, multilingual, and infrastructure conditions. |
| Partial-observation test | The paper claims edge, gateway, client, federated, site-local, or sensor-limited operation. | Can local or partial evidence support the intended decision? | Observation map, sensor/client ablation, local and global metrics, missing-feature sensitivity, and tier comparison. | Partial-evidence reasoning at the stated observation point. |
| Delayed-label or adaptive test | The paper claims streaming learning, drift handling, reinforcement learning, or online response. | Can the system act safely before labels or rewards are complete? | Label-latency assumptions, pre/post-update performance, reward ablation, escalation threshold, safety constraint, and rollback result. | Bounded adaptation under incomplete feedback. |
| Explanation validation | The paper claims explainability, interpretability, analyst usefulness, or audit support. | Are explanations faithful, stable, semantically meaningful, and useful for the stated task? | Fidelity, stability, semantic checks, runtime cost, incomplete-information disclosure, and analyst-task evidence where claimed. | Validated explanation rather than decorative XAI. |
| Adversarial probing | The paper claims robustness or security under manipulation. | Can attackers exploit weak support regions, feature manipulation, poisoning, or explanation instability? | Attacker model, feasible perturbation constraints, clean and attacked metrics, degradation curve, recovery behavior, and explanation-integrity result. | Domain-constrained adversarial robustness. |
| Deployment and evidence provenance | The paper claims device, gateway, fog, cloud, SOC, real-time, tamper-evident, zero-trust, or data-sovereign deployment. | Can inference, explanation, and any evidence chain be executed and verified within the stated deployment budget? | Latency, memory, energy, bandwidth, update and proof size, construction and verification time, disclosure scope, storage, offloading, failure handling, and fallback mode. | Operational feasibility and evidence integrity for the measured tier and workload; these measurements do not independently establish detection effectiveness. |
| Analyst and governance task | The IDS output is intended to support triage, escalation, response approval, audit, or rollback. | Does the explanation improve or discipline the human decision process? | Triage time or quality, escalation accuracy, false-alarm handling, feedback quality, action boundary, version record, and rollback procedure. |
Analyst-centered and governance-aware decision support. |
These templates function as review contracts: they allow a narrow, well-supported result to stand without rewarding language that extends beyond what the experiment can sustain.
13. Governance and Responsible Operational Use
13.1. Alert, Explanation, and Authority
An IDS explanation becomes consequential when it enters an operational decision process. Alerts can alter triage priority, escalation, containment, configuration, model updates, and audit. When rule coverage, attack examples, observations, labels, or distributional support are limited, governance must ensure that the system communicates both the basis of the alert and the boundary of what it can justify. Explanation is therefore one component of controlled decision making, not a substitute for authority, safety, monitoring, or rollback.
Governance complements rather than replaces technical evaluation. Responsible-AI and XAI research informs intelligibility, usefulness, and accountability [31,32,130]; security guidance constrains response authority and software assurance [26,29]; and threat sources provide contextual information [30,33]. None of these sources establishes predictive performance, robustness, operation under incom-plete information, or deployment cost for a specific IDS. Their role is to define the conditions under which technical outputs may be used responsibly.
A governed alert should record six elements: the observations used; the relevant information gap, such as interpolation, weak support, partial visibility, delayed labels, rare-family evidence, or open-set status; the explanation type; confidence, calibration, abstention, or escalation status; the action boundary; and the versions of the model, feature extractor, rule base, explanation method, and policy. Together, these elements permit subsequent review to reconstruct both the decision and the authority under which it was acted upon.
13.2. Feedback, Update, and Recovery
Feedback requires equivalent control. Its source, confidence, timing, and context determine whether it is suitable for updating a rule, model, threshold, policy, or federated aggregate. A triage label may differ from a forensic confirmation; analyst disagreement may reflect ambiguous information; and an attacker may target feedback channels when online or federated updates are accepted without validation [25,113,114,144]. Feedback should therefore be staged, quality checked, and versioned, with rollback available where degradation would be costly.
Action authority is particularly important in OT, smart-grid, IoT, and enterprise systems, where an erroneous response can disrupt service or create unsafe behavior [26,98]. Low-impact actions, such as logging, enrichment, rate-limited notification, and queueing, may be automated under documented conditions. Blocking industrial traffic, isolating fleets, disabling accounts, or changing production policy should require approval unless safety, latency, and rollback have been validated independently. Under incomplete information, abstention, escalation, or a bounded recommendation will often be more appropriate than automatic containment.
Table 18 links governance controls to their operational purpose. The objective is not merely to produce compliance documentation, but to prevent limited information, unstable explanations, unsafe updates, or untested deployment assumptions from being translated into consequential actions without adequate review.
Recent research on assurance and autonomous defense adds requirements for provenance and policy orchestration. Tamper-evident telemetry and blockchain or zero-trust designs can record the information available, the principal that accessed it, and the rule, model, or policy version involved [52,104,105,106]. Federated-learning synthesis contributes controls over updates and local-data movement [89]; explainable response, SOC playbook, smart-city, and critical-infrastructure frameworks contribute graded authority, policy triggers, override, and rollback [50,108,142,148]. These controls improve auditability but do not establish detector accuracy, robustness, or policy safety.
Figure 13 represents governance as a feedback-control loop. An alert discloses its information boundary and explanatory limitations; an analyst reviews a bounded recommendation; validated feedback may alter rules, models, thresholds, or policies; and versioning, monitoring, and rollback protect the lifecycle if performance or safety deteriorates.
Table 18.
Governance controls for analyst-facing IDS decisions under incomplete information.
| Governance element | What should be provided | Why it matters | Role under incomplete information |
|---|---|---|---|
| Alert explanation | Observed evidence, incomplete-information condition, reason, confidence or support status, and limitation statement. | Supports triage without encouraging blind reliance on the model. | Makes incomplete rule coverage, weak support, partial observation, delayed labels, or rare evidence visible to the analyst. |
| Action boundary | Distinction between logging, enrichment, queueing, escalation, containment, rollback, and high-impact response. | Prevents model output from being converted into unsafe automation. | Allows incomplete information to trigger abstention or escalation rather than unjustified autonomous action. |
| Versioning | Model version, feature extractor, rule base, membership functions, explanation method, thresholds, policy, and update history. | Enables audit, reproducibility, incident review, and controlled rollback. | Identifies whether an incomplete-information decision came from a specific rule base, model state, explanation layer, or adaptive policy. |
| Human feedback | Analyst role, label confidence, timestamp, evidence context, disagreement handling, and confirmation status. | Prevents noisy or premature feedback from corrupting model adaptation. | Distinguishes provisional labels from validated evidence in delayed-label and adaptive settings. |
| Update control | Staging, validation, approval, monitoring, and rollback for rule, model, threshold, policy, or federated updates. | Reduces the risk of silent degradation, poisoning, or unsafe adaptation. | Ensures that newly validated observations improve coverage without destabilizing previously reliable decision regions. |
| Threat-context mapping | Mapping from alert evidence to campaign, tactic, technique, asset, or operational context where supported. | Helps analysts interpret an alert within a broader incident hypothesis. | Prevents partial local evidence from being overinterpreted as full campaign attribution. |
| Privacy and data movement | Statement of what data, features, gradients, explanations, and feedback move across tiers or organizations. | Clarifies privacy, ownership, communication, and audit assumptions. | Shows whether incomplete local evidence is caused or intensified by privacy-preserving or federated design. |
| Rollback and recovery | Previous model, rule, threshold, Enables recovery after drift, policy, and explanation states, plus poisoning, update failure, or criteria for reverting. analyst-confirmed degradation. | Provides a safety mechanism when incomplete information leads to unstable adaptation or incorrect escalation. | |
| Limitation statement | Unsupported attacks, weakly represented classes, unavailable Prevents overclaiming and sensors, dataset limits, deployment supports responsible release. assumptions, and adversarial limits. |
Bounds the decision claim to the incomplete-information conditions actually evaluated. | |
Governance translates information limits into explicit system behavior: disclose, abstain, escalate, authorize, monitor, and roll back. At this stage, explainability becomes a component of system safety rather than a visualization add-on
14. Comparative Synthesis by Method Family
Comparison among methods is meaningful only after the decision condition has been fixed. No family is uniformly preferable across sparse-rule coverage, rare or unseen attacks, partial observation, delayed labels, adversarial manipulation, deployment constraints, and analyst use. The relevant question is not which method is generally superior, but which role it can perform under a specified information gap, with a specified explanation and operational output.
Each family is therefore treated as a conditional design choice. FRI is well suited to sparse fuzzy-rule coverage; trees and feature-selection pipelines are appropriate for compact, semantically meaningful evidence; and deep models and autoencoders provide high-capacity representation but require separate explanation validation. Federated methods address distributed ownership without au-tomatically ensuring privacy, robustness, or competence under incomplete information. Reinforcement learning supports sequential decision making but requires safety and rollback provisions. GANs and synthetic data can probe weak-support or adversarial regions only when generated samples respect domain semantics. Threat and governance frameworks delimit operational use without replacing detector validation.
Table 19 records these conditional strengths and limitations. A listed claim is supportable only when the corresponding evaluation evidence is available.
Recent studies illustrate this conditional comparison. One-hot DDoS features and PSO/GWO optimization represent compact or optimized pipelines [68,102]; BiPAM, streaming learners, and family-held-out DQN detection represent high-capacity, online, and adaptive approaches [54,69,101]; federated IoT research contributes local-data collaboration [53]; and GAN attack-and-recovery research contributes adversarial stress and recovery [122,123]. MuZero, XRL, SOC-playbook, and autonomous-infrastructure frameworks are retained as design proposals whose claims remain bounded by their validation status [49,50,108,142].
Table 19.
Conditional comparison of method families by role, explanation, evaluation, and limitation.
Table 19.
Conditional comparison of method families by role, explanation, evaluation, and limitation.
| Method family | Best-supported role | Explanation affordance | Required evaluation | Principal limitation |
|---|---|---|---|---|
| FRI and fuzzy rules | Interpretable reasoning under incomplete coverage in a sparse fuzzy rule base. | Rule trace, membership degree, neighboring-rule rationale, interpolation status. | Rule-base coverage, interpolation frequency, distance metric, membership-function sensitivity, and correct/incorrect interpolation traces. | Readable rules may still be incomplete, biased by membership design, or unsupported outside covered regions. |
| Trees, rule lists, and feature selection | Compact feature-level reasoning when features retain operational meaning. | Decision path, selected-feature profile, local split condition, feature-importance summary. | Feature semantics, split stability, deployment availability, leakage analysis, rare-class behavior, and missing-feature sensitivity. | Feature importance or compactness can be mistaken for causal, stable, or actionable explanation. |
| Deep models and autoencoders | High-capacity detection of complex, nonlinear, temporal, or high-dimensional patterns. | Post hoc attribution, saliency, local surrogate, prototype, reconstruction error, or model-health summary. |
Shift tests, rare-family or cross-dataset tests, post hoc explanation fidelity and stability, adversarial stress testing, and runtime placement. | High clean accuracy may hide opacity, weak-support errors, adversarial fragility, or infeasible explanation cost. |
| Federated and collaborative models | Distributed learning under local data ownership, partial client evidence, or cross-site constraints. |
Local proxy explanation, client evidence summary, global update note, uncertainty or support flag. | Client partition, non-IID severity, local and global performance, communication cost, privacy mechanism, update leakage risk, and poisoning resistance. |
Federated learning does not by itself establish privacy, robustness, fairness across clients, or reasoning under incomplete information. |
| Reinforcement learning and adaptive response | Sequential decision-making under delayed feedback, drift, or unseen states. | Policy rationale, state evidence, reward component, drift signal, escalation or rollback recommendation. | State/action/reward Adaptation can be misread specification, reward as safe autonomy despite ablation, delayed-label reward misalignment, behavior, safety constraints, unsafe exploration, or human-approval boundary, unstable updates. and rollback. |
|
| GANs, synthetic data, and adversarial stress testing | Weak-support probing, rare-class augmentation, evasion analysis, poisoning analysis, or recovery testing. | Generated-example rationale, perturbation trace, degradation curve, explanation-integrity report. | Semantic validity, diversity, Synthetic or perturbed leakage checks, attacker samples can inflate model, feasible feature performance or robustness constraints, held-out if they violate domain transfer, recovery behavior, constraints. and explanation stability. |
|
| Operational, threat, and governance frameworks | Deployment realism, response boundaries, threat-context mapping, auditability, and responsible release. | Limitation statement, threat-context mapping, action boundary, model-version record, audit and rollback trace. | Mapping to deployment tier, safety and availability Guidance and standards constraints, analyst constrain claims but do not workflow, governance validate detector accuracy, controls, feedback handling, behavior under incomplete and empirical IDS evidence information, or robustness. from separate evaluation. |
|
Figure 14.
