Abstract
The increasing sophistication of cyber threats demands advanced and transparent intrusion detection systems (IDS) for the Internet of Medical Things (IoMT). While deep learning has enhanced IDS performance in handling complex data, its black box nature and lack of interpretability undermine trust, accountability, and forensic analysis in critical healthcare environments. This paper proposes XBiLD-IDS, a novel explainable IDS framework designed specifically for IoMT networks. It introduces a transparent feature selection mechanism that integrates SHapley Additive exPlanations (SHAP) with human expertise, enabling interpretable and reliable model insights. This explainable layer is embedded within a hybrid deep learning model that integrates bidirectional long short-term memory (BiLSTM) network with a deep neural network (DNN), which effectively captures temporal dependencies and high-level feature interactions. By quantifying each features contribution to model predictions, our XBiLD-IDS allows experts to refine the feature space for both efficiency and interpretability. Evaluation on the CICIoMT2024 dataset demonstrates the framework’s robustness, achieving 98.70% accuracy, 99.04% precision, 98.78% recall, and 98.69% F1-score. These results establish XBiLD-IDS as a trustworthy, high-performing paradigm that reconciles accuracy with transparency by maintaining high performance across the majority of attack classes while ensuring explainability, thereby empowering security analysts with actionable, transparent threat intelligence for resilient IoMT operations.
Similar content being viewed by others
Data availability
No datasets were generated or analyzed during the current study.
References
Burke W, Stranieri A, Oseni T, Gondal I (2024) The need for cybersecurity self-evaluation in healthcare. BMC Med Inform Decis Mak 24(1):133. https://doi.org/10.1186/s12911-024-02551-x
Razaque A, Amsaad F, Khan MJ, Hariri S, Chen S, Siting C, Ji X (2019) Survey: cybersecurity vulnerabilities, attacks and solutions in the medical domain. IEEE Access 7:168774–168797. https://doi.org/10.1109/ACCESS.2019.2950849
Alhaj TA, Abdulla SM, Iderss MAE, Ali AAA, Elhaj FA, Remli MA, Gabralla LA (2022) A survey: to govern, protect, and detect security principles on Internet of Medical Things (IoMT). IEEE Access 10:124777–124791. https://doi.org/10.1109/ACCESS.2022.3225038
Mahmood-Ur-Rahaman S, Sudheer S (2025) Analyzing the efficiency of hybrid explainable ai models for feature extraction and pattern recognition in high-dimensional data mining tasks. Int J Innov Sci Res Technol. https://doi.org/10.38124/ijisrt/25jul1197
Gupta M, Kumar M, Dhir R (2025) FedMed-XAI: a collaborative and trustworthy framework for skin cancer detection using federated learning and explainable AI. J Supercomput 81(15):1–44. https://doi.org/10.1007/s11227-025-07941-0
Neupane S, Ables J, Anderson W, Mittal S, Rahimi S, Banicescu I, Seale M (2022) Explainable intrusion detection systems (x-ids): a survey of current methods, challenges, and opportunities. IEEE Access 10:112392–112415. https://doi.org/10.1109/ACCESS.2022.3216617
Samek W, Wiegand T, Müller KR (2019) Explainable artificial intelligence: understanding, visualizing and interpreting deep learning models
Alaa M (2021) Artificial intelligence: explainability, ethical issues and bias. https://doi.org/10.17352/ara.000011
Vale D, El-Sharif A, Ali M (2022) Explainable artificial intelligence (XAI) post-hoc explainability methods: risks and limitations in non-discrimination law. AI Ethics 2(4):815–826. https://doi.org/10.1007/s43681-022-00142-y
