<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">69110</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2025.069110</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Intrusion Detection and Security Attacks Mitigation in Smart Cities with Integration of Human-Computer Interaction</article-title>
<alt-title alt-title-type="left-running-head">Intrusion Detection and Security Attacks Mitigation in Smart Cities with Integration of Human-Computer Interaction</alt-title>
<alt-title alt-title-type="right-running-head">Intrusion Detection and Security Attacks Mitigation in Smart Cities with Integration of Human-Computer Interaction</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Alnuaim</surname><given-names>Abeer</given-names></name><email>abalnuaim@ksu.edu.sa</email></contrib>
<aff id="aff-1"><institution>Department of Computer Science and Engineering, College of Applied Studies, King Saud University</institution>, <addr-line>Riyadh, 11451</addr-line>, <country>Saudi Arabia</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Abeer Alnuaim. Email: <email>abalnuaim@ksu.edu.sa</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2025</year></pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>10</day>
<month>11</month>
<year>2025</year>
</pub-date>
<volume>86</volume>
<issue>1</issue>
<fpage>1</fpage>
<lpage>33</lpage>
<history>
<date date-type="received">
<day>15</day>
<month>6</month>
<year>2025</year>
</date>
<date date-type="accepted">
<day>01</day>
<month>8</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2025 The Author.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_69110.pdf"></self-uri>
<abstract>
<p>The rapid digitalization of urban infrastructure has made smart cities increasingly vulnerable to sophisticated cyber threats. In the evolving landscape of cybersecurity, the efficacy of Intrusion Detection Systems (IDS) is increasingly measured by technical performance, operational usability, and adaptability. This study introduces and rigorously evaluates a Human-Computer Interaction (HCI)-Integrated IDS with the utilization of Convolutional Neural Network (CNN), CNN-Long Short Term Memory (LSTM), and Random Forest (RF) against both a Baseline Machine Learning (ML) and a Traditional IDS model, through an extensive experimental framework encompassing many performance metrics, including detection latency, accuracy, alert prioritization, classification errors, system throughput, usability, ROC-AUC, precision-recall, confusion matrix analysis, and statistical accuracy measures. Our findings consistently demonstrate the superiority of the HCI-Integrated approach utilizing three major datasets (CICIDS 2017, KDD Cup 1999, and UNSW-NB15). Experimental results indicate that the HCI-Integrated model outperforms its counterparts, achieving an AUC-ROC of 0.99, a precision of 0.93, and a recall of 0.96, while maintaining the lowest false positive rate (0.03) and the fastest detection time (&#x007E;1.5 s). These findings validate the efficacy of incorporating HCI to enhance anomaly detection capabilities, improve responsiveness, and reduce alert fatigue in critical smart city applications. It achieves markedly lower detection times, higher accuracy across all threat categories, reduced false positive and false negative rates, and enhanced system throughput under concurrent load conditions. The HCI-Integrated IDS excels in alert contextualization and prioritization, offering more actionable insights while minimizing analyst fatigue. Usability feedback underscores increased analyst confidence and operational clarity, reinforcing the importance of user-centered design. These results collectively position the HCI-Integrated IDS as a highly effective, scalable, and human-aligned solution for modern threat detection environments.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Anomaly detection</kwd>
<kwd>smart cities</kwd>
<kwd>Internet of Things (IoT)</kwd>
<kwd>HCI</kwd>
<kwd>CNN</kwd>
<kwd>LSTM</kwd>
<kwd>random forest</kwd>
<kwd>intelligent secure solutions</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>King Saud University</funding-source>
<award-id>ORF-2025-314</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>The rapid development of urban technology made the emergence of smart cities a reality, as higher-level systems and IoT devices enhance urban living quality. These smart infrastructures rely on real-time data collection and analysis to optimize traffic flow, energy grid distribution, and public safety. However, with the introduction of numerous IoT devices and complex networks, significant cybersecurity concerns arise, such as vulnerability to anomalies and malicious attacks. Anomaly detection is now a key component in identifying uncommon patterns that may signal security compromises or system failures within smart city environments. Traditional approaches do not work in defining the dynamic and complex nature of urban data. Thus, more emphasis is being laid on applying advanced technologies such as Artificial Intelligence (AI) and ML to enhance the detection and prevention of security threats [<xref ref-type="bibr" rid="ref-1">1</xref>]. Moreover, the application of HCI principles to smart city infrastructure is growing. HCI designs user-centric interfaces and interactions and ensures that the human aspect remains at the forefront in monitoring, decision-making, and responding to anomalies. By combining anomaly detection mechanisms with effective HCI strategies, smart cities can achieve a more resilient and responsive infrastructure [<xref ref-type="bibr" rid="ref-2">2</xref>]. The HCI-based conceptual scenario is given in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>.</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Conceptual scenario of HCI in smart cities with attack mitigation</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-1.tif"/>
</fig>
<p>The growing use of IoT, cloud technology, smart city frameworks, and advanced information systems has transformed urban areas into unprecedented efficiency and innovation hubs. With these technologies&#x2019; new possibilities come new operational risks and cybersecurity concerns. Cyber-physical systems, and the services enabling them, usually come with weak or no security measures to defend against cyberattacks, data breaches, or system malfunctions. Although AI and machine learning have enabled smarter anomaly detection systems, many of them are too static, lack situational awareness, or do not have enough collaboration with human intelligence and governance. Moreover, the lack of effective HCI mechanisms limits the ability of system administrators, urban planners, and end-users to interact intuitively with anomaly detection platforms, hindering real-time understanding, response, and mitigation. Therefore, there is a critical need to develop an integrated framework combining intelligent anomaly detection with robust HCI design, enabling smart city systems to be autonomous and human-centric in detecting, interpreting, and responding to security threats. This study presents a novel approach to IDS by integrating HCI with advanced machine learning models, specifically CNN, CNN-LSTM, and RF. The key contributions of this research are as follows;</p>
<p><italic>HCI-Integrated IDS Framework:</italic> Introducing an HCI-Integrated IDS for smart cities significantly improves technical performance with operational usability. This system improves detection accuracy and enhances user experience, addressing the crucial issue of alert fatigue among analysts.</p>
<p><italic>Comprehensive Evaluation Framework:</italic> This study employs a rigorous experimental framework that evaluates the performance of the proposed HCI-Integrated IDS against traditional machine learning and baseline IDS models. It assesses a wide range of performance metrics, including detection latency, accuracy, system throughput, usability, and alert prioritization, offering a holistic view of IDS performance.</p>
<p><italic>Improved Performance and Usability:</italic> The HCI-Integrated IDS outperforms existing models in key areas such as precision, recall, detection time, false positive rates, and AUC-ROC score. The model demonstrates significantly faster detection times (approximately 1.5 s) and higher accuracy across all datasets, highlighting its practical application in real-time threat detection scenarios.</p>
<p><italic>Enhanced Analyst Efficiency:</italic> By integrating HCI principles, the system offers more actionable insights through better alert contextualization and prioritization, directly reducing analyst fatigue and improving overall operational clarity. Usability feedback from the system underscores its effectiveness in boosting analyst confidence and enhancing decision-making processes.</p>
<p><italic>Scalability and Adaptability for Smart Cities:</italic> The proposed system is designed to scale efficiently in the dynamic environments of smart cities, effectively handling concurrent loads while maintaining high detection performance. This makes the HCI-Integrated IDS a highly adaptable solution for securing modern urban infrastructures against evolving cyber threats. These contributions position the HCI-Integrated IDS as an innovative, human-aligned solution, advancing the field of anomaly detection in smart city applications.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Literature Review</title>
<p>Anomaly detection in smart cities involves identifying divergences from normal trends in urban data streams, which might represent risks to security or system inefficiencies. Research in recent times has explored a diversity of approaches. Artificial intelligence-based anomaly detection systems have been proposed to identify anomalies and security threats within the smart city IoT networks. These models utilize machine learning algorithms to scan vast amounts of data for unusual patterns [<xref ref-type="bibr" rid="ref-1">1</xref>]. New approaches have been formulated for detecting anomalies caused by cyberattacks against IoT systems in smart cities, highlighting the need for strong cybersecurity practices as things become even more pervasive in the Internet of Things [<xref ref-type="bibr" rid="ref-3">3</xref>]. The application of edge computing in conjunction with cloud processes has been studied to enable real-time anomaly detection, thus enabling fast-track response time and reduced network strain [<xref ref-type="bibr" rid="ref-4">4</xref>]. Securing vulnerabilities in smart cities requires a holistic approach. Several machine learning methods, including Logistic Regression, Support Vector Machines, Decision Trees, RFs, Artificial Neural Networks, and K-Nearest Neighbors, have been applied to detect and counteract the threats to IoT within the framework of smart city systems [<xref ref-type="bibr" rid="ref-5">5</xref>]. The unique characteristics of smart city systems pose challenges in ensuring security. Major challenges include the need for efficient cybersecurity, stakeholder collaboration, and prophylactic action that can help ease the burden imposed by cyberattacks [<xref ref-type="bibr" rid="ref-6">6</xref>]. Integrating computer vision-based, autonomous anomaly detection techniques into surveillance systems has been proposed to create a stronger sense of security in smart cities, reducing reliance on the presence of humans [<xref ref-type="bibr" rid="ref-7">7</xref>]. HCI is crucial for smart city systems. Intuitive interfaces facilitate fast anomaly detection and reactions [<xref ref-type="bibr" rid="ref-2">2</xref>]. Cognitive cities utilize HCI to facilitate collaboration between citizens and systems through IoT [<xref ref-type="bibr" rid="ref-8">8</xref>]. Research emphasizes cybersecurity risks, suggesting HCI solutions [<xref ref-type="bibr" rid="ref-9">9</xref>]. HCI is essential for anomaly detection and smart city security. New technology and user-oriented designs enhance defenses against attacks, safeguarding citizens. Sarker Emon et al. [<xref ref-type="bibr" rid="ref-10">10</xref>] introduced CityShield, an AI-IoT-based real-time system for detecting threats, focusing on edge processing for accuracy and speed. Khan et al. [<xref ref-type="bibr" rid="ref-11">11</xref>] designed a context-aware framework for AI-IoT to detect anomalies in smart cities, with HCI for improved decision-making. Ahmed et al. [<xref ref-type="bibr" rid="ref-12">12</xref>] presented a honeypot-based system for detecting early IoT cyberattacks and isolating them to improve the security in smart cities. Rahmati [<xref ref-type="bibr" rid="ref-13">13</xref>] suggested a privacy-preserving federated learning approach for real-time threat detection. It emphasizes decentralized learning to maintain data privacy while enhancing detection robustness across heterogeneous IoT nodes. Akif et al. [<xref ref-type="bibr" rid="ref-14">14</xref>] developed hybrid ML models using a comprehensive IoT dataset to improve intrusion detection. Their work illustrates that ensemble and stacking techniques offer significant performance gains, especially in multi-class attack scenarios. Hussain et al. [<xref ref-type="bibr" rid="ref-15">15</xref>] proposed a technique for detecting and avoiding all possible spoofing attacks on LiDAR signals to create smart transportation systems that promote security, safety, resilience, and responsiveness. Protick et al. [<xref ref-type="bibr" rid="ref-16">16</xref>] reviewed through sentiment analysis of user reviews, and this study identifies major security and privacy concerns associated with smart home IoT devices. It offers insights for integrating user feedback into HCI-centric security interface design. Pawar and Anuradha [<xref ref-type="bibr" rid="ref-17">17</xref>] presented a novel LSTM-based method for detecting black-hole and wormhole attacks in wireless sensor networks. The study uses optimized deep learning to enhance the early detection of routing-based threats prevalent in smart infrastructure. Priyadarshini [<xref ref-type="bibr" rid="ref-18">18</xref>] combined federated and split learning models to create a distributed anomaly detection system for smart cities. The solution ensures privacy while achieving high detection accuracy, supporting scalable, HCI-informed IDS development. Garg et al. [<xref ref-type="bibr" rid="ref-19">19</xref>] introduced a multi-stage anomaly detection pipeline that integrates filtering, classification, and prioritization stages. The approach is tailored to improve detection granularity and reduce false positives in IoT-enabled applications. Thomas et al. [<xref ref-type="bibr" rid="ref-20">20</xref>] explore using privacy models on smart building datasets, particularly in CO<sub>2</sub> prediction. It highlights how privacy constraints affect data utility and model accuracy, offering implications for HCI-aware system transparency. George [<xref ref-type="bibr" rid="ref-21">21</xref>] broadly reviewed emerging AI trends in cybersecurity. This paper discusses adaptive learning, adversarial robustness, and the importance of interpretable models in AI-IDS systems. It calls for integration with HCI to bridge usability and security. Fan et al. [<xref ref-type="bibr" rid="ref-22">22</xref>] proposed a new outlier detection technique, MRAAD-OF, to improve anomaly scoring in complex datasets. Their method increases anomaly localization precision, essential for real-time IoT threat monitoring. de Chaves and Benitti [<xref ref-type="bibr" rid="ref-23">23</xref>] comprehensively surveyed and outlined current research trends in user-centered privacy and data protection. The study underscores the role of HCI in ensuring transparency, control, and trust in security technologies. Sz&#x00FC;cs et al. [<xref ref-type="bibr" rid="ref-24">24</xref>] focused on digital literacy and interface design; the authors examine HCI&#x2019;s influence on security awareness in digitally immersive environments. Their findings stress the need for interactive, intelligible interfaces in IDS systems. Ortloff et al. [<xref ref-type="bibr" rid="ref-25">25</xref>] qualitatively analysed how security researchers perceive statistical effect sizes; this study informs interface design for data presentation in IDS dashboards. It is relevant to HCI-based alert visualizations. Jiang et al. [<xref ref-type="bibr" rid="ref-26">26</xref>] introduce an adaptive federated learning method for HCI systems, employing actor-critic selection to optimize privacy and performance. It reinforces the trend toward intelligent, context-aware interfaces in cybersecurity, and Shafik [<xref