XBiLD-IDS: toward an explainable hybrid BiLSTM-DNN architecture for trustworthy intrusion detection in IoMT networks
Abstract
The increasing sophistication of cyber threats demands advanced and transparent intrusion detection systems (IDS) for the Internet of Medical Things (IoMT). While deep learning has enhanced IDS performance in handling complex data, its black box nature and lack of interpretability undermine trust, accountability, and forensic analysis in critical healthcare environments. This paper proposes XBiLD-IDS, a novel explainable IDS framework designed specifically for IoMT networks. It introduces a transparent feature selection mechanism that integrates SHapley Additive exPlanations (SHAP) with human expertise, enabling interpretable and reliable model insights. This explainable layer is embedded within a hybrid deep learning model that integrates bidirectional long short-term memory (BiLSTM) network with a deep neural network (DNN), which effectively captures temporal dependencies and high-level feature interactions. By quantifying each features contribution to model predictions, our XBiLD-IDS allows experts to refine the feature space for both efficiency and interpretability. Evaluation on the CICIoMT2024 dataset demonstrates the framework’s robustness, achieving 98.70% accuracy, 99.04% precision, 98.78% recall, and 98.69% F1-score. These results establish XBiLD-IDS as a trustworthy, high-performing paradigm that reconciles accuracy with transparency by maintaining high performance across the majority of attack classes while ensuring explainability, thereby empowering security analysts with actionable, transparent threat intelligence for resilient IoMT operations.
Similar content being viewed by others
Data availability
No datasets were generated or analyzed during the current study.
References
Burke W, Stranieri A, Oseni T, Gondal I (2024) The need for cybersecurity self-evaluation in healthcare. BMC Med Inform Decis Mak 24(1):133. https://doi.org/10.1186/s12911-024-02551-x
Razaque A, Amsaad F, Khan MJ, Hariri S, Chen S, Siting C, Ji X (2019) Survey: cybersecurity vulnerabilities, attacks and solutions in the medical domain. IEEE Access 7:168774–168797. https://doi.org/10.1109/ACCESS.2019.2950849
Alhaj TA, Abdulla SM, Iderss MAE, Ali AAA, Elhaj FA, Remli MA, Gabralla LA (2022) A survey: to govern, protect, and detect security principles on Internet of Medical Things (IoMT). IEEE Access 10:124777–124791. https://doi.org/10.1109/ACCESS.2022.3225038
Mahmood-Ur-Rahaman S, Sudheer S (2025) Analyzing the efficiency of hybrid explainable ai models for feature extraction and pattern recognition in high-dimensional data mining tasks. Int J Innov Sci Res Technol. https://doi.org/10.38124/ijisrt/25jul1197
Gupta M, Kumar M, Dhir R (2025) FedMed-XAI: a collaborative and trustworthy framework for skin cancer detection using federated learning and explainable AI. J Supercomput 81(15):1–44. https://doi.org/10.1007/s11227-025-07941-0
Neupane S, Ables J, Anderson W, Mittal S, Rahimi S, Banicescu I, Seale M (2022) Explainable intrusion detection systems (x-ids): a survey of current methods, challenges, and opportunities. IEEE Access 10:112392–112415. https://doi.org/10.1109/ACCESS.2022.3216617
Samek W, Wiegand T, MĂĽller KR (2019) Explainable artificial intelligence: understanding, visualizing and interpreting deep learning models
Alaa M (2021) Artificial intelligence: explainability, ethical issues and bias. https://doi.org/10.17352/ara.000011
Vale D, El-Sharif A, Ali M (2022) Explainable artificial intelligence (XAI) post-hoc explainability methods: risks and limitations in non-discrimination law. AI Ethics 2(4):815–826. https://doi.org/10.1007/s43681-022-00142-y
