Source-linked AI summary

Explainable Artificial Intelligence for Industrial Cybersecurity: A Review of Methods, Operational Integration, and Research Challenges

Amr S. Mohamed, Charlotte Fritz, Ahmad Mohammad Saber, Yiqun Ma, Ratinder Kaur, Mohammed Al-Darwbi, Daniela Friedrich, Deepa Kundur

arXiv:2609.00171v1cs.CReess.SY

TL;DR

Industrial IT/OT convergence expands cyberattack exposure while opaque AI decisions challenge trust, safety, and regulatory compliance. This paper reviews XAI methods and their operational integration in industrial SOCs, concluding that trustworthy deployment requires domain-specific approaches addressing industrial workflows and constraints.

  • Problem

    Opaque AI and ML decisions are difficult to interpret in industrial environments where operational trust, safety, and regulatory compliance are essential.

  • Method

    The paper comprehensively reviews industrial cybersecurity XAI methods, SOC workflows, datasets, visualizations, evaluation practices, and operational deployment requirements.

  • Results

    The review identifies SHAP as the most widely applied surveyed XAI method and examines complementary global and local explanation use through SHAP and LIME.

  • Takeaways & Limitations

    Industrial XAI solutions should support analyst decision-making, incident investigation, and emerging regulatory and governance requirements for trustworthy AI.

  • Takeaways & Limitations

    Industrial XAI evaluation lacks universally accepted criteria, standardized thresholds, and consistent terminology, limiting automated evaluation.

Abstract

from arXiv · show

The increasing digitalization of industrial infrastructure and the convergence of information technology (IT) and operational technology (OT) have expanded the cyberattack surface of industrial systems. To address the growing complexity of cyber threats, artificial intelligence (AI) and machine learning (ML) techniques are increasingly deployed within industrial cybersecurity operations, particularly in Security Operations Centers (SOCs). While these approaches improve anomaly detection, threat analysis, and automated response, their opaque decision-making presents challenges for operational trust, regulatory compliance, and incident response. EXplainable Artificial Intelligence (XAI) has emerged as a promising paradigm to improve the transparency and interpretability of AI-driven cybersecurity systems and decisions. This paper provides a comprehensive review of XAI techniques in industrial cybersecurity, focusing on industrial SOC environments and operational security workflows. We examine the role of AI in industrial SOC workflows, the types of operational data leveraged in industrial environments, and the benefits and limitations of AI-based threat detection. We then review major families of XAI approaches, including feature attribution methods, surrogate models, rule-based explanations, and visualization techniques, and analyze their applicability to industrial use cases. We further discuss the operational, regulatory, and safety requirements that distinguish industrial systems from traditional IT environments. Key challenges are examined, including limited labeled datasets, model reliability, explainability-performance tradeoffs, and the integration of XAI tools into SOC workflows. Finally, we identify open research directions and opportunities for developing trustworthy, operationally viable, and domain-specific XAI-enabled cybersecurity solutions for industrial environments.

I. INTRODUCTION

Industrial digitalization and IT/OT convergence increase connectivity, data complexity, and cyberattack exposure, while AI/ML adoption creates a need for explainable and operationally trustworthy security decisions. This review addresses the industrial-specific gap by examining XAI methods, SOC workflows, and the regulatory, safety, and accountability requirements shaping deployment.

  • Industrial Context: Industrial infrastructures combine physical processes, OT, communication networks, computing platforms, and human operators across increasingly interconnected environments.IIoT, cloud services, wireless communications, and IT/OT convergence expand connectivity and operational complexity.
  • AI Adoption: AI and ML are increasingly adopted to detect threats, identify anomalies, and support security decision-making from operational and security-relevant data.Unlike predefined rules, modern ML approaches learn patterns directly from data to identify abnormal or potentially malicious behavior.
  • Explainability Gap: Opaque ML decisions are difficult to interpret or justify, yet industrial environments require outputs that are understandable, trustworthy, auditable, and operationally actionable.These requirements matter to analysts, operators, engineers, and regulators in safety-critical and compliance-regulated settings.
  • Research Gap: Existing XAI surveys emphasize traditional IT, whereas industrial environments impose distinct operational, safety, data, and regulatory constraints centered increasingly on SOC operations.These constraints influence how industrial AI and XAI systems are designed, deployed, and evaluated.
  • Review Scope: This paper reviews industrial-security XAI literature, categorizes methods, assesses operational suitability, and examines how explanations support stakeholder decision-making in industrial SOCs.It also addresses regulatory, safety, auditability, accountability, research gaps, and future directions for domain-specific systems.
  • Industrial Stakes: Industrial security must account for consequences including equipment damage, environmental harm, economic loss, regulatory penalties, criminal liability, and threats to human safety.These consequences distinguish industrial cybersecurity priorities from conventional IT security concerns.