Meske C, Bunde E (2020) Transparency and trust in human-ai-interaction: the role of model-agnostic explanations in computer vision-based decision support. In: Degen, H., Reinerman-Jones, L. (eds.) Artificial Intelligence in HCI. HCII 2020. Lecture notes in computer science, vol 12217. Springer, Cham. https://doi.org/10.1007/978-3-030-50334-5_4
Thalpage N (2013) Unlocking the black box: explainable artificial intelligence (XAI) for trust and transparency in AI systems. J Digit Art Humanit 4(1):31–36. https://doi.org/10.33847/2712-8148.4.1_4
Hassija V, Chamola V, Mahapatra A, Singal A, Goel D, Huang K, Hussain A (2024) Interpreting black-box models: a review on explainable artificial intelligence. Cogn Comput 16(1):45–74. https://doi.org/10.1007/s12559-023-10179-8
Shand C, Fong R, Butt U (2024) How explainable artificial intelligence (XAI) models can be used within intrusion detection systems (ids) to enhance an analyst’s trust and understanding. In: Jahankhani, H. (ed.) Cybersecurity Challenges in the Age of AI, Space Communications and Cyborgs. ICGS3 2023. Advanced sciences and technologies for security applications. Springer, Cham. https://doi.org/10.1007/978-3-031-47594-8_17
Ribeiro MT, Singh S, Guestrin C (2016) "why should i trust you?" explaining the predictions of any classifier. In: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp 1135–1144. https://doi.org/10.1145/2939672.2939778
Lundberg SM, Lee SI (2017) A unified approach to interpreting model predictions. Adv Neural Inf Process Syst 30. https://github.com/slundberg/shap
Iqbal A, Amin R (2025) An efficient mechanism for time series forecasting and anomaly detection using explainable artificial intelligence. J Supercomput 81(4):523. https://doi.org/10.1007/s11227-025-07040-0
Kruschel S, Hambauer N, Weinzierl S, Zilker S, Kraus M, Zschech P (2025) Challenging the performance-interpretability trade-off: an evaluation of interpretable machine learning models. Bus Inf Syst Eng 68(1):159–183. https://doi.org/10.1007/s12599-024-00922-2
Ahmed U, Jiangbin Z, Almogren A, Sadiq M, Rehman AU, Sadiq MT, Choi J (2024) Hybrid bagging and boosting with shap based feature selection for enhanced predictive modeling in intrusion detection systems. Sci Rep 14(1):30532. https://doi.org/10.1038/s41598-024-81151-1
Roy K, Farid DM (2024) An adaptive feature selection algorithm for student performance prediction. IEEE Access 12:75577–75598. https://doi.org/10.1109/ACCESS.2024.3406252
Gebreyesus Y, Dalton D, Nixon S, De Chiara D, Chinnici M (2023) Machine learning for data center optimizations: feature selection using shapley additive explanation (shap). Future Internet 15(3):88. https://doi.org/10.3390/fi15030088
Ren K, Zeng Y, Zhong Y, Sheng B, Zhang Y (2023) MAFSIDS: a reinforcement learning-based intrusion detection model for multi-agent feature selection networks. J Big Data 10(1):137. https://doi.org/10.1186/s40537-023-00814-4
Shafin SS (2025) An explainable feature selection framework for web phishing detection with machine learning. Data Sci Manag 8(2):127–136. https://doi.org/10.1016/j.dsm.2024.08.004
Van Lent M, Fisher W, Mancuso M (2004) An explainable artificial intelligence system for small-unit tactical behavior. Proceedings of the National Conference on Artificial Intelligence. AAAI Press, Menlo Park, pp 900–907
Bonvillian WB, Van Atta R (2011) ARPA-E and DARPA: applying the DARPA model to energy innovation. J Technol Transf 36(5):469–513. https://doi.org/10.1007/s10961-011-9223-x