ref-type="bibr" rid="ref-27">27</xref>] explored HCI technologies in socially-enabled AI systems, emphasizing ethical and interactional aspects. It provides a conceptual foundation for integrating HCI with cybersecurity in smart and social environments. Hazman et al. [<xref ref-type="bibr" rid="ref-28">28</xref>] proposed a hybrid LSTM and XGBoost model to detect anomalies and threats in IoT-enabled smart cities. Their approach leverages LSTM&#x2019;s strength in temporal pattern recognition and XGBoost&#x2019;s capability for robust classification. This model demonstrated improved performance in early threat detection, particularly in dynamic and real-time environments, offering a practical solution for urban security operations. Uppal et al. [<xref ref-type="bibr" rid="ref-29">29</xref>] emphasized ensemble machine learning techniques for intrusion detection and privacy preservation, highlighting the effectiveness of combining multiple weak learners for accurate threat classification. Their results reveal that ensemble models significantly enhance detection accuracy while minimizing false positives in smart city network layers. Yedalla [<xref ref-type="bibr" rid="ref-30">30</xref>] explored the broader integration of AI and big data for enhancing cyber resilience in urban infrastructures. The work supports proactive threat mitigation in highly dense smart ecosystems by contextualizing AI&#x2019;s role in predictive analytics, surveillance, and incident response. Brabin et al. [<xref ref-type="bibr" rid="ref-31">31</xref>] introduced CycleGANs to model sophisticated cyberattacks and detect anomalies in IoT streams. The cycle-consistent generative adversarial network enabled unsupervised learning of complex attack patterns, thereby enhancing detection without requiring vast labeled datasets. Pillai et al. [<xref ref-type="bibr" rid="ref-32">32</xref>] developed an LSTM-based privacy-preserving model integrated with blockchain, enhanced by the Archimedes framework, for secure IoT operations. Their approach ensures end-to-end encryption, tamper-proof logging, and adaptive prediction, aligning well with decentralized smart city environments. Hossain and Hasan [<xref ref-type="bibr" rid="ref-33">33</xref>] provided a conceptual and practical overview of cybersecurity challenges in smart cities, covering system vulnerabilities, attack surfaces, and regulatory shortcomings. Their chapter underlines the need for holistic security governance. Ragab et al. [<xref ref-type="bibr" rid="ref-34">34</xref>] contributed a dual reinforcement by working on federated learning-based AI frameworks. They emphasized privacy-preserving threat detection by enabling decentralized learning across edge devices. This federated approach ensures data locality while enabling global model improvement, which is crucial for cities with large-scale sensor deployments. Kezron [<xref ref-type="bibr" rid="ref-35">35</xref>] presented a framework integrating AI with cyber-defense strategies for building resilient and secure smart cities. The study discusses layered defenses, anomaly prediction, and AI policy integration to achieve cyber resilience. Hussain et al. [<xref ref-type="bibr" rid="ref-36">36</xref>] explored blockchain-based secure authentication for smart IoT edge networks, particularly addressing user privacy. Their decentralized model mitigates single-point failures and supports scalability in heterogeneous environments. Goje et al. [<xref ref-type="bibr" rid="ref-37">37</xref>] examined the privacy of electronic health records (EHRs) in smart cities using blockchain. Their study bridges the intersection of eHealth and smart infrastructure, advocating immutable, traceable, and controlled EHR access. Sharma and Singh [<xref ref-type="bibr" rid="ref-38">38</xref>] anticipated security and privacy challenges in 6G-enabled smart cities, discussing terahertz wave interference, quantum attacks, and cross-layer vulnerabilities. Their chapter advocates future-proof security frameworks embedded in 6G architectures. Nyangaresi et al. [<xref ref-type="bibr" rid="ref-39">39</xref>] introduced an anonymous authentication scheme using physically unclonable functions (PUFs) and biometrics, providing robust identity protection. Their solution effectively prevents identity spoofing and ensures trust in smart environments without compromising user privacy. Finally, Abu Al-Haija and Droos [<xref ref-type="bibr" rid="ref-40">40</xref>] delivered a comprehensive survey on deep learning-based intrusion detection systems for IoT. Their work categorized state-of-the-art IDS techniques, evaluated their performance, and highlighted challenges in model generalization, interpretability, and data imbalance. <xref ref-type="table" rid="table-1">Table 1</xref> presents a summary of the most recent literature review.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Summarizing the work, limitations, and comparison with our HCI-Integrated IDS model</title>
</caption>
<table>
<colgroup>
<col/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th>Ref.</th>
<th align="center">Work</th>
<th align="center">Limitations</th>
<th align="center">Comparison with the HCI-Integrated IDS Model</th>
</tr>
</thead>
<tbody>
<tr>
<td>[<xref ref-type="bibr" rid="ref-28">28</xref>]</td>
<td>Proposed a model integrating LSTM and XGBoost to improve security in IoT-enabled smart cities.</td>
<td>Does not consider the usability aspect or human-centered design for improving analyst experience and decision-making.</td>
<td>Our HCI-Integrated IDS integrates LSTM and CNN with HCI principles to improve usability and reduce analyst fatigue, focusing on security and user experience.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-29">29</xref>]</td>
<td>Focused on enhancing accuracy in IDS through ensemble-based machine learning for smart city networks.</td>
<td>Does not incorporate HCI or focus on improving analysts&#x2019; usability and operational engagement.</td>
<td>Our HCI-Integrated IDS model includes HCI to enhance usability, reduce fatigue, and allow for real-time feedback, addressing challenges not covered in this ensemble approach.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-30">30</xref>]</td>
<td>Discussed the role of AI and big data in building cyber-resilient smart cities.</td>
<td>Focuses on AI and big data without addressing the usability and human-centered aspects of IDS.</td>
<td>Our HCI-Integrated IDS model integrates AI with HCI to improve user interaction and reduce alert fatigue, essential for operational efficiency in smart cities.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-31">31</xref>]</td>
<td>Proposed a CycleGAN-based approach to strengthen security in IoT-enabled smart cities.</td>
<td>Does not focus on user experience or HCI, leaving the usability aspect unaddressed.</td>
<td>Our HCI-Integrated IDS integrates HCI to improve the analyst&#x2019;s experience, enhance decision-making, and reduce fatigue, which is not tackled in this GAN-based approach.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-32">32</xref>]</td>
<td>Proposed an LSTM model integrated with blockchain for privacy-preserving IoT systems in smart cities.</td>
<td>Does not consider HCI integration, making it less effective in terms of analyst usability and feedback in real-time.</td>
<td>Our model integrates HCI with LSTM to improve real-time usability, provide actionable insights, and allow analysts to make informed decisions, which is not covered in this blockchain-based approach.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-33">33</xref>]</td>
<td>Reviewed cybersecurity concerns in smart cities.</td>
<td>Does not propose an IDS solution or consider usability and HCI integration for improving the analyst experience.</td>
<td>Our HCI-Integrated IDS model focuses explicitly on human-centered design to improve usability, which is a gap in this review.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-34">34</xref>]</td>
<td>Proposed an AI-based federated learning framework for cyberthreat detection in IoT-enabled smart cities.</td>
<td>Lacks HCI integration for usability, focusing on privacy-preserving aspects and technical performance.</td>
<td>Our model integrates HCI principles to enhance usability and reduce alert fatigue, providing a more holistic solution for smart city cybersecurity.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-35">35</xref>]</td>
<td>Discussed AI in cybersecurity for smart cities, focusing on security frameworks.</td>
<td>Does not consider usability improvements or HCI integration in the IDS process.</td>
<td>Our model integrates HCI to improve usability, making it more human-centered and practical for real-time decision-making compared to purely technical approaches.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-36">36</xref>]</td>
<td>Proposed a blockchain-based authentication method for secure user privacy in edge-based smart city networks.</td>
<td>Focuses on privacy and security without addressing usability or HCI integration for analysts.</td>
<td>Our HCI-Integrated IDS integrates HCI to improve the system&#x2019;s and analysts&#x2019; interaction, focusing on real-time feedback and usability, which is not addressed in this blockchain-based approach.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-37">37</xref>]</td>
<td>Focused on the security and privacy of electronic health records (EHRs) in smart cities using blockchain technology.</td>
<td>Does not address the anomaly detection or usability aspects of smart city IDS systems.</td>
<td>Our HCI-Integrated IDS explicitly addresses the usability of IDS for real-time threat detection and analyst engagement, which is not covered in this blockchain approach.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-38">38</xref>]</td>
<td>Discussed the security and privacy challenges in 6G-enabled smart cities.</td>
<td>Lacks a focus on HCI integration or the usability of IDS systems in a 6G environment.</td>
<td>Our model integrates HCI with advanced machine learning models to ensure better usability, which is not considered in this review of 6G security challenges.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-39">39</xref>]</td>
<td>Proposed an anonymous authentication scheme using physically unclonable functions and biometrics for smart cities.</td>
<td>Does not address anomaly detection or HCI in the context of improving IDS usability.</td>
<td>Our HCI-Integrated IDS model addresses usability by providing real-time feedback to reduce alert fatigue, a factor not covered in this authentication scheme.</td>
</tr>
<tr>
<td>[<xref ref-type="bibr" rid="ref-40">40</xref>]</td>
<td>Provided Future Trends for Cyber Security for Smart Cities and Homes.</td>
<td>Does not focus on human-centered design or the usability of IDS systems.</td>
<td>Our HCI-Integrated IDS integrates deep learning with HCI principles to optimize usability, which is not addressed in this survey.</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><bold><italic>Motivation</italic></bold></p>
<p>The HCI-Integrated IDS proposed in our work significantly advances the capabilities of traditional IDS systems by integrating three powerful machine learning techniques: CNN, CNN-LSTM networks, and RF. Each of these models contributes to the overall strength of the system in unique ways. The CNN is adept at capturing local spatial patterns within data, making it highly effective at identifying features indicative of anomalies, such as traffic spikes or irregular sensor behavior. This is particularly useful in detecting specific local irregularities in the smart city environment, where individual devices or sensors may exhibit abnormal behavior. However, anomalies in a smart city network often evolve, and this is where the CNN-LSTM combination adds tremendous value. While CNN focuses on spatial patterns, LSTM excels at capturing sequential dependencies, making it ideal for understanding time-series data and detecting attacks that unfold progressively. By incorporating both CNN and LSTM in the feature extraction process, our method can identify immediate anomalies and those that develop and escalate over time. This allows the system to adapt more effectively to evolving attack patterns that traditional systems may fail to detect, particularly when predefined signatures or static anomaly baselines do not recognize these attacks.</p>
<p>Furthermore, including RF in our approach further enhances the system&#x2019;s robustness and accuracy. RF is a powerful ensemble learning method that combines multiple decision trees to make predictions, which improves classification accuracy by reducing overfitting. This technique is particularly effective in handling complex decision-making processes, especially when the relationships between features are nonlinear and complex. Unlike traditional IDS systems that may rely on single-model approaches, our hybrid method leverages the strengths of CNN, LSTM, and RF in a complementary manner. The CNN and LSTM layers provide high-quality feature extraction and sequential learning, while the RF uses these extracted features to make more informed and accurate predictions. This combination not only improves the system&#x2019;s detection capabilities but also significantly reduces the occurrence of false positives, a common challenge in traditional anomaly detection systems.</p>
<p>Additionally, our method incorporates a feedback loop facilitated by the HCI interface, allowing continuous model refinement based on user interactions. This makes the system more adaptive and effective in real-time scenarios, ensuring that the IDS stays relevant and accurate over time. By integrating these advanced machine learning techniques with an interactive user interface, our method surpasses the limitations of baseline machine learning IDS and traditional IDS systems, offering a more dynamic, responsive, and accurate solution to smart city security.</p>
</sec>
<sec id="s3">
<label>3</label>
<title>Methodology</title>
<p>Our proposed HCI-Integrated IDS leverages powerful ML techniques, combining CNN, CNN-LSTM, and RF models to provide a comprehensive and adaptive approach to detecting and mitigating security threats in smart cities. The system enables real-time feedback by integrating HCI, improving its ability to adapt to new threats and user input dynamically. CNN plays a crucial role in our system by extracting spatial features from the input data, such as network traffic and IoT sensor data. The convolutional layers of the CNN perform the primary task of detecting local patterns, applying a filter (kernel) to the input feature map, and producing a feature map that highlights relevant spatial characteristics. This is followed by an activation function, such as ReLU, which introduces non-linearity, and a pooling layer to reduce the spatial dimensions of the feature map, ensuring efficient processing. The final step of the CNN is a fully connected layer that uses Softmax to classify the data into different categories, making it highly effective for detecting specific anomalies like sudden traffic spikes or irregular sensor data. <xref ref-type="fig" rid="fig-2">Fig. 2</xref> shows the proposed threat mitigation model, in which the first stage shows the threat model and 2nd stage shows the proposed mitigation model. The integration of CNN with LSTM furthers the system&#x2019;s detection capabilities by capturing temporal dependencies in the data. The CNN extracts spatial features at each time step, while the LSTM layer processes these extracted features over time, capturing sequential patterns essential for understanding how anomalies evolve. The LSTM uses hidden and cell states to maintain memory of previous time steps, making it ideal for detecting attacks that unfold gradually, such as DDoS attacks or long-term data manipulations. After processing the sequential data, the output is passed through a fully connected layer with Softmax activation for classification, ensuring that the system can handle both spatial and temporal aspects of the data simultaneously.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Proposed threat mitigation model</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-2.tif"/>
</fig>
