Abstract

Distributed Energy Resource (DER) environments rely on network communication protocols to coordinate control commands, measurements, and device states across edge assets and cloud systems. Edge anomaly detection systems (ADS) monitor this traffic to identify deviations from normal communication behavior, flagging suspicious flows for further investigation. When the ADS flags abnormal network traffic, a single attack label is often insufficient for operational response: the label reports the detector's selected class but does not expose alternative threat interpretations that may warrant investigation. This paper presents Cybersecurity Threat Reasoning with Explainable Artificial Intelligence (CyTReX), an evidence-grounded threat reasoning framework for DER security that transforms network-level anomaly alerts into ranked, analyst-facing threat hypotheses designed to support Security Operations Center (SOC) triage and investigation. CyTReX constrains large language model (LLM) reasoning through a structured evidence packet, defined as a consolidated record of detection outputs, model explanations, and cyber threat intelligence (CTI) context. The evidence packet integrates edge-layer anomaly detection evidence, cloud reasoning layer attack interpretation, Shapley Additive Explanations (SHAP) network-feature attributions, surrogate decision rules, and Model Context Protocol (MCP)-enabled CTI enrichment. This ensures that every ranked hypothesis and attack-tree branch is traceable to explicit evidence rather than free-form LLM inference, and that incomplete or conflicting evidence is communicated rather than suppressed. Evaluation across five configurations shows that additional reasoning components improve hypothesis specificity, evidence traceability, and analytical grounding, with the complete pipeline providing the richest evidence-grounded reasoning context.

Keywords

Publication details

Journal
Not available
Open access
Green open access

Cite this article

APA 7

Popoola, D., Bhattacharya, S., & Govindarasu, M. (2026). CyTReX: Explainable AI-Based Cybersecurity Threat Reasoning Framework for DER Networks. https://omanscience.com/en/articles/cytrex-explainable-ai-based-cybersecurity-threat-reasoning-framework-for-der-networks

MLA 9

Popoola, Damilola, et al. "CyTReX: Explainable AI-Based Cybersecurity Threat Reasoning Framework for DER Networks." https://omanscience.com/en/articles/cytrex-explainable-ai-based-cybersecurity-threat-reasoning-framework-for-der-networks.

Chicago (author–date)

Popoola, Damilola, Souradeep Bhattacharya, and Manimaran Govindarasu. 2026. "CyTReX: Explainable AI-Based Cybersecurity Threat Reasoning Framework for DER Networks." https://omanscience.com/en/articles/cytrex-explainable-ai-based-cybersecurity-threat-reasoning-framework-for-der-networks.

Harvard

Popoola, D., Bhattacharya, S. and Govindarasu, M. (2026) 'CyTReX: Explainable AI-Based Cybersecurity Threat Reasoning Framework for DER Networks', Available at: https://omanscience.com/en/articles/cytrex-explainable-ai-based-cybersecurity-threat-reasoning-framework-for-der-networks.

Vancouver

Popoola D, Bhattacharya S, Govindarasu M. CyTReX: Explainable AI-Based Cybersecurity Threat Reasoning Framework for DER Networks. https://omanscience.com/en/articles/cytrex-explainable-ai-based-cybersecurity-threat-reasoning-framework-for-der-networks

IEEE

D. Popoola, S. Bhattacharya, and M. Govindarasu, "CyTReX: Explainable AI-Based Cybersecurity Threat Reasoning Framework for DER Networks," https://omanscience.com/en/articles/cytrex-explainable-ai-based-cybersecurity-threat-reasoning-framework-for-der-networks.