Conditional method-family selection. Information condition and required output determine method role, explanation affordance, evidentiary burden, and the limit of comparison.
Figure 14.
Conditional method-family selection. Information condition and required output determine method role, explanation affordance, evidentiary burden, and the limit of comparison.

14.1. Cross-Cutting Findings
Four findings recur across method families. First, the decision condition—not the algorithm abel—determines whether incomplete information is present. Second, predictive performance and explanation quality are independent claims that require different tests. Third, transfer and robustness depend on explicit holdout, attacker, and recovery assumptions. Fourth, operational value depends on where computation occurs and who is authorized to act on the output. These findings explain why the following comparison is conditional rather than a universal ranking.
14.2. Fuzzy and Rule-Based Methods
Fuzzy and rule-based methods are appropriate when meaningful antecedents can be specified and sparse rule coverage is the relevant information deficit. FRI supports inference when no exact rule is available [7,8,9,39,40,41,61,143], making it suitable for network, SNMP-MIB, URL, or device features that can be expressed as interpretable fuzzy conditions. Its distinctive explanatory affordance is a trace of the contributing rules, membership degrees, distance or similarity relations, and interpolated conclusion.
This transparency does not establish validity. Coverage may be inadequate, membership functions arbitrary, scaling unstable, or rules tied to dataset artifacts rather than attack semantics. Reports should document rule-base construction, coverage, interpolation frequency, distance metric, sensitivity, and both successful and failed interpolations. Conclusions must remain specific to the evaluated feature space, rule base, and sparse-rule condition.
14.3. Tree Ensembles and Feature-Selection Pipelines
Tree ensembles, rule lists, and feature-selection pipelines support compact feature-level reasoning when variables retain operational meaning. They can expose paths, split conditions, selected variables, or importance summaries [42,43,71,72,156], which may be useful for traffic, URL, phishing, and device telemetry that analysts can interpret directly.
Their principal risk is artifact-based reasoning. Predictive variables may encode collection bias, duplicates, chronology, device identity, leakage, or dataset construction rather than attack behavior. Evaluation should report feature definitions and deployment availability, split stability, leakage con-trols, rare-class sensitivity, and behavior under missing or manipulated variables. A tree path describes the model’s decision process; it does not constitute causal evidence without separate validation.
Recent DDoS and Sunburst studies continue to employ categorical encoding, conventional or tree-based baselines, and metaheuristic optimization [68,102]. Their relevance lies in reinforcing the need for leakage checks, feature-availability analysis, and rare-class evaluation, not in demonstrating that encoding or optimization itself produces an explanation.
14.4. Deep Models and Autoencoders
Deep models, autoencoders, and related high-capacity detectors are useful for nonlinear, temporal, or high-dimensional attack behavior that is difficult to express through explicit rules [23,82,157,158,159,160]. In traffic, IoT, malware, and anomaly detection, learned representations can capture complex structure; their relevance to incomplete information is greatest when evaluated through rare-class, weak-support, cross-dataset, device-holdout, or chronological tests rather than random splits alone.
Predictive competence and explanation quality remain separate. A deep IDS may perform well while producing explanations that are unstable, unfaithful, or semantically uninformative. Post hoc methods therefore require evidence concerning fidelity, stability, domain validity, adversarial stress, and runtime placement [10,11,13,14,131,132]. Studies should also state whether explanations are computed locally, approximated at the edge, or offloaded to fog, cloud, or SOC systems.
Recent studies of smart-grid integrity, BiPAM ICS, streaming, and family-held-out DQN detection make distinct deep or adaptive claims [54,69,99,101]. Their numerical results remain conditional on dataset, split, and output, while parameter count and per-sample benchmark time remain distinct from end-to-end deployability.
14.5. Federated and Collaborative Models
Federated and collaborative learning is justified when raw observations cannot be centralized because of privacy, ownership, bandwidth, regulation, or operational constraints [15,17,18,19,86]. It intersects with incomplete information when clients hold partial, non-IID, delayed, or locally weak evidence. A local client may lack attack diversity, while a global aggregate may obscure minority behavior or amplify poisoned updates; Byzantine-robust learning addresses malicious aggregation rather than the underlying rationale for data locality [144].
A recurrent overclaim is that federation automatically resolves incomplete information or guaran-tees privacy and robustness. Credible reporting should include client partitions, non-IID severity, local and global metrics, client-level degradation, communication cost, secure-aggregation or privacy as-sumptions, leakage risk, poisoning resistance, and behavior under dropout or delay [15,17,18,19,86,144]. Local explanations should remain distinct from campaign-level conclusions.
A recent FedAvg study using N-BaIoT reports collaborative detection results, while a companion synthesis emphasizes non-IID data, communication, privacy, and poisoning concerns [53,89]. Consid-ered together, these sources demonstrate that retaining raw data locally is not, by itself, evidence of privacy or robustness.
14.6. Reinforcement Learning and Adaptive Response
Reinforcement learning, moving-target defense, online updating, and adaptive response are suited to decisions that unfold over time under delayed or changing feedback [16,36,44,125,126]. Their information deficits include unseen states, partial observations, delayed labels, and reward signals that imperfectly represent the security objective. Process-control research adds physical-safety constraints [98]. These methods can support triage, thresholding, allocation, or bounded response when state, action, and reward are explicitly defined.
Safety is the central limitation. A policy may optimize its reward while increasing false alarms, analyst burden, service disruption, or attacker leverage. Evaluation should address state and ac-tion spaces, reward components and ablations, delayed labels, exploration limits, safety envelopes, approval boundaries, versioning, and rollback [16,26,98,126]. In high-impact environments, the war-ranted output may be abstention or a bounded recommendation rather than containment.
Studies of reward functions, self-healing AMI, moving-target defense, MuZero, explainable response, and critical-infrastructure frameworks extend adaptation from classification toward policy and action [49,50,51,87,108,127,129]. Across these approaches, credible evaluation requires an explicit link among state information, reward or cost, authority, safety intervention, and rollback.
14.7. GANs, Synthetic Data, and Adversarial Evaluation
GANs, synthetic data, and adversarial stress tests can probe weak-support regions, test evasion, augment rare classes, or examine recovery [24,25,28,109,110,117,118,119,120,121]. Their role is experimental: they may reveal vulnerabilities in decision boundaries, explanations, or update mechanisms, but they do not independently establish performance against operational attacks.
Semantic validity is therefore decisive. Generated or perturbed records should represent feasible traffic, protocols, URLs, devices, applications, or physical processes. Reports should specify attacker knowledge, objective, budget, constraints, diversity, leakage, held-out transfer, clean and attacked performance, degradation, recovery, and explanation integrity. Synthetic data should be treated as an evaluation or augmentation hypothesis rather than a substitute for representative operational observations.
14.8. Operational, Threat, and Governance Frameworks
Threat frameworks and landscape reports provide context rather than detection algorithms [30,33]. OT and secure-by-design guidance separately constrains safety, response authority, auditability, asset criticality, software assurance, and governance [26,29]. These sources are especially important where model outputs can affect service availability or physical safety.
Their evidentiary scope remains limited. Threat frameworks can organize campaigns, and opera-tional guidance can define response expectations, but neither validates detector accuracy, explanation quality, robustness, or behavior under incomplete information. Such sources should delimit empirical claims rather than replace benchmarks, information-gap tests, explanation validation, or deployment measurement.
Recent work on zero trust, telemetry integrity, blockchain-assisted AMI, SOC playbooks, and autonomous critical-infrastructure defense contributes useful patterns for access, provenance, policy, and response [52,104,106,108,142]. These sources remain governance and assurance evidence rather than substitutes for detector benchmarks or safety evaluation.
The comparison identifies no universal winner. Instead, it delineates a portfolio of method roles whose value depends on the information condition, explanation requirement, deployment budget, and consequence of error.
15. Research Agenda and Practical Priorities
Future progress should be assessed by whether an IDS makes better-supported decisions under realistic information constraints, rather than by the proliferation of model variants. The central research question is whether a system can justify a label, score, explanation, abstention, escalation, or response when information available at decision time is incomplete. Addressing this question requires coordi-nated advances in problem formulation, benchmark construction, explanation validation, adversarial and distributed evaluation, systems measurement, and lifecycle governance. The intended decision and information gap should therefore be specified before selecting the model family, explanation mechanism, deployment tier, or evaluation protocol.
15.1. Immediate Priorities
The immediate priority is to make incomplete-information conditions explicit and reproducible. Studies should distinguish incomplete rule coverage, rare or unseen attacks, partial observation, delayed or missing labels, weak support regions, non-IID local data, and unseen states. Broad constructs such as uncertainty, class imbalance, concept drift, privacy, and federation should enter the formulation only when they create a defined shortage of decision-relevant information. Dataset reports should document feature semantics, collection context, preprocessing, class distribution, chronology, duplicate and leakage checks, split construction, and unsupported conditions [5,6,27]. Explanation studies should specify the intended user and task and then report fidelity, stability, semantic validity runtime, and the information boundary communicated to that user [10,11,13,14,35,130,131,132,136,137,138]. These practices require comparatively little additional infrastructure, yet they substantially improve reproducibility and prevent method labels from substituting for evaluated conditions. Near-term reporting should also connect every output to its operational use. A classification claim requires documented predictive performance; an abstention claim requires coverage and error analysis; 17 an explanation claim requires independent validation; and a deployment claim requires resource and failure measurements at the stated tier. When a system proposes an action, the report should specify the authority boundary, fallback behavior, and recovery path. This output-centered discipline permits comparison across studies that use different model families without implying that their claims are equivalent.
15.2. Medium-Term Comparative Evidence
The medium-term priority is to develop shared, condition-controlled evaluation protocols. Ratherthan compare headline accuracy across unrelated datasets, benchmark families should vary the relevantinformation constraint explicitly: sparse-rule coverage, attack-family or chronological holdout, weak support regions, device or site separation, partial sensor visibility, delayed labels, or cross-datasettransfer. Recent zero-day and cross-dataset studies demonstrate why the holdout and transfer protocoldetermines the strength of a generalization claim [21,45,46,47,54,69]. Comparisons among FRI, compactrules, tree ensembles, deep detectors, autoencoders, federated models, adaptive policies, and posthoc XAI should report trade-offs in detection quality, calibration or abstention, explanation validity,adversarial degradation, runtime placement, and analyst utility. The objective is not a universalranking but a reusable account of which methods remain reliable under which information conditions. 1033
Adversarial evaluation should advance from isolated attack demonstrations toward joint tests ofprediction, explanation, and recovery. Attacker knowledge, objective, budget, and domain constraintsmust be specified, and perturbations should preserve feasible traffic, protocol, device, application, orprocess behavior [24,25,28,109,117,118,119]. Evaluation should determine whether explanations remainfaithful and stable, whether misleading rationales arise before labels change, and whether the detectorrecovers after attack or contaminated updates. Recent work on adversarial recovery, GAN-based stresstesting, and explanation-drift monitoring provides complementary starting points for such a protocol[122,123,124].
Distributed evaluation requires comparable rigor. Federated and edge studies should describeclient and site partitions, non-IID severity, local and global performance, minority-client degradation,communication cost, privacy or secure-aggregation assumptions, update leakage, poisoning resistance,dropout behavior, and fallback mechanisms under limited connectivity [15,17,18,19,34,53,55,86,90,144].
These measurements are necessary to determine whether collaboration reduces an information deficitor merely relocates it between clients and the aggregate model. Local explanations should also bedistinguished from global campaign attribution, particularly when a client observes only a narrowdevice population or time window.
