Explainable Artificial Intelligence for Zero-Day Cyberattack Detection in Healthcare: A Critical Review and an Integrated Framework for Clinical Cybersecurity
Lucky Omamuzo Ogagayere-Osagie, Opeoluwa Kajero
Asian Journal of Research in Computer Science · pp. 107–130 · Published 5 Oct 2026
10.9734/ajrcos/2026/v19i10922Abstract
Healthcare delivery organisations have become preferred targets for cyber intrusion, and the clinical consequences of successful attacks now extend beyond information loss to measurable disruption of emergency, critical and diagnostic care. Signature-based defences cannot recognise previously unseen exploits, which has driven interest in machine learning detectors capable of identifying anomalous behaviour without prior knowledge of an attack pattern. Because such detectors are opaque, explainable artificial intelligence has been proposed as the mechanism through which their outputs can be audited, trusted and acted upon in clinical settings. This review examines whether that proposition is supported by the available evidence. Literature was identified through structured searching of open scholarly indexes, supplemented by backward and forward citation searching, and appraised for methodological adequacy, evidential strength and relevance to clinical deployment rather than for benchmark performance alone. The synthesis indicates that the two research streams have developed with limited contact. Work on detection of previously unseen attacks is dominated by retrospective evaluation on a small number of network datasets in which novelty is simulated by withholding labelled classes, a design that systematically flatters reported performance. Work on explanation is dominated by post-hoc feature attribution, whose faithfulness, stability and adversarial robustness remain contested, and which is poorly suited to characterising events that lie outside the training distribution. Healthcare-specific studies inherit both limitations while adding constraints related to medical device heterogeneity, data governance and clinical safety. Evidence that explanation improves analyst or clinician decision quality in security contexts is scarce, and current regulatory expectations for transparency are not matched by validated evaluation methods. An integrated framework is proposed that separates detection novelty, explanation target, explainee role and governance obligation as distinct design decisions, and that treats explanation quality as an empirical property requiring prospective human-centred evaluation rather than an assumed benefit.
Cited by 0
No indexed citations yet.
Related research
- A Real-Time Oil Pipeline Anti-Intrusion System Using Acoustic Sensors — shares topic coverage
- A State of the Art Survey of Machine Learning Algorithms for IoT Security — shares topic coverage
- Deep Learning Approaches for Intrusion Detection — shares topic coverage
- An Enhanced Model for Intrusion Detection in a Cloud Computing Environment — shares topic coverage
- Enhancing Network Performance: A Comprehensive Analysis of Hybrid Routing Algorithms — shares topic coverage
Article metrics
Real usage data collected on this platform.
0
Page views
0
PDF downloads
0
Outbound clicks
0
Citations
Views by country
Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".
No views recorded yet.
Traffic sources
Referring site, by host.
No traffic recorded yet.
Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.