Skip to main navigation Skip to search Skip to main content

Multi-Agent LLM-Based Explainable Intrusion Detection for Proactive Video-Injection Attack Warning in IP Surveillance Systems

  • Mudassir Saleem

Student thesis: Master's Dissertation

Abstract

IP-based surveillance systems are increasingly deployed in critical facilities and smart-city environments, and commonly streaming video over Real-time Transport Protocol using the User Datagram Protocol between cameras and recorder-side components. This reliance on networked video delivery exposes these systems to cyber threats such as video injection attacks (VIA), where adversaries can replace or manipulate video content while the stream remains operational, potentially misleading operators and delaying response. Traditional protection approaches often emphasize post-incident forensic verification, leaving a gap for timely, network-side detection that can warn operators before manipulated content becomes visually evident. This thesis investigated whether packet loss behavior and related stream statistics can provide reliable early-warning detection of VIA in surveillance systems. We proposed and evaluated a lightweight multi-agent framework that includes Detector Agent for onset prediction and Explanator Agent that generates operator-oriented summaries to support triage and response. The study first benchmarked zero-shot large language model (LLM) detection against an XGBoost baseline using three different approaches, then fine-tuned multiple compact LLM backbones on the early-warning representation and evaluated robustness under deployment-like conditions. Based on detection quality, robustness, temporal generalization, and deployment considerations, a fine-tuned Qwen2.5-1.5B-Instruct was selected as the final Detector Agent backbone. Qualitative explainability results further demonstrated that the Explanator Agent can translate detector outputs into actionable messages that clarify what is affected, why an alert matters, and what immediate steps should be considered in a surveillance environment. Overall, the findings demonstrated how coupling detection with explanation can improve operational usability in real-world surveillance monitoring.
Date of Award2026
Original languageAmerican English
Awarding Institution
  • HBKU College of Science and Engineering

Keywords

  • Early-warning detection
  • Explainable AI
  • Intrusion detection
  • IP surveillance systems
  • Large language models
  • Video injection attack

Cite this

'