15.3. Long-Term Governed Adaptation
The principal long-term challenge is governed adaptive defense. Online updates, reinforcement-learning response, self-healing, and moving-target strategies can address changing conditions, butthey also create obligations concerning safety, auditability, and rollback [16,36,44,50,51,56,125,126].
Models, rules, thresholds, feature extractors, explanation methods, feedback records, and responsepolicies should be versioned as interconnected lifecycle objects. Updates should be staged, monitored,and reversible following poisoning, drift failure, explanation degradation, or analyst-confirmed error.
In OT, smart-grid, and critical-infrastructure settings, the same lifecycle should include explicit actionlimits, approval rules, safety envelopes, and recovery procedures [26,29,98,103,108]. Progress towardautonomy should therefore be assessed by controlled authority and recoverability rather than by thenumber of automated actions.
Tiered explainability is a complementary systems-level direction. Devices and gateways canexpose sensor state, rule hits, interpolation status, support warnings, confidence, and escalation flags.
Fog and site-edge nodes can add multi-device correlation, cached explanations, local support estimates, and model-health summaries. Cloud and SOC infrastructure can perform more computationally intensive attribution, counterfactual analysis, poisoning audits, federated aggregation, cross-site comparison, and long-horizon drift monitoring. Analyst and governance processes should translate these outputs into bounded recommendations, approvals, feedback, and rollback decisions. Research should measure explanation latency, memory, bandwidth, energy, availability during disconnection, and task value at each tier rather than assume that the richest explanation should be computed where the alert originates [51,52,57,93,101].
Across these time horizons, recent studies make six priorities especially concrete. Generalization 1071 protocols should include family, language, client, site, chronology, and cross-dataset boundaries rather 1072 than relying only on random splits [21,45,46,54,57,69]. Adaptive systems require policy explanations 1073 that expose state evidence, reward components, safety interventions, and operator authority [49– 1074 51,56]. Robustness studies should measure post-adversarial recovery in addition to degradation [122– 1075 124]. Deployment studies should quantify proof, communication, inference, and explanation costs 1076 [52,93,101]. Federated systems require client-aware and poisoning-resistant evaluation [34,53,55,90]. 1077 Autonomous-defense proposals require override, versioning, and rollback before high-impact response 1078 claims can be justified [49,50,51,108]. Shared protocols across these priorities would provide stronger 1079 evidence of progress than accuracy values derived from non-equivalent tasks.
15.4. Practical Heuristics
Several practical heuristics translate this agenda into study design. Begin with the decision and information gap, and only then select the method. Treat feature compression as beneficial only when it preserves operational semantics and sensitivity to rare cases. Distinguish explanation time from decision time, because analyst-grade analysis may be appropriate at the SOC but infeasible within a gateway deadline. Evaluate abstention, escalation, and fallback alongside classification. Use synthetic and adversarial samples as controlled experimental instruments rather than as substitutes for representative operational observations. Report mixed and negative results when they reveal minority-client degradation, weak family-holdout behavior, explanation instability, or deployment cost. Finally, formulate limitations as precise design boundaries that identify unsupported attacks, sensors, tiers, and authority assumptions.
Table 20 translates these priorities into research actions and observable indicators of progress. The horizons are cumulative rather than independent: long-term adaptive deployment depends on the reporting discipline and shared evaluation infrastructure established in the earlier stages.
Table 20.
Prioritized research agenda with methodological requirements and observable progress.
| Horizon | Research priority | Required study design | Observable progress |
|---|---|---|---|
| Short term | Define the decision and incomplete-information condition. | State the intended output and distinguish rule gaps, rare or unseen attacks, partial observation, delayed labels, weak support, non-IID local data, and unseen states from broader uncertainty or privacy concepts. | Study profiles identify the information gap, observation boundary, intended decision, and conditions under which the conclusion is valid. |
| Short term | Standardize dataset and split documentation. | Report feature semantics, collection context, preprocessing, chronology, class distribution, duplicate and leakage checks, and family/device/site partitions. | Reproducible split definitions, unsupported-class statements, and fewer conclusions based only on random closed-world partitions. |
| Short term | Validate explanation claims. | Match the explanation to a user task and measure fidelity, stability, semantic validity, runtime, and disclosure of unavailable or weakly supported information. |
Explanations are evaluated for both correct and failed decisions and are not justified solely by illustrative plots. |
| Short term | Measure inference and explanation placement. | Declare the execution tier and report latency, memory, energy, bandwidth, update size, offloading, communication failure, and fallback behavior. | Deployment claims are bounded to measured hardware, workload, connectivity and response assumptions. |
| Medium term | Build shared information-condition benchmarks. | Use sparse-rule tests, family and chronology holdouts, cross-dataset transfer, weak-support probing, partial-observation scenarios, and delayed-label evaluation. |
Common protocols support condition-matched comparisons and report calibration, abstention, and failure cases as well as aggregate accuracy. |
| Medium term | Compare method families on equivalent tasks. | Evaluate interpretable, black-box, federated, adaptive, and post hoc XAI approaches under the same information condition and operational output. | Results expose trade-offs among detection, explanation, robustness, resource cost, and analyst utility without assuming a universal winner. |
| Medium term | Join adversarial robustness, explanation integrity, and recovery. | State a domain-constrained attacker model; measure clean and attacked behavior, explanation degradation, recovery, and post-update effects. | Robustness reports include feasible perturbations, degradation curves, misleading-explanation analysis, and recovery evidence. |
| Medium term | Evaluate distributed and analyst-facing behavior. | Report client/site partitions, non-IID effects, communication and poisoning risks, local/global disagreement, and task-based analyst outcomes where claimed. | Client-level and analyst-level results reveal who benefits, who degrades, and when escalation or higher-tier context is required. |
| Long term | Develop governed adaptive defense. | Version and audit models, rules, thresholds, explanations, feedback, and policies; stage updates; constrain actions; and test rollback. | Adaptive systems demonstrate recoverability, safety intervention, operator authority, and post-update monitoring under delayed or corrupted feedback. |
| Long term | Operationalize tiered explainability. | Allocate proxy, site-level, global, and governance explanations to device, gateway, fog, cloud/SOC, and analyst tiers; measure cost and continuity. | Studies quantify explanation value and resource demand at each tier, including operation during disconnection or backend failure. |
| Long term | Establish accountable lifecycle governance. | Integrate action boundaries, approval rules, audit trails, feedback controls, limitation statements, and recovery procedures with technical evaluation. | High-impact IDS decisions are traceable, reviewable, reversible, and explicitly bounded by the information and safety conditions evaluated. |
The roadmap is cumulative: credible adaptive and autonomous operation depends on the re- 1095 porting, benchmarking, explanation, deployment, and recovery infrastructure established at earlier 1096 horizons. Taken together, the agenda redirects attention from the proliferation of model variants toward cumulative, testable knowledge. A method constitutes progress when it closes a documented information gap, improves a measured operational trade-off, or strengthens the reliability and governance of an existing decision process. Novelty without a matched condition, comparison protocol, and claimboundary should not be interpreted as evidence of operational advancement.
Figure 15.
Research roadmap. Reporting and benchmark foundations enable comparative stress and recovery studies, which in turn support governed adaptive defense and tiered explainability.
Figure 15.
Research roadmap. Reporting and benchmark foundations enable comparative stress and recovery studies, which in turn support governed adaptive defense and tiered explainability.

16. Conclusion
Intrusion detection under incomplete information is best conceptualized as a decision-support problem rather than as a new algorithmic category. The relevant question is whether the information available at decision time is sufficient to justify the intended output—a label, score, explanation, abstention, escalation, or response. Sparse rule coverage, rare or unseen attacks, partial observation, delayed labels, and weak distributional support are recurring forms of this deficit. Uncertainty, privacy, federation, adaptation, concept drift, and opacity may contribute to the problem, but they are not interchangeable with it.
The review yields three substantive conclusions. First, no method family resolves every information condition. FRI has a precise role when a sparse fuzzy rule base lacks an exact match and can expose coverage, membership, neighboring rules, and interpolation status [7,8,9,39,40,41,61]. Deep, federated, adaptive, and post hoc approaches address different primary problems and must be linked to an explicit information deficit before broader claims are warranted. Second, explanation is a distinct empirical object. Local surrogates, additive attributions, counterfactuals, prototypes, saliency, and policy accounts can make complex systems more inspectable, but their fidelity, stability, semantic validity, runtime, and analyst value require independent validation [10,11,13,14,131,132]. An explanation intended for operational use must also disclose what was missing, interpolated, weakly supported, delayed, or observed only locally. Third, deployment placement and governance determine whether a technically valid output can support action. Devices and gateways are suited to sensing, compact feature extraction, local proxy reasons, and escalation; fog or site-edge nodes can add correlation and cached analysis; cloud and SOC infrastructure can support more computationally intensive attribution, aggregation, poisoning checks, and drift monitoring; and analysts and governance processes should control high-impact approval, feedback, audit, and rollback. This allocation does not guarantee trustworthiness, but it converts implicit assumptions about resources, failure, and authority into testable system properties.
The evaluation implications are direct. Rare-family, chronological, device, site, partial-observation, delayed-label, weak-support, and cross-dataset protocols are required when the corresponding conditions are claimed. Explanation must be tested rather than merely displayed; robustness must include feasible attacks, explanation integrity, and recovery; and federated or adaptive designs must report client, communication, safety, versioning, and rollback behavior. Recent adversarial-recovery and explanation-drift studies provide different forms of robustness evidence [122,124]; self-healing AMI response and PPO-based adaptive detection address different sequential outputs [51,56]; and ICS anomaly detection, federated IoT learning, and family-held-out ransomware detection remain specific to their datasets and protocols [54,55,90,101]. Cross-dataset and staged zero-day studies further demonstrate that a generalization claim is only as strong as its holdout and transfer design [21,45,46].
The taxonomy, evidence map, deployment architecture, evaluation protocol, design patterns, reporting templates, and roadmap developed in this paper are intended to make these dependencies explicit. Progress is demonstrated when a study closes a documented information gap, improves a measured operational trade-off, or strengthens the reliability and recoverability of an existing decision process. The field will become more credible not by eliminating uncertainty, which is impossible, but by making information limits visible, explanations testable, deployment assumptions measurable, and consequential actions reviewable and reversible.
Conflicts of Interest
The authors declare no conflicts of interest.
Use of Artificial Intelligence
AI-assisted tools were used for language editing and formatting support.