<p>Finally, RF enhances decision-making by providing a robust ensemble learning mechanism. Each decision tree in the RF makes a prediction based on a subset of the input features, and the final classification is determined by majority voting across all trees. This approach is particularly useful for handling complex decision-making scenarios, where a single model may not easily capture the relationships between features. RF also mitigates overfitting, ensuring that the IDS remains accurate even when dealing with noisy or incomplete data. By combining these three models, CNN for spatial feature extraction, LSTM for sequential learning, and RF for robust classification, our HCI-Integrated IDS offers a powerful and adaptable solution for detecting, classifying, and mitigating threats in real-time, making it more effective than baseline and traditional IDS approaches. The HCI integration further improves the system by allowing user feedback to refine the model continuously, ensuring that it stays relevant and responsive to emerging security threats in the dynamic environment of smart cities.</p>
<p><list list-type="bullet">
<list-item>
<p><bold>Datasets</bold></p></list-item>
</list></p>
<p>The CICIDS 2017 dataset, created by the Canadian Institute for Cybersecurity, is tailored for IDS research and contains labeled network traffic data, including various attacks such as DDoS and brute force, making it ideal for training IDS models in smart cities. The KDD Cup 1999 dataset, one of the most widely used for intrusion detection, offers diverse network traffic data with labeled attack types like backdoors and denial-of-service, providing a foundation for evaluating IDS models with an HCI perspective. Lastly, the UNSW-NB15 dataset, developed by the University of New South Wales, includes over 2.5 million records, covering modern and traditional attack methods, and is highly suitable for smart city security research that integrates user behavior patterns with IDS for enhanced attack detection and prevention.</p>
<p>In the context of a smart city, the infrastructure is embedded with a vast network of interconnected devices such as sensors, cameras, meters, and actuators. These devices constantly generate real-time data streams representing urban phenomena, traffic flow, air quality, energy consumption, and user behavior. Let the data generated from various devices at time <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mi>t</mml:mi></mml:math></inline-formula> be denoted as a multivariate time-series <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:mi>X</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, where each <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mi>t</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> corresponds to the data from a specific device or sensor. This raw data forms the foundational input for the anomaly detection process. The next phase is data collection, where all generated sensor data is aggregated and transmitted, typically using IoT gateways and edge computing infrastructure, to a centralized or distributed cloud storage. The collected dataset <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:mi>D</mml:mi><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>X</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>X</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>X</mml:mi><mml:mrow><mml:mi>T</mml:mi></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> is then prepared for analysis. Preprocessing steps such as normalization, noise removal, and temporal alignment may be applied to improve quality. <xref ref-type="fig" rid="fig-3">Fig. 3</xref> illustrates the basic flowchart of the proposed methodology.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Flowchart of proposed method</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-3.tif"/>
</fig>
<p><bold>System Mathematical Model</bold></p>
<sec id="s3_1">
<label>3.1</label>
<title>Data Collection Process</title>
<p>Let <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> represent the data point from an IoT sensor at time <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:mi>t</mml:mi></mml:math></inline-formula>, where <inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:mi>n</mml:mi></mml:math></inline-formula> is the number of features (sensors). The data is continuously added to a dynamic dataset, <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>.
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>&#x222A;</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow><mml:mrow><mml:mtext>where</mml:mtext></mml:mrow><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msup></mml:math></disp-formula>where, <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>: The dataset at time <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:mi>t</mml:mi></mml:math></inline-formula> after collecting new data <inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, and <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>: It is a new data entry from the IoT system.</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Feature Extraction Process</title>
<p>At each time step <inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:mi>t</mml:mi></mml:math></inline-formula>, the raw data <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is transformed into a feature vector <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>, where <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:mi>m</mml:mi></mml:math></inline-formula> is the number of features extracted from <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>.
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>E</mml:mi><mml:mi>x</mml:mi><mml:mi>t</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>F</mml:mi><mml:mi>e</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>u</mml:mi><mml:mi>r</mml:mi><mml:mi>e</mml:mi><mml:mi>s</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mtext>for each</mml:mtext></mml:mrow><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula>
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:msub><mml:mi>z</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>z</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>z</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>m</mml:mi></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow><mml:mrow><mml:mtext>&#xA0;where</mml:mtext></mml:mrow><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi></mml:mrow></mml:msup></mml:math></disp-formula>where, <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is the feature vector extracted from the raw data point <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>.</p>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Anomaly Detection Process</title>
<p>Let the <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mi>M</mml:mi><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mi>m</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> (CNN, LSTM, and RF) be composed of a sequence of operations that process the input feature vector <inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>.
<list list-type="bullet">
<list-item>
<p><bold>Reconstruction Step</bold></p></list-item>
</list></p>
<p>The <inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:mi>M</mml:mi><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mi>M</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> Reconstructs the feature vector <inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> to obtain <inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mrow><mml:mover><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>, where the reconstruction is learned through the training process.
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mrow><mml:mover><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>M</mml:mi><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mi>M</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mtext>where</mml:mtext></mml:mrow><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mrow><mml:mover><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow></mml:mrow></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mrow><mml:mi>m</mml:mi></mml:mrow></mml:msup></mml:math></disp-formula>
<list list-type="bullet">
<list-item>
<p><bold>Anomaly Score Calculation</bold></p></list-item>
</list></p>
<p>The anomaly score <inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is calculated as the squared Euclidean distance between the original feature vector <inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and its reconstructed version <inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mrow><mml:mover><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>.
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=&#x2225;</mml:mo><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mrow><mml:mover><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow></mml:mrow></mml:msub><mml:msup><mml:mo>&#x2225;</mml:mo><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>m</mml:mi></mml:mrow></mml:munderover><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>z</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mrow><mml:mover><mml:mi>z</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></disp-formula>where, <inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:msub><mml:mi>z</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>: The <inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:msup><mml:mi>k</mml:mi><mml:mrow><mml:mrow><mml:mtext>th</mml:mtext></mml:mrow></mml:mrow></mml:msup></mml:math></inline-formula> feature in the original feature vector <inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, and <inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:msub><mml:mrow><mml:mover><mml:mi>z</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mi>i</mml:mi><mml:mi>k</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>: The <inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:msup><mml:mi>k</mml:mi><mml:mrow><mml:mrow><mml:mtext>th</mml:mtext></mml:mrow></mml:mrow></mml:msup></mml:math></inline-formula> feature in the reconstructed feature vector <inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mrow><mml:mover><mml:mi>i</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>. If <inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> exceeds a predefined threshold <inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:mi>&#x03B8;</mml:mi></mml:math></inline-formula>, an alert is generated.
<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:mi>A</mml:mi><mml:mi>l</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mrow><mml:msub><mml:mi>Z</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>G</mml:mi><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>A</mml:mi><mml:mi>l</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>t</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mrow><mml:msub><mml:mi>Z</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mi>i</mml:mi><mml:mi>f</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:mrow><mml:mo>&#x003E;</mml:mo><mml:mi>&#x03B8;</mml:mi></mml:math></disp-formula>where, <inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:mi>A</mml:mi><mml:mi>l</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>t</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is the alert generated for anomaly detection, and <inline-formula id="ieqn-37"><mml:math id="mml-ieqn-37"><mml:mi>&#x03B8;</mml:mi></mml:math></inline-formula> is the anomaly detection threshold.</p>
</sec>
<sec id="s3_4">
<label>3.4</label>
<title>User Interaction and Classification</title>
<p>Upon generating an alert, the alert is displayed to the user through the UI. The user then classifies the threat <italic>UserClass</italic> based on the alert. The classification can be represented as a decision function <inline-formula id="ieqn-38"><mml:math id="mml-ieqn-38"><mml:mi>f</mml:mi></mml:math></inline-formula> as;
<disp-formula id="eqn-7"><label>(7)</label><mml:math id="mml-eqn-7" display="block"><mml:mi>U</mml:mi><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>C</mml:mi><mml:mi>l</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:mo>=</mml:mo><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>A</mml:mi><mml:mi>l</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula>where, <inline-formula id="ieqn-39"><mml:math id="mml-ieqn-39"><mml:mi>U</mml:mi><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>C</mml:mi><mml:mi>l</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>C</mml:mi><mml:mi>l</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:mi>l</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:mi>l</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:mi>N</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> represents the threat class identified by the user, and <inline-formula id="ieqn-40"><mml:math id="mml-ieqn-40"><mml:mi>f</mml:mi></mml:math></inline-formula> is a function that processes the alert and outputs a threat class.</p>
</sec>
<sec id="s3_5">
<label>3.5</label>
<title>Mitigation Strategy</title>
<p>The system recommends a mitigation action <inline-formula id="ieqn-41"><mml:math id="mml-ieqn-41"><mml:mi>A</mml:mi><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:math></inline-formula> based on the classified threat <inline-formula id="ieqn-42"><mml:math id="mml-ieqn-42"><mml:mi>U</mml:mi><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>C</mml:mi><mml:mi>l</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>s</mml:mi></mml:math></inline-formula>. This is represented as a function <inline-formula id="ieqn-43"><mml:math id="mml-ieqn-43"><mml:mi>R</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi><mml:mi>M</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>g</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:math></inline-formula> that maps the user class to an appropriate action.
<disp-formula id="eqn-8"><label>(8)</label><mml:math id="mml-eqn-8" display="block"><mml:mi>A</mml:mi><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mo>=</mml:mo><mml:mi>R</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi><mml:mi>M</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>g</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>U</mml:mi><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>C</mml:mi><mml:mi>l</mml:mi><mml:mi>a</mml:mi><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>where, <inline-formula id="ieqn-44"><mml:math id="mml-ieqn-44"><mml:mi>A</mml:mi><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:math></inline-formula> is the mitigation action recommended for the identified threat, <inline-formula id="ieqn-45"><mml:math id="mml-ieqn-45"><mml:mi>R</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>m</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi><mml:mi>M</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>g</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:math></inline-formula> is a decision-making function that assigns the appropriate mitigation strategy based on the classified threat. The action <inline-formula id="ieqn-46"><mml:math id="mml-ieqn-46"><mml:mi>A</mml:mi><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi></mml:math></inline-formula> is then executed as;
<disp-formula id="eqn-9"><label>(9)</label><mml:math id="mml-eqn-9" display="block"><mml:mi>E</mml:mi><mml:mi>x</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>M</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>g</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>A</mml:mi><mml:mi>c</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
</sec>
<sec id="s3_6">
<label>3.6</label>
<title>Feedback Loop for Model Improvement</title>
<p>User feedback <inline-formula id="ieqn-47"><mml:math id="mml-ieqn-47"><mml:mi>F</mml:mi><mml:mi>e</mml:mi><mml:mi>e</mml:mi><mml:mi>d</mml:mi><mml:mi>b</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>k</mml:mi></mml:math></inline-formula> is obtained regarding the alert and mitigation action. If the feedback is valid, it is used to update the machine learning model <inline-formula id="ieqn-48"><mml:math id="mml-ieqn-48"><mml:mi>M</mml:mi><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mi>M</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>.</p>
<p>Let the user feedback be denoted as <inline-formula id="ieqn-49"><mml:math id="mml-ieqn-49"><mml:mi>F</mml:mi><mml:mi>e</mml:mi><mml:mi>e</mml:mi><mml:mi>d</mml:mi><mml:mi>b</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>k</mml:mi><mml:mo>&#x2208;</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mrow><mml:mi>q</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>, where <inline-formula id="ieqn-50"><mml:math id="mml-ieqn-50"><mml:mi>q</mml:mi></mml:math></inline-formula> is the dimensionality of the feedback data. The feedback is processed to adjust the model parameters.