A. The Typical Workflow of an Industrial SOC

Industrial SOC workflows span preparation, real-time operations, and post-incident activities under strict timing and safety constraints. AI and XAI are positioned to improve monitoring, analysis, decision support, and accountability across these activities.

  • Workflow Phases: An OT SOC workflow comprises preparation, real-time operations, and post-incident activities.Preparation includes asset inventories, behavioral baselining, and OT data integration; later phases address detection, response, analysis, reporting, and improvement.
  • Risks and Barriers: Industrial SOC-specific XAI adoption remains constrained by data availability, evaluation challenges, regulatory verification, and risks from erroneous responses.The section identifies these issues as barriers requiring operationally grounded treatment.
  • Benefits of AI: AI can improve situational awareness, transform understanding of complex threats, and reduce data and alert overload in industrial SOC operations.These benefits correspond to operational needs for handling large volumes of security-relevant information.
  • Operational Value: XAI can improve trust, human-AI collaboration, error detection, accountability, and automated regulatory compliance when integrated into industrial security operations.The review frames these benefits as operational and governance contributions rather than merely model-performance improvements.
  • XAI Methods: XAI methods support industrial SOC decision-making through feature influence visualization, model-agnostic explanations, and complementary local and global interpretations.SHAP is used for global feature importance, while LIME provides local, instance-level explanations.

B. Emerging Research Needs for Industrial SOC-specific XAI

Research on industrial SOC-specific XAI must address data, evaluation, validation, reasoning, and workflow-integration needs. Proposed directions emphasize domain-aware, stakeholder-driven, interactive, and operationally deployable explanations.

  • Lifecycle and Validation: Industrial XAI research needs stronger integration into the AI design lifecycle and validation procedures that build trust in operational settings.Trust-oriented validation is presented alongside lifecycle integration as a research priority.
  • Data Availability: Heavy reliance on IT and IoT datasets motivates realistic data-generation solutions for industrial security research.The direction responds to limitations in representative industrial data availability.
  • Human-Centered Design: Industrial explanations should align with human reasoning and be driven by stakeholder needs across operational security roles.This places analyst, engineer, and operator requirements at the center of explanation design.
  • Interactive Explanations: Future systems should investigate sequential, engaging, and interactive XAI techniques for industrial environments.These approaches aim to make explanations more usable within operational workflows.
  • Domain-Specific Methods: Physics-informed learning, knowledge-graph contextualization, and industrial foundation models are identified as domain-specific research directions.The listed directions connect explanations with process simulations, contextual knowledge, and emerging model architectures.

1) Operational Constraints:

Industrial operational constraints make security monitoring, patching, threat response, and visibility more difficult than in conventional IT environments. Safety, availability, heterogeneous legacy assets, and limited logging require cautious and often passive security practices.

  • Availability and Safety: OT prioritizes uninterrupted availability and operational safety, so shutdowns, reboots, updates, and patches require significant lead time and coordination.Consequently, unpatched systems may remain exposed to known vulnerabilities for extended periods.
  • Threat Response: Automated OT threat responses must be carefully scrutinized because interruptions to essential industrial services can create operational risks.During incidents, systems may remain operational while cyber response proceeds in parallel, with manual operation retained.
  • Monitoring Constraints: OT monitoring often requires passive techniques because active IT tools may interfere with time-critical functions or introduce unpredictable behavior.Real-time or active antivirus and network scanners are therefore limited or absent in OT environments.
  • Limited Visibility: Limited OT visibility restricts identification, monitoring, and collection of data on connected assets, network traffic, and security events.Visibility supports asset management, vulnerability identification, intrusion detection, compliance, incident response, and operational awareness.
  • Technology Constraints: Heterogeneous legacy devices, vendor-specific operating systems and protocols, resource constraints, and weak logging impede comprehensive monitoring and complex detection models.Many OT devices lack modern security capabilities, integration with monitoring platforms, or basic logging functionality.
  • Threat Consequences: Industrial cyberattacks can cause equipment damage, environmental harm, economic loss, regulatory penalties, criminal liability, and threats to human safety.These consequences raise the stakes for accurate, accountable, and operationally safe security decisions.
  • Regulatory Requirements: Evolving regulations require continuous monitoring, threat detection, incident reporting, and operational visibility across critical infrastructure sectors.Examples include NERC CIP provisions for monitoring and analysis and NIS2 requirements for real-time or near-real-time monitoring.