References
- Axelsson, S. The Base-Rate Fallacy and the Difficulty of Intrusion Detection. ACM Trans. Inf. Syst. Secur. 2000, 3, 186–205. [Google Scholar] [CrossRef]
- Sommer, R.; Paxson, V. Outside the Closed World: On Using Machine Learning for Network Intrusion Detection. In Proceedings of the 2010 IEEE Symposium on Security and Privacy; IEEE, 2010; pp. 305–316. [Google Scholar] [CrossRef]
- Scheirer, W.J.; de Rezende Rocha, A.; Sapkota, A.; Boult, T.E. Toward Open Set Recognition. IEEE Trans. N Pattern Anal. Mach. Intell. 2013, 35, 1757–1772. [Google Scholar] [CrossRef]
- Hendrycks, D.; Gimpel, K. A Baseline for Detecting Misclassified and Out-of-Distribution Examples i eural Networks. In Proceedings of the International Conference on Learning Representations, 2017. [Google Scholar]
- Ring, M.; Wunderlich, S.; Scheuring, D.; Landes, D.; Hotho, A. A Survey of Network-Based Intrusio etection Data Sets. Comput. Secur. 2019, 86, 147–167. [Google Scholar] [CrossRef]
- Hindy, H.; Brosset, D.; Bayne, E.; Seeam, A.K.; Tachtatzis, C.; Atkinson, R.; Bellekens, X. A Taxonomy o etwork Threats and the Effect of Current Datasets on Intrusion Detection Systems. IEEE Access 2020, 8, 104650–104675. [Google Scholar] [CrossRef]
- Kóczy, L.T.; Hirota, K. Approximate Reasoning by Linear Rule Interpolation and General Approximation. Int. J. Approx. Reason. 1993, 9, 197–225. [Google Scholar] [CrossRef]
- Baranyi, P.; Kóczy, L.T.; Gedeon, T.D. A Generalized Concept for Fuzzy Rule Interpolation. IEEE Trans. N Fuzzy Syst. 2004, 12, 820–837. [Google Scholar] [CrossRef]
- Yang, L.; Shen, Q. Adaptive Fuzzy Interpolation. IEEE Trans. Fuzzy Syst. 2011, 19, 1107–1126. [Google Scholar] [CrossRef]
- Ribeiro, M.T.; Singh, S.; Guestrin, C. “Why Should I Trust You?”: Explaining the Predictions of Any Classifier. In Proceedings of the Proceedings of the 22nd ACM SIGKDD International Conference on Knowledg iscovery and Data Mining, 2016; ACM; pp. 1135–1144. [Google Scholar] [CrossRef]
- Lundberg, S.M.; Lee, S.I. A Unified Approach to Interpreting Model Predictions. Proceedings of th dvances in Neural Information Processing Systems, 2017; Curran Associates, Inc.; Vol. 30. [Google Scholar]
- Rudin, C. Stop Explaining Black Box Machine Learning Models for High Stakes Decisions and Use Inter-pretable Models Instead. Nat. Mach. Intell. 2019, 1, 206–215. [Google Scholar] [CrossRef]
- Adebayo, J.; Gilmer, J.; Muelly, M.; Goodfellow, I.; Hardt, M.; Kim, B. Sanity Checks for Saliency Maps. In Proceedings of the Advances in Neural Information Processing Systems; Curran Associates, Inc., 2018; Vol. 31. [Google Scholar]
- Ghorbani, A.; Abid, A.; Zou, J. Interpretation of Neural Networks Is Fragile. Proc. AAA Onference Artif. Intell. 2019, 33, 3681–3688. [Google Scholar] [CrossRef]
- McMahan, H.B.; Moore, E.; Ramage, D.; Hampson, S.; Agüera y Arcas, B. Communication-Efficient Learnin f Deep Networks from Decentralized Data. In Proceedings of the Proceedings of the 20th Internationa onference on Artificial Intelligence and Statistics. PMLR, Proceedings of Machine Learnin esearch, 2017; Vol. 54, pp. 1273–1282. [Google Scholar]
- Sutton, R.S.; Barto, A.G. Reinforcement Learning: An Introduction, 2nd ed.; The MIT Press, 2018. [Google Scholar]
- Nguyen, D.C.; Ding, M.; Pathirana, P.N.; Seneviratne, A.; Li, J.; Poor, H.V. Federated Learning for Interne f Things: A Comprehensive Survey. IEEE Commun. Surv. Tutor. 2021, 23, 1622–1658. [Google Scholar] [CrossRef]
- Kairouz, P.; McMahan, H.B.; Avent, B.; Bellet, A.; Bennis, M.; Bhagoji, A.N.; Bonawitz, K.; Charles, Z.; Cormode, G.; Cummings, R.; et al. Advances and Open Problems in Federated Learning. Found. An. Rends Mach. Learn. 2021, 14, 1–210. [Google Scholar] [CrossRef]
- Bonawitz, K.; Ivanov, V.; Kreuter, B.; Marcedone, A.; McMahan, H.B.; Patel, S.; Ramage, D.; Segal, A.; Seth, K. Practical Secure Aggregation for Privacy-Preserving Machine Learning. In Proceedings of the Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, 2017; ACM; pp. 1175–1191. [Google Scholar] [CrossRef]
- Wali, S.; Farrukh, Y.A.; Khan, I. Explainable AI and Random Forest Based Reliable Intrusion Detectio ystem. Comput. Secur. 2025, 157, 104542. [Google Scholar] [CrossRef]
- Cevallos Moreno, J.F.; Rizzardi, A.; Sicari, S.; Coen-Porisini, A. HERO: From High-Dimensional Networ raffic to Zero-Day Attack Detection. Comput. Netw. 2025, 265, 111264. [Google Scholar] [CrossRef]
- Buczak, A.L.; Guven, E. A Survey of Data Mining and Machine Learning Methods for Cyber Securit ntrusion Detection. IEEE Commun. Surv. Tutor. 2016, 18, 1153–1176. [Google Scholar] [CrossRef]
- Ferrag, M.A.; Maglaras, L.; Moschoyiannis, S.; Janicke, H. Deep Learning for Cyber Security Intrusio etection: Approaches, Datasets, and Comparative Study. J. Inf. Secur. Appl. 2020, 50, 102419. [Google Scholar] [CrossRef]
- Goodfellow, I.J.; Shlens, J.; Szegedy, C. Explaining and Harnessing Adversarial Examples. Proceedings o he International Conference on Learning Representations, 2015. [Google Scholar]
- Vassilev, A.; Oprea, A.; Fordyce, A.; Anderson, H. Adversarial Machine Learning: A Taxonomy an erminology of Attacks and Mitigations; Technical Report NIST AI 100-2e2023; National Institute o tandards and Technology: Gaithersburg, MD, 2024. [Google Scholar] [CrossRef]
- Stouffer, K.; Pease, M.; Tang, C.; Zimmerman, T.; Pillitteri, V.; Lightman, S.; Hahn, A.; Saravia, S.; Sherule, A.; Thompson, M. 2023. Guide to Operational Technology (OT) Security. Technical Report NIST SP 800-82 Rev. 3. National Institute of Standards and Technology: Gaithersburg, MD. [Google Scholar] [CrossRef]
- Gharib, A.; Sharafaldin, I.; Habibi Lashkari, A.; Ghorbani, A.A. An Evaluation Framework for Intrusio etection Dataset. In Proceedings of the 2016 International Conference on Information Science and Security (ICISS); IEEE, 2016; pp. 1–6. [Google Scholar] [CrossRef]
- Biggio, B.; Roli, F. Wild Patterns: Ten Years After the Rise of Adversarial Machine Learning. Patter Ecognition 2018, 84, 317–331. [Google Scholar] [CrossRef]
- Cybersecurity and Infrastructure Security Agency. Shifting the Balance of Cybersecurity Risk: Principle nd Approaches for Secure by Design Software. Cybersecurity and Infrastructure Securit gency, Technical report. 2023. Updated October 25, 2023. [Google Scholar]
- The MITRE Corporation. MITRE ATT&CK Knowledge Base, Version 19.1. Online. 2026. (accessed on 21 July 2026). [Google Scholar]
- Gunning, D.; Aha, D.W. DARPA’s Explainable Artificial Intelligence Program. AI Mag. 2019, 40, 44–58. [Google Scholar] [CrossRef]
- Barredo Arrieta, A.; Díaz-Rodríguez, N.; Del Ser, J.; Bennetot, A.; Tabik, S.; Barbado, A.; García, S.; Gil- López, S.; Molina, D.; Benjamins, R.; et al. Explainable Artificial Intelligence (XAI): Concepts, Taxonomies, Opportunities and Challenges Toward Responsible AI. Inf. Fusion 2020, 58, 82–115. [Google Scholar] [CrossRef]
- European Union Agency for Cybersecurity (ENISA). ENISA Threat Landscape 2025. Enisa report, Europea nion Agency for Cybersecurity, 2025. Version 1.2, revised. accessed. 2026. (accessed on 21 July 2026). [Google Scholar]
- Buyuktanir, B.; Altinkaya, S.; Karatas Baydogmus, G.; Yildiz, K. Federated Learning in Intrusion Detection: Advancements, Applications, and Future Directions. Clust. Comput. 2025, 28, 473. [Google Scholar] [CrossRef]
- Al, S.; Sagiroglu, S. Explainable Artificial Intelligence Models in Intrusion Detection Systems. Eng. Pplications Artif. Intell. 2025, 144, 110145. [Google Scholar] [CrossRef]
- Gama, J.; Žliobaite, I.; Bifet, A.; Pechenizkiy, M.; Bouchachia, A. A Survey on Concept Drift Adaptation. ACM Comput. Surv. 2014, 46, 44:1–44:37. [Google Scholar] [CrossRef]
- Dubois, D.; Prade, H. The Three Semantics of Fuzzy Sets. Fuzzy Sets Syst. 1997, 90, 141–150. [Google Scholar] [CrossRef]
- Hüllermeier, E. Fuzzy Methods in Machine Learning and Data Mining: Status and Prospects. Fuzzy Sets An. Ystems 2005, 156, 387–406. [Google Scholar] [CrossRef]
- Almseidin, M.; Kovács, S. Intrusion Detection Mechanism Using Fuzzy Rule Interpolation. J. O Heoretical Appl. Inf. Technol. 2018, 96, 5473–5488. [Google Scholar]
- Kóczy, L.T.; Hirota, K. Interpolative Reasoning with Insufficient Evidence in Sparse Fuzzy Rule Bases. Inf. Sci. 1993, 71, 169–201. [Google Scholar] [CrossRef]
- Kovács, S.; Kóczy, L.T. Approximate Fuzzy Reasoning Based on Interpolation in the Vague Environment o he Fuzzy Rulebase as a Practical Alternative of the Classical CRI. In Proceedings of the Proceedings of the 7th International Fuzzy Systems Association World Congress, Prague, Czech Republic, 1997; pp. 144–149. [Google Scholar]
- Chandrashekar, G.; Sahin, F. A Survey on Feature Selection Methods. Comput. Electr. Eng. 2014, 40, 16–28. [Google Scholar] [CrossRef]
- Guyon, I.; Elisseeff, A. An Introduction to Variable and Feature Selection. J. Mach. Learn. Res. 2003, 3, 1157–1182. [Google Scholar] [CrossRef]
- Nguyen, T.T.; Reddi, V.J. Deep Reinforcement Learning for Cyber Security. IEEE Trans. Neura Etworks Learn. Syst. 2023, 34, 3779–3795. [Google Scholar] [CrossRef]
- Park, Y.S.; Lim, Y.S. Hybrid Multi-Stage Framework for Identifying Zero-Day Attacks and Known Threats i etwork Traffic. Comput. Netw. 2026, 275, 111875. [Google Scholar] [CrossRef]
- Hossain, M.M.; Turja, S.D.; Tasnim, S.; Juboraj, M.F.U.A.; Hossain, M.I. A Cross-Dataset Based Zero-Da ntrusion Detection System by Integrating Siamese Network and Reinforcement Learning. ICT Express 2026, 12, 752–757. [Google Scholar] [CrossRef]
- Krishnan, D.; Singh, S.; Sugumaran, V. Explainable AI for Zero-Day Attack Detection in IoT Networks Usin ttention Fusion Model. Discov. Internet Things 2025, 5, 83. [Google Scholar] [CrossRef]
- Debar, H.; Dacier, M.; Wespi, A. Towards a Taxonomy of Intrusion-Detection Systems. Comput. Netw. 1999, 31, 805–822. [Google Scholar] [CrossRef]
- Alauthman, M.; Aldweesh, A.; Al-Qerem, A.; Almomani, A.; Khalaf, B.; Alkasassbeh, M. MuZero-Base utonomous Cyber Defense Agents for Software-Defined Networks (SDN). In Proceedings of the 2026 2nd International Conference on Computational Intelligence Approaches and Applications, ICCIAA 2026 - Proceedings; IEEE, 2026. [Google Scholar] [CrossRef]
