Volume 10 • Issue 2 • PP: 01–07 • 2025
An Explainable AI-Driven Zero-Day Attack Detection Framework for Securing Edge Devices in Smart Cities
Open Access & Copyright
© 2025 The Author(s). Published by ASPG. This article is licensed under the Creative Commons Attribution 4.0 International License (CC BY 4.0).
Abstract
The rapid proliferation of edge computing in smart cities has enhanced real-time data processing capabilities, but it has also exposed critical vulnerabilities to sophisticated cyber threats such as zero-day attacks. Traditional signature-based intrusion detection systems often fail to identify these previously unknown threats due to their lack of adaptive intelligence and interpretability. This research proposes an Explainable Artificial Intelligence (XAI)-driven zero-day attack detection framework tailored for edge devices deployed in smart city environments. The proposed system combines deep anomaly detection using a hybrid Convolutional Neural Network–Long Short-Term Memory (CNN–LSTM) model with SHAP (SHapley Additive exPlanations)-based interpretability to detect and explain anomalous behaviors in real-time network traffic. The model is trained on diverse datasets mimicking heterogeneous edge devices in smart infrastructures, ensuring robustness and scalability. Experimental results demonstrate high detection accuracy, low false-positive rates, and strong resilience against unseen attack patterns. Moreover, the integration of XAI components provides actionable insights to administrators, thereby enhancing trust, transparency, and decision-making in cybersecurity operations. This framework marks a significant step toward proactive and explainable security solutions for safeguarding smart urban ecosystems.
Keywords
References
[1] M. S. Kiruthika and R. Manjula, “Edge computing in smart cities: A comprehensive survey,” J. Netw. Comput. Appl., vol. 179, p. 102983, 2021.
[2] M. A. Khan, M. H. Rehmani, and A. Rachedi, “When smart cities meet edge computing: Challenges and future directions,” IEEE Commun. Mag., vol. 56, no. 10, pp. 110–117, Oct. 2018.
[3] Y. Liu et al., “Zero-day attacks detection based on deep learning and dynamic behavior analysis,” IEEE Access, vol. 7, pp. 12092–12103, 2019.
[4] F. A. Gers, J. Schmidhuber, and F. Cummins, “Learning to forget: Continual prediction with LSTM,” Neural Comput., vol. 12, no. 10, pp. 2451–2471, 2000.
[5] Goodfellow, Y. Bengio, and A. Courville, Deep Learning. MIT Press, 2016.
[6] R. Shapira and Y. Goldberg, “A survey of explainable AI techniques in NLP,” arXiv preprint arXiv: 2108.08824, 2021.
[7] S. M. Lundberg and S.-I. Lee, “A unified approach to interpreting model predictions,” in Proc. 31st Int. Conf. Neural Inf. Process. Syst. (NeurIPS), 2017, pp. 4765–4774.
[8] R. Kumar and A. Singh, “Anomaly detection in smart cities using LSTM-based deep learning models,” Int. J. Inf. Manag. Data Insights, vol. 1, no. 2, p. 100021, 2021.
[9] L. Zhang et al., “Explainable deep learning models in cybersecurity,” Future Gener. Comput. Syst., vol. 136, pp. 27–39, 2022.
[10] Roy et al., “A hybrid CNN-LSTM model for detecting anomalies in network traffic,” Comput. Commun., vol. 184, pp. 42–52, 2022.
[11] S. S., S. S., and U. M. R., “Soft computing based brain tumor categorization with machine learning techniques,” in Proc. 2022 Int. Conf. Adv. Comput. Technol. Appl. (ICACTA), Coimbatore, India, 2022, pp. 1–9, doi: 10.1109/ICACTA54488.2022.9752880.
[12] Kumar, R. K. Gupta, and M. K. Gupta, “Deep learning-based image classification for medical diagnosis,” J. Med. Syst., vol. 45, no. 4, pp. 1–10, 2021, doi: 10.1007/s10916-021-01785-4.
[13] U. M. Rajendran and J. Paulchamy, “Analysis and classification of gait characteristics,” Iconic Research and Engineering Journals, vol. 4, no. 12, 2021.
[14] B. Paulchamy, S. Chidambaram, J. Jaya, and R. U. Maheshwari, “Diagnosis of retinal disease using retinal blood vessel extraction,” in Int. Conf. Mobile Comput. Sustainable Informatics (ICMCSI 2020), Springer, 2021, pp. 343–359.
[15] B. Thiyaneswaran et al., “Environmental pollution and weather data monitoring using LoRa low power VLSI solution,” in Proc. 9th Int. Conf. Sci. Technol. Eng. Math. (ICONSTEM), 2024, doi: 10.1109/ICONSTEM60960.2024.10568664.
[16] D. S. S. Raja et al., “A compact dual-feed wide-band slotted antenna for future wireless applications,” Analog Integr. Circuits Signal Process., vol. 118, pp. 291–305, 2024, doi: 10.1007/s10470-023-02233-0.
[17] B. Yan and Y. Hao, “A lightweight CNN model with explainability for edge-enabled cybersecurity,” Sensors, vol. 21, no. 13, p. 4382, 2021.
[18] H. Wang et al., “An explainable deep learning framework for intrusion detection in IoT networks,” IEEE Access, vol. 9, pp. 146940–146950, 2021.
[19] S. Vinayakumar, K. P. Soman, and P. Poornachandran, “Evaluating deep learning approaches to intrusion detection system,” Procedia Comput. Sci., vol. 132, pp. 195–203, 2018.
[20] H. Zhong, Y. Liu, and M. Yu, “Federated learning meets explainability: A survey,” arXiv preprint arXiv: 2201.12161, 2022.
Cite This Article
Choose your preferred format
Publisher's Note
The statements, opinions, and data presented in this article are solely those of the author(s) and do not necessarily represent those of ASPG, the journal, or its editors. ASPG and the editors disclaim responsibility for any harm arising from the use of any ideas, methods, instructions, or products described in this article, to the fullest extent permitted by applicable law.