III. AI IN INDUSTRIAL SECURITY OPERATIONS CENTERS

AI supports industrial SOCs by processing heterogeneous telemetry, detecting anomalies, prioritizing alerts, and automating routine work under demanding operational conditions. Its use also extends to compliance workflows and continuous monitoring.

  • AI-enabled monitoring: AI analyzes large-scale industrial security data to identify anomalies, correlate events, and infer emerging threats from incomplete or noisy observations.These capabilities can improve situational awareness for SOC analysts.
  • AI-enabled monitoring: Industrial AI systems automate telemetry processing, event correlation, and continuous monitoring across complex IT/OT infrastructures under strict timing, reliability, and safety constraints.
  • Threat detection: AI processes massive heterogeneous datasets and can detect deviations from normal industrial process behavior without relying on predefined signatures.
  • SOC workflow support: AI can prioritize alerts using contextual relevance, historical trends, and dynamic risk scoring, reducing false positives, analysis times, and mean times to detect incidents.
  • Workforce support: AI automates routine SOC tasks, allowing less experienced personnel to manage more complex operations while shifting analyst roles toward supervision, threat hunting, and validation.
  • Compliance support: AI can automate log analysis, audit preparation, and network baselining to support compliance and continuous monitoring across varying OT environments.

B. Risks and Barriers to Adopting AI in Industrial SOCs

AI adoption in industrial SOCs offers operational benefits but introduces risks involving erroneous decisions, model security, workforce capability, and domain-specific deployment. XAI addresses these concerns through interpretable, auditable, and context-sensitive explanations, while requiring careful method selection and evaluation.

  • Risks and barriers: Poorly designed AI can generate false positives, erroneous responses, operational disruption, and security vulnerabilities in OT environments.
  • Risks and barriers: Early OT AI adoption may increase system risk before model accuracy, infrastructure maturity, and system alignment are established.
  • Risks and barriers: Industrial AI requires protection of model algorithms and training data because leakage can create new avenues for adversarial disruption.
  • Risks and barriers: AI-enabled attacks demonstrate the dual-use nature of AI, supporting defense while enabling phishing, deepfakes, malware, and DDoS attacks.
  • Risks and barriers: A shortage of cybersecurity professionals and specialized AI expertise limits widespread implementation, while ICS/OT deployment demands knowledge of control systems, operational constraints, and model behavior.
  • XAI response: XAI provides human-interpretable justifications that support responsible, trustworthy, auditable, and operationally actionable AI use.
  • XAI response: XAI objectives include justifying decisions, revealing learned patterns, exposing biases and errors, and supporting accountability and maintenance.
  • XAI methods: XAI explanations may target data, model architecture, or predictions and can be ante-hoc or post-hoc, global, local, or cohort-level.

B. Benefits of XAI in Industrial SOCs

XAI improves industrial SOC operations by exposing model errors, enriching alerts with actionable context, and supporting faster, more informed analyst decisions. Domain-grounded explanations can further improve user understanding and satisfaction.

  • Reliability: Industrial AI models face misclassification risks from bias, operational drift, adversarial manipulation, and noisy or incomplete data.
  • Reliability: XAI exposes feature contributions and underlying decision logic, enabling stakeholders to identify biases, correct errors, improve data quality, and retrain models.
  • Reliability: XAI helps distinguish why false positives and false negatives occur, supporting refinement of detection strategies and reducing costly operational consequences.
  • Alert contextualization: Industrial SOC alerts often lack context, forcing analysts to reconstruct attack activity across data sources and delaying incident response.
  • Alert contextualization: Alert contextualization enriches raw alerts with actionable information for triage, prioritization, investigation, escalation, documentation, and root-cause analysis.
  • Domain grounding: Contextualized explanations can significantly enhance users’ objective understanding and satisfaction, especially when incorporating domain knowledge or relevant training examples.
  • Domain grounding: MITRE ATT&CK-grounded explanations and attack graphs organize security events by adversarial technique and attack phase for analyst interpretation.
  • Operational impact: SOC-tailored XAI can deliver contextual insights that support timely, informed, and confident decision-making.