- Alauthman, M.; Almomani, A.; Al-Qerem, A.; Albesani, G.; Alkasassbeh, M. Explainable Reinforcemen earning for Automated Incident Response in Critical Infrastructure. In Proceedings of the 2026 2n nternational Conference on Computational Intelligence Approaches and Applications, ICCIAA 2026 - Proceedings; IEEE, 2026. [Google Scholar] [CrossRef]
- Younisse, R.; Alkasassbeh, M. Heartbeat-Aware Multi-Agent Self-Healing for Availability Resilience i liced 5G AMI Networks. Arabian Journal for Science and Engineering. 2026. [CrossRef]
- Mosa, H.; Alkasassbeh, M. Blockchain Tamper Evident Telemetry for RPL IoT Security Analytics. In I roceedings of the 2026 2nd International Conference on Computational Intelligence Approaches an pplications, ICCIAA 2026 - Proceedings; IEEE, 2026. [Google Scholar] [CrossRef]
- Saleh, A.; Alkasassbeh, M.; Almseidin, M. Iot botnet intrusion detection system using federated learnin echniques. Wirel. Netw. 2026, 32, 1113–1129. [Google Scholar] [CrossRef]
- Alkasassbeh, M.; Omoush, E.H.; Almseidin, M.; Aldweesh, A. A Self-Adaptive Intrusion Detection Syste or Zero-Day Attacks Using Deep Q-Networks. IEEE Access 2025, 13, 174280–174296. [Google Scholar] [CrossRef]
- Asiri, F. Explainable Federated Learning through Causal Reasoning for Intrusion Detection in IoT. Discove Nternet Things 2026, 6, 23. [Google Scholar] [CrossRef]
- Suresh, A.; Jose, A.C. Adaptive Network Intrusion Detection Using Reinforcement Learning with Proxima olicy Optimization. ACM Trans. Priv. Secur. 2025, 28, 48:1–48:24. [Google Scholar] [CrossRef]
- Alauthman, M.; Aldweesh, A.; Al-Qerem, A.; Khalaf, B.; Alkasassbeh, M. Sovereign AI Defense: Bilingua LM-Driven Phishing Detection for Low-Resource Languages. In Proceedings of the 2026 2nd Internationa onference on Computational Intelligence Approaches and Applications, ICCIAA 2026 - Proceedings; IEEE, 2026. [Google Scholar] [CrossRef]
- Zadeh, L.A. Fuzzy Sets. Inf. Control 1965, 8, 338–353. [Google Scholar] [CrossRef]
- Mamdani, E.H.; Assilian, S. An Experiment in Linguistic Synthesis with a Fuzzy Logic Controller. Interna-Tional J. Man.-Mach. Stud. 1975, 7, 1–13. [Google Scholar] [CrossRef]
- Takagi, T.; Sugeno, M. Fuzzy Identification of Systems and Its Applications to Modeling and Control. IEE Ransactions Syst. Man. Cybern. 1985, SMC-15, 116–132. [Google Scholar] [CrossRef]
- Almseidin, M.; Al-kasassbeh, M.; Kovács, S. Fuzzy Rule Interpolation and SNMP-MIB for Emerging Networ bnormality. Int. J. Adv. Sci. Eng. Inf. Technol. 2019, 9, 735–744. [Google Scholar] [CrossRef]
- Huang, Z.; Shen, Q. Fuzzy Interpolative Reasoning via Scale and Move Transformations. IEEE Trans. N Fuzzy Syst. 2006, 14, 340–359. [Google Scholar] [CrossRef]
- Alzubi, M.; Johanyák, Z.C.; Kovács, S. Fuzzy Rule Interpolation Methods and FRI Toolbox. J. O Heoretical Appl. Inf. Technol. 2018, 96, 7227–7244. [Google Scholar]
- Tikk, D.; Baranyi, P. Comprehensive Analysis of a New Fuzzy Rule Interpolation Method. IEEE Trans. N Fuzzy Syst. 2000, 8, 281–296. [Google Scholar] [CrossRef]
- Liao, H.J.; Lin, C.H.R.; Lin, Y.C.; Tung, K.Y. Intrusion Detection System: A Comprehensive Review. J. O Etwork Comput. Appl. 2013, 36, 16–24. [Google Scholar] [CrossRef]
- Bhuyan, M.H.; Bhattacharyya, D.K.; Kalita, J.K. Network Anomaly Detection: Methods, Systems and Tools. IEEE Commun. Surv. Tutor. 2014, 16, 303–336. [Google Scholar] [CrossRef]
- MontazeriShatoori, M.; Davidson, L.; Kaur, G.; Habibi Lashkari, A. Detection of DoH Tunnels Usin ime-Series Classification of Encrypted Traffic. In Proceedings of the 2020 IEEE International Conferenc n Dependable, Autonomic and Secure Computing, International Conference on Pervasive Intelligenc nd Computing, International Conference on Cloud and Big Data Computing, International Conference o yber Science and Technology Congress (DASC/PiCom/CBDCom/CyberSciTech); IEEE, 2020; pp. 63–70. [Google Scholar] [CrossRef]
- Alodibat, S.; Alkasassbeh, M. An Enhanced Model of DDoS Attacks Detection using One-Hot Encoding o eature’s Categories. In In Proceedings of the 2025 International Conference on New Trends in Computin ciences, ICTCS 2025, 2025; IEEE; pp. 133–140. [Google Scholar] [CrossRef]
- Saleh, A.; Mosa, H.; Alkasassbeh, M. Streaming-Based Intrusion Detection with Big Data and Onlin earning Algorithms. In In Proceedings of the 2025 International Conference on New Trends in Computin ciences, ICTCS 2025, 2025; IEEE; pp. 299–306. [Google Scholar] [CrossRef]
- Aburrous, M.; Hossain, M.A.; Dahal, K.; Thabtah, F. Intelligent Phishing Detection System for E-Bankin sing Fuzzy Data Mining. Expert Syst. With Appl. 2010, 37, 7913–7921. [Google Scholar] [CrossRef]
- Ma, J.; Saul, L.K.; Savage, S.; Voelker, G.M. Beyond Blacklists: Learning to Detect Malicious Web Sites fro uspicious URLs. In Proceedings of the Proceedings of the 15th ACM SIGKDD International Conference o nowledge Discovery and Data Mining, 2009; ACM; pp. 1245–1254. [Google Scholar] [CrossRef]
- Sahingoz, O.K.; Buber, E.; Demir, O.; Diri, B. Machine Learning Based Phishing Detection from URLs. Exper Ystems With Appl. 2019, 117, 345–357. [Google Scholar] [CrossRef]
- Mohammad, R.M.; Thabtah, F.; McCluskey, L. Intelligent Rule-Based Phishing Websites Classification. IE Nformation Secur. 2014, 8, 153–160. [Google Scholar] [CrossRef]
- Arp, D.; Spreitzenbarth, M.; Hübner, M.; Gascon, H.; Rieck, K. DREBIN: Effective and Explainable Detectio f Android Malware in Your Pocket. In Proceedings of the Proceedings of the Network and Distribute ystem Security Symposium (NDSS), 2014; Internet Society. [Google Scholar] [CrossRef]
- Sarker, I.H.; Kayes, A.S.M.; Badsha, S.; Alqahtani, H.; Watters, P.; Ng, A. Cybersecurity Data Science: A verview from Machine Learning Perspective. J. Big Data 2020, 7, 41. [Google Scholar] [CrossRef]
- Almomani, A.; Aoudi, S.; Al-Qerem, A.; Aldweesh, A.; Alkasassbeh, M. Behavioral Analysis of AI-Generate alware: New Frontiers in Threat Detection. In Examining Cybersecurity Risks Produced by Generative AI; IG lobal, 2025; pp. 211–234. [Google Scholar] [CrossRef]
- Alauthman, M.; Aldweesh, A.; Al-Qerem, A.; Alkasassbeh, M.; Alateef, S.; Almomani, A. Synthetic Conten eneration Impacts on Phishing and Impersonation Attacks. In Examining Cybersecurity Risks Produced b enerative AI; IGI Global, 2025; pp. 189–210. [Google Scholar] [CrossRef]
- Ishtaiwi, A.; Alateef, S.; Alkasassbeh, M. Generative AI in Ransomware Evolution: Challenges and Coun- termeasures. In Examining Cybersecurity Risks Produced by Generative AI; IGI Global, 2025; pp. 329–356. [Google Scholar] [CrossRef]
- Koroniotis, N.; Moustafa, N.; Sitnikova, E.; Turnbull, B. Towards the Development of Realistic Botnet Datase n the Internet of Things for Network Forensic Analytics: Bot-IoT Dataset. Future Gener. Comput. Ystems 2019, 100, 779–796. [Google Scholar] [CrossRef]
- Moustafa, N. A New Distributed Architecture for Evaluating AI-Based Security Systems at the Edge: Network TON_IoT Datasets. Sustain. Cities Soc. 2021, 72, 102994. [Google Scholar] [CrossRef]
- Garcia, S.; Parmisano, A.; Erquiaga, M.J. IoT-23: A Labeled Dataset with Malicious and Benign IoT Networ raffic, 2020. Dataset. [CrossRef]
- Mirsky, Y.; Doitshman, T.; Elovici, Y.; Shabtai, A. Kitsune: An Ensemble of Autoencoders for Online Networ ntrusion Detection. In Proceedings of the Proceedings of the Network and Distributed System Securit ymposium (NDSS), 2018; Internet Society. [Google Scholar] [CrossRef]
- Ferrag, M.A.; Friha, O.; Hamouda, D.; Maglaras, L.; Janicke, H. Edge-IIoTset: A New Comprehensiv ealistic Cyber Security Dataset of IoT and IIoT Applications for Centralized and Federated Learning. IEE Ccess 2022, 10, 40281–40306. [Google Scholar] [CrossRef]
- Raza, S.; Wallgren, L.; Voigt, T. SVELTE: Real-Time Intrusion Detection in the Internet of Things. Ad. Ho Etworks 2013, 11, 2661–2674. [Google Scholar] [CrossRef]
- Meidan, Y.; Bohadana, M.; Mathov, Y.; Mirsky, Y.; Shabtai, A.; Breitenbacher, D.; Elovici, Y. N-BaIoT: Network-Based Detection of IoT Botnet Attacks Using Deep Autoencoders. IEEE Pervasive Comput. 2018, 17, 12–22. [Google Scholar] [CrossRef]
- Li, T.; Sahu, A.K.; Zaheer, M.; Sanjabi, M.; Talwalkar, A.; Smith, V. Federated Optimization in Heterogeneou etworks. Proc. Proc. Mach. Learn. Syst. MLSys 2020, Vol. 2, 429–450. [Google Scholar]
- Alkasassbeh, M.; Khalil, A.; Almseidin, M. Self-Adaptive Moving Target Defense with Cyberdeception fo roactive Defense of IoT Networks. In In Proceedings of the 2025 International Conference on New Trends i omputing Sciences, ICTCS 2025, 2025; IEEE; pp. 119–126. [Google Scholar] [CrossRef]
- Al-Qerem, A.; Alauthman, M.; Alateef, S.; Alkasassbeh, M.; Almomani, A. IoT security architecture protectin nterconnected digital assets in smart environments. In Complexities and Challenges for Securing Digital Asset nd Infrastructure; IGI Global, 2025; pp. 115–136. [Google Scholar] [CrossRef]
- Alauthman, M.; Aldweesh, A.; Al-Qerem, A.; Alkasassbeh, M.; Alateef, S.; Almomani, A. Federated learnin n distributed cyber defense: Privacy-preserving collaborative security through decentralized AI training. In I I-Driven Security Systems and Intelligent Threat Response Using Autonomous Cyber Defense; IGI Global, 2025; pp. 161–184. [Google Scholar] [CrossRef]
- Selvam, P.; Karthikeyan, P.; Manochitra, S.; Sujith, A.V.L.N.; Ganesan, T.; Ayyasamy, R.; Shuaib, M.; Alam, S.; Rajendran, A. Federated Learning-Based Hybrid Convolutional Recurrent Neural Network for Multi-Clas ntrusion Detection in IoT Networks. Discov. Internet Things 2025, 5, 39. [Google Scholar] [CrossRef]
- Dwork, C. Differential Privacy. In Automata, Languages and Programming;Lecture Notes in Computer Science; Bugliesi, M., Preneel, B., Sassone, V., Wegener, I., Eds.; Springer: Berlin, Heidelberg, 2006; Vol. 4052, pp. 1–12. [Google Scholar] [CrossRef]
- Sicari, S.; Rizzardi, A.; Grieco, L.A.; Coen-Porisini, A. Security, Privacy and Trust in Internet of Things: Th oad Ahead. Comput. Netw. 2015, 76, 146–164. [Google Scholar] [CrossRef]
- Nameh, N.A.; Almajali, S.; Odeh, A.; Alkasassbeh, M. Innovative Applications of Edge Computing an achine Learning for Enhanced Efficiency and Security. In Proceedings of the Proceedings - 2025 IEEE 11t nternational Conference on Edge Computing and Scalable Cloud, EdgeCom 2025, 2025; IEEE; pp. 132–137. [Google Scholar] [CrossRef]
- Ashibani, Y.; Mahmoud, Q.H. Cyber Physical Systems Security: Analysis, Challenges and Solutions. Comput. Secur. 2017, 68, 81–97. [Google Scholar] [CrossRef]