Meske C, Bunde E (2020) Transparency and trust in human-ai-interaction: the role of model-agnostic explanations in computer vision-based decision support. In: Degen, H., Reinerman-Jones, L. (eds.) Artificial Intelligence in HCI. HCII 2020. Lecture notes in computer science, vol 12217. Springer, Cham. https://doi.org/10.1007/978-3-030-50334-5_4
Thalpage N (2013) Unlocking the black box: explainable artificial intelligence (XAI) for trust and transparency in AI systems. J Digit Art Humanit 4(1):31–36. https://doi.org/10.33847/2712-8148.4.1_4
Hassija V, Chamola V, Mahapatra A, Singal A, Goel D, Huang K, Hussain A (2024) Interpreting black-box models: a review on explainable artificial intelligence. Cogn Comput 16(1):45–74. https://doi.org/10.1007/s12559-023-10179-8
Shand C, Fong R, Butt U (2024) How explainable artificial intelligence (XAI) models can be used within intrusion detection systems (ids) to enhance an analyst’s trust and understanding. In: Jahankhani, H. (ed.) Cybersecurity Challenges in the Age of AI, Space Communications and Cyborgs. ICGS3 2023. Advanced sciences and technologies for security applications. Springer, Cham. https://doi.org/10.1007/978-3-031-47594-8_17
Ribeiro MT, Singh S, Guestrin C (2016) "why should i trust you?" explaining the predictions of any classifier. In: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp 1135–1144. https://doi.org/10.1145/2939672.2939778
Lundberg SM, Lee SI (2017) A unified approach to interpreting model predictions. Adv Neural Inf Process Syst 30. https://github.com/slundberg/shap
Iqbal A, Amin R (2025) An efficient mechanism for time series forecasting and anomaly detection using explainable artificial intelligence. J Supercomput 81(4):523. https://doi.org/10.1007/s11227-025-07040-0
Kruschel S, Hambauer N, Weinzierl S, Zilker S, Kraus M, Zschech P (2025) Challenging the performance-interpretability trade-off: an evaluation of interpretable machine learning models. Bus Inf Syst Eng 68(1):159–183. https://doi.org/10.1007/s12599-024-00922-2
Ahmed U, Jiangbin Z, Almogren A, Sadiq M, Rehman AU, Sadiq MT, Choi J (2024) Hybrid bagging and boosting with shap based feature selection for enhanced predictive modeling in intrusion detection systems. Sci Rep 14(1):30532. https://doi.org/10.1038/s41598-024-81151-1
Roy K, Farid DM (2024) An adaptive feature selection algorithm for student performance prediction. IEEE Access 12:75577–75598. https://doi.org/10.1109/ACCESS.2024.3406252
Gebreyesus Y, Dalton D, Nixon S, De Chiara D, Chinnici M (2023) Machine learning for data center optimizations: feature selection using shapley additive explanation (shap). Future Internet 15(3):88. https://doi.org/10.3390/fi15030088
Ren K, Zeng Y, Zhong Y, Sheng B, Zhang Y (2023) MAFSIDS: a reinforcement learning-based intrusion detection model for multi-agent feature selection networks. J Big Data 10(1):137. https://doi.org/10.1186/s40537-023-00814-4
Shafin SS (2025) An explainable feature selection framework for web phishing detection with machine learning. Data Sci Manag 8(2):127–136. https://doi.org/10.1016/j.dsm.2024.08.004
Van Lent M, Fisher W, Mancuso M (2004) An explainable artificial intelligence system for small-unit tactical behavior. Proceedings of the National Conference on Artificial Intelligence. AAAI Press, Menlo Park, pp 900–907
Bonvillian WB, Van Atta R (2011) ARPA-E and DARPA: applying the DARPA model to energy innovation. J Technol Transf 36(5):469–513. https://doi.org/10.1007/s10961-011-9223-x
Arrieta AB, DĂaz-RodrĂguez N, Del Ser J, Bennetot A, Tabik S, Barbado A, Herrera F (2020) Explainable artificial intelligence (XAI): concepts, taxonomies, opportunities and challenges toward responsible AI. Inf Fusion 58:82–115
