{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T06:57:12Z","timestamp":1781765832094,"version":"3.54.5"},"reference-count":23,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,5,10]],"date-time":"2026-05-10T00:00:00Z","timestamp":1778371200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"},{"start":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T00:00:00Z","timestamp":1781740800000},"content-version":"vor","delay-in-days":39,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Discov Artif Intell"],"DOI":"10.1007\/s44163-026-01317-w","type":"journal-article","created":{"date-parts":[[2026,5,10]],"date-time":"2026-05-10T08:14:18Z","timestamp":1778400858000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["An explainable and latency-aware unified framework for hybrid graph cyberattack detection"],"prefix":"10.1007","volume":"6","author":[{"given":"Aniruddha","family":"Prabhu B.P.","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"N. R.","family":"Sunitha","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,5,10]]},"reference":[{"key":"1317_CR1","doi-asserted-by":"publisher","first-page":"1","DOI":"10.52783\/pmj.v35.i1s.2313","volume":"35","author":"BD Shendkar","year":"2025","unstructured":"Shendkar BD, Dhotre D, Hirve SA, Sontakke P, Hingoliwala H, Sambare GB. Explainable machine learning models for real time threat detection in cybersecurity. Panam Math J. 2025;35:1\u201318. https:\/\/doi.org\/10.52783\/pmj.v35.i1s.2313.","journal-title":"Panamerican Math J"},{"key":"1317_CR2","doi-asserted-by":"publisher","unstructured":"Moustafa N, Slay J UNSW-NB15: A comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In 2015 Military communications and information systems conference (MilCIS) (pp. 1\u20136). IEEE. (2015) https:\/\/doi.org\/10.1109\/MilCIS.2015.7348942","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"1317_CR3","doi-asserted-by":"publisher","DOI":"10.1080\/19393555.2015.1125974","author":"N Moustafa","year":"2016","unstructured":"Moustafa N, Slay J. The evaluation of network anomaly detection systems: statistical analysis of the UNSW-NB15 dataset and the comparison with the KDD99 dataset. Inf Secur J: Glob Perspect. 2016;25(1\u20133):18\u201331. https:\/\/doi.org\/10.1080\/19393555.2015.1125974"},{"key":"1317_CR4","doi-asserted-by":"publisher","first-page":"127","DOI":"10.1007\/978-3-319-59439-2_5","volume-title":"Data analytics and decision support for cybersecurity","author":"N Moustafa","year":"2017","unstructured":"Moustafa N, Creech G, Slay J. Big data analytics for intrusion detection system: statistical decision-making using finite Dirichlet mixture models. In: Palomares Carrascosa I, Kalutarage H, Huang Y, editors. Data analytics and decision support for cybersecurity. Cham: Springer; 2017. pp. 127\u201356. https:\/\/doi.org\/10.1007\/978-3-319-59439-2_5."},{"key":"1317_CR5","doi-asserted-by":"publisher","unstructured":"Sarhan M, Layeghy S, Moustafa N, Portmann M. NetFlow datasets for machine learning-based network intrusion detection systems. In: Deze Z, Huang H, Hou R, Rho S, Chilamkurti N, editors. Big data technologies and applications: BDTA WiCON 2020. Lecture notes of the institute for computer sciences, social informatics and telecommunications engineering. Volume 371. Cham: Springer; 2021. https:\/\/doi.org\/10.1007\/978-3-030-72802-1_9.","DOI":"10.1007\/978-3-030-72802-1_9"},{"issue":"4","key":"1317_CR6","doi-asserted-by":"publisher","first-page":"481","DOI":"10.1109\/TBDATA.2017.2715166","volume":"5","author":"N Moustafa","year":"2019","unstructured":"Moustafa N, Slay J, Creech G. Novel geometric area analysis technique for anomaly detection using trapezoidal area estimation on large-scale networks. IEEE Trans Big Data. 2019;5(4):481\u201394. https:\/\/doi.org\/10.1109\/TBDATA.2017.2715166.","journal-title":"IEEE Trans Big Data"},{"key":"1317_CR7","doi-asserted-by":"publisher","unstructured":"Wang