- Yan, Y.; Qian, Y.; Sharif, H.; Tipper, D. A Survey on Cyber Security for Smart Grid Communications. IEE Ommunications Surv. Tutor. 2012, 14, 998–1010. [Google Scholar] [CrossRef]
- He, H.; Yan, J. Cyber-Physical Attacks and Defences in the Smart Grid: A Survey. IET Cyber-Phys. Syst. Theory Appl. 2016, 1, 13–27. [Google Scholar] [CrossRef]
- Cárdenas, A.A.; Amin, S.; Sastry, S. Secure Control: Towards Survivable Cyber-Physical Systems. In I roceedings of the 2008 28th International Conference on Distributed Computing Systems Workshops; IEEE, 2008; pp. 495–500. [Google Scholar] [CrossRef]
- Cárdenas, A.A.; Amin, S.; Lin, Z.S.; Huang, Y.L.; Huang, C.Y.; Sastry, S. Attacks Against Process Contro ystems: Risk Assessment, Detection, and Response. In Proceedings of the Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, 2011; ACM; p. 355. [Google Scholar] [CrossRef]
- Younisse, R.; AlKasassbeh, M. Evaluating Deep Learning for Detecting Data Integrity Attacks in Energ mart Grids. In Proceedings of the 2025 International Conference on New Trends in Computing Sciences, ICTCS IEEE, 2025; pp. 368–372. [Google Scholar] [CrossRef]
- Younisse, R.; AlKasassbeh, M.; Aldweesh, A. A Fog-Based Approach for Theft Detection and Zero-Da ttack Prevention in Smart Grid Systems. Comput. Mater. Contin. 2025, 85, 4921–4941. [Google Scholar] [CrossRef]
- Alhadidi, M.; Alkasassbeh, M. BiPAM: Bidirectional Parallel Attention-Mamba for Efficient Anomaly Detection in Industrial Control Systems. In Proceedings of the 2026 2nd International Conference o omputational Intelligence Approaches and Applications, ICCIAA 2026 - Proceedings; IEEE, 2026. [Google Scholar] [CrossRef]
- Almseidin, M.; Gawanmeh, A.; Alzubi, M.; Al-Sawwa, J.; Mashaleh, A.S.; Alkasassbeh, M. Hybrid Dee eural Network Optimization with Particle Swarm and Grey Wolf Algorithms for Sunburst Attack Detection. Computers 2025, 14, 107. [Google Scholar] [CrossRef]
- Bani Younisse, R.; Alkasassbeh, M.; Aldweesh, A. Advanced Technologies to Smart Grid Systems: Challenge nd Demands. IEEE Access 2025, 13, 117732–117752. [Google Scholar] [CrossRef]
- Alauthman, M.; al Qerem, A.H.; Aldweesh, A.; Alkasassbeh, M.; Hamarsheh, A. Blockchain-driven zero- trust architectures for critical infrastructure. In Blockchain Applications for the Energy and Utilities Industry; IG lobal, 2025; pp. 81–102. [Google Scholar] [CrossRef]
- Alauthman, M.; Hamarsheh, A.; Almomani, A.; Aldweesh, A.; Alateef, S.; Alkasassbeh, M. Securin lockchain solutions in the energy sector: Mitigating Advanced Persistent Threats (APTs). In Blockchai pplications for the Energy and Utilities Industry; IGI Global, 2025; pp. 323–348. [Google Scholar] [CrossRef]
- Alauthman, M.; Almomani, A.; Al-Qerem, A.; Alateef, S.; Aldweesh, A.; Alkasassbeh, M. AI and blockchai ntegration for Advanced Metering Infrastructure (AMI). In Blockchain Applications for the Energy and Utilitie ndustry; IGI Global, 2025; pp. 213–234. [Google Scholar] [CrossRef]
- Alauthman, M.; Aldweesh, A.; Al-Qerem, A.; Alkasassbeh, M.; Almomani, A. Securing 5G networks: Opportunities and threats in next-generation connectivity. In Complexities and Challenges for Securing Digita ssets and Infrastructure; IGI Global, 2025; pp. 531–562. [Google Scholar] [CrossRef]
- Alauthman, M.; Mashaleh, A.; Aslam, N.; Alkasassbeh, M.; Almomani, A. Next-Generation Critica nfrastructure Security: A Framework for Autonomous Defense Systems. In Proceedings of the 2025 1s nternational Conference on Computational Intelligence Approaches and Applications, ICCIAA 2025 - Proceedings; IEEE, 2025. [Google Scholar] [CrossRef]
- Szegedy, C.; Zaremba, W.; Sutskever, I.; Bruna, J.; Erhan, D.; Goodfellow, I.; Fergus, R. Intriguing Propertie f Neural Networks. In Proceedings of the International Conference on Learning Representations, 2014. [Google Scholar]
- Carlini, N.; Wagner, D. Towards Evaluating the Robustness of Neural Networks. In Proceedings of the 2017 IEEE Symposium on Security and Privacy; IEEE, 2017; pp. 39–57. [Google Scholar] [CrossRef]
- Madry, A.; Makelov, A.; Schmidt, L.; Tsipras, D.; Vladu, A. Towards Deep Learning Models Resistant t dversarial Attacks. In Proceedings of the International Conference on Learning Representations, 2018. [Google Scholar]
- Papernot, N.; McDaniel, P.; Goodfellow, I.; Jha, S.; Celik, Z.B.; Swami, A. Practical Black-Box Attacks Agains achine Learning. In Proceedings of the Proceedings of the 2017 ACM on Asia Conference on Compute nd Communications Security, 2017; ACM; pp. 506–519. [Google Scholar] [CrossRef]
- Huang, L.; Joseph, A.D.; Nelson, B.; Rubinstein, B.I.P.; Tygar, J.D. Adversarial Machine Learning. In I roceedings of the Proceedings of the 4th ACM Workshop on Security and Artificial Intelligence; ACM, 2011; pp. 43–58. [Google Scholar] [CrossRef]
- Barreno, M.; Nelson, B.; Joseph, A.D.; Tygar, J.D. The Security of Machine Learning. Mach. Learn. 2010, 81, 121–148. [Google Scholar] [CrossRef]
- Tramèr, F.; Kurakin, A.; Papernot, N.; Goodfellow, I.; Boneh, D.; McDaniel, P. Ensemble Adversarial Training: Attacks and Defenses. In Proceedings of the International Conference on Learning Representations, 2018. [Google Scholar]
- Athalye, A.; Carlini, N.; Wagner, D. Obfuscated Gradients Give a False Sense of Security: Circumventin efenses to Adversarial Examples. In Proceedings of the Proceedings of the 35th International Conference on Machine Learning; PMLR; Dy, J., Krause, A., Eds.; Proceedings of Machine Learning Research, 2018; Vol. 80, pp. 274–283. [Google Scholar]
- Zhang, H.; Han, D.; Zhuang, S.; Wang, Z.; Sun, J.; Liu, Y.; Liu, J.; Dong, J. Explainable and Transferabl dversarial Attack for ML-Based Network Intrusion Detectors. IEEE Trans. Dependable Secur Omputing 2025, 22, 5090–5107. [Google Scholar] [CrossRef]
- Usama, M.; Asim, M.; Latif, S.; Qadir, J.; Al-Fuqaha, A. Generative Adversarial Networks for Launching an hwarting Adversarial Attacks on Network Intrusion Detection Systems. In Proceedings of the 2019 15t nternational Wireless Communications & Mobile Computing Conference (IWCMC); IEEE, 2019; pp. 78–83. [Google Scholar] [CrossRef]
- Ibitoye, O.; Shafiq, O.; Matrawy, A. Analyzing Adversarial Attacks Against Deep Learning for Intrusion De- tection in IoT Networks. In Proceedings of the 2019 IEEE Global Communications Conference (GLOBECOM); IEEE, 2019; pp. 1–6. [Google Scholar] [CrossRef]
- Goodfellow, I.J.; Pouget-Abadie, J.; Mirza, M.; Xu, B.; Warde-Farley, D.; Ozair, S.; Courville, A.; Bengio, Y. Generative Adversarial Nets. In Proceedings of the Advances in Neural Information Processing Systems; Curran Associates, Inc., 2014; Vol. 27. [Google Scholar]
- Creswell, A.; White, T.; Dumoulin, V.; Arulkumaran, K.; Sengupta, B.; Bharath, A.A. Generative Adversaria etworks: An Overview. IEEE Signal Process. Mag. 2018, 35, 53–65. [Google Scholar] [CrossRef]
- Alslman, Y.; Alkasassbeh, M.; Abdel-Rahman, M.J. Breaking and Healing: GAN-Based Adversarial Attack nd Post-Adversarial Recovery for 5G IDSs. IEEE Access 2025, 13, 132109–132125. [Google Scholar] [CrossRef]
- Alslman, Y.; Alkasassbeh, M.; Abdel-Rahman, M.J. Exploiting GANs Against IDSs: A Systematic Review, Meta-Analysis, and Case Study Evaluation. IEEE Trans. Artif. Intell. 2026. [Google Scholar] [CrossRef]
- Maseno, E.M.; Sun, Y.; Wang, Z. Detecting Adversarial Evasion in Deep Learning Intrusion Detectio ystems Using Explainable AI. Int. J. Inf. Secur. 2026, 25, 125. [Google Scholar] [CrossRef]
- Huang, Y.; Huang, L.; Zhu, Q. Reinforcement Learning for Feedback-Enabled Cyber Resilience. Annu. Eviews Control 2022, 53, 273–295. [Google Scholar] [CrossRef]
- Jajodia, S.; Ghosh, A.K.; Swarup, V.; Wang, C.; Wang, X.S. (Eds.) Moving Target Defense: Creating Asymmetri ncertainty for Cyber Threats. In Advances in Information Security; Springer: New York, NY, 2011; Vol. 54. [Google Scholar] [CrossRef]
- Alauthman, M.; Aldweesh, A.; Al-Qerem, A.; Daoud, I.; Alkasassbeh, M.; Gawanmeh, A. Evaluatin einforcement Learning Reward Functions for APT Detection in Industrial IoT Systems. In Proceedings o he 2025 1st International Conference on Computational Intelligence Approaches and Applications, ICCIAA 2025 - Proceedings; IEEE, 2025. [Google Scholar] [CrossRef]
- Mnih, V.; Kavukcuoglu, K.; Silver, D.; Rusu, A.A.; Veness, J.; Bellemare, M.G.; Graves, A.; Riedmiller, M.; Fidjeland, A.K.; Ostrovski, G.; et al. Human-Level Control through Deep Reinforcement Learning. Nature 2015, 518, 529–533. [Google Scholar] [CrossRef]
- Alauthman, M.; Aldweesh, A.; Al-Qerem, A.; Alateef, S.; Alkasassbeh, M. Reinforcement learning fo daptive cyber defense training autonomous systems for dynamic threat response and strategy optimization. In AI-Driven Security Systems and Intelligent Threat Response Using Autonomous Cyber Defense; IGI Global, 2025; pp. 209–234. [Google Scholar] [CrossRef]
- Miller, T. Explanation in Artificial Intelligence: Insights from the Social Sciences. Artif. Intell. 2019, 267, 1–38. [Google Scholar] [CrossRef]
- Guidotti, R.; Monreale, A.; Ruggieri, S.; Turini, F.; Giannotti, F.; Pedreschi, D. A Survey of Methods fo xplaining Black Box Models. ACM Comput. Surv. 2018, 51, 93:1–93:42. [Google Scholar] [CrossRef]
- Warnecke, A.; Arp, D.; Wressnegger, C.; Rieck, K. Evaluating Explanation Methods for Deep Learning i ecurity. In Proceedings of the 2020 IEEE European Symposium on Security and Privacy; IEEE, 2020; pp. 158–174. [Google Scholar] [CrossRef]
- Samek, W.; Montavon, G.; Vedaldi, A.; Hansen, L.K.; Müller, K.R. (Eds.) Explainable AI: Interpreting, Explainin nd Visualizing Deep Learning. In Lecture Notes in Computer Science; Springer International Publishing, 2019; Vol. 11700. [Google Scholar] [CrossRef]
- Wachter, S.; Mittelstadt, B.; Russell, C. Counterfactual Explanations without Opening the Black Box: Automated Decisions and the GDPR. Harv. J. Law Technol. 2018, 31, 841–887. [Google Scholar]
- Molnar, C. Interpretable Machine Learning: A Guide for Making Black Box Models Explainable, 2nd ed.; Christop olnar, 2022. [Google Scholar]
- Muhammad, A.E.; Yow, K.C.; Bacanin-Dzakula, N.; Khan, M.A. L-XAIDS: A LIME-Based Explainable A ramework for Intrusion Detection Systems. Clust. Comput. 2025, 28, 654. [Google Scholar] [CrossRef]
