ANSCDF-ETI: An Adaptive Neuro-Symbolic Cyber Defense Framework with Explainable Temporal Intelligence for Intelligent Intrusion Detection in Software-Defined Networks
DOI:
https://doi.org/10.70917/ijcisim-2026-4092Keywords:
Software-Defined Networking, Intrusion Detection System, Neuro-Symbolic Artificial Intelligence, Explainable Artificial Intelligence, Temporal Intelligence, Deep Learning, Cybersecurity, Network SecurityAbstract
Software-Defined Networks (SDNS) are for flexible, centralized network management, programmability and dynamic resource discovery and allocation, facilitating the enabling of future communication infrastructures. Nevertheless, the inherent architecture design of SDNs is susceptible to a set of security issues such as the DDoS attack, the compromise of the control-plane and flow tables, reconnaissance and zero-day attacks. Traditional intrusion detection systems results in time constraints due to a low level of adaptiveness, lower learning ability of temporal features, interpretability problems and high false alarm rates.In order to overcome the deficiencies, this paper presents ANSCDF-ETI- an Adaptive Neuro-Symbolic Cyber Defense Framework with Explainable Temporal Intelligence for autonomous cyber security management in SDN. The framework leverages the Hybrid Temporal Intelligence by CNN, BiLSTM and multi-head attention to learn high-complexity spatiotemporal attack patterns, and combines the deep learning predictions with cyber security policy in the Neuro-Symbolic Reasoning Engine to achieve more robust attack detection process. Besides, an Explainable Artificial Intelligence (XAI) module is built to explore the transparent explaination for the cyber security policy with feature attribution and symbolic reasoning, and on-policy adaptation mechanism is adopted to iteratively optimize the security policy based on the detection results and operating feedbacks.The framework was tested and validated over the benchmark datasets: CICIDS2017, CSE-CIC-IDS2018, NSL-KDD and UNSW-NB15. The experimental results show the malicious attack detection accuracy of 98.70% with precision, recall and F1-score of 98.65%, 98.68% and 98.66%, respectively, and ROC-AUC of 0.994 rate while the false positive rate was shown with 0.42% and average detection latency of 12.45 ms. The comparative performance demonstrated the effectiveness of the ANSCDF-ETI framework over traditional machine learning and deep learning models in terms of intrusion detection accuracy, interpretability and adaptability.