Junaid and Algarni, Fahad and Khan, Muhammad Ijaz and Shah, Syed Tariq and Alluhaidan, Ala Saleh and Ullah, insaf (2026) An AI-Driven Framework for Intrusion Detection and Predictive Threat Modeling in UAV Ecosystem. Internet of Things. (In Press)
Junaid and Algarni, Fahad and Khan, Muhammad Ijaz and Shah, Syed Tariq and Alluhaidan, Ala Saleh and Ullah, insaf (2026) An AI-Driven Framework for Intrusion Detection and Predictive Threat Modeling in UAV Ecosystem. Internet of Things. (In Press)
Junaid and Algarni, Fahad and Khan, Muhammad Ijaz and Shah, Syed Tariq and Alluhaidan, Ala Saleh and Ullah, insaf (2026) An AI-Driven Framework for Intrusion Detection and Predictive Threat Modeling in UAV Ecosystem. Internet of Things. (In Press)
Abstract
The escalation of Internet of Things (IoT)-enabled unmanned aerial vehicle (UAV) networks and autonomous vehicles has increased their exposure to cyber threats, highlighting the need for explainable intrusion detection systems (IDSs). In this paper, we propose a framework that combines a Transformer-based model, reinforcement learning (RL)- based decision thresholding, and explainable artificial intelligence (XAI) using Local Interpretable Model-agnostic Explanations (LIME). The framework is tested on UAVIDS-2025, which includes 122,171 flows from four attack categories (Blackhole, Wormhole, Sybil, and Flooding) and Normal Traffic. A leakage-free protocol is used, with feature scaling and SMOTE-based class balancing applied only to the training partition, while the validation and test partitions are held out. The accuracy, F1-score, and ROC-AUC of the model for binary intrusion detection are 97.73%, 98.53%, and 99.97%, respectively, with a false positive rate (FPR) of 0.10% and a false negative rate (FNR) of 2.86%. The multi-classifier with a shared Transformer backbone achieves 92.72% accuracy and a macro F1 score of 92.87%. There are 399,745 trainable parameters in the architecture, and a footprint of 1.54 MB. Ablation studies and comparisons with five machine-learning baselines validate the design choices. LIME has shown it is accurate, interpretable, reliable, and suitable for use with UAVs by identifying features such as flow duration, packet/byte rates, and drop-rate statistics.
| Item Type: | Article |
|---|---|
| Uncontrolled Keywords: | IDS; UAV; IOV; security; Autonomous vehicles; Transformer networks; Reinforcement learning; Explainable AI; Predictive threat modeling |
| Divisions: | Faculty of Science and Health Faculty of Science and Health > Computer Science and Electronic Engineering, School of |
| SWORD Depositor: | Unnamed user with email elements@essex.ac.uk |
| Depositing User: | Unnamed user with email elements@essex.ac.uk |
| Date Deposited: | 14 Sep 2026 09:59 |
| Last Modified: | 14 Sep 2026 10:09 |
| URI: | http://repository.essex.ac.uk/id/eprint/43845 |