- Sadhwani, S.; Navare, A.; Mohan, A.; Muthalagu, R.; Pawar, P.M. IoT-Based Intrusion Detection System Usin xplainable Multi-Class Deep Learning Approaches. Comput. Electr. Eng. 2025, 123, 110256. [Google Scholar] [CrossRef]
- Ozawa, N.; Sunahara, S.; Hagihara, S. Evaluation Criteria for Explainable AI in Intrusion Detection t nsure the Creation of High-Quality Threat Intelligence. In Proceedings of the Proceedings of the 2025 14th International Conference on Software and Computer Applications (ICSCA ’25), 2025; ACM; pp. 60–66. [Google Scholar] [CrossRef]
- Doshi-Velez, F.; Kim, B. Towards a Rigorous Science of Interpretable Machine Learning. arXiv 2017, arXiv:stat. [Google Scholar]
- Lipton, Z.C. The Mythos of Model Interpretability. Commun. ACM 2018, 61, 36–43. [Google Scholar] [CrossRef]
- Ahmad, I.; Kumar, T.; Liyanage, M.; Okwuibe, J.; Ylianttila, M.; Gurtov, A. Overview of 5G Securit hallenges and Solutions. IEEE Commun. Stand. Mag. 2018, 2, 36–43. [Google Scholar] [CrossRef]
- Alauthman, M.; Aldweesh, A.; Al-Qerem, A.; Alangari, S.; Alkasassbeh, M. AI Augmented Incident Respons laybooks: Aligning Policy Triggers With SOC Automation. In Cybersecurity Insurance Frameworks an nnovations in the AI Era; IGI Global, 2025; pp. 251–276. [Google Scholar] [CrossRef]
- Almseidin, M.; Alkasassbeh, M.; Alzubi, M.; Al-Sawwa, J. Cyber-Phishing Website Detection Using Fuzz ule Interpolation. Cryptography 2022, 6, 24. [Google Scholar] [CrossRef]
- Blanchard, P.; El Mhamdi, E.M.; Guerraoui, R.; Stainer, J. Machine Learning with Adversaries: Byzantine Tolerant Gradient Descent. In Proceedings of the Advances in Neural Information Processing Systems; Curran Associates, Inc., 2017; Vol. 30. [Google Scholar]
- Mirkovic, J.; Reiher, P. A Taxonomy of DDoS Attack and DDoS Defense Mechanisms. ACM SIGCOM Omputer Commun. Rev. 2004, 34, 39–53. [Google Scholar] [CrossRef]
- Alauthman, M.; Alkasassbeh, M.S.; Alateef, S.; Al-Qerem, A.; Almomani, A. Automotive and autonomou ehicle cybersecurity. In Complexities and Challenges for Securing Digital Assets and Infrastructure; IGI Global, 2025; pp. 353–376. [Google Scholar] [CrossRef]
- Alzubi, M.M.; Almseidin, M.; Alkasassbeh, M.; Bashabsheh, M.; Al-Sawwa, J.; Mashaleh, A.S. AI-Drive hreat Detection in Business Intelligence Systems. In Strategic AI Integration in Business Intelligence; IG lobal, 2025; pp. 111–134. [Google Scholar] [CrossRef]
- Al Maqousi, A.; Basu, K.; Aldweesh, A.; Alkasassbeh, M. Autonomous cyber defense in smart cities: An AI-driven framework for integrated urban infrastructure protection. In AI-Driven Security Systems and Intelligent Threat Response Using Autonomous Cyber Defense; IGI Global, 2025; pp. 465–499. [Google Scholar] [CrossRef]
- Alauthman, M.; Hadi, W.; Al-Qerem, A.; Alateef, S.; Ashraf, M.; Alkasassbeh, M. Securing the digita ackbone of smart cities: Threat detection, infrastructure hardening, and data governance. In Revolutionizing Urban Development and Governance With Emerging Technologies; IGI Global, 2025; pp. 323–342. [Google Scholar] [CrossRef]
- Tavallaee, M.; Bagheri, E.; Lu, W.; Ghorbani, A.A. A Detailed Analysis of the KDD CUP 99 Data Set. In Proceedings of the 2009 IEEE Symposium on Computational Intelligence for Security and Defens pplications; IEEE, 2009; pp. 1–6. [Google Scholar] [CrossRef]
- University of California. KDD Cup 1999 Data. UCI KDD Archive; Accessed. Irvine. (accessed on 21 July 2026).
- Lippmann, R.P.; Fried, D.J.; Graf, I.; Haines, J.W.; Kendall, K.R.; McClung, D.; Weber, D.; Webster, S.E.; Wyschogrod, D.; Cunningham, R.K.; et al. Evaluating Intrusion Detection Systems: The 1998 DARP ff-Line Intrusion Detection Evaluation. Proc. Proc. DARPA Informatio Urvivability Conf. Expo. (DISCEX’00) 2000, Vol. 2, 12–26. [Google Scholar] [CrossRef]
- Sharafaldin, I.; Habibi Lashkari, A.; Ghorbani, A.A. Toward Generating a New Intrusion Detection Datase nd Intrusion Traffic Characterization. In Proceedings of the Proceedings of the 4th International Conferenc n Information Systems Security and Privacy. SCITEPRESS, 2018; pp. 108–116. [Google Scholar] [CrossRef]
- Moustafa, N.; Slay, J. UNSW-NB15: A Comprehensive Data Set for Network Intrusion Detection Systems. In Proceedings of the 2015 Military Communications and Information Systems Conference (MilCIS); IEEE, 2015; pp. 1–6. [Google Scholar] [CrossRef]
- Kent, A.D. Cyber Security Data Sources for Dynamic Network Research. In Dynamic Networks and Cyber- Security; Adams, N.M., Heard, N.A., Eds.; World Scientific (Europe); Security Science an echnology, 2016; Vol. 1, pp. 37–65. [Google Scholar] [CrossRef]
- Moustafa, N.; Turnbull, B.; Choo, K.K.R. An Ensemble Intrusion Detection Technique Based on Propose tatistical Flow Features for Protecting Network Traffic of Internet of Things. IEEE Internet Things J. 2019, 6, 4815–4830. [Google Scholar] [CrossRef]
- Aldweesh, A.; Derhab, A.; Emam, A.Z. Deep Learning Approaches for Anomaly-Based Intrusion Detection Systems: A Survey, Taxonomy, and Open Issues. Knowl.-Based Syst. 2020, 189, 105124. [Google Scholar] [CrossRef]
- Shone, N.; Ngoc, T.N.; Phai, V.D.; Shi, Q. A Deep Learning Approach to Network Intrusion Detection. IEE Ransactions Emerg. Top. Comput. Intell. 2018, 2, 41–50. [Google Scholar] [CrossRef]
- Apruzzese, G.; Colajanni, M.; Ferretti, L.; Guido, A.; Marchetti, M. On the Effectiveness of Machine and Dee earning for Cyber Security. In Proceedings of the 2018 10th International Conference on Cyber Conflict (CyCon); IEEE, 2018; pp. 371–390. [Google Scholar] [CrossRef]
- Javaid, A.; Niyaz, Q.; Sun, W.; Alam, M. A Deep Learning Approach for Network Intrusion Detection System. Proceedings of the Proceedings of the 9th EAI International Conference on Bio-inspired Information and Communications Technologies (formerly BIONETICS) 2016, BICT, 21–26. [Google Scholar] [CrossRef]
Figure 2.
Claim-level evidence normalization. Sources are classified by function and then filtered according to whether they directly support, qualify, or cannot justify the claim under review.
Figure 2.
Claim-level evidence normalization. Sources are classified by function and then filtered according to whether they directly support, qualify, or cannot justify the claim under review.

Figure 4.
Six-axis study profile. Environment, observable information, reasoning and explanation, information condition, failure model, and operational output jointly determine the evidence a study must report.
Figure 4.
Six-axis study profile. Environment, observable information, reasoning and explanation, information condition, failure model, and operational output jointly determine the evidence a study must report.

Figure 5.
Evidence-stream integration. Observable traffic, domain telemetry, and rule knowledge are transformed through reasoning, stress testing, and placement constraints into a supportable IDS claim.
Figure 5.
Evidence-stream integration. Observable traffic, domain telemetry, and rule knowledge are transformed through reasoning, stress testing, and placement constraints into a supportable IDS claim.

Figure 9.
Claim-control gate. A method claim passes only when its information condition, validation evidence, deployment scope, failure model, and authority boundary are explicit and evaluated.
Figure 9.
Claim-control gate. A method claim passes only when its information condition, validation evidence, deployment scope, failure model, and authority boundary are explicit and evaluated.

Figure 10.
Design-pattern sequence. The information condition and required decision determine method role, explanation form, validation depth, placement, and the final claim boundary.
Figure 10.
Design-pattern sequence. The information condition and required decision determine method role, explanation form, validation depth, placement, and the final claim boundary.

Figure 11.
Domain-aware design cycle. The operational setting determines observable information, the conse-quential gap, explanation semantics, benchmark design, and the boundary of transfer.
Figure 11.
Domain-aware design cycle. The operational setting determines observable information, the conse-quential gap, explanation semantics, benchmark design, and the boundary of transfer.

Figure 12.
Evidence ladder for stronger operational claims. Each stage accumulates the information-condition, explanation, adversarial, deployment, and governance evidence required by the next claim level.
Figure 12.
Evidence ladder for stronger operational claims. Each stage accumulates the information-condition, explanation, adversarial, deployment, and governance evidence required by the next claim level.

Figure 13.
Governed decision loop. Transparent alerts are converted into bounded recommendations, reviewed under explicit authority, updated through validated feedback, and protected by lifecycle safeguards.
Figure 13.
Governed decision loop. Transparent alerts are converted into bounded recommendations, reviewed under explicit authority, updated through validated feedback, and protected by lifecycle safeguards.

Table 1.
Research questions, analytical purpose, and expected survey output.
| RQ | Research question | Purpose and survey output |
|---|---|---|
| RQ1 | What constitutes incomplete decision information in IDS? | Establishes the decision-relative definition and the five recurring information conditions used throughout the survey. |
| RQ2 | How should FRI, feature-level reasoning, post hoc XAI, federated learning, and reinforcement learning be related without conflating them? | Separates methods that directly address sparse rule coverage from mechanisms whose relevance depends on a stated information gap. |
| RQ3 | Which evidence streams inform explainable IDS under incomplete information? | Organizes seven evidence streams and identifies the information, explanation, and evaluation boundary of each. |
| RQ4 | How should explanation, robustness analysis, and model updates be placed across device, gateway, fog, cloud, and analyst tiers? | Maps observation, inference, explanation, update, and authority to device, gateway, fog, cloud/SOC, and governance tiers. |
| RQ5 | What evidence should future studies report to substantiate claims about handling incomplete information, explainability, robustness, and deployment? | Defines the evidence needed for predictive, explanatory, robustness, deployment, and analyst-use conclusions. |
Table 2.