<disp-formula id="eqn-10"><label>(10)</label><mml:math id="mml-eqn-10" display="block"><mml:mi>F</mml:mi><mml:mi>e</mml:mi><mml:mi>e</mml:mi><mml:mi>d</mml:mi><mml:mi>b</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mi>G</mml:mi><mml:mi>e</mml:mi><mml:mi>t</mml:mi><mml:mi>U</mml:mi><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>F</mml:mi><mml:mi>e</mml:mi><mml:mi>e</mml:mi><mml:mi>d</mml:mi><mml:mi>b</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>k</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>A</mml:mi><mml:mi>l</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula></p>
<p>If the feedback is valid, then;
<disp-formula id="eqn-11"><label>(11)</label><mml:math id="mml-eqn-11" display="block"><mml:mi>U</mml:mi><mml:mi>p</mml:mi><mml:mi>d</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>M</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>M</mml:mi><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mi>M</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>F</mml:mi><mml:mi>e</mml:mi><mml:mi>e</mml:mi><mml:mi>d</mml:mi><mml:mi>b</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>k</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>where, <inline-formula id="ieqn-51"><mml:math id="mml-ieqn-51"><mml:mi>U</mml:mi><mml:mi>p</mml:mi><mml:mi>d</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>M</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>M</mml:mi><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mi>M</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>F</mml:mi><mml:mi>e</mml:mi><mml:mi>e</mml:mi><mml:mi>d</mml:mi><mml:mi>b</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>k</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is a function that updates the machine learning model <inline-formula id="ieqn-52"><mml:math id="mml-ieqn-52"><mml:mi>M</mml:mi><mml:msub><mml:mi>L</mml:mi><mml:mrow><mml:mi>M</mml:mi><mml:mi>o</mml:mi><mml:mi>d</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi><mml:mi>s</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> using the collected feedback. Algorithm 1 shows the schematic process of the proposed model.</p>
<fig id="fig-30">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-30.tif"/>
</fig>
<p>The Algorithm 1 integrates CNN, CNN-LSTM networks, and Random Forest (RF) models for anomaly detection. The CNN is responsible for extracting spatial features, while the LSTM captures sequential dependencies in the data, and RF performs robust classification based on the features extracted by CNN and LSTM. The hyperparameters used for each model are as follows: for the CNN, the network consists of three convolutional layers with filter sizes [32, 64, 128], a kernel size of (3, 3), and a ReLU activation function. Max pooling is applied with a pool size of (2, 2), and the fully connected layer contains 512 units. A dropout rate of 0.5 and a learning rate of 0.001 are used. For the LSTM, the model includes two layers with 64 hidden units per layer, a tanh activation function, a learning rate of 0.001, a batch size of 64, and a dropout rate of 0.3. The Random Forest model uses 100 trees, a max depth of 10, a minimum sample size of 2 to split nodes, and considers the square root of features when making splits. Following data collection, the system moves into feature extraction, a process essential for reducing dimensionality and extracting meaningful representations from raw data. Suppose a function <inline-formula id="ieqn-53"><mml:math id="mml-ieqn-53"><mml:mi>&#x03D5;</mml:mi><mml:mo>&#x003A;</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mi>R</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> maps high-dimensional data <inline-formula id="ieqn-54"><mml:math id="mml-ieqn-54"><mml:msub><mml:mi>X</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> to a feature space <inline-formula id="ieqn-55"><mml:math id="mml-ieqn-55"><mml:mi>Z</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mi>&#x03D5;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>X</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where <inline-formula id="ieqn-56"><mml:math id="mml-ieqn-56"><mml:mi>k</mml:mi><mml:mo>&#x226A;</mml:mo><mml:mi>n</mml:mi></mml:math></inline-formula>. These features may include statistical measures like mean, standard deviation, entropy, or frequency components, which help capture temporal and spatial dependencies across devices. Subsequently, these features are input into an anomaly detection model, often driven by machine learning or deep learning techniques. One common approach is to use a probabilistic model or an autoencoder that learns the distribution <inline-formula id="ieqn-57"><mml:math id="mml-ieqn-57"><mml:msub><mml:mi>P</mml:mi><mml:mrow><mml:mi>Z</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> of normal behavior. An anomaly score <inline-formula id="ieqn-58"><mml:math id="mml-ieqn-58"><mml:msub><mml:mi>A</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> can then be computed using the reconstruction error or likelihood, for instance, which is given in <xref ref-type="disp-formula" rid="eqn-12">Eq. (12)</xref> as
<disp-formula id="eqn-12"><label>(12)</label><mml:math id="mml-eqn-12" display="block"><mml:mi>A</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>t</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>Z</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>t</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mover><mml:mi>Z</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>t</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></disp-formula>where, <inline-formula id="ieqn-59"><mml:math id="mml-ieqn-59"><mml:mrow><mml:mover><mml:mi>Z</mml:mi><mml:mo stretchy="false">&#x005E;</mml:mo></mml:mover></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>t</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is the reconstructed feature from the model. If <inline-formula id="ieqn-60"><mml:math id="mml-ieqn-60"><mml:mi>A</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>t</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x003E;</mml:mo><mml:mi>&#x03B8;</mml:mi></mml:math></inline-formula> for some predefined threshold <inline-formula id="ieqn-61"><mml:math id="mml-ieqn-61"><mml:mi>&#x03B8;</mml:mi></mml:math></inline-formula>, the event is flagged as anomalous. This detection triggers the alert generation step, producing a warning signal and initiating the mitigation workflow.</p>
<p>Once an alert is triggered, it is routed to a user interface for alert presentation, enabling system administrators or city security personnel to visualize and interact with the event. This interaction is governed by principles of HCI, where the system&#x2019;s transparency, interpretability, and responsiveness are paramount. The system presents the anomaly and contextual metadata such as timestamp, device ID, anomaly score, and probable cause. Using domain knowledge and interface support, the human operator performs threat classification, analyzing the alert to determine whether it represents a benign irregularity or a serious cyber threat such as a DDoS attack, intrusion, or sensor spoofing. Formally, a threat classifier <inline-formula id="ieqn-62"><mml:math id="mml-ieqn-62"><mml:mi>f</mml:mi><mml:mo>&#x003A;</mml:mo><mml:msup><mml:mi>R</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msup><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> may be used to assist the human in labeling the anomaly into one of C known threat classes. Based on this classification, the operator selects or confirms a mitigation strategy, including automatic responses (e.g., IP blocking, data routing adjustments) or manual interventions (e.g., dispatching field teams, disabling components). A critical part of this framework is the feedback loop via Human-Computer Interaction, where the user can provide validation (confirm or reject alerts), improving the model over time. This loop enables a semi-supervised learning mechanism, where human feedback is used. <inline-formula id="ieqn-63"><mml:math id="mml-ieqn-63"><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> is used to retrain or fine-tune the anomaly detection model, minimizing future false positives and negatives. This can be formulated as an online learning problem, and is given in <xref ref-type="disp-formula" rid="eqn-13">Eq. (13)</xref> as
<disp-formula id="eqn-13"><label>(13)</label><mml:math id="mml-eqn-13" display="block"><mml:munder><mml:mo movablelimits="true" form="prefix">min</mml:mo><mml:mrow><mml:mi>&#x03B8;</mml:mi></mml:mrow></mml:munder><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:munder><mml:mi>L</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>f</mml:mi><mml:mi>&#x03B8;</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>Z</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>t</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mi>y</mml:mi><mml:mi>t</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula>where, <inline-formula id="ieqn-64"><mml:math id="mml-ieqn-64"><mml:mi>L</mml:mi></mml:math></inline-formula> is the loss function and <italic>&#x03B8;</italic> are model parameters updated over time using user interaction data. The proposed framework integrates smart city data flows with intelligent anomaly detection and human-centered decision-making. It combines real-time analytics, machine intelligence, and intuitive interaction design to ensure timely and accurate mitigation of security attacks, balancing automation with human oversight in a dynamic urban environment. <xref ref-type="fig" rid="fig-4">Fig. 4</xref> illustrates the proposed model&#x2019;s framework.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Illustration of the proposed model&#x2019;s framework</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-4.tif"/>
</fig>
<p>Each model in the system (CNN, CNN-LSTM, and RF) contributes uniquely to the overall anomaly detection and mitigation process in the smart city framework. The CNN focuses on spatial feature extraction, the CNN-LSTM captures sequential dependencies, and the RF aggregates predictions for a robust decision-making process. At each time step, the datasets are updated by appending the new sensor reading, allowing them to grow as new data points are continuously collected. Each new data point is then transformed into a structured feature vector, which helps capture the essential characteristics of the IoT sensor readings. The system computes the anomaly score to detect anomalies by measuring the Euclidean squared distance between the original and reconstructed feature vectors. An alert is triggered if the anomaly score exceeds a predefined threshold, indicating a detected anomaly. When the anomaly score surpasses the threshold, the system generates an alert and activates the HCI interface to notify the user. Based on the alert, the user classifies the threat into predefined categories, with the classification label output by a function. The recommended mitigation action is then determined based on the user&#x2019;s classification, and the action is executed to address the detected anomaly or threat. After mitigation, user feedback is collected, which is then used to update the machine learning models (CNN, CNN-LSTM, and RF). This feedback loop ensures the model improves over time based on real-world interactions, continuously enhancing the system&#x2019;s performance.</p>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Results</title>
<p>The experiments used Python 3.8 as the primary programming language, with key ML libraries such as TensorFlow 2.5, Keras, and scikit-learn. The models were trained and tested on a system with an NVIDIA RTX 3080 GPU, an Intel Core i7-10700K CPU, and 32 GB of RAM, ensuring the environment was consistent across all experiments to guarantee fair comparisons. CNN, CNN-LSTM networks, and Random Forest (RF) were used for the model implementations. The CNN model was employed for spatial feature extraction from the data, while the CNN-LSTM hybrid model was utilized for capturing both spatial and temporal dependencies. The RF model provided robust classification based on the extracted features from CNN and LSTM. The models were implemented using TensorFlow 2.5 for CNN and LSTM, and scikit-learn 0.24 for the RF model. Hyperparameters for the models were optimized using grid search, with values as follows. <italic>CNN</italic>: 3 convolutional layers with filter sizes [32, 64, 128], kernel size (3, 3), ReLU activation function, max pooling with pool size (2, 2), fully connected layer with 512 units, dropout rate of 0.5, and a learning rate of 0.001. <italic>LSTM</italic>: 2 LSTM layers with 64 hidden units, tanh activation function, dropout rate of 0.3, learning rate of 0.001, and a batch size of 64. <italic>Random Forest</italic>: 100 trees, max depth of 10, minimum samples per split of 2, and maximum features as the square root of the total features. The datasets used for training and testing were CICIDS 2017, KDD Cup 1999, and UNSW-NB15. These datasets were preprocessed by performing normalization, noise removal, and temporal alignment to improve the quality of the input data. Each dataset was split into training (80%) and testing (20%) sets. The splits were consistent across all models to ensure a fair comparison. These datasets are well-suited for evaluating IDS performance, as they contain various attack types, including DDoS, brute force, and others, representing real-world security threats. The baseline systems used for comparison included traditional IDS based on classic ML models like Support Vector Machines (SVM), k-Nearest Neighbors (k-NN), and Decision Trees. These models were implemented using scikit-learn 0.24 and were trained and tested on the same datasets, following the same preprocessing steps to ensure consistency in the evaluation. Several performance metrics were calculated for the assessment, including accuracy, precision, recall, AUC-ROC, false positive rate, and detection latency. Each of these metrics was used to assess the effectiveness of the models. The evaluation was performed under identical experimental conditions for all models. Additionally, 10-fold cross-validation was applied for each model to account for any variability in the results and ensure that the reported performance metrics were robust and reliable.</p>