Guidotti R, Monreale A, Ruggieri S, Turini F, Giannotti F, Pedreschi D (2018) A survey of methods for explaining black box models. ACM Comput Surv 51(5):1–42. https://doi.org/10.1145/3236009
Aleksandra N, Bojana J, Maryan R, Dimitar T (2025) Evaluating trustworthiness in ai: risks, metrics, and applications across industries. Electronics 14(13):2717. https://doi.org/10.3390/electronics14132717
Chinnaraju A (2025) Explainable AI (XAI) for trustworthy and transparent decision-making: a theoretical framework for ai interpretability. World J Adv Eng Technol Sci 14(3):170–207. https://doi.org/10.30574/wjaets.2025.14.3.0106
Danesh T, Ouaret R, Floquet P, Negny S (2023) Hybridization of model-specific and model-agnostic methods for interpretability of neural network predictions: application to a power plant. Comput Chem Eng 176:108306. https://doi.org/10.1016/j.compchemeng.2023.108306
Madsen A, Lakkaraju H, Reddy S, Chandar S (2024) Interpretability needs a new paradigm. https://doi.org/10.48550/arXiv.2405.05386
Van Zyl C, Ye X, Naidoo R (2024) Harnessing explainable artificial intelligence for feature selection in time series energy forecasting: a comparative analysis of Grad-CAM and SHAP. Appl Energy 353:122079. https://doi.org/10.1016/j.apenergy.2023.122079
Zacharias J, Zahn M, Chen J, Hinz O (2022) Designing a feature selection method based on explainable artificial intelligence. Electron Mark 32(4):2159–2184. https://doi.org/10.1007/s12525-022-00608-1
Ahadzadeh B, Abdar M, Safara F, Khosravi A, Menhaj MB, Suganthan PN (2023) SFE: a simple, fast, and efficient feature selection algorithm for high-dimensional data. IEEE Trans Evol Comput 27(6):1896–1911. https://doi.org/10.1109/TEVC.2023.3238420
Lei C, Liu C, Zhang Y, Cheng J, Zhao R (2025) Comparisons of filter, wrapper, and embedded feature selection for rockfall susceptibility prediction and mapping. Nat Hazards 121(2):1911–1943. https://doi.org/10.1007/s11069-024-06878-6
Ewees AA, Alshahrani MM, Alharthi AM, Gaheen MA (2025) Optimizing feature selection and remote sensing classification with an enhanced machine learning method. J Supercomput 81(2):370. https://doi.org/10.1007/s11227-024-06790-7
Lima HC, Otero FE, Merschmann LH, Souza MJ (2021) A novel hybrid feature selection algorithm for hierarchical classification. IEEE Access 9:127278–127292. https://doi.org/10.1109/ACCESS.2021.3112396
Araya-Martinez JM, Tom T, Sardari S, Reig AS, Mohan G, Shukla A, Krüger J (2025) Domain adaptation using vision transformers and XAI for fully synthetic industrial training. Procedia CIRP 136:904–909. https://doi.org/10.1016/j.procir.2025.08.154
Wang M, Zheng K, Yang Y, Wang X (2020) An explainable machine learning framework for intrusion detection systems. IEEE Access 8:73127–73141. https://doi.org/10.1109/ACCESS.2020.2988359
Rabbi F, Hossain NUI, Das S (2025) A comparative analysis of machine learning techniques for detecting probing attack with SHAP algorithm. Expert Syst Appl 271:126718. https://doi.org/10.1016/j.eswa.2025.126718
Ullah I, Rios A, Gala V, Mckeever S (2021) Explaining deep learning models for tabular data using layer-wise relevance propagation. Appl Sci 12(1):136. https://doi.org/10.3390/app12010136
Savanovic N, Bozovic A, Antonijevic M, Kvascev G, Nikolic B, Venkatachalam K, Zivkovic M (2025) Hybrid CNN-XGBoost intrusion detection approach tuned by modified sine cosine algorithm towards better cloud security. Connect Sci 37(1):2549581. https://doi.org/10.1080/09540091.2025.2549581
Sivamohan S, Sridhar SS, Krishnaveni S (2023) TEA-EKHO-IDS: an intrusion detection system for industrial cps with trustworthy explainable AI and enhanced krill herd optimization. Peer-to-Peer Netw Appl 16(4):1993–2021. https://doi.org/10.1007/s12083-023-01507-8