Scope boundaries and claim-level normalization criteria.
| Evidence domain | Included evidence Outside scope for this claim | Normalization question | |
|---|---|---|---|
| Reasoning under incomplete information | FRI, sparse fuzzy rule bases, Fuzzy or rule-based work with no membership functions, incomplete IDS setting and no antecedents, interpolation traces, incomplete-information condition. and rule-coverage analysis. |
Does the method explicitly reason when direct rule or evidence coverage is absent? | |
| Explainability | Interpretable rules, local surrogates, additive feature attributions, counterfactuals, saliency checks, prototypes, and analyst-centered explanations. | Generic interpretation claims without fidelity, stability, semantic, cost, or analyst-task evidence. | What explanation is produced, and what evidence supports its reliability or usefulness? |
| IDS evidence | Flow features, SNMP-MIB counters, packet or session summaries, URL and domain features, application behavior, device telemetry, logs, meter readings, and cyber-physical measurements. |
Feature sets whose semantics, collection point, or deployment availability are undocumented. | Can the evidence be observed at the claimed deployment tier, and is it meaningful for triage? |
| Benchmark and dataset evidence | Dataset descriptions, split policies, Accuracy-only benchmark reports leakage concerns, class imbalance, with insufficient dataset family or device partitions, and documentation or unverifiable cross-dataset evaluation. split design. | Does the evaluation test the incomplete-information condition rather than only closed-world classification? | |
| Evasion, poisoning, weak-support probing, explanation stability, Robustness and adversarial testing recovery behavior, and domain-constrained adversarial samples. |
Unconstrained numerical perturbations that cannot represent feasible network, device, or process behavior. | Are attacker knowledge, objective, budget, and semantic constraints stated? | |
| Edge/fog/cloud placement, latency, memory, communication, Deployment and governance privacy, analyst workflow, auditability, rollback, and responsible release. |
Pure benchmark studies that make no deployability or governance claim. | Can the claimed computation and explanation be performed at the stated operational tier? | |
Table 3.
Operational forms of incomplete information, IDS manifestations, and evidence to report.
| Condition | Decision implication | IDS manifestation | Evidence to report |
|---|---|---|---|
| Sparse rule coverage | The rule base lacks a direct antecedent–consequent rule for the observed feature region. | An FRI detector interpolates between neighboring phishing, traffic, or SNMP-MIB rules rather than using an exact match. | Rule-base coverage, interpolation frequency, distance metric, membership design, and representative interpolation traces. |
| Rare or unseen attack evidence | The detector has too few labeled examples, incomplete family coverage, or no representative examples of a relevant attack type. | A model assigns a known label to an underrepresented or family-held-out attack instance. | Per-class recall, precision–recall behavior where appropriate, rare-family or zero-day holdout, calibration, and abstention behavior. |
| Partial observation | The detector observes only a gateway, host, device, time window, attack stage, feature subset, or local client view. |
An IoT gateway sees local device traffic but lacks campaign-level or cross-site context. | Sensor or client evidence map, unobserved assumptions, tier placement, and sensitivity to missing features or viewpoints. |
| Delayed or missing labels | Ground truth is unavailable when the alert or response decision must be made. | A streaming or adaptive IDS updates risk estimates before analyst confirmation or forensic labeling is available. | Label-latency assumptions, confidence or uncertainty estimates, escalation policy, delayed-label evaluation, and rollback procedure. |
| Weak support region | The input lies outside dense training support even though the model can still produce a label. | A classifier reports high confidence for traffic whose feature combination is poorly represented in the training data. | Distance-to-support or support-density estimate, calibration, abstention threshold, and error analysis for weak-support cases. |
Table 4.
Relationship between incomplete information and adjacent mechanisms or conditions.
| Mechanism or condition | Primary function | Relationship to incomplete information | Evidence needed |
|---|---|---|---|
| Fuzzy rule interpolation | Inference from sparse fuzzy rule bases. | Direct: incomplete rule coverage is the formal inference problem. | Rule coverage, neighboring-rule selection, interpolation trace, distance metric, and membership-function sensitivity. |
| Open-set or out-of-distribution detection | Recognition of inputs outside known class or training support. | Closely related: it identifies cases where closed-world evidence may be insufficient. | Known/unknown split design, support or confidence criterion, rejection or abstention behavior, and error analysis. |
| Class imbalance and rare classes | Uneven representation of attack and benign classes. | Conditional: imbalance creates incomplete information when rare examples provide inadequate support for the decision. | Per-class metrics, rare-family holdout, precision–recall behavior where appropriate, and base-rate-aware false-alarm reporting. |
| Concept drift | Temporal change in the data-generating process. | Conditional: drift creates incomplete information when current events are weakly supported by prior evidence. | Temporal split, drift signal, update policy, delayed-label handling, and pre/post-drift performance. |
| Feature selection | Evidence compression and model simplification. | Conditional: selected features may Feature semantics, stability across preserve, remove, or distort splits, deployment availability, and decision evidence. rare-class sensitivity. | |
| Federated learning | Collaborative learning without centralizing raw client data. | Client partition, non-IID severity, Conditional: clients may hold communication cost, privacy partial, non-IID, or locally limited mechanism, update leakage, and information. poisoning resistance. |
|
| Reinforcement learning or adaptive control | Sequential policy learning under feedback. | Conditional: delayed rewards, State/action/reward definition, unseen states, or partial states can delayed-feedback test, safety create incomplete decision constraints, ablation, escalation, information. and rollback. |
|
| Post hoc XAI | Explanation of an already trained model. | Indirect: it can expose evidence Fidelity, stability, semantic validity use but does not itself provide runtime cost, analyst usefulness, reasoning under incomplete and perturbation robustness. information. |
|
Table 5.
Six-axis analytical profile for explainable IDS under incomplete information.
| Axis | Profiling question | Typical values Evaluation consequence | |
|---|---|---|---|
| Attack and deployment environment | Where is the detector expected to operate, and what threat setting is represented? | Enterprise network, cloud service, Constrains sensor visibility, latency IoT gateway, 5G slice, Android safety, privacy, and whether results endpoint, smart grid, industrial can be transferred across domains. control, edge/fog/cloud SOC. |
|
| Evidence representation | What observable evidence is available at decision time? | Flow features, SNMP-MIB counters, packet or session Determines whether explanations summaries, URL/domain features, have operational semantics and application behavior, device whether features are observable at telemetry, logs, meter readings, the claimed deployment tier. synthetic traces. | |
| Reasoning and explanation paradigm | How is the decision produced and what explanation form can be inspected? | FRI, fuzzy inference, rule lists, decision trees, ensembles, deep models, autoencoders, federated learning, reinforcement learning, GAN-assisted testing, post hoc XAI. |
Identifies the expected explanation type, such as rule trace, membership degree, feature attribution, prototype, counterfactual, policy rationale, or model-health report. |
| Incomplete-information condition | Sparse rule coverage, rare or unseen class, missing or delayed What information is incomplete for label, partial observation, weak the decision being claimed? support region, open-set input, non-IID local evidence, unseen state. | Requires incomplete-information tests such as rule-coverage reporting, interpolation frequency, rare-family holdout, delayed-label evaluation, support-distance analysis, calibration, or abstention. | |
| Adversarial and failure assumption | None, natural drift, black-box evasion, gray-box evasion, What failure or attacker model is white-box evasion, poisoning, considered? model extraction, explanation manipulation, semantic perturbation. |
Robustness claims require attacker knowledge, objective, budget, domain constraints, recovery behavior, and explanation-integrity evidence [25]. | |
| Operational output and decision use | Class label, anomaly score, risk score, confidence, abstention, rule What does the IDS return to a trace, top-k feature reason, downstream user or process? counterfactual, response recommendation, update note, escalation flag. |
Determines whether the evaluation should measure classification quality only or also triage value, analyst usefulness, deployment cost, action safety, and governance traceability. |
|
Table 6.
Evidence streams across IDS contexts, associated information gaps, and validation risks.
| Evidence stream | Typical observables Information gap Validation risk | ||
|---|---|---|---|
| FRI and fuzzy rules | Explanations can expose Directly addresses incomplete rule neighboring rules and membership Fuzzy antecedents, membership coverage when no exact degrees, but validity depends on functions, sparse rule bases, antecedent–consequent rule rule semantics, coverage, distance interpolation distances, rule traces. matches the observed case. design, and interpolation sensitivity. |
||
| Traffic and SNMP-MIB evidence | Flow features, counters, rates, packet or session summaries, management-information variables. | Counter- or flow-level Provides semantically meaningful explanations can support triage, but partial infrastructure evidence, but evaluations must check feature often observable without full availability, manipulation risk, and payload visibility. false-alarm cost. |
|
| Phishing, web, and mobile evidence | URL, domain, certificate, content, redirection, application-behavior, and mobile telemetry features. | Represents incomplete campaign evidence because the detector often sees only a limited pre-click, pre-execution, or short-window view. |
Feature-level explanations may be analyst-readable, but leakage, family overfitting, chronology violations, and privacy constraints must be controlled. |
| IoT, edge, and botnet evidence | Device telemetry, local traffic windows, gateway aggregates, federated client partitions, lightweight anomaly scores. | Captures partial local observation under resource limits, heterogeneous devices, and non-IID client behavior. | Local proxy explanations should be distinguished from full attribution; evaluation must report device holdout, latency, energy, communication, and poisoning resistance. |
| Meter readings, process variables, Smart grid, OT, and cyber-physical control commands, topology evidence assumptions, safety constraints, physical consistency checks. |
Safety and availability requirements, limited instrumentation, and restricted public attack data constrain the information available to the detector. |
Explanations should connect cyber evidence to process plausibility; evaluation must avoid unsafe automation and oversimplified physical assumptions. | |
| Evasion, poisoning, Adversarial robustness and model-extraction, explanation explanation integrity manipulation, weak-support probing, semantic perturbations. |
Robustness claims require feasible Tests whether attackers can exploit attacker models, domain weakly supported regions of the constraints, degradation curves, evidence space. recovery behavior, and explanation-stability checks. |
||
| Streaming observations, delayed Adaptive learning and online rewards, drift indicators, response moving-target policies, analyst feedback, rollback state. |
Policy explanations must state Addresses gaps produced by reward logic and uncertainty; delayed labels, unseen states, and evaluation must include reward changing operating conditions. ablation, safety constraints, delayed feedback, and rollback. | ||
Table 8.
Deployment-tier allocation of information, functions, explanation, and control.
| Tier | Information available | Appropriate functions | Functions requiring qualification | Explanation / control output |
|---|---|---|---|---|
| Device | Local counters, health state, short telemetry windows, limited host or sensor view. | Sensing, lightweight thresholds, local sanity checks, event buffering, compact feature extraction. | Heavy post hoc XAI, global training, poisoning audits, long-horizon drift analysis, autonomous high-impact response. | Minimal event metadata, local state, threshold reason, confidence flag, and safe fallback state. |
| Gateway | Aggregated local traffic, device-group behavior, short-window statistics, local client evidence. | Windowing, aggregation, lightweight anomaly proxy, local drift indicator, coarse rule trace, escalation trigger. | Full SHAP or counterfactual analysis for every event, cross-site attribution, federated aggregation at high frequency, expensive audit routines. |
Local proxy reason, observed evidence summary, support warning confidence or abstention flag, and escalation packet. |
| Fog / site edge | Multi-device or site-level context, cached baselines, local rules, compact models, recent analyst feedback. | Local correlation, compact model inference, FRI or tree trace, cached explanation, site-specific support estimation, update staging. | Large-scale cross-site training, global poisoning analysis, irreversible response without approval. | Site-level rationale, interpolation or rule-coverage status, local support estimate, model-version note, and recommended escalation. |
| Cloud / SOC backend | Cross-site telemetry, historical data, federated updates, threat intelligence, analyst labels, long-term model records. | Global training, heavy attribution, counterfactual analysis, prototype comparison, federated aggregation, poisoning analysis, drift monitoring, benchmark replay. | Millisecond local control decisions, safety-critical autonomous containment without site context. |
Full explanation report, campaign context, model-health report, robustness and drift summary, update recommendation. |
| Analyst and governance | Model outputs plus business, mission, safety, legal, and incident-response context. | Triage, response approval, exception handling, feedback validation, rollback authorization, audit review. | Blind approval of opaque high-impact actions, untracked manual overrides, unmanaged feedback loops. | Human-readable rationale, action boundary, limitation statement, feedback record, audit trail, and rollback decision. |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.