3) Increased Trust, Adoption, and Human-AI Collaboration:

Trust and explainability shape the adoption of AI in industrial SOCs, where personnel remain responsible for interpreting and acting on AI recommendations. Regulatory frameworks increasingly emphasize transparency, oversight, accountability, and traceability, while deployment remains constrained by scarce industrial cybersecurity data.

  • Trust and collaboration: Industrial SOC personnel operate in human-in-the-loop or human-on-the-loop workflows, interpreting, validating, and acting on AI-generated security insights.
  • Trust and collaboration: Limited explanation of prediction rationale constrains machine-learning adoption, while over half of surveyed AI users report wariness about trusting AI.
  • Trust and collaboration: Explainability supports calibrated trust by enabling analysts to interrogate, validate, or challenge outputs while improving situational awareness and decision quality.
  • Trust and collaboration: Research reports that transparent and interpretable algorithms increase user confidence in AI systems.
  • Governance and regulation: OECD principles and NIST guidance emphasize transparency, explainability, accountability, and trustworthiness across AI development, deployment, and evaluation.
  • Governance and regulation: The EU AI Act requires risk management and identifies certain AI systems used as safety components in critical infrastructure as high-risk.
  • Governance and regulation: High-risk systems must support transparency, effective human oversight, and instructions for interpreting outputs and maintaining the system.
  • Governance and regulation: Industrial cybersecurity frameworks such as IEC 62443 impose expectations for accountability, traceability, auditability, and secure operational management of AI-enabled systems.

A. Datasets

The surveyed literature predominantly uses labeled IDS benchmark datasets and supervised tabular ML models, while industrial OT/ICS context is often incomplete. XAI methods, especially SHAP, are applied to interpret these models and support SOC analysis.

  • Datasets: Most surveyed studies use IDS datasets containing labeled benign and malicious traffic for training and evaluating ML models.These datasets commonly categorize malicious traffic by attack type and support supervised classification.
  • Datasets: Many benchmark datasets are not OT/ICS-native because they omit industrial protocols, asset roles, and process-level variables.Consequently, explanations may be faithful to available model features but less actionable for process behavior, safety, and engineering decisions.
  • Datasets: A smaller subset uses unsupervised LSTM autoencoders trained on normal data, detecting anomalies through reconstruction failure.The models learn normal operational patterns and identify anomalous inputs through reconstruction error.
  • XAI methods: SHAP is the most widely applied XAI method, assigning feature contributions to model predictions through Shapley-value-based attribution.Efficient approximations such as TreeSHAP and FastSHAP can support faster explanation computation.
  • XAI methods: SHAP visualizations include force, waterfall, decision, bar, and beeswarm plots for local explanations, evolving prediction contributions, or global feature importance.In industrial SOC workflows, these visualizations can identify network, device, or process variables contributing to alerts and support triage and root-cause analysis.

2) Local Interpretable Model-Agnostic Explanations (LIME):

LIME explains individual black-box predictions by fitting an interpretable local surrogate to perturbed samples. Across industrial-security studies, LIME is used alone or with SHAP and can be aggregated through SP-LIME for broader attack-pattern insights.

  • Local explanation: LIME explains an individual complex-model prediction by fitting a simple surrogate model to perturbed samples around the instance.The surrogate is typically linear or a decision tree and approximates the black-box model locally.
  • Local explanation: SP-LIME selects diverse representative instances and aggregates their local explanations to provide broader feature or pattern insights.This aggregation does not constitute a strict global explanation like SHAP.
  • Applications: Industrial-security studies apply LIME to intrusion detection, malware-infected IoT traffic, and gas-pipeline control-loop attack intelligence.In the gas-pipeline study, LIME translated black-box predictions into actionable attack signatures, while SP-LIME derived generalized attack rules.
  • Applications: LIME and SHAP are often combined because LIME provides local instance explanations while SHAP provides global feature importance.One HVAC study used both methods to interpret models trained on sensor readings, control signals, and power consumption.
  • Applications: One study used XAI-guided feature selection to improve accuracy from 95.59% to 97.02%.The study combined XGBoost with SHAP and LIME and applied recursive feature elimination in an IoT-security setting.
  • Applications: Industrial and cybersecurity studies also combine LIME with SHAP, PDP, ICE, ALE, and permutation feature importance across tabular, sequential, and sensor datasets.These combinations support local explanations, global importance, feature effects, and feature-influence analysis.

5) Rule-based Explanations:

Rule-based explanations expose prediction logic through human-readable conditions, while related attribution and contrastive methods provide complementary views of model behavior. Their use spans transparent decision trees, RuleFit, and custom industrial-security frameworks.