<p>To assess the efficacy of the proposed HCI-Integrated IDS, we conducted a comparative evaluation against a Baseline ML Model and a Traditional IDS using several performance metrics. The assessment encompassed classification effectiveness, error analysis, detection latency, and overall system reliability.</p>
<sec id="s4_1">
<label>4.1</label>
<title>Classification Performance</title>
<p>ROC and PR curves evaluated the quality of classification at varying thresholds. HCI-Integrated performed AUC-ROC &#x003D; 0.99, higher than Baseline ML (AUC &#x003D; 0.92) and Traditional IDS (AUC &#x003D; 0.87). A PR curve reflected a high precision for most recall values in HCI-Integrated, with a good discrimination in unbalanced data. These outcomes signify the higher quality of HCI-Integrated in proper classification with low false negatives and positives.</p>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Confusion Matrix Analysis</title>
<p>A detailed examination of the confusion matrices highlights that the classification outcomes for each model are discussed as follows. <italic>HCI-Integrated</italic>: 491 True Positives (TP), 19 False Negatives (FN), 456 True Negatives (TN), 34 False Positives (FP), <italic>Baseline ML</italic>: 442 TP, 68 FN, 403 TN, 87 FP, and <italic>Traditional IDS</italic>: 396 TP, 114 FN, 387 TN, 103 FP. The HCI-Integrated system demonstrated the lowest false negative and false positive rates, translating to a higher detection rate and fewer erroneous alerts. This balance is critical for minimizing security risks while maintaining operational efficiency.</p>
</sec>
<sec id="s4_3">
<label>4.3</label>
<title>Detection Latency</title>
<p>Detection speed is a crucial metric in real-time intrusion detection. A box plot comparison of detection times reveals that HCI-Integrated had the fastest median detection time (&#x007E;1.5 s), with minimal variance, and Baseline ML recorded a median of &#x007E;2.6 s. Traditional IDS was the slowest, with a median above 3 s and higher variability. The HCI-Integrated model&#x2019;s ability to deliver rapid and consistent detection significantly enhances its practicality for deployment in dynamic, high-throughput environments.</p>
</sec>
<sec id="s4_4">
<label>4.4</label>
<title>Comparative Performance Metrics</title>
<p>Across key evaluation metrics, the HCI-Integrated model consistently outperformed the other approaches;</p>
<p>In the comparative evaluation of the HCI-Integrated IDS against the Baseline ML model and Traditional IDS, a multidimensional performance analysis was conducted across latency, accuracy, usability, cost-efficiency, and resource consumption. The HCI-Integrated model consistently demonstrated superior performance across nearly all evaluated metrics, supporting its potential as a robust advancement in IDS technologies. <xref ref-type="fig" rid="fig-5">Fig. 5</xref> shows evaluation of accuracy, recall, precision, and false positive, <xref ref-type="fig" rid="fig-6">Fig. 6</xref> shows a confusion matrix, <xref ref-type="fig" rid="fig-7">Fig. 7</xref> shows detection speed in terms of time (s), <xref ref-type="fig" rid="fig-8">Fig. 8</xref> illustrates a curve of false positive and recall, while <xref ref-type="table" rid="table-2">Table 2</xref> presents performance evaluations in numeric illustrations.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Evaluation of accuracy, recall, precision, and false positive</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-5.tif"/>
</fig><fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Confusion matrix</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-6.tif"/>
</fig><fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>Detection speed in terms of time (s)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-7.tif"/>
</fig><fig id="fig-8">
<label>Figure 8</label>
<caption>
<title>Curve of false positive and recall</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-8.tif"/>
</fig><table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Performance evaluations in numeric illustrations</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Metric</th>
<th>HCI-Integrated</th>
<th>Baseline ML</th>
<th>Traditional IDS</th>
</tr>
</thead>
<tbody>
<tr>
<td>Accuracy</td>
<td>0.94</td>
<td>0.89</td>
<td>0.85</td>
</tr>
<tr>
<td>Precision</td>
<td>0.93</td>
<td>0.87</td>
<td>0.83</td>
</tr>
<tr>
<td>Recall (Sensitivity)</td>
<td>0.96</td>
<td>0.89</td>
<td>0.81</td>
</tr>
<tr>
<td>False Positive Rate</td>
<td>0.03</td>
<td>0.07</td>
<td>0.12</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s4_5">
<label>4.5</label>
<title>Detection Latency and Time Distribution</title>
<p>The histogram and Kernel Density Estimation (KDE) plots clearly show that the HCI-Integrated system outperforms Baseline ML and Traditional IDS in terms of detection speed. The detection time for HCI-Integrated clusters is between 1.2 and 1.7 s, with a pronounced peak at approximately 1.5 s, indicating a highly consistent and rapid response. In contrast, the Baseline ML exhibits a broader distribution centered around 2.6 s, while Traditional IDS lags further with a peak near 3.3 s. The KDE plot reaffirms this performance gap, highlighting not only the faster but also more predictable latency of the HCI-Integrated model. <xref ref-type="fig" rid="fig-9">Fig. 9</xref> shows the Detection Time Distribution of HCI-Integrated IDS (Proposed), <xref ref-type="fig" rid="fig-10">Fig. 10</xref> illustrates the Detection Time Distribution of Baseline IDS, and <xref ref-type="fig" rid="fig-11">Fig. 11</xref> shows the Detection Time Distribution of Traditional IDS.</p>
<fig id="fig-9">
<label>Figure 9</label>
<caption>
<title>Detection time distribution of HCI-integrated IDS (proposed)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-9.tif"/>
</fig><fig id="fig-10">
<label>Figure 10</label>
<caption>
<title>Detection time distribution of baseline IDS</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-10.tif"/>
</fig><fig id="fig-11">
<label>Figure 11</label>
<caption>
<title>Detection time distribution of traditional IDS</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-11.tif"/>
</fig>
</sec>
<sec id="s4_6">
<label>4.6</label>
<title>Accuracy Trends over Time</title>
<p>The exhaustive longitudinal analysis that carefully explores detection accuracy at different time steps demonstrates that the HCI-Integrated model invariably has a significantly higher accuracy. The model displays a credible mean accuracy that oscillates between a value of nearly 0.94 and as high as 0.95. In stark contrast, the Baseline ML model also demonstrates notable fluctuations in performance, with a mean accuracy that hovers closely around the value of nearly 0.90. Alternatively, the Traditional IDS model is static in a low mean accuracy, oscillating closely at almost 0.86. The unflinching stability revealed in the performance of the HCI-Integrated model over time denotes the presence of a strong learning mechanism. The mechanism adapts and learns in the constantly varying threat environments it is subjected to. <xref ref-type="fig" rid="fig-12">Fig. 12</xref> shows the Accuracy Evolution Evaluation over Time.</p>
<fig id="fig-12">
<label>Figure 12</label>
<caption>
<title>Accuracy evolution evaluation over time</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-12.tif"/>
</fig>
</sec>
<sec id="s4_7">
<label>4.7</label>
<title>Detection Accuracy by Threat Category</title>
<p>Amidst the intricate and multidimensional background of different categories of threats, including Denial of Service (DoS) attacks, Probe activities, Remote to Local (R2L) incursions, User to Root (U2R) breaches, as well as what is commonly categorized as Normal traffic, the HCI-Integrated Intrusion Detection System (IDS) presents a staggering capability that dramatically improves detection accuracy compared to its industry equivalents. It exhibits a phenomenally high degree of near-perfect accuracy, ranging between 0.97 and 0.98 for DoS and Normal traffic categories, respectively. In addition, this novel system depicts a remarkable edge over other current detection systems in terms of detecting more intricate and subtle types of attacks, especially those falling under the U2R and R2L categories. These phenomenal findings strongly indicate that the HCI approach surpasses others in successfully identifying high-volume attack patterns. However, it also demonstrates its effectiveness in uncovering more subtle, targeted intrusions, which have historically been challenging to detect and properly regulate. <xref ref-type="fig" rid="fig-13">Fig. 13</xref> illustrates the KDE Evaluation of Detection Latency, and <xref ref-type="fig" rid="fig-14">Fig. 14</xref> shows Threat Categories vs. Detection Accuracy.</p>
<fig id="fig-13">
<label>Figure 13</label>
<caption>
<title>KDE evaluation of detection latency</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-13.tif"/>
</fig><fig id="fig-14">
<label>Figure 14</label>
<caption>
<title>Threat categories vs. accuracy of detection</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-14.tif"/>
</fig>
<p>To calculate the Confidence Intervals (CIs) for the detection accuracy of each IDS method (HCI-Integrated, Baseline ML, and Traditional IDS) across various threat categories (DoS, Probe, R2L, U2R, and Normal), several assumptions were made based on typical experimental setups. <inline-formula id="ieqn-65"><mml:math id="mml-ieqn-65"><mml:mi>S</mml:mi><mml:mi>a</mml:mi><mml:mi>m</mml:mi><mml:mi>p</mml:mi><mml:mi>l</mml:mi><mml:mi>e</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mi>S</mml:mi><mml:mi>i</mml:mi><mml:mi>z</mml:mi><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>n</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>: A sample size of 30 was assumed, which is commonly used in experimental setups to ensure sufficient statistical power. <inline-formula id="ieqn-66"><mml:math id="mml-ieqn-66"><mml:mi>S</mml:mi><mml:mi>t</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>d</mml:mi><mml:mi>a</mml:mi><mml:mi>r</mml:mi><mml:mi>d</mml:mi><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace" /><mml:mi>D</mml:mi><mml:mi>e</mml:mi><mml:mi>v</mml:mi><mml:mi>i</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>: The standard deviation was supposed to be 0.05, a reasonable value in classification accuracy experiments across datasets. <inline-formula id="ieqn-67"><mml:math id="mml-ieqn-67"><mml:mi>Z</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mi>v</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mi>u</mml:mi><mml:mi>e</mml:mi></mml:math></inline-formula>: A <italic>Z</italic>-value of 1.96 was used for the <bold>95% confidence level</bold>, which is standard for statistical confidence interval calculations. The <inline-formula id="ieqn-68"><mml:math id="mml-ieqn-68"><mml:mi>C</mml:mi><mml:mi>I</mml:mi></mml:math></inline-formula> is calculated using <xref ref-type="disp-formula" rid="eqn-14">Eq. (14)</xref> as;
<disp-formula id="eqn-14"><label>(14)</label><mml:math id="mml-eqn-14" display="block"><mml:mi>C</mml:mi><mml:mi>I</mml:mi><mml:mo>=</mml:mo><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mo>&#x00B1;</mml:mo><mml:mi>Z</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mfrac><mml:mi>&#x03C3;</mml:mi><mml:msqrt><mml:mi>n</mml:mi></mml:msqrt></mml:mfrac></mml:math></disp-formula>where, <italic>mean</italic> is the detection accuracy for each method, <italic>Z</italic> is the <italic>Z</italic>-value for a 95% confidence level, 1.96, <italic>&#x03C3;</italic> is the standard deviation, assumed to be 0.05, and <italic>n</italic> is the sample size, supposed to be 30. The calculation of CIs for each threat category is given below. DoS: HCI-Integrated: 0.97 &#x00B1; 0.018 &#x2192; [0.952, 0.988], Baseline ML: 0.85 &#x00B1; 0.018 &#x2192; [0.832, 0.868], and Traditional IDS: 0.75 &#x00B1; 0.018 &#x2192; [0.732, 0.768]. Probe: HCI-Integrated: 0.95 &#x00B1; 0.018 &#x2192; [0.932, 0.968], Baseline ML: 0.85 &#x00B1; 0.018 &#x2192; [0.832, 0.868], and Traditional IDS: 0.70 &#x00B1; 0.018 &#x2192; [0.682, 0.718]. R2L: HCI-Integrated: 0.90 &#x00B1; 0.018 &#x2192; [0.882, 0.918], Baseline ML: 0.80 &#x00B1; 0.018 &#x2192; [0.782, 0.818], and Traditional IDS: 0.70 &#x00B1; 0.018 &#x2192; [0.682, 0.718]. U2R: HCI-Integrated: 0.92 &#x00B1; 0.018 &#x2192; [0.902, 0.938], Baseline ML: 0.75 &#x00B1; 0.018 &#x2192; [0.732, 0.768], and Traditional IDS: 0.65 &#x00B1; 0.018 &#x2192; [0.632, 0.668]. Normal Traffic: HCI-Integrated: 0.98 &#x00B1; 0.018 &#x2192; [0.962, 0.998], Baseline ML: 0.90 &#x00B1; 0.018 &#x2192; [0.882, 0.918], and Traditional IDS: 0.80 &#x00B1; 0.018 &#x2192; [0.782, 0.818]. These results indicate the confidence intervals for each detection method across different categories. The HCI-Integrated IDS system consistently shows the highest detection accuracy with the narrowest confidence intervals, indicating strong and reliable performance, especially in identifying high-volume and subtle attack patterns. In contrast, the Traditional IDS exhibits lower detection accuracy and wider confidence intervals, highlighting its comparatively less effective performance in the same categories. By estimating these confidence<xref ref-type="fig" rid="fig-15"> </xref> intervals, we can quantitatively understand the precision of each method&#x2019;s detection accuracy across different threat categories. <xref ref-type="fig" rid="fig-15">Fig. 15 </xref> shows Confusion matrix.</p>
<fig id="fig-15">
<label>Figure 15</label>
<caption>
<title>Confusion matrix of the undertaken attacks</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-15.tif"/>
</fig>
</sec>
<sec id="s4_8">
<label>4.8</label>
<title>Error Analysis</title>
<p>The in-depth and comprehensive explanation of Type I errors, popularly known as false positives and those known by simpler terminology as false negatives, clearly highlights another prime strength that is inherently built into the HCI-Integrated system. This very advanced and cutting-edge system has the incredible advantage of detecting and recording the absolute minimum number of error occurrences in both critical dimensions, which, in return, amazingly relieves the working burden commonly linked with false alarms. Additionally, it reduces the risk potential for allowing the threats to escape detection and thus remain unnoticed, making the entire environment much safer for everyone participating in the activities. On the contrary, the Traditional IDS falls victim to a prohibitively excessive proportion of Type II errors, which ironically highlights its built-in weaknesses in detecting danger in a timely and efficient manner, consistently and reliably. <xref ref-type="fig" rid="fig-16">Fig. 16</xref> shows the Error Evaluation of Type I and Type II FP and FN.</p>
