XG-RAID: Explainable Graph Neural Network for Risk-Aware Intrusion Detection in IoT Ecosystems
作者:Nasser Aljabri, Mustafa Al Samara, N. Litayem, Abdelhak Belhi, Okba Ben Atia, Ismail Bennis · 发表于:2026 IFIP Networking Conference (IFIP Networking) · 年份:2026 · DOI:10.23919/IFIPNetworking70592.2026.11579124
The rapid expansion of the Internet of Things (IoT) has significantly increased the attack surface of modern networks, exposing heterogeneous devices to diverse cyber threats. While Graph Neural Networks (GNNs) can model complex traffic patterns, existing approaches often lack interpretability and operational risk awareness. This paper presents XG-RAID, an explainable graph-based intrusion detection framework that integrates relational learning with interpretability and risk-oriented analysis. Network flows from the CICIoT2023 dataset are represented as nodes in a similarity-based graph constructed using feature-space proximity. A GraphSAGE model performs multi-class classification across 23 attack categories. To enhance transparency, the framework incorporates SHAP, LIME, and Grad-CAM to provide feature-level and structural explanations. A risk scoring mechanism is introduced by combining prediction confidence with explanation consistency to prioritize alerts. Experimental results show that XG-RAID outperforms conventional machine learning models and a vanilla GraphSAGE baseline, while providing actionable insights for security analysts. Although the approach relies on similarity-based graph construction rather than explicit network topology, it offers a scalable and interpretable solution for IoT intrusion detection.