Amudha M, Brindha K (2024) Effective feature selection based HOBS pruned-ELM model for tomato plant leaf disease classification. PLoS ONE 19(12):0315031. https://doi.org/10.1371/journal.pone.0315031
Si-ahmed A, Al-Garadi MA, Boustia N (2024) Explainable machine learning-based security and privacy protection framework for Internet of Medical Things systems. https://arxiv.org/abs/2403.09752
Bhardwaj T, Sumangali K (2025) An explainable federated blockchain framework with privacy-preserving ai optimization for securing healthcare data. Sci Rep 15(1):21799. https://doi.org/10.1038/s41598-025-04083-4
Dadkhah S, Neto ECP, Ferreira R, Molokwu RC, Sadeghi S, Ghorbani AA (2024) CICIoMT2024: a benchmark dataset for multi-protocol security assessment in IoMT. Internet Things 28:101351. https://doi.org/10.1016/j.iot.2024.101351
Benahmed H, M’Hamedi M, Merzoug M, Hadjila M, Bekkouche A, Etchiali A, Mahmoudi S (2025) HBiLD-IDS: an efficient hybrid BiLSTM-DNN model for real-time intrusion detection in IoMT networks. Information 16(8):669. https://doi.org/10.3390/info16080669
Tany NS, Suresh S, Sinha DN, Shinde C, Stolojescu-Crisan C, Khondoker R (2022) Cybersecurity comparison of brain-based automotive electrical and electronic architectures. Information 13(11):518. https://doi.org/10.3390/info13110518
Shaikh JA, Wang C, Us Sima MW, Arshad M, Owais M, Hassan DSM, Muthanna MSA (2025) A deep reinforcement learning-based robust intrusion detection system for securing IoMT healthcare networks. Front Med 12:1524286. https://doi.org/10.3389/fmed.2025.1524286
Sharma N, Shambharkar PG (2025) Multi-attention DeepCRNN: an efficient and explainable intrusion detection framework for Internet of Medical Things environments. Knowl Inf Syst 67(7):5783–5849. https://doi.org/10.1007/s10115-025-02402-9
Berrezzek A, Djellali H, Mallardi G, Mahnane L (2026) Explainable hybrid feature selection for intrusion detection in Internet of Medical Things environments
Alabbadi A, Bajaber F (2025) X-fuserlstm: a cross-domain explainable intrusion detection framework in IoT using the attention-guided dual-path feature fusion and residual LSTM. Sensors 25(12):3693. https://doi.org/10.3390/s25123693
Author information
Authors and Affiliations
Contributions
Conceptualization: H.B., M.H., Z.K.; methodology: H.B., M.M. (Mohammed M’hamedi), M.M. (Mohammed Merzoug); software: H.B.; validation: M.H., Z.K., H.B, S.M.; formal analysis: H.B, M.M. (Mohammed M’hamedi), A.B.; investigation: H.B, M.M. (Mo-hammed M’hamedi), Z.K., M.H., S.M.; writing: H.B., M.M. (Mohammed M’hamedi), M.M. (Mohammed Merzoug), M.H., Z.K., S.M., A.B.; visualization: H.B.; supervision: M.M. (Mohammed Merzoug), A.B., M.H., S.M.; project administration: M.M. (Mohammed Merzoug); funding acquisition: S.M., M.M. (Mohammed Merzoug). All authors have read and agreed to the published version of the manuscript.
Corresponding authors
Ethics declarations
Conflict of interest
The authors declare no conflict of interest.
Additional information
Publisher's Note
Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.
Rights and permissions
Springer Nature or its licensor (e.g. a society or other partner) holds exclusive rights to this article under a publishing agreement with the author(s) or other rightsholder(s); author self-archiving of the accepted manuscript version of this article is solely governed by the terms of such publishing agreement and applicable law.
About this article
Cite this article
Benahmed, H., Merzoug, M., Koudad, Z. et al. XBiLD-IDS: toward an explainable hybrid BiLSTM-DNN architecture for trustworthy intrusion detection in IoMT networks. J Supercomput 82, 703 (2026). https://doi.org/10.1007/s11227-026-08855-1
Received:
Accepted:
Published:
Version of record:
DOI: https://doi.org/10.1007/s11227-026-08855-1
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.