Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
@article{207035,
author = {Chandras Batheja and Tathagat Suryavanshi and Tanmay Suryavanshi},
title = {Adaptive Multi-Granularity Explainable AI for Real-Time Cybersecurity Threat Detection: Bridging the Trust-Latency-Novelty Gap: A Conceptual Framework},
journal = {International Journal of Innovative Research in Technology},
year = {2026},
volume = {13},
number = {2},
pages = {3794-3802},
issn = {2349-6002},
url = {https://ijirt.org/article?manuscript=207035},
abstract = {Machine learning models deployed for intrusion detection, malware classification, and phishing identification have achieved high predictive accuracy, yet their opaque decision-making limits adoption in security operations centers (SOCs), where analysts must justify actions to auditors, regulators, and incident-response teams within seconds. Explainable Artificial Intelligence (XAI) has been proposed as a remedy, but the cybersecurity-XAI literature remains dominated by static, post-hoc explanation techniques applied to offline benchmark datasets, evaluated primarily for fidelity to the underlying model rather than for usefulness to the humans who must act on them. This paper identifies four interlocking gaps in the current literature: the absence of stakeholder-adaptive explanation granularity, the neglect of explanation robustness under adversarial perturbation, the mismatch between real-time detection latency budgets and the computational cost of explanation generation, and the unresolved question of how to explain predictions for novel or zero-day attacks that fall outside a model's learned taxonomy. To address these gaps, we propose Adaptive Multi-Granularity Explainable AI (AMG-XAI), a conceptual framework that couples a novelty-aware detection layer with a stakeholder-conditioned explanation generator and an adversarial-robustness auditor, operating within an explicit latency budget. We detail the framework's architecture, propose an evaluation methodology spanning fidelity, robustness, latency, and human-centered usability metrics, and discuss the implications for SOC workflows, regulatory compliance, and future research. The contribution is deliberately framed as a conceptual and methodological one: it synthesizes a fragmented literature into a coherent research agenda and offers a concrete, testable framework rather than a single-dataset empirical result.},
keywords = {Explainable AI, cybersecurity, intrusion detection, SHAP, adversarial robustness, security operations centers, human-computer trust, zero-day detection.},
month = {July},
}
Submit your research paper and those of your network (friends, colleagues, or peers) through your IPN account, and receive 800 INR for each paper that gets published.
Join NowNational Conference on Sustainable Engineering and Management - 2024 Last Date: 15th March 2024
Submit inquiry