Explainable Artificial Intelligence for Industrial Cybersecurity: A Review of Methods, Operational Integration, and Research Challenges

📅 2026-08-31
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文探讨了使用可解释人工智能(XAI)技术解决工业网络安全中因采用AI和机器学习导致的决策不透明问题,综述了XAI方法及其在安全运营中的应用与挑战。
📝 Abstract
The increasing digitalization of industrial infrastructure and the convergence of information technology (IT) and operational technology (OT) have expanded the cyberattack surface of industrial systems. To address the growing complexity of cyber threats, artificial intelligence (AI) and machine learning (ML) techniques are increasingly deployed within industrial cybersecurity operations, particularly in Security Operations Centers (SOCs). While these approaches improve anomaly detection, threat analysis, and automated response, their opaque decision-making presents challenges for operational trust, regulatory compliance, and incident response. EXplainable Artificial Intelligence (XAI) has emerged as a promising paradigm to improve the transparency and interpretability of AI-driven cybersecurity systems and decisions. This paper provides a comprehensive review of XAI techniques in industrial cybersecurity, focusing on industrial SOC environments and operational security workflows. We examine the role of AI in industrial SOC workflows, the types of operational data leveraged in industrial environments, and the benefits and limitations of AI-based threat detection. We then review major families of XAI approaches, including feature attribution methods, surrogate models, rule-based explanations, and visualization techniques, and analyze their applicability to industrial use cases. We further discuss the operational, regulatory, and safety requirements that distinguish industrial systems from traditional IT environments. Key challenges are examined, including limited labeled datasets, model reliability, explainability-performance tradeoffs, and the integration of XAI tools into SOC workflows. Finally, we identify open research directions and opportunities for developing trustworthy, operationally viable, and domain-specific XAI-enabled cybersecurity solutions for industrial environments.
Problem

Research questions and friction points this paper is trying to address.

Explainable Artificial Intelligence
Industrial Cybersecurity
Operational Trust
Regulatory Compliance
Incident Response
Innovation

Methods, ideas, or system contributions that make the work stand out.

Explainable Artificial Intelligence (XAI)
Industrial Cybersecurity
Security Operations Centers (SOCs)
Feature Attribution Methods
Surrogate Models
A
Amr S. Mohamed
German University in Cairo, Cairo, Egypt
C
Charlotte Fritz
University of Toronto, Toronto, ON, Canada
Ahmad Mohammad Saber
Ahmad Mohammad Saber
University of Toronto
Smart GridsMachine LearningCyber-Physical SecurityMicrogridsRenewable Energy
Y
Yiqun Ma
University of Illinois Urbana-Champaign, Champaign, IL, USA
Ratinder Kaur
Ratinder Kaur
Siemens Canada, Canada
M
Mohammed Al-Darwbi
Siemens Canada, Canada
D
Daniela Friedrich
Siemens Canada, Canada
Deepa Kundur
Deepa Kundur
Canada Research Chair in Cybersecurity of Intelligent Critical Infrastructure, University of Toronto
Cyber-Physical SecuritySmart GridSmart Grid SecurityMental Health InformaticsMultimedia