<fig id="fig-16">
<label>Figure 16</label>
<caption>
<title>Error evaluation of Type I and Type II FP and FN</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-16.tif"/>
</fig>
</sec>
<sec id="s4_9">
<label>4.9</label>
<title>Cost-Benefit Trade-Off</title>
<p>When one considers the many facets of operational expenses, including the costs of correct detection and the issue of alert fatigue, it is apparent that the HCI-Integrated model offers the most favorable balance in this context. This specific model has the lowest overall cumulative costs, a consideration in which the very low rate of false positives is a major contributing factor, and one that directly mitigates analyst fatigue. Conversely, the Traditional Intrusion Detection System, commonly abbreviated as IDS, has the highest operational expenses, a reality in which the frequency of false positives and the inefficiencies intrinsic to its threat detection are contributing factors. <xref ref-type="fig" rid="fig-17">Fig. 17</xref> shows the Analysis and Evaluation of Cost-Benefit.</p>
<fig id="fig-17">
<label>Figure 17</label>
<caption>
<title>Analysis and evaluation of cost-benefit</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-17.tif"/>
</fig>
</sec>
<sec id="s4_10">
<label>4.10</label>
<title>Usability and Human-Centric Evaluation</title>
<p>The radar chart representing the usability feedback from users clearly shows that the HCI-Integrated system is the highest rated on all dimensions measured, particularly in areas relating to ease of use, understandability of alerts, and confidence levels reported by analysts using the system. This high ranking is precisely in line with its underlying design philosophy, which is HCI-centered. The prioritization of HCI in its design ensures that the model is not just computationally highly efficient but also seamlessly fits into the decision-making workflows used by human operators. Consequently, this careful integration considerably adds to the practical value and effectiveness for security teams that use these systems. The usability evaluation involved simulated users modeled after cybersecurity analysts and IT professionals typically responsible for monitoring intrusion detection systems. These users were modeled based on standard smart cities &#x0026; industry profiles, with varying experience in dealing with IDS alerts. Each simulated user interacted with the system under different scenarios, including high-traffic periods and complex attack patterns, representing the variety of real-world smart city environments. The feedback was anonymously collected and analyzed using statistical methods to gauge the system&#x2019;s performance. The primary focus of the analysis was to determine how well the system reduced alert fatigue and enhanced decision-making clarity, which are crucial for real-world operational environments. The results of this analysis are presented in <xref ref-type="fig" rid="fig-18">Fig. 18</xref>, demonstrating that the HCI-Integrated IDS performed well across all metrics, especially in areas like ease of use, clarity of alerts, and the overall confidence users had in the system&#x2019;s suggestions. These results underscore the system&#x2019;s user-centered design approach, which is key to improving usability and mitigating analyst fatigue.</p>
<fig id="fig-18">
<label>Figure 18</label>
<caption>
<title>Usability feedback (1&#x2013;5 Scale) evaluation by Radar Plot</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-18.tif"/>
</fig>
</sec>
<sec id="s4_11">
<label>4.11</label>
<title>Resource Efficiency</title>
<p>Despite its remarkable and strong performance, the HCI-Integrated system surpasses and stands as the most efficient alternative when considering computational resources. This cutting-edge system requires the least training time and memory in the critical model development phase, which is a great boon. It also consistently has the lowest CPU, memory, and energy consumption levels throughout its operation phase, highlighting its efficiency. In stark contrast, the Traditional IDS has a very different profile, as it requires the highest resource usage levels for all the observed metrics. Such high usage only enhances its operational inefficiency, rendering it a less desirable alternative. <xref ref-type="fig" rid="fig-19">Fig. 19</xref> illustrates the Evaluation of System Resource Utilization regarding MBs, GBs, time, and Energy. Continuing the holistic assessment of the HCI-Integrated Intrusion Detection System, the supplementary experimental findings help further strengthen its outstanding superiority on several important fronts, such as contextual alert management, real-time threat analysis, classification integrity, and operational scalability. Each of these facets is vitally important to the real-world application of these systems in dynamic and high-load environments, being able to cope with the demands imposed by such scenarios.</p>
<fig id="fig-19">
<label>Figure 19</label>
<caption>
<title>Evaluation of system resource utilization regarding MBs, GBs, time, and energy</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-19.tif"/>
</fig>
</sec>
<sec id="s4_12">
<label>4.12</label>
<title>Alert Context Awareness and Distribution</title>
<p>The alert context frequency graph offers a clear and revealing insight into the HCI-Integrated system&#x2019;s added functionality and, more importantly, its advanced contextual differentiation capacity. It is particularly interesting to note that this system raises the most alerts for Network Scans and Unauthorized Access incidents, which are generally acknowledged as early warning signs or precursors of possible reconnaissance activity and intrusion attempts at security compromise. In rather stark contrast, the Traditional IDS appears to have a tendency or a bias for detecting and alerting on instances of Malware Activity and Normal Traffic. This tendency typically results in a high rate of false positives, undermining effective security monitoring and response. In addition, the behavior of the HCI-Integrated system is in perfect agreement with the previously noted reduced Type I error rates, which further supports its competence in contextual discernment as well as accuracy of prioritization. <xref ref-type="fig" rid="fig-20">Fig. 20</xref> shows the Frequency Evaluation of Alert Context.</p>
<fig id="fig-20">
<label>Figure 20</label>
<caption>
<title>Frequency evaluation of alert context</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-20.tif"/>
</fig>
</sec>
<sec id="s4_13">
<label>4.13</label>
<title>Threat Severity Responsiveness</title>
<p>The graph demonstrating the correlation between Time-to-Detect and Threat Severity displays a characteristically linear relationship across all models under examination. That said, it is apparent that the HCI-Integrated system has a notable and evident performance benefit over the others. In the case of critical threats, the HCI-Integrated model impressively detects threats within a striking time frame of around 2.0 s. Conversely, the Baseline Machine Learning model and the Traditional Intrusion Detection System have longer detection times, taking roughly 3.4 and 4.5 s to detect threats. This kind of quick responsiveness that the HCI-Integrated model provides is critical to successfully reducing potential harm in situations with especially high stakes. It also speaks to the operational significance and value of implementing HCI-focused optimization techniques within real-time security systems to improve their general efficacy and reliability. <xref ref-type="fig" rid="fig-21">Fig. 21</xref> illustrates Time to Detect vs. Thread Severity Evaluation.</p>
<fig id="fig-21">
<label>Figure 21</label>
<caption>
<title>Time to detect vs. thread severity evaluation</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-21.tif"/>
</fig>
</sec>
<sec id="s4_14">
<label>4.14</label>
<title>Alert Prioritization and Triage Efficiency</title>
<p>For prioritization, HCI-Integrated more frequently categorizes alerts as &#x201C;Urgent&#x201D; and &#x201C;High&#x201D;, with fewer low-priority alerts. This distribution pattern indicates better triage intelligence, directing analysts to focus on the most impactful threats. Classical IDS has a relatively flat distribution across priority levels, undermining the urgency signal and compounding alert fatigue. <xref ref-type="fig" rid="fig-22">Fig. 22</xref> shows Alert Prioritization Distribution Evaluation.</p>
<fig id="fig-22">
<label>Figure 22</label>
<caption>
<title>Alert prioritization distribution evaluation</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-22.tif"/>
</fig>
</sec>
<sec id="s4_15">
<label>4.15</label>
<title>Throughput under Load</title>
<p>System throughput at increasing concurrency indicates the HCI-Integrated solution&#x2019;s scalability. At 800 concurrent connections, the system retains more than 900 requests/s, far exceeding Baseline ML (&#x007E;760) and Traditional IDS (&#x007E;650). This establishes the HCI-Integrated framework&#x2019;s architectural effectiveness and real-time processing capability, making it useful in enterprise-level and high-demand scenarios. <xref ref-type="fig" rid="fig-23">Fig. 23</xref> shows System Throughput Evaluation Under Load.</p>
<fig id="fig-23">
<label>Figure 23</label>
<caption>
<title>System throughput evaluation under load</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-23.tif"/>
</fig>
</sec>
<sec id="s4_16">
<label>4.16</label>
<title>Classification Performance Metrics</title>
<p>Comparative performance using F1 Score and Matthews Correlation Coefficient (MCC) further cements the dominance of the HCI-Integrated system. With an F1 score of around 0.94 and MCC of about 0.92, the model easily surpasses Baseline ML (F1 &#x007E;0.89, MCC &#x007E;0.82) and Traditional IDS (F1 &#x007E;0.82, MCC &#x007E;0.75). These metrics provide for balanced precision and recall, which is paramount in adversarial threat landscapes where detection effectiveness cannot be gained at the cost of high false positives. <xref ref-type="fig" rid="fig-24">Fig. 24</xref> shows the F1-score and MCC Evaluation.</p>
<fig id="fig-24">
<label>Figure 24</label>
<caption>
<title>F1-Score and MCC evaluation</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-24.tif"/>
</fig>
</sec>
<sec id="s4_17">
<label>4.17</label>
<title>Error Distribution by Attack Class</title>
<p>A detailed examination of classification error distribution concerning attack classes (Normal, DoS, Probe, R2L, U2R) indicates that HCI-Integrated has consistently low error rates even for low-frequency and hard-to-detect attacks like U2R and R2L. This is compared to the sharp error gradient seen with Traditional IDS, which is poor, especially with sophisticated and stealthy intrusions. The Baseline ML model, though reasonably good, still lags in reliability and stability. <xref ref-type="fig" rid="fig-25">Fig. 25</xref> shows the Classification Error Distribution per Attack Class.</p>
<fig id="fig-25">
<label>Figure 25</label>
<caption>
<title>Classification error distribution per attack class</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-25.tif"/>
</fig>
</sec>
<sec id="s4_18">
<label>4.18</label>
<title>Threat Detection Rates</title>
<p>Detection rates across the four primary attack classes, DoS, Probe, R2L, and U2R, show the HCI-Integrated model nearing or exceeding 0.90. This consistent performance indicates comprehensive threat coverage, whereas both Baseline ML and Traditional IDS demonstrate a decline in detection rates as attack complexity increases. The radar plot visually reaffirms this trend, where HCI-Integrated traces the most uniform and outward-reaching profile, indicating a more balanced and effective detection strategy. <xref ref-type="fig" rid="fig-26">Fig. 26</xref> shows Threat Detection Rate by Attack Category, and <xref ref-type="fig" rid="fig-27">Fig. 27</xref> illustrates Detection Rates by Attack Category.</p>
<fig id="fig-26">
<label>Figure 26</label>
<caption>
<title>Threat detection rate by attack category</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-26.tif"/>
</fig><fig id="fig-27">
<label>Figure 27</label>
<caption>
<title>Detection rates by attack category</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-27.tif"/>
</fig>
<p><xref ref-type="fig" rid="fig-28">Fig. 28</xref> shows the testing and training of the three major datasets, while <xref ref-type="fig" rid="fig-29">Fig. 29</xref> shows their comparative evaluations. These long-term results highlight the HCI-Integrated IDS&#x2019;s maturity of operations and strategic advantage on technical and human-centered performance dimensions. By optimizing alert context interpretation, reducing time-to-detect, effectively prioritizing, scaling under load, and maintaining classification integrity, the system resolves the critical conditions for deployment within contemporary cybersecurity architectures. The cumulative evidence validates the HCI-Integrated model as a technological advancement and a paradigm-shifting approach to intrusion detection design. The evidence collectively and vehemently supports the assertion that the HCI-Integrated IDS represents a substantial enhancement over conventional IDS solutions. It offers faster and more accurate detections, lowers operational costs, enhances user experience, and conserves computational resources. These multi-faceted advantages validate the value of integrating human-centered design principles and modern machine learning techniques in the design of intelligent security systems. The HCI-Integrated system ranked the highest in every category, demonstrating its overall superiority in intrusion detection, efficiency, and accuracy. The reduced false positive rate is particularly significant, lowering the cognitive burden on security analysts and averting alert fatigue. The experimental results demonstrate the HCI-Integrated IDS&#x2019;s substantial improvement over traditional rule-based systems and standard machine learning techniques. Its better accuracy, precision, recall, and low false positive rate, coupled with quick detection time, demonstrate its viability as a next-generation IDS solution. Integrating HCI concepts renders the system more usable and facilitates intelligent and effective anomaly detection. This performance confirms the potential of HCI-based approaches to cybersecurity, particularly in configurations requiring real-time threat detection and high decision reliability.</p>
