Explainable Transformer- zero day based Intrusion Detection Systems: A Comprehensive Research Framework
Contributors
Dr Sanjith Sathya Joseph
Dr S K Manju Bargavi
Keywords
Proceeding
Track
General Track
License
Copyright (c) 2026 Sustainable Global Societies Initiative

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Abstract
The main aim of the proposed research is to design the innovative architecture of IDS based on Hierarchical Transformer with Explainability (HT-IDS-XAI) to address the significant limitations of the previous research work concerning the application of Transformer IDS. Our solution is based on the use of three types of hierarchical encoders (on packet-level, flow-level, session-level) as well as the development of attention fusion for multi-scale recognition of the patterns. In order to address the problem of black-box nature of deep learning in the security-sensitive domain, the combination of four different explainability techniques was proposed: SHAP, LIME, Attention Visualization and Grad-CAM to be integrated into one Explainability Dashboard which enables the analyst to verify the outcome. Additionally, our solution will include a step of human-in-the-loop feedback to increase the model's effectiveness (in particular, to decrease the false alarm rate (FAR) by 35-45%). We are going to evaluate our approach using five benchmark datasets (CICIDS2017, CSE-CIC-IDS2018, TON_IoT, NF-UQ-NIDS and Edge-IIoTset) including 22M+ data entries and 49 attacks and we are aiming at achieving the accuracy improvement of 15-25% from the eight baselines while maintaining the real-time inference speed below 50ms.