  • Rule-based explanations: Decision trees provide auditable explanations because internal nodes encode feature splits and root-to-leaf paths form human-readable rules.However, single trees can overfit, miss complex nonlinear relationships, and become unstable under small training-data changes.
  • Rule-based explanations: RuleFit combines tree-derived rules with original features in a sparse linear model, using L1 regularization to select informative rules.Its rule-importance plots and per-instance rule contributions provide transparent prediction breakdowns.
  • Applications: A decision-tree IDS framework achieved comparable precision, recall, and F1score to SVM and logistic regression while providing transparent IF-THEN rules.The experiments used the NSL-KDD dataset for binary classification.
  • Applications: RuleFit and SHAP were combined to explain IoT intrusion-detection decisions using feature-importance, force, and distribution visualizations.These methods were applied to a DNN trained on UNSW-NB15.
  • Custom methods: TRUST uses latent factors, mutual information, and class-conditional Gaussian distributions to generate probabilistic rationales for predictions.The method was demonstrated on WUSTL-IIoT, NSL-KDD, and UNSW-BW datasets.
  • Explanation taxonomy: The surveyed methods address distinct explanation questions, including how, why, why not, what if, and how to obtain another prediction.Counterfactuals describe minimal changes for a different prediction, while anchors provide high-precision conditions preserving the current prediction.

VI. OPERATIONAL INTEGRATION, SECURITY CONSIDERATIONS, AND RESEARCH DIRECTIONS

The paper frames XAI as an operational aid for industrial SOC triage, investigation, escalation, and documentation, but emphasizes that deployment must account for stakeholder needs, explanation scope, security, reliability, and computational cost.

  • Research directions: The literature provides limited mapping between explanations and specialized industrial stakeholders or SOC tasks, restricting operational applicability.The paper responds with a non-exhaustive mapping of XAI methods to representative SOC tasks.
  • Operational integration: XAI is positioned for alert triage, correlation, prioritization, validity assessment, escalation, cross-team collaboration, and documentation within SOC workflows.Training and explainer fitting occur during preparation, while explanations support real-time analyst interpretation of detected threats.
  • Operational integration: SHAP, LIME, counterfactuals, and contrastive explanations can identify influential features, explain alerts, and indicate changes needed to flip predictions.These outputs can help analysts prioritize artifacts and distinguish borderline behavior from highly anomalous events.
  • Operational integration: Anchor coverage can distinguish rare edge-case alerts from rules that generalize well enough to inform future automated triage.Low coverage suggests further scrutiny, whereas large coverage indicates broader rule applicability.
  • Security considerations: Explanation misinterpretation can distract analysts, justify incorrect predictions, and produce flawed security rules.The paper identifies a literature gap concerning XAI security implications and calls for systematic evaluation of scope, assumptions, vulnerabilities, and secure deployment.
  • Security considerations: LIME may produce divergent explanations because local sampling assumes local linearity, while correlated features can bias simplified explanations from PDP, PFI, SHAP, and LOCO.These limitations create a trade-off between interpretability and fidelity.
  • Security considerations: Computationally intensive explanations can delay incident response, compete with monitoring functions, and introduce performance bottlenecks or denial-of-service risks.Exposing XAI systems can also reveal sensitive model or data information and create opportunities for adversarial manipulation.

B. Emerging Research Needs for Industrial SOC-specific XAI

Industrial SOC-specific XAI requires explainability to be designed around operational stakeholders, domain requirements, and measurable evaluation criteria. Current research remains limited in quantitative and user-centered validation, while contrastive and stakeholder-tailored approaches remain underdeveloped.

  • Industrial SOC-specific XAI Design: Explainability requirements should shape model selection, architecture, and evaluation from the outset to avoid misleading or irrelevant operational explanations.The utility of an explanation also depends on alignment between input-data design and the selected XAI technique.
  • Evaluation Gaps: Only a few surveyed studies quantitatively evaluated their XAI methods, indicating limited evidence for method effectiveness.The review identifies Kalakoti et al. and Arreche et al. as examples that performed quantitative assessment.
  • Evaluation Gaps: Industrial security lacks universally accepted explainability criteria, standardized thresholds, and consistent metric terminology.Researchers therefore use relative comparisons or human-centered validation, which introduce subjectivity and hinder automated evaluation.
  • Industrial Security-specific XAI Evaluation Metrics: Domain-specific metrics and absolute operational-fitness thresholds are feasible and necessary for industrial security explanations.The review does not advocate universal metrics, but calls for defined industrial-security criteria and thresholds.
  • Stakeholder-Centered Validation: User validation should involve actual stakeholders in realistic tasks because explanation effectiveness depends on expertise, context, cognitive capacity, alertness, and available time.Stakeholder participation is costly and scarce, while interviews and questionnaires require careful design to produce reliable results.
  • Emerging Research Needs: Most surveyed studies use associative explanations, leaving contrastive methods and stakeholder-centered XAI design as important research gaps.Contrastive explanations may better align with human explanatory preferences, while existing methods are rarely tailored to industrial stakeholders’ needs.

