Agentic AI-driven Threat Intelligence and Situational Awareness using Explainable Deep Reinforcement Learning and Multi-Agent Secure Rerouting for IoT-enabled Smart Traffic Networks
DOI:
https://doi.org/10.70917/ijcisim-2026-4202Keywords:
IoT security, intelligent transportation systems, agentic AI, deep reinforcement learning, explainable AI, SHAP, LIME, threat intelligence, secure routing, ant colony optimization, multi-agent systems, self-healing networksAbstract
Urban traffic infrastructure is increasingly built on Internet of Things (IoT) devices, vehicle-to-everything (V2X) communication, and edge computing, enabling real-time control but exposing critical attack surfaces to cyber adversaries. Recent work in explainable AI (XAI) and deep learning intrusion detection has shown that high detection accuracy can be achieved for IoT environments, yet many approaches still suffer from high false positive rates (FPR) and limited integration with operational decision-making in cyber-physical systems. This paper proposes an integrated agentic AI framework that combines an explainable deep reinforcement learning (DRL) intrusion detection system (IDS), a threat intelligence engine, and a multi-agent secure rerouting and self-healing mechanism for IoT-enabled smart traffic networks. At the cyber layer, a CNN–LSTM–Attention IDS is enhanced with a Deep Q-Network (DQN) agent that adaptively selects the decision threshold to minimise false positives while preserving high recall on attacks, leveraging XAI methods such as SHAP and LIME for interpretability. At the network control layer, node-level threat scores are aggregated and clustered via K-Means into risk tiers that parameterise an Ant Colony Optimization (ACO)-based secure routing engine. A four-layer multi-agent architecture—sensor/vehicle agents, roadside unit (RSU) agents, edge coordination agents (ECAs), and a Traffic Management Center (TMC) agent—coordinates detection, containment, rerouting, and staged recovery through a five-phase self-healing protocol. Experiments on the CICIoT2023 dataset for IDS evaluation and a 64-intersection SUMO-based urban network demonstrate that the RL-enhanced IDS reduces FPR from 11.782% to 3.194% while maintaining recall above 99%, and that the MASIR (Multi-Agent Secure and Intelligent Rerouting) framework improves resilience and travel time compared to non-secure and non-agentic baselines. These results show that combining explainable deep RL with threat-aware multi-agent routing yields a deployment-ready IDS and control framework for IoT-enabled smart traffic networks.