Explainable Artificial Intelligence for Zero-Day Cyberattack Detection in Healthcare: A Critical Review and an Integrated Framework for Clinical Cybersecurity
Lucky Omamuzo Ogagayere-Osagie *
Department of Physiology, Faculty of Basic Medical Sciences, University of Delta, Agbor, Delta State, Nigeria.
Opeoluwa Kajero
Department of Information Technology, American Ntercontinental University, Houston, Texas, USA.
*Author to whom correspondence should be addressed.
Abstract
Healthcare delivery organisations have become preferred targets for cyber intrusion, and the clinical consequences of successful attacks now extend beyond information loss to measurable disruption of emergency, critical and diagnostic care. Signature-based defences cannot recognise previously unseen exploits, which has driven interest in machine learning detectors capable of identifying anomalous behaviour without prior knowledge of an attack pattern. Because such detectors are opaque, explainable artificial intelligence has been proposed as the mechanism through which their outputs can be audited, trusted and acted upon in clinical settings. This review examines whether that proposition is supported by the available evidence. Literature was identified through structured searching of open scholarly indexes, supplemented by backward and forward citation searching, and appraised for methodological adequacy, evidential strength and relevance to clinical deployment rather than for benchmark performance alone. The synthesis indicates that the two research streams have developed with limited contact. Work on detection of previously unseen attacks is dominated by retrospective evaluation on a small number of network datasets in which novelty is simulated by withholding labelled classes, a design that systematically flatters reported performance. Work on explanation is dominated by post-hoc feature attribution, whose faithfulness, stability and adversarial robustness remain contested, and which is poorly suited to characterising events that lie outside the training distribution. Healthcare-specific studies inherit both limitations while adding constraints related to medical device heterogeneity, data governance and clinical safety. Evidence that explanation improves analyst or clinician decision quality in security contexts is scarce, and current regulatory expectations for transparency are not matched by validated evaluation methods. An integrated framework is proposed that separates detection novelty, explanation target, explainee role and governance obligation as distinct design decisions, and that treats explanation quality as an empirical property requiring prospective human-centred evaluation rather than an assumed benefit.
Keywords: Explainable artificial intelligence, zero-day attack, intrusion detection, healthcare cybersecurity, Internet of Medical Things, clinical decision support, concept drift