6) Sequential XAI Techniques for Industrial Environments :

Sequential industrial data and evolving anomalies require XAI methods that represent temporal context rather than only static feature importance. Promising complementary directions include interactive explanations, physics-informed models, and knowledge-graph-based contextual reasoning.

  • Sequential XAI Techniques: Existing sequential-model studies generally apply static feature-importance explanations without accounting for temporal dynamics.This creates a gap because industrial anomalies may emerge through feature changes across multiple time steps.
  • Sequential XAI Techniques: Temporal XAI should identify influential time steps, transitions, and feature-value evolution contributing to predictions.Without temporal interpretability, static explanations may obscure the causes of time-dependent incidents.
  • Engaging and Interactive XAI Systems: Most reviewed XAI methods are static, whereas dialogue and flexible exploration can improve comprehension, trust, and collaboration.Interactive questioning helps users connect explanations to prior knowledge and deepen understanding.
  • Contextualized Explanations Supported by Knowledge Graphs: Knowledge-graph question answering and LLMs offer a route to contextual, user-question-driven explanations for SOC tasks.Retrieval-Augmented Generation can retrieve structured facts and relationships to improve factual grounding and contextual relevance.
  • Physics-Informed XAI: Physics-informed machine learning can ground industrial anomaly detection, attack classification, and explanations in governing physical dynamics.Its use in industrial security remains nascent, with early work particularly surveying potential in power systems.
  • Hybrid Industrial XAI: Knowledge graphs and physics-informed models can be combined to support semantic context, physical consistency, and multimodal reasoning.Knowledge graphs capture roles, configurations, and dependencies, while physics-informed models enforce governing equations.

10) Operational Integration of Large Language Models (LLMs) and Industrial Foundation Models (FMs):

Industrial cybersecurity increasingly combines conventional ML/DL for numerical operational data with LLMs and foundation models for textual, contextual, and multimodal support. The review emphasizes that practical deployment remains constrained by limited realism, scale, and real-world validation in available datasets and studies.

  • LLM and FM Integration: Industrial cybersecurity products and SOC pipelines increasingly integrate LLMs for enrichment, recommendations, and decision support using retrieval, fine-tuning, or human feedback.These systems are aligned with business needs through combinations of RAG, fine-tuning, and human feedback.
  • Complementary Model Roles: Traditional ML/DL processes numerical sensor, visual-defect, and time-series data, while LLMs handle manuals, documentation, logs, and code.The complementary division supports deterministic prediction alongside contextual enrichment and interpretability.
  • Industrial Foundation Models: Industrial foundation models can adapt pretrained transformers to sensor-driven and time-series tasks using parameter-efficient fine-tuning.Freezing most weights and updating small adapter modules or selected layers reduces data and compute requirements.
  • LLM and FM Explainability: LLM and foundation-model explanations include reasoning traces, supervised or reinforcement-based alignment, and retrieval or attribution to source documents.These explanation forms involve different trade-offs between fidelity and usability.
  • Scope Boundary: The survey does not provide an in-depth treatment of LLM and foundation-model explainability.It identifies this topic as an active area within the broader development of transparent and trustworthy industrial AI.
  • Dataset Limitations: Most surveyed research relies on public IT/IoT benchmark IDS datasets, concentrating industrial-security XAI on network-traffic analysis.These datasets support rapid experimentation, reproducibility, and direct performance comparisons, but are not primarily industrial.
  • Dataset Limitations: Synthetic and small-scale datasets often omit realistic behavior, industrial heterogeneity, protocol diversity, and adversary complexity, limiting deployment generalization.Large-scale real-world evaluation across equipment and operational contexts also remains rare.
  • Future Data Sources: Digital twins, ICS honeypots, and reinforcement learning are proposed to improve the realism and richness of industrial attack data.Digital twins provide synchronized multimodal data, honeypots capture authentic attack traces, and RL can generate adaptive attack strategies.
Loading 2609.00171v1…