Arrieta AB, Díaz-Rodríguez N, Del Ser J, Bennetot A, Tabik S, Barbado A, Herrera F (2020) Explainable artificial intelligence (XAI): concepts, taxonomies, opportunities and challenges toward responsible AI. Inf Fusion 58:82–115
Guidotti R, Monreale A, Ruggieri S, Turini F, Giannotti F, Pedreschi D (2018) A survey of methods for explaining black box models. ACM Comput Surv 51(5):1–42. https://doi.org/10.1145/3236009
Aleksandra N, Bojana J, Maryan R, Dimitar T (2025) Evaluating trustworthiness in ai: risks, metrics, and applications across industries. Electronics 14(13):2717. https://doi.org/10.3390/electronics14132717
Chinnaraju A (2025) Explainable AI (XAI) for trustworthy and transparent decision-making: a theoretical framework for ai interpretability. World J Adv Eng Technol Sci 14(3):170–207. https://doi.org/10.30574/wjaets.2025.14.3.0106
Danesh T, Ouaret R, Floquet P, Negny S (2023) Hybridization of model-specific and model-agnostic methods for interpretability of neural network predictions: application to a power plant. Comput Chem Eng 176:108306. https://doi.org/10.1016/j.compchemeng.2023.108306
Madsen A, Lakkaraju H, Reddy S, Chandar S (2024) Interpretability needs a new paradigm. https://doi.org/10.48550/arXiv.2405.05386
Van Zyl C, Ye X, Naidoo R (2024) Harnessing explainable artificial intelligence for feature selection in time series energy forecasting: a comparative analysis of Grad-CAM and SHAP. Appl Energy 353:122079. https://doi.org/10.1016/j.apenergy.2023.122079
Zacharias J, Zahn M, Chen J, Hinz O (2022) Designing a feature selection method based on explainable artificial intelligence. Electron Mark 32(4):2159–2184. https://doi.org/10.1007/s12525-022-00608-1
Ahadzadeh B, Abdar M, Safara F, Khosravi A, Menhaj MB, Suganthan PN (2023) SFE: a simple, fast, and efficient feature selection algorithm for high-dimensional data. IEEE Trans Evol Comput 27(6):1896–1911. https://doi.org/10.1109/TEVC.2023.3238420
Lei C, Liu C, Zhang Y, Cheng J, Zhao R (2025) Comparisons of filter, wrapper, and embedded feature selection for rockfall susceptibility prediction and mapping. Nat Hazards 121(2):1911–1943. https://doi.org/10.1007/s11069-024-06878-6
Ewees AA, Alshahrani MM, Alharthi AM, Gaheen MA (2025) Optimizing feature selection and remote sensing classification with an enhanced machine learning method. J Supercomput 81(2):370. https://doi.org/10.1007/s11227-024-06790-7
Lima HC, Otero FE, Merschmann LH, Souza MJ (2021) A novel hybrid feature selection algorithm for hierarchical classification. IEEE Access 9:127278–127292. https://doi.org/10.1109/ACCESS.2021.3112396
Araya-Martinez JM, Tom T, Sardari S, Reig AS, Mohan G, Shukla A, Krüger J (2025) Domain adaptation using vision transformers and XAI for fully synthetic industrial training. Procedia CIRP 136:904–909. https://doi.org/10.1016/j.procir.2025.08.154
Wang M, Zheng K, Yang Y, Wang X (2020) An explainable machine learning framework for intrusion detection systems. IEEE Access 8:73127–73141. https://doi.org/10.1109/ACCESS.2020.2988359
Rabbi F, Hossain NUI, Das S (2025) A comparative analysis of machine learning techniques for detecting probing attack with SHAP algorithm. Expert Syst Appl 271:126718. https://doi.org/10.1016/j.eswa.2025.126718
Ullah I, Rios A, Gala V, Mckeever S (2021) Explaining deep learning models for tabular data using layer-wise relevance propagation. Appl Sci 12(1):136. https://doi.org/10.3390/app12010136
