Reducing False Positives in AI-Based Intrusion Detection Systems Using Hybrid Artificial Intelligence for Oil and Gas Critical Infrastructure
Abstract: The increasing frequency and sophistication of cyberattacks targeting critical infrastructure have accelerated the adoption of Artificial Intelligence (AI)-based Intrusion Detection Systems (IDSs) for real-time cyber threat detection. Although machine learning and deep learning techniques have significantly improved intrusion detection accuracy, high false-positive rates remain one of the most significant challenges affecting operational cybersecurity. Excessive false alerts overwhelm Security Operations Centres (SOCs), increase analyst workload, delay incident response, and may lead to alert fatigue, causing genuine cyber threats to be overlooked. This challenge is particularly critical within oil and gas environments, where cyber incidents can disrupt industrial operations, compromise safety, and result in substantial economic losses. This study proposes a Hybrid Artificial Intelligence (Hybrid AI) approach designed to reduce false positives while maintaining high detection accuracy for intrusion detection systems deployed within oil and gas critical infrastructure. The proposed architecture combines traditional machine learning algorithms, deep learning models, confidence-based decision fusion, and Explainable Artificial Intelligence (XAI) into a unified detection framework. Machine learning algorithms provide efficient classification of structured attack patterns, while deep learning models capture complex spatial and temporal characteristics of network traffic. Decision fusion integrates predictions from multiple AI models using weighted confidence scoring to improve classification reliability and minimize erroneous alerts. The proposed hybrid model is evaluated using publicly available benchmark cybersecurity datasets, including CICIDS2017, UNSW-NB15, NSL-KDD, and a hybrid Operational Technology (OT)/Information Technology (IT) dataset representative of industrial environments. Model performance is assessed using accuracy, precision, recall, F1-score, false positive rate (FPR), false negative rate (FNR), Matthews Correlation Coefficient (MCC), Area Under the Receiver Operating Characteristic Curve (ROC-AUC), and detection latency. The expected findings demonstrate that integrating complementary AI models through intelligent decision fusion significantly reduces false-positive alerts while preserving high detection accuracy and operational efficiency. The study contributes to cybersecurity research by presenting a practical Hybrid AI architecture that improves intrusion detection reliability, enhances analyst confidence through explainable AI, and supports proactive cyber defence within critical infrastructure environments. The proposed approach provides valuable guidance for organizations seeking to improve the effectiveness of AI-enabled intrusion detection systems while reducing operational costs associated with excessive false alarms.