<fig id="fig-28">
<label>Figure 28</label>
<caption>
<title>Training and testing loss of undertakan three datasets</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-28a.tif"/>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-28b.tif"/>
</fig><fig id="fig-29">
<label>Figure 29</label>
<caption>
<title>Comparison of training and testing loss of datasets</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_69110-fig-29.tif"/>
</fig>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Conclusions</title>
<p>This study proposes an HCI-Integrated IDS as a visionary solution for anomaly detection and cyberattack mitigation in smart cities. By incorporating HCI principles into the design of the IDS, the model proposed in this study achieves tremendous enhancements in detection accuracy and operational efficiency. Across a broad spectrum of performance metrics and diagnoses, the HCI-Integrated model consistently demonstrates superior capability on detection accuracy, responsiveness, resource efficiency, usability, and operational scalability. Empirical findings show that HCI-Integrated IDS experiences significantly lower detection latency, particularly under high threat severity and higher throughput under load, which indicates its real-time processing capacity. Its precision in contextual alert differentiation and prioritization facilitates timely and relevant alerting to analysts, reducing cognitive overload and false positive fatigue. Quantitative metrics regarding F1 score, MCC, and threat-wise detection rates validate its technical correctness and classification effectiveness, especially for difficult attack classes such as R2L and U2R. The model also shows minimal error propagation, with fewer Type I and Type II error counts across all threat categories consistently.</p>
<p>Along with lowered operational cost and improved human usability ratings, the HCI-Integrated IDS emerges not only as a top-performing algorithmic solution but also as an effective human-centered system, demonstrating the dividend of integrating principles of human-computer interaction into cybersecurity system design. Future research explores integrating adaptive learning techniques to allow continued model optimization in response to evolving threat landscapes. Moreover, adding HCI modules for explainability and active analyst feedback loops can also aid in system transparency and trust. Deployment on distributed architectures or zero-trust network settings can validate the model&#x2019;s scalability and robustness in production-grade settings.</p>
</sec>
</body>
<back>
<ack>
<p>This work was supported by the Ongoing Research Funding program (ORF-2025-314), King Saud University, Riyadh, Saudi Arabia.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>This work was funded and supported by the Ongoing Research Funding program (ORF-2025-314), King Saud University, Riyadh, Saudi Arabia.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>The data and materials used in this study can be found via the following weblinks. <ext-link ext-link-type="uri" xlink:href="https://www.unb.ca/cic/datasets/index.html">https://www.unb.ca/cic/datasets/index.html</ext-link>, <ext-link ext-link-type="uri" xlink:href="http://kdd.ics.uci.edu/databases/kddcup99/kddcup99.html">http://kdd.ics.uci.edu/databases/kddcup99/kddcup99.html</ext-link>, and <ext-link ext-link-type="uri" xlink:href="https://www.unsw.edu.au/about-us/our-story/our-story-1">https://www.unsw.edu.au/about-us/our-story/our-story-1</ext-link> (accessed on 10 July 2025).</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest to report regarding the present study.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zeng</surname> <given-names>H</given-names></string-name>, <string-name><surname>Yunis</surname> <given-names>M</given-names></string-name>, <string-name><surname>Khalil</surname> <given-names>A</given-names></string-name>, <string-name><surname>Mirza</surname> <given-names>N</given-names></string-name></person-group>. <article-title>Towards a conceptual framework for AI-driven anomaly detection in smart city IoT networks for enhanced cybersecurity</article-title>. <source>J Innov Knowl</source>. <year>2024</year>;<volume>9</volume>(<issue>4</issue>):<fpage>100601</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jik.2024.100601</pub-id>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lytras</surname> <given-names>A</given-names></string-name>, <string-name><surname>Visvizi</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Human-computer interaction and smart city surveillance systems</article-title>. <source>Comput Hum Behav</source>. <year>2021</year>;<volume>124</volume>(<issue>4</issue>):<fpage>106923</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.chb.2021.106923</pub-id>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Islam</surname> <given-names>M</given-names></string-name>, <string-name><surname>Dukyil</surname> <given-names>AS</given-names></string-name>, <string-name><surname>Alyahya</surname> <given-names>S</given-names></string-name>, <string-name><surname>Habib</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Anomaly detection of IoT cyberattacks in smart cities using machine learning</article-title>. <source>J Cybersecur Priv</source>. <year>2023</year>;<volume>8</volume>(<issue>3</issue>):<fpage>21</fpage>. doi:<pub-id pub-id-type="doi">10.3390/bdcc8030021</pub-id>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sharma</surname> <given-names>AK</given-names></string-name>, <string-name><surname>Gupta</surname> <given-names>RK</given-names></string-name></person-group>. <article-title>Network anomaly detection for IoT systems in smart city using edge and cloud collaboration</article-title>. <source>Afr J Biomed Res</source>. <year>2025</year>;<volume>28</volume>(<issue>2</issue>):<fpage>1641</fpage>&#x2013;<lpage>51</lpage>. doi:<pub-id pub-id-type="doi">10.53555/AJBR.v28i2S.7290</pub-id>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Alrashdi</surname> <given-names>M</given-names></string-name>, <string-name><surname>Alqazzaz</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Cyberattacks detection in IoT-based smart city applications using machine learning techniques</article-title>. <source>Int J Environ Res Public Health</source>. <year>2020</year>;<volume>17</volume>(<issue>24</issue>):<fpage>9347</fpage>. doi:<pub-id pub-id-type="doi">10.1109/ccwc.2019.8666450</pub-id>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Islam</surname> <given-names>SMR</given-names></string-name>, <string-name><surname>Hossain</surname> <given-names>MS</given-names></string-name>, <string-name><surname>Muhammad</surname> <given-names>G</given-names></string-name></person-group>. <article-title>The challenges of securing smart cities from cyber-attacks</article-title>. <source>J Emerg Trends Comput Inf Sci</source>. <year>2024</year>;<volume>2024</volume>:<fpage>258</fpage>&#x2013;<lpage>66</lpage>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Islam</surname> <given-names>M</given-names></string-name>, <string-name><surname>Dukyil</surname> <given-names>AS</given-names></string-name>, <string-name><surname>Alyahya</surname> <given-names>S</given-names></string-name>, <string-name><surname>Habib</surname> <given-names>S</given-names></string-name></person-group>. <article-title>An IoT enable anomaly detection system for smart city surveillance</article-title>. <source>Sensors</source>. <year>2023</year>;<volume>23</volume>(<issue>4</issue>):<fpage>2358</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s23042358</pub-id>; <pub-id pub-id-type="pmid">36850955</pub-id></mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>Cognitive city</collab></person-group>. <article-title>Wikipedia [Internet]</article-title>. <comment>[cited 2025 Jan 1]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://en.wikipedia.org/wiki/Cognitive_city">https://en.wikipedia.org/wiki/Cognitive_city</ext-link>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Aslam</surname> <given-names>N</given-names></string-name>, <string-name><surname>Ullah Khan</surname> <given-names>I</given-names></string-name>, <string-name><surname>Abdulrahman Bader</surname> <given-names>S</given-names></string-name>, <string-name><surname>Alansari</surname> <given-names>A</given-names></string-name>, <string-name><surname>Abdullah Alaqeel</surname> <given-names>L</given-names></string-name>, <string-name><surname>Mohammed Khormy</surname> <given-names>R</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Explainable classification model for Android malware analysis using API and permission-based features</article-title>. <source>Comput Mater Contin</source>. <year>2023</year>;<volume>76</volume>(<issue>3</issue>):<fpage>3167</fpage>&#x2013;<lpage>88</lpage>. doi:<pub-id pub-id-type="doi">10.32604/cmc.2023.039721</pub-id>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Sarker Emon</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Abdullah Al Sohan</surname> <given-names>MF</given-names></string-name>, <string-name><surname>Hossain Munna</surname> <given-names>MM</given-names></string-name>, <string-name><surname>Ahmed</surname> <given-names>M</given-names></string-name>, <string-name><surname>Redwan</surname> <given-names>K</given-names></string-name></person-group>. <article-title>CityShield: an IoT-driven and AI-based threat detection system for smart city operations</article-title>. In: <conf-name>Proceedings of the 2025 2nd International Conference on Advanced Innovations in Smart Cities (ICAISC); 2025 Feb 9&#x2013;11</conf-name>; <publisher-loc>Jeddah, Saudi Arabia</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Khan</surname> <given-names>J</given-names></string-name>, <string-name><surname>Elfakharany</surname> <given-names>R</given-names></string-name>, <string-name><surname>Saleem</surname> <given-names>H</given-names></string-name>, <string-name><surname>Pathan</surname> <given-names>M</given-names></string-name>, <string-name><surname>Shahzad</surname> <given-names>E</given-names></string-name>, <string-name><surname>Dhou</surname> <given-names>S</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Can machine learning enhance intrusion detection to safeguard smart city networks from multi-step cyberattacks?</article-title> <source>Smart Cities</source>. <year>2025</year>;<volume>8</volume>(<issue>1</issue>):<fpage>13</fpage>. doi:<pub-id pub-id-type="doi">10.3390/smartcities8010013</pub-id>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ahmed</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Beyioku</surname> <given-names>K</given-names></string-name>, <string-name><surname>Yousefi</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Securing smart cities through machine learning: a honeypot-driven approach to attack detection in Internet of Things ecosystems</article-title>. <source>IET Smart Cities</source>. <year>2024</year>;<volume>6</volume>(<issue>3</issue>):<fpage>180</fpage>&#x2013;<lpage>98</lpage>. doi:<pub-id pub-id-type="doi">10.1049/smc2.12084</pub-id>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Rahmati</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Federated learning-driven cybersecurity framework for IoT networks with privacy-preserving and real-time threat detection capabilities</article-title>. <comment>arXiv:2502.10599. 2025</comment>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Akif</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Butun</surname> <given-names>I</given-names></string-name>, <string-name><surname>Williams</surname> <given-names>A</given-names></string-name>, <string-name><surname>Mahgoub</surname> <given-names>I</given-names></string-name></person-group>. <article-title>Hybrid machine learning models for intrusion detection in IoT: leveraging a real-world IoT Dataset</article-title>. <comment>arXiv:2502.12382. 2025</comment>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hussain</surname> <given-names>T</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>MN</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>B</given-names></string-name>, <string-name><surname>Attar</surname> <given-names>RW</given-names></string-name>, <string-name><surname>Alhomoud</surname> <given-names>A</given-names></string-name></person-group>. <article-title>LiDAR point cloud transmission: adversarial perspectives of spoofing attacks in autonomous driving</article-title>. <source>Comput Secur</source>. <year>2025</year>;<volume>157</volume>(<issue>5</issue>):<fpage>104544</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.cose.2025.104544</pub-id>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Protick</surname> <given-names>TI</given-names></string-name>, <string-name><surname>Sabir</surname> <given-names>A</given-names></string-name>, <string-name><surname>Abhinaya</surname> <given-names>S</given-names></string-name>, <string-name><surname>Bartlett</surname> <given-names>A</given-names></string-name>, <string-name><surname>Das</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Unveiling users&#x2019; security and privacy concerns regarding smart home IoT products from online reviews</article-title>. <source>ACM J Comput Sustain Soc</source>. <year>2024</year>;<volume>2</volume>(<issue>4</issue>):<fpage>1</fpage>&#x2013;<lpage>41</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3685929</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Pawar</surname> <given-names>MV</given-names></string-name>, <string-name><surname>Anuradha</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Detection and prevention of black-hole and wormhole attacks in wireless sensor network using optimized LSTM</article-title>. <source>Int J Pervasive Comput Commun</source>. <year>2023</year>;<volume>19</volume>(<issue>1</issue>):<fpage>124</fpage>&#x2013;<lpage>53</lpage>. doi:<pub-id pub-id-type="doi">10.1108/ijpcc-10-2020-0162</pub-id>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Priyadarshini</surname> <given-names>I</given-names></string-name></person-group>. <article-title>Anomaly detection of IoT cyberattacks in smart cities using federated learning and split learning</article-title>. <source>Big Data Cogn Comput</source>. <year>2024</year>;<volume>8</volume>(<issue>3</issue>):<fpage>21</fpage>. doi:<pub-id