Savanovic N, Bozovic A, Antonijevic M, Kvascev G, Nikolic B, Venkatachalam K, Zivkovic M (2025) Hybrid CNN-XGBoost intrusion detection approach tuned by modified sine cosine algorithm towards better cloud security. Connect Sci 37(1):2549581. https://doi.org/10.1080/09540091.2025.2549581
Sivamohan S, Sridhar SS, Krishnaveni S (2023) TEA-EKHO-IDS: an intrusion detection system for industrial cps with trustworthy explainable AI and enhanced krill herd optimization. Peer-to-Peer Netw Appl 16(4):1993–2021. https://doi.org/10.1007/s12083-023-01507-8
Amudha M, Brindha K (2024) Effective feature selection based HOBS pruned-ELM model for tomato plant leaf disease classification. PLoS ONE 19(12):0315031. https://doi.org/10.1371/journal.pone.0315031
Si-ahmed A, Al-Garadi MA, Boustia N (2024) Explainable machine learning-based security and privacy protection framework for Internet of Medical Things systems. https://arxiv.org/abs/2403.09752
Bhardwaj T, Sumangali K (2025) An explainable federated blockchain framework with privacy-preserving ai optimization for securing healthcare data. Sci Rep 15(1):21799. https://doi.org/10.1038/s41598-025-04083-4
Dadkhah S, Neto ECP, Ferreira R, Molokwu RC, Sadeghi S, Ghorbani AA (2024) CICIoMT2024: a benchmark dataset for multi-protocol security assessment in IoMT. Internet Things 28:101351. https://doi.org/10.1016/j.iot.2024.101351
Benahmed H, M’Hamedi M, Merzoug M, Hadjila M, Bekkouche A, Etchiali A, Mahmoudi S (2025) HBiLD-IDS: an efficient hybrid BiLSTM-DNN model for real-time intrusion detection in IoMT networks. Information 16(8):669. https://doi.org/10.3390/info16080669
Tany NS, Suresh S, Sinha DN, Shinde C, Stolojescu-Crisan C, Khondoker R (2022) Cybersecurity comparison of brain-based automotive electrical and electronic architectures. Information 13(11):518. https://doi.org/10.3390/info13110518
Shaikh JA, Wang C, Us Sima MW, Arshad M, Owais M, Hassan DSM, Muthanna MSA (2025) A deep reinforcement learning-based robust intrusion detection system for securing IoMT healthcare networks. Front Med 12:1524286. https://doi.org/10.3389/fmed.2025.1524286
Sharma N, Shambharkar PG (2025) Multi-attention DeepCRNN: an efficient and explainable intrusion detection framework for Internet of Medical Things environments. Knowl Inf Syst 67(7):5783–5849. https://doi.org/10.1007/s10115-025-02402-9
Berrezzek A, Djellali H, Mallardi G, Mahnane L (2026) Explainable hybrid feature selection for intrusion detection in Internet of Medical Things environments
Alabbadi A, Bajaber F (2025) X-fuserlstm: a cross-domain explainable intrusion detection framework in IoT using the attention-guided dual-path feature fusion and residual LSTM. Sensors 25(12):3693. https://doi.org/10.3390/s25123693
Author information
Authors and Affiliations
Contributions
Conceptualization: H.B., M.H., Z.K.; methodology: H.B., M.M. (Mohammed M’hamedi), M.M. (Mohammed Merzoug); software: H.B.; validation: M.H., Z.K., H.B, S.M.; formal analysis: H.B, M.M. (Mohammed M’hamedi), A.B.; investigation: H.B, M.M. (Mo-hammed M’hamedi), Z.K., M.H., S.M.; writing: H.B., M.M. (Mohammed M’hamedi), M.M. (Mohammed Merzoug), M.H., Z.K., S.M., A.B.; visualization: H.B.; supervision: M.M. (Mohammed Merzoug), A.B., M.H., S.M.; project administration: M.M. (Mohammed Merzoug); funding acquisition: S.M., M.M. (Mohammed Merzoug). All authors have read and agreed to the published version of the manuscript.
Corresponding authors
Ethics declarations
Conflict of interest
The authors declare no conflict of interest.
Additional information
Publisher's Note
Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.
