LLM-Based Explainable Intrusion Detection System for IoT Networks
2026 International Conference on Smart Applications, Communications and Networking, SmartNets 2026, Rome, İtalya, 7 - 09 Temmuz 2026, (Tam Metin Bildiri)
- Yayın Türü: Bildiri / Tam Metin Bildiri
- Doi Numarası: 10.1109/smartnets69662.2026.11604781
- Basıldığı Şehir: Rome
- Basıldığı Ülke: İtalya
- Anahtar Kelimeler: Explainable Artificial, Fine-Tuning, Intelligence (XAI), Internet of Things (IoT, Intrusion Detection System (IDS), Large Language Models (LLMs)
- Hacettepe Üniversitesi Adresli: Evet
Özet
The rapid proliferation of the Internet of Things (IoT) has increased network complexity and exposed IoT infrastructures to diverse and evolving cyber threats. Traditional intrusion detection systems (IDSs), whether signature based or machine learning based, often struggle to adapt to emerging attack patterns and frequently operate as 'black boxes' with limited interpretability. To address these challenges, this paper proposes a novel Large Language Model-based Explainable IDS for IoT networks. The system fine-tunes an open-source large language model, LLaMA 3.3, to jointly perform intrusion detection and natural-language explanation generation. The model is trained on multiple IoT security datasets, namely CIC-IoT-2023 [1], BoT-IoT [2], and ToN-IoT [3] to recognize various attack types, including distributed denial-of-service (DDoS), botnet activity, man-in-the-middle (MITM), and data exfiltration. Experimental results show that the fine-tuned LLM outperforms both zero-shot LLM baselines and traditional machine learning classifiers, achieving competitive accuracy while delivering concise, human-readable explanations for each prediction. By integrating detection and explainability within a single model, the proposed framework enhances transparency, interpretability, and usability.