pub-id-type="doi">10.3390/bdcc8030021</pub-id>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Garg</surname> <given-names>S</given-names></string-name>, <string-name><surname>Kaur</surname> <given-names>K</given-names></string-name>, <string-name><surname>Batra</surname> <given-names>S</given-names></string-name>, <string-name><surname>Kaddoum</surname> <given-names>G</given-names></string-name>, <string-name><surname>Kumar</surname> <given-names>N</given-names></string-name>, <string-name><surname>Boukerche</surname> <given-names>A</given-names></string-name></person-group>. <article-title>A multi-stage anomaly detection scheme for augmenting the security in IoT-enabled applications</article-title>. <source>Future Gener Comput Syst</source>. <year>2020</year>;<volume>104</volume>(<issue>5</issue>):<fpage>105</fpage>&#x2013;<lpage>18</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.future.2019.09.038</pub-id>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Thomas</surname> <given-names>LT</given-names></string-name>, <string-name><surname>Zorzo</surname> <given-names>AF</given-names></string-name>, <string-name><surname>Morisset</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Impact of using a privacy model on smart buildings data for CO<sup>2</sup> prediction</article-title>. In: <conf-name>Proceedings of the Data and Applications Security and Privacy XXXVII: 37th Annual IFIP WG 11.3 Conference (DBSec 2023); 2023 Jul 19&#x2013;21</conf-name>; <publisher-loc>Sophia-Antipolis, France</publisher-loc>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>George</surname> <given-names>AS</given-names></string-name></person-group>. <article-title>Emerging trends in AI-driven cybersecurity: an in-depth analysis</article-title>. <source>Partn Univers Innov Res Publ</source>. <year>2024</year>;<volume>2</volume>(<issue>4</issue>):<fpage>15</fpage>&#x2013;<lpage>28</lpage>. doi:<pub-id pub-id-type="doi">10.5281/zenodo.13333202</pub-id>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Fan</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Luangsodsai</surname> <given-names>A</given-names></string-name>, <string-name><surname>Sinapiromsaran</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Mass-ratio-average-absolute-deviation based outlier factor for anomaly scoring</article-title>. In: <conf-name>Proceedings of the 2024 21st International Joint Conference on Computer Science and Software Engineering (JCSSE); 2024 Jun 19&#x2013;22</conf-name>; <publisher-loc>Phuket, Thailand</publisher-loc>. p. <fpage>488</fpage>&#x2013;<lpage>93</lpage>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>de Chaves</surname> <given-names>SA</given-names></string-name>, <string-name><surname>Benitti</surname> <given-names>F</given-names></string-name></person-group>. <article-title>User-centred privacy and data protection: an overview of current research trends and challenges for the human-computer interaction field</article-title>. <source>ACM Comput Surv</source>. <year>2025</year>;<volume>57</volume>(<issue>7</issue>):<fpage>1</fpage>&#x2013;<lpage>36</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3715903</pub-id>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sz&#x00FC;cs</surname> <given-names>V</given-names></string-name>, <string-name><surname>Ar&#x00E1;ny</surname> <given-names>G</given-names></string-name>, <string-name><surname>D&#x00E1;vid</surname> <given-names>&#x00C1;</given-names></string-name></person-group>. <article-title>Security awareness of HCI in DigitAll reality</article-title>. <source>Acta Polytech Hung</source>. <year>2025</year>;<volume>22</volume>(<issue>6</issue>):<fpage>9</fpage>&#x2013;<lpage>23</lpage>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Ortloff</surname> <given-names>AM</given-names></string-name>, <string-name><surname>Grohs</surname> <given-names>JA</given-names></string-name>, <string-name><surname>Lenau</surname> <given-names>S</given-names></string-name>, <string-name><surname>Smith</surname> <given-names>M</given-names></string-name></person-group>. <article-title>A qualitative study on how usable security and HCI researchers judge the size and importance of odds ratio and Cohen&#x2019;s d effect sizes</article-title>. In: <conf-name>Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems; 2025 Apr&#x2013;May 1</conf-name>; <publisher-loc>Yokohama, Japan</publisher-loc>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jiang</surname> <given-names>B</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Yue</surname> <given-names>G</given-names></string-name>, <string-name><surname>Cui</surname> <given-names>X</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>HH</given-names></string-name></person-group>. <article-title>Privacy safeguarding for human-computer interaction based on adaptive federated learning with actor-critic selection</article-title>. <source>IEEE Trans Consum Electron</source>. <year>2025</year>. doi:<pub-id pub-id-type="doi">10.1109/tce.2024.3525186</pub-id>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Shafik</surname> <given-names>W</given-names></string-name></person-group>. <chapter-title>Human-Computer Interaction (HCI) technologies in socially-enabled artificial intelligence</chapter-title>. In: <source>Future of digital technology and AI in social sectors</source>. <publisher-loc>Hershey, PA, USA</publisher-loc>: <publisher-name>IGI Global</publisher-name>; <year>2025</year>. p. <fpage>121</fpage>&#x2013;<lpage>50</lpage> doi:<pub-id pub-id-type="doi">10.4018/979-8-3693-5533-6.ch005</pub-id>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hazman</surname> <given-names>C</given-names></string-name>, <string-name><surname>Guezzaz</surname> <given-names>A</given-names></string-name>, <string-name><surname>Benkirane</surname> <given-names>S</given-names></string-name>, <string-name><surname>Azrour</surname> <given-names>M</given-names></string-name></person-group>. <article-title>A smart model integrating LSTM and XGBoost for improving IoT-enabled smart cities security</article-title>. <source>Clust Comput</source>. <year>2024</year>;<volume>28</volume>(<issue>1</issue>):<fpage>70</fpage>. doi:<pub-id pub-id-type="doi">10.1007/s10586-024-04780-1</pub-id>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Uppal</surname> <given-names>M</given-names></string-name>, <string-name><surname>Gulzar</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Gupta</surname> <given-names>D</given-names></string-name>, <string-name><surname>Uppal</surname> <given-names>J</given-names></string-name>, <string-name><surname>Kumar</surname> <given-names>M</given-names></string-name>, <string-name><surname>Saini</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Enhancing accuracy through ensemble based machine learning for intrusion detection and privacy preservation over the network of smart cities</article-title>. <source>Discov Internet Things</source>. <year>2025</year>;<volume>5</volume>(<issue>1</issue>):<fpage>11</fpage>. doi:<pub-id pub-id-type="doi">10.1007/s43926-025-00101-z</pub-id>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Yedalla</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Building cyber&#x2014;resilient smart cities: the role of AI and big data in urban security</article-title>. <source>Int J Sci Res</source>. <year>2025</year>;<volume>14</volume>(<issue>2</issue>):<fpage>648</fpage>&#x2013;<lpage>52</lpage>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Brabin</surname> <given-names>DD</given-names></string-name>, <string-name><surname>Kumar</surname> <given-names>KK</given-names></string-name>, <string-name><surname>Sunitha</surname> <given-names>T</given-names></string-name></person-group>. <article-title>Strengthening security in IoT-based smart cities utilizing cycle-consistent generative adversarial networks for attack detection and secure data transmission</article-title>. <source>Peer Peer Netw Appl</source>. <year>2025</year>;<volume>18</volume>(<issue>2</issue>):<fpage>79</fpage>. doi:<pub-id pub-id-type="doi">10.1007/s12083-024-01838-0</pub-id>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Somanathan Pillai</surname> <given-names>SEV</given-names></string-name>, <string-name><surname>Vallabhaneni</surname> <given-names>R</given-names></string-name>, <string-name><surname>Vaddadi</surname> <given-names>SA</given-names></string-name>, <string-name><surname>Addula</surname> <given-names>SR</given-names></string-name>, <string-name><surname>Ananthan</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Archimedes assisted LSTM model for blockchain based privacy preserving IoT with smart cities</article-title>. <source>Indones J Electr Eng Comput Sci</source>. <year>2025</year>;<volume>37</volume>(<issue>1</issue>):<fpage>488</fpage>&#x2013;<lpage>97</lpage>. doi:<pub-id pub-id-type="doi">10.11591/ijeecs.v37.i1</pub-id>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Hossain</surname> <given-names>MI</given-names></string-name>, <string-name><surname>Hasan</surname> <given-names>R</given-names></string-name></person-group>. <chapter-title>Smart cities: cybersecurity concerns</chapter-title>. In: <source>Computer and information security handbook</source>. <publisher-loc>Amsterdam, The Netherlands</publisher-loc>: <publisher-name>Elsevier</publisher-name>; <year>2025</year>. p. <fpage>1397</fpage>&#x2013;<lpage>412</lpage> doi:<pub-id pub-id-type="doi">10.1016/b978-0-443-13223-0.00089-8</pub-id>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ragab</surname> <given-names>M</given-names></string-name>, <string-name><surname>Ashary</surname> <given-names>EB</given-names></string-name>, <string-name><surname>Alghamdi</surname> <given-names>BM</given-names></string-name>, <string-name><surname>Aboalela</surname> <given-names>R</given-names></string-name>, <string-name><surname>Alsaadi</surname> <given-names>N</given-names></string-name>, <string-name><surname>Maghrabi</surname> <given-names>LA</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Advanced artificial intelligence with federated learning framework for privacy-preserving cyberthreat detection in IoT-assisted sustainable smart cities</article-title>. <source>Sci Rep</source>. <year>2025</year>;<volume>15</volume>(<issue>1</issue>):<fpage>4470</fpage>. doi:<pub-id pub-id-type="doi">10.1038/s41598-025-88843-2</pub-id>; <pub-id pub-id-type="pmid">39915579</pub-id></mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kezron</surname> <given-names>IE</given-names></string-name></person-group>. <article-title>AI and the future of cybersecurity in smart cities: a framework for secure and resilient urban environments</article-title>. <source>Iconic Res Eng J</source>. <year>2025</year>;<volume>8</volume>(<issue>7</issue>):<fpage>612</fpage>&#x2013;<lpage>17</lpage>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hussain</surname> <given-names>A</given-names></string-name>, <string-name><surname>Akbar</surname> <given-names>W</given-names></string-name>, <string-name><surname>Hussain</surname> <given-names>T</given-names></string-name>, <string-name><surname>Kashif Bashir</surname> <given-names>A</given-names></string-name>, <string-name><surname>Al Dabel</surname> <given-names>MM</given-names></string-name>, <string-name><surname>Ali</surname> <given-names>F</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Ensuring zero trust IoT data privacy: differential privacy in blockchain using federated learning</article-title>. <source>IEEE Trans Consum Electron</source>. <year>2025</year>;<volume>71</volume>(<issue>1</issue>):<fpage>1167</fpage>&#x2013;<lpage>79</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tce.2024.3444824</pub-id>.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Goje</surname> <given-names>NS</given-names></string-name>, <string-name><surname>Das</surname> <given-names>D</given-names></string-name>, <string-name><surname>Rani</surname> <given-names>NA</given-names></string-name>, <string-name><surname>Behera</surname> <given-names>SK</given-names></string-name>, <string-name><surname>Pradhan</surname> <given-names>D</given-names></string-name></person-group>. <chapter-title>Security and privacy of EHRs sharing through blockchain technology in smart cities</chapter-title>. In: <source>5G green communication networks for smart cities</source>. <publisher-loc>Palm Bay, FL, USA</publisher-loc>: <publisher-name>Apple Academic Press</publisher-name>; <year>2025</year>. p. <fpage>215</fpage>&#x2013;<lpage>27</lpage> doi:<pub-id pub-id-type="doi">10.1016/b978-0-323-95407-5.00011-6</pub-id>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Sharma</surname> <given-names>K</given-names></string-name>, <string-name><surname>Singh</surname> <given-names>N</given-names></string-name></person-group>. <chapter-title>Security and privacy challenges in 6G enabled smart city</chapter-title>. In: <source>Building tomorrow&#x2019;s smart cities with 6G infrastructure technology</source>. <publisher-loc>Hershey, PA, USA</publisher-loc>: <publisher-name>IGI Global Scientific Publishing</publisher-name>; <year>2025</year>. p. <fpage>39</fpage>&#x2013;<lpage>64</lpage>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Nyangaresi</surname> <given-names>VO</given-names></string-name>, <string-name><surname>AlRababah</surname> <given-names>AA</given-names></string-name>, <string-name><surname>Yenurkar</surname> <given-names>GK</given-names></string-name>, <string-name><surname>Chinthaginjala</surname> <given-names>R</given-names></string-name>, <string-name><surname>Yasir</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Anonymous authentication scheme based on physically unclonable function and biometrics for smart cities</article-title>. <source>Eng Rep</source>. <year>2025</year>;<volume>7</volume>(<issue>1</issue>):<fpage>e13079</fpage>. doi:<pub-id pub-id-type="doi">10.1002/eng2.13079</pub-id>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Abu Al-Haija</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Droos</surname> <given-names>A</given-names></string-name></person-group>. <article-title>A comprehensive survey on deep learning-based intrusion detection systems in Internet of Things (IoT)</article-title>. <source>Expert Syst</source>. <year>2025</year>;<volume>42</volume>(<issue>2</issue>):<fpage>e13726</fpage>. doi:<pub-id pub-id-type="doi">10.1111/exsy.13726</pub-id>.</mixed-citation></ref>
</ref-list>
</back></article>