Rights and permissions
Springer Nature or its licensor (e.g. a society or other partner) holds exclusive rights to this article under a publishing agreement with the author(s) or other rightsholder(s); author self-archiving of the accepted manuscript version of this article is solely governed by the terms of such publishing agreement and applicable law.
About this article
Cite this article
Benahmed, H., Merzoug, M., Koudad, Z. et al. XBiLD-IDS: toward an explainable hybrid BiLSTM-DNN architecture for trustworthy intrusion detection in IoMT networks. J Supercomput 82, 703 (2026). https://doi.org/10.1007/s11227-026-08855-1
Received:
Accepted:
Published:
Version of record:
DOI: https://doi.org/10.1007/s11227-026-08855-1
Facts Only
* H. Benahmed, M. Merzoug, Z. Koudad, and other contributors developed XBiLD-IDS.
* XBiLD-IDS is an explainable intrusion detection system framework for Internet of Medical Things (IoMT) networks.
* The framework integrates a bidirectional long short-term memory (BiLSTM) network with a deep neural network (DNN).
* SHapley Additive exPlanations (SHAP) are used within a feature selection mechanism.
* The system was evaluated using the CICIoMT2024 dataset.
* Accuracy was measured at 98.70%.
* Precision was measured at 99.04%.
* Recall was measured at 98.78%.
* F1-score was measured at 98.69%.
* The work is published in the Journal of Supercomputing, volume 82, article 703 (2026).
* The researchers declare no conflict of interest.
Executive Summary
The XBiLD-IDS framework addresses a critical tension in healthcare cybersecurity: the trade-off between the high performance of "black box" deep learning models and the transparency required for forensic accountability in medical environments. By combining a hybrid BiLSTM-DNN architecture with SHAP-based feature selection, the system attempts to capture complex temporal dependencies in network data while providing human-interpretable insights into which features drive specific threat detections.
Testing on the CICIoMT2024 dataset indicates high efficacy, with accuracy and precision metrics exceeding 98%. This approach allows security analysts to refine the feature space using a combination of mathematical quantification and human expertise. While the results demonstrate robustness across most attack classes, the primary value proposition lies in transforming raw detection into actionable intelligence, thereby increasing trust in automated security systems within the Internet of Medical Things (IoMT) ecosystem.
Full Take
This research operates in ACADEMIC MODE, contributing to the evolving field of Explainable AI (XAI) within critical infrastructure.
1. METHODOLOGY CHECK: The design utilizes a hybrid architecture (BiLSTM-DNN) to handle the sequential nature of network traffic and the high-dimensional nature of feature sets. However, a peer reviewer would likely query the "human expertise" component of the feature selection process; if the refinement is subjective, it introduces a variable that is difficult to replicate across different institutional settings. Furthermore, the reliance on a single benchmark dataset (CICIoMT2024) may not fully capture the entropy of diverse, real-world hospital networks.
2. CLAIMS vs EVIDENCE: The claims of "trustworthiness" and "transparency" are supported by the integration of SHAP, which is a mathematically grounded method for local feature importance. The performance metrics are high, though the abstract emphasizes "maintaining high performance across the majority of attack classes," suggesting some classes may exhibit lower reliability—a detail that warrants closer inspection in the full results.
3. LITERATURE CONTEXT: The work extends the HBiLD-IDS model by adding an explainability layer. It positions itself as a solution to the "black box" problem cited in broader XAI literature, moving from simple detection to interpretable intelligence.
4. REAL-WORLD IMPLICATIONS: For this to matter outside the lab, the "explainable" output must be usable by security analysts in real-time. If the SHAP values require a data scientist to interpret, the transparency is nominal rather than operational.
5. BRIDGE QUESTIONS: How does the model's latency increase when the explainability layer is active? Would the system's accuracy degrade if the human-refined feature set were replaced by a purely automated SHAP selection?
Sentinel — Human
This appears to be a piece of primary research reporting advanced machine learning methodology applied to cybersecurity challenges within the IoMT domain.
