Adaptive Multi-Granularity Explainable AI for Real-Time Cybersecurity Threat Detection: Bridging the Trust-Latency-Novelty Gap: A Conceptual Framework

  • Unique Paper ID: 207035
  • Volume: 13
  • Issue: 2
  • PageNo: 3794-3802
  • Abstract:
  • Machine learning models deployed for intrusion detection, malware classification, and phishing identification have achieved high predictive accuracy, yet their opaque decision-making limits adoption in security operations centers (SOCs), where analysts must justify actions to auditors, regulators, and incident-response teams within seconds. Explainable Artificial Intelligence (XAI) has been proposed as a remedy, but the cybersecurity-XAI literature remains dominated by static, post-hoc explanation techniques applied to offline benchmark datasets, evaluated primarily for fidelity to the underlying model rather than for usefulness to the humans who must act on them. This paper identifies four interlocking gaps in the current literature: the absence of stakeholder-adaptive explanation granularity, the neglect of explanation robustness under adversarial perturbation, the mismatch between real-time detection latency budgets and the computational cost of explanation generation, and the unresolved question of how to explain predictions for novel or zero-day attacks that fall outside a model's learned taxonomy. To address these gaps, we propose Adaptive Multi-Granularity Explainable AI (AMG-XAI), a conceptual framework that couples a novelty-aware detection layer with a stakeholder-conditioned explanation generator and an adversarial-robustness auditor, operating within an explicit latency budget. We detail the framework's architecture, propose an evaluation methodology spanning fidelity, robustness, latency, and human-centered usability metrics, and discuss the implications for SOC workflows, regulatory compliance, and future research. The contribution is deliberately framed as a conceptual and methodological one: it synthesizes a fragmented literature into a coherent research agenda and offers a concrete, testable framework rather than a single-dataset empirical result.

Copyright & License

Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.

BibTeX

@article{207035,
        author = {Chandras Batheja and Tathagat Suryavanshi and Tanmay Suryavanshi},
        title = {Adaptive Multi-Granularity Explainable AI for Real-Time Cybersecurity Threat Detection: Bridging the Trust-Latency-Novelty Gap: A Conceptual Framework},
        journal = {International Journal of Innovative Research in Technology},
        year = {2026},
        volume = {13},
        number = {2},
        pages = {3794-3802},
        issn = {2349-6002},
        url = {https://ijirt.org/article?manuscript=207035},
        abstract = {Machine learning models deployed for intrusion detection, malware classification, and phishing identification have achieved high predictive accuracy, yet their opaque decision-making limits adoption in security operations centers (SOCs), where analysts must justify actions to auditors, regulators, and incident-response teams within seconds. Explainable Artificial Intelligence (XAI) has been proposed as a remedy, but the cybersecurity-XAI literature remains dominated by static, post-hoc explanation techniques applied to offline benchmark datasets, evaluated primarily for fidelity to the underlying model rather than for usefulness to the humans who must act on them. This paper identifies four interlocking gaps in the current literature: the absence of stakeholder-adaptive explanation granularity, the neglect of explanation robustness under adversarial perturbation, the mismatch between real-time detection latency budgets and the computational cost of explanation generation, and the unresolved question of how to explain predictions for novel or zero-day attacks that fall outside a model's learned taxonomy. To address these gaps, we propose Adaptive Multi-Granularity Explainable AI (AMG-XAI), a conceptual framework that couples a novelty-aware detection layer with a stakeholder-conditioned explanation generator and an adversarial-robustness auditor, operating within an explicit latency budget. We detail the framework's architecture, propose an evaluation methodology spanning fidelity, robustness, latency, and human-centered usability metrics, and discuss the implications for SOC workflows, regulatory compliance, and future research. The contribution is deliberately framed as a conceptual and methodological one: it synthesizes a fragmented literature into a coherent research agenda and offers a concrete, testable framework rather than a single-dataset empirical result.},
        keywords = {Explainable AI, cybersecurity, intrusion detection, SHAP, adversarial robustness, security operations centers, human-computer trust, zero-day detection.},
        month = {July},
        }

Cite This Article

Batheja, C., & Suryavanshi, T., & Suryavanshi, T. (2026). Adaptive Multi-Granularity Explainable AI for Real-Time Cybersecurity Threat Detection: Bridging the Trust-Latency-Novelty Gap: A Conceptual Framework. International Journal of Innovative Research in Technology (IJIRT), 13(2), 3794–3802.

Related Articles