Abstract The increasing heterogeneity and scale of Internet of Things (IoT) ecosystems have intensified cybersecurity challenges associated with highly imbalanced traffic distributions, evolving attack patterns, and resource-constrained deployment environments. Conventional cloud-centric intrusion detection systems often introduce communication overhead and latency constraints, while minority attack classes remain difficult to detect under severely skewed traffic conditions. To address these challenges, this study proposes EHiD-FC, an explainable hierarchical two-stage intrusion diagnosis framework for IoT Fog–Cloud environments. The proposed framework employs lightweight anomaly screening at the Fog layer using Autoencoder (AE), Isolation Forest (IF), and One-Class Support Vector Machine (OCSVM), followed by Cloud-level multi-class attack diagnosis using an Ensemble + XGBoost classifier. Stage-specific explainability is incorporated through LIME-based local interpretation at the Fog layer and SHAP-based global feature attribution at the Cloud layer. Experimental evaluation was conducted using the CIC-IoT2023 dataset under multiple operational scenarios involving Fog-layer anomaly screening, Cloud-level diagnosis, real-time traffic simulation, and explainability assessment. The framework demonstrated competitive intrusion detection performance across multiple evaluation metrics, including Precision, Recall, F1-score, Macro-F1, Specificity, False Positive Rate (FPR), False Negative Rate (FNR), and G-Mean under highly imbalanced traffic conditions. The results indicate that EHiD-FC supports interpretable and imbalance-aware intrusion diagnosis in Fog–Cloud IoT environments while highlighting the need for further validation under large-scale real-world deployment conditions. Subjects Acknowledgements This research is supported by Princess Nourah bint Abdulrahman University (PNU) Researchers Supporting Project number (PNURSP2026R194), Princess Nourah bint Abdulrahman University, Riyadh, Saudi Arabia. Funding Open access funding provided by Manipal Academy of Higher Education, Manipal. Ethics declarations Competing interests The authors declare no competing interests. Ethical approval This study uses the publicly available CIC-IoT2023 dataset, which contains anonymized network traffic data and does not involve human participants, personal data, or sensitive information. Therefore, ethical approval was not required for this study. Additional information Publisher’s note
An explainable hierarchical Fog–Cloud intrusion diagnosis framework for <b>IoT</b> ecosystems ...
Read the original article
nature.com →