HLPMM–GRSPHTRU: An explainable cross-layer temporal framework for multi-stage attack detection in IoT-CPS

Authors

  • Mohan Kumar Electronics Engineering, Faculty of Engineering and Technology, JAIN (Deemed-to-be University), Kanakapura Main Road, Bengaluru, 562112, Karnataka, India. https://orcid.org/0009-0005-7201-721X
  • Malode Vishwanatha Panduranga Rao Computer Science and Engineering, Faculty of Engineering and Technology, JAIN (Deemed-to-be University), Kanakapura Main Road, Bengaluru, 562112, Karnataka, India. https://orcid.org/0000-0003-3674-2092
  • Ezhilarasan Ganesan Department of Electrical and Electronics Engineering, Faculty of Engineering and Technology, JAIN (Deemed-to-be University), Kanakapura Main Road, Bengaluru, 562112, Karnataka, India. https://orcid.org/0000-0002-5335-2347
  • Keerthana P Malode Computer Science and Engineering, Faculty of Engineering and Technology, JAIN (Deemed-to-be University), Kanakapura Main Road, Bengaluru, 562112, Karnataka, India. https://orcid.org/0009-0000-9082-9928

DOI:

https://doi.org/10.18488/76.v13i2.4927

Abstract

The high growth rate of Internet of Things (IoT)-powered Cyber-Physical Systems (CPS) has led to advanced, multi-level cyber-attacks such as ransomware, distributed denial-of-service (DDoS), and malware, which tend to spread across various system levels over time. Current intrusion detection systems often fail to detect these cross-layer temporal dependencies and offer weak interpretability, limiting their trustworthiness in safety-critical CPS environments. To address these issues, this paper proposes an explainable cross-layer temporal correlation system for detecting multi-stage cyber-attacks in IoT-enabled CPS. The framework combines the Hidden Laguerre Polynomial Markov Model (HLPMM), a probabilistic sequence model that enables flexible state transition learning, with a Gated Rastrigin Sphere Penalized Hyperbolic Tangent Recurrent Unit (GRSPHTRU), an improved gated recurrent neural network designed for healthy temporal feature learning. Principal Griewank Component Analysis is employed for dimensionality reduction, while an adaptive density-based clustering mechanism groups behavioral patterns. Model transparency is achieved through a Shapley-based explainability module, and system integrity is maintained via blockchain-based tamper-resistant logging. The federated learning structure decentralizes training across multiple distributed CPS nodes, reducing raw data sharing and enhancing privacy. Experimental analysis using benchmark ransomware, malware, and CIC-DDoS2019 datasets demonstrates high performance, with detection accuracy and explainability fidelity reaching up to 99 percent compared to conventional RNN, LSTM, BiLSTM, and GRU models. Additionally, feature compression and federated aggregation significantly impact computational load and communication overhead, facilitating scalable deployment.

Keywords:

Blockchain logging, Cyber-physical systems, Federated learning, Hidden Markov model, Internet of Things, Intrusion detection system.

Downloads

Download data is not yet available.

Published

2026-04-22

How to Cite

Kumar, . . M. ., Rao, M. V. P., Ganesan, E. ., & Malode, K. P. . (2026). HLPMM–GRSPHTRU: An explainable cross-layer temporal framework for multi-stage attack detection in IoT-CPS . Review of Computer Engineering Research, 13(2), 1–21. https://doi.org/10.18488/76.v13i2.4927