M, Zheng K, Yang Y, Wang X. An explainable machine learning framework for intrusion detection systems. IEEE Access, 2020;8:73127\u201373141 https:\/\/doi.org\/10.1109\/ACCESS.2020.2988359","DOI":"10.1109\/ACCESS.2020.2988359"},{"key":"1317_CR8","doi-asserted-by":"publisher","first-page":"170","DOI":"10.3126\/nprcjmr.v1i9.74177","volume":"1","author":"D Adhikari","year":"2024","unstructured":"Adhikari D, Thapaliya S, Explainable. AI for cyber security: interpretable models for malware analysis and network intrusion detection. NPRC J Multidiscip Res. 2024;1:170\u20139. https:\/\/doi.org\/10.3126\/nprcjmr.v1i9.74177.","journal-title":"NPRC J Multidisciplinary Res"},{"key":"1317_CR9","doi-asserted-by":"publisher","unstructured":"Ouhssini M, Afdel K, Akouhar M, Agherrabi E, Abarda A. Interpretable deep learning for DDoS Defense: A SHAP-based Approach in cloud computing. In: 2024 International conference on circuit, systems and communication (ICCSC) . 2024, pp. 1\u20138. https:\/\/doi.org\/10.1109\/ICCSC62074.2024.10616654.","DOI":"10.1109\/ICCSC62074.2024.10616654"},{"key":"1317_CR10","doi-asserted-by":"publisher","first-page":"101092","DOI":"10.1016\/j.iot.2024.101092","volume":"25","author":"S Bahadoripour","year":"2024","unstructured":"Bahadoripour S, Karimipour H, Jahromi AN, Islam A. An explainable multi-modal model for advanced cyber-attack detection in industrial control systems. Internet Things. 2024;25:101092. https:\/\/doi.org\/10.1016\/j.iot.2024.101092.","journal-title":"Internet Things"},{"key":"1317_CR11","doi-asserted-by":"publisher","first-page":"150","DOI":"10.1186\/s13677-024-00712-x","volume":"13","author":"U Ahmed","year":"2024","unstructured":"Ahmed U, Jiangbin Z, Almogren A, et al. Explainable AI-based innovative hybrid ensemble model for intrusion detection. J Cloud Comput. 2024;13:150. https:\/\/doi.org\/10.1186\/s13677-024-00712-x.","journal-title":"J Cloud Comput"},{"key":"1317_CR12","doi-asserted-by":"publisher","first-page":"126","DOI":"10.3390\/bdcc6040126","volume":"6","author":"R Younisse","year":"2022","unstructured":"Younisse R, Ahmad A, Abu Al-Haija Q. Explaining intrusion detection\u2013based convolutional neural networks using Shapley additive explanations (SHAP). Big Data Cogn Comput. 2022;6:126. https:\/\/doi.org\/10.3390\/bdcc6040126.","journal-title":"Big Data Cogn Comput"},{"key":"1317_CR13","doi-asserted-by":"publisher","unstructured":"Uysal I, Kose U. Analysis of network intrusion detection via explainable artificial intelligence: applications with SHAP and LIME, cyber awareness and research symposium (CARS), Grand Forks, ND, USA, 2024, pp. 1\u20136. https:\/\/doi.org\/10.1109\/CARS61786.2024.10778742","DOI":"10.1109\/CARS61786.2024.10778742"},{"key":"1317_CR14","doi-asserted-by":"publisher","first-page":"197","DOI":"10.1007\/s44230-023-00032-4","volume":"3","author":"A Bogdanova","year":"2023","unstructured":"Bogdanova A, Imakura A, Sakurai T. DC SHAP method for consistent explainability in privacy preserving distributed machine learning. Hum Centric Intell Syst. 2023;3:197\u2013210. https:\/\/doi.org\/10.1007\/s44230-023-00032-4.","journal-title":"Hum Centric Intell Syst"},{"key":"1317_CR15","doi-asserted-by":"publisher","first-page":"3227","DOI":"10.1007\/s10618-022-00870-z","volume":"38","author":"L Veyrin-Forrer","year":"2024","unstructured":"Veyrin-Forrer L, Kamal A, Duffner S, et al. On GNN explainability with activation rules. Data Min Knowl Disc. 2024;38:3227\u201361. https:\/\/doi.org\/10.1007\/s10618-022-00870-z.","journal-title":"Data Min Knowl Disc"},{"key":"1317_CR16","doi-asserted-by":"publisher","unstructured":"Finelli F, Oma\u00f1a M, Metra C. Impact of soft errors on high performance autoencoders for cyberattack detection. In: 2022 IEEE 23rd Latin American test symposium (LATS), 2022, pp. 1\u20136 . https:\/\/doi.org\/10.1109\/LATS57337.2022.9936956","DOI":"10.1109\/LATS57337.2022.9936956"},{"key":"1317_CR17","doi-asserted-by":"publisher","first-page":"115736","DOI":"10.1016\/j.eswa.2021.115736","volume":"186","author":"L Antwarg","year":"2021","unstructured":"Antwarg L, Miller RM, Shapira B, Rokach L. Explaining anomalies detected by autoencoders using Shapley additive explanations. Expert Syst Appl. 2021;186:115736. https:\/\/doi.org\/10.1016\/j.eswa.2021.115736.","journal-title":"Expert Syst Appl"},{"key":"1317_CR18","doi-asserted-by":"publisher","first-page":"7632","DOI":"10.1038\/s41598-025-90420-6","volume":"15","author":"M Saied","year":"2025","unstructured":"Saied M, Guirguis S(. Explainable artificial intelligence for botnet detection in internet of things. Sci Rep. 2025;15:7632. https:\/\/doi.org\/10.1038\/s41598-025-90420-6.","journal-title":"Sci Rep"},{"key":"1317_CR19","doi-asserted-by":"publisher","unstructured":"Shukla A, Dubey S, Nithya P, Shankar B, Vankayalapati RK, Khatana K. Edge-optimized and explainable deep learning framework for real-time intrusion detection in industrial IoT. In: Proc. 3rd International conference on optimization techniques in the field of engineering (ICOFE-2024). 2024. https:\/\/doi.org\/10.2139\/ssrn.5077557","DOI":"10.2139\/ssrn.5077557"},{"key":"1317_CR20","doi-asserted-by":"publisher","unstructured":"Ghazal TM, Janjua JI, Abushiba W, Ahmad M, Ihsan A, Al-Dmour NA. Cybersecurity revolution via large language models and explainable AI. In: 2024 17th International conference on security of information and networks (SIN), 2024, pp. 1\u20136. https:\/\/doi.org\/10.1109\/SIN63213.2024.10871324","DOI":"10.1109\/SIN63213.2024.10871324"},{"key":"1317_CR21","doi-asserted-by":"publisher","unstructured":"Prabha M, Hossain MA, Samiun M, Saleh MA, Dhar SR, Al Mahmud MA. (2024). AI-driven cyber threat detection: revolutionizing security frameworks in management information systems, In: 2024 International conference on intelligent cybernetics technology & applications (ICICyTA), Bali, Indonesia, 2024, pp. 357\u2013362. https:\/\/doi.org\/10.1109\/ICICYTA64807.2024.10912927","DOI":"10.1109\/ICICYTA64807.2024.10912927"},{"key":"1317_CR22","doi-asserted-by":"publisher","unstructured":"Bulgakova EV, Vasilevskiy PA, Doynikov DS, Kubankov AN. Analysis of explainable artificial intelligence methods in SIEM systems. In: 2025 Systems of signals generating and processing in the field of on board communications, 2025, 1\u20135. https:\/\/doi.org\/10.1109\/IEEECONF64229.2025.10948089","DOI":"10.1109\/IEEECONF64229.2025.10948089"},{"key":"1317_CR23","doi-asserted-by":"publisher","unstructured":"Singh VK, Mohankumar P, Kamal A. Cyber threat detection by leveraging contextual and semantic knowledge. In: International conference on data-processing and networking. Springer Nature Singapore. 2024. https:\/\/doi.org\/10.1007\/978-981-96-3102-5_27","DOI":"10.1007\/978-981-96-3102-5_27"}],"container-title":["Discover Artificial Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s44163-026-01317-w","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s44163-026-01317-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s44163-026-01317-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T06:34:47Z","timestamp":1781764487000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s44163-026-01317-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,10]]},"references-count":23,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["1317"],"URL":"https:\/\/doi.org\/10.1007\/s44163-026-01317-w","relation":{"references":[{"id-type":"doi","id":"10.1080\/19393555.2015.1125974","asserted-by":"subject"}]},"ISSN":["2731-0809"],"issn-type":[{"value":"2731-0809","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,10]]},"assertion":[{"value":"7 November 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 April 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 May 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"557"}}