Roberto Pazzi, Università degli Studi dell’Insubria, Italy
Davide Facheris, Università degli Studi dell’Insubria, Italy
Davide Tosi, Università degli Studi dell’Insubria, Italy
Resilient digital transformation increasingly depends on trustworthy cyber-physical software, where Digital Twin (DT) ecosystems—virtual replicas of low-power Internet of Things (IoT) devices, edge gateways and industrial assets— must remain available, observable and explainable under attack. These environments are particularly exposed to zero-day threats that exploit the semantic gap between physical states and virtual expectations, while heterogeneous topologies, concept drift and constrained edge resources erode the assumptions of conventional Intrusion Detection Systems (IDSs). We present Ψ-Risk-DT, a Neurosymbolic (NeSy) framework that couples entropy-based anomaly detection with an Associated Random Neural Network (ARNN) and an RDF/SPARQL semantic-reasoning layer through a formal entropy-gated operator Ψ; a Modular Semantic Update (MSU) mechanism rewrites only the affected portions of the DT knowledge graph, and a hybrid loss aligns classification accuracy, graph coherence and semantic consistency with Lyapunov-style stability guarantees. The framework is directly validated in a containerised Network Time Protocol (NTP) amplification scenario representative of volumetric zero-day-like attacks against DT ecosystems, where it achieves an Area Under the Curve (AUC) of 0.993, a False-Positive Rate (FPR) of 0.021 and an end-to-end pipeline latency of approximately 25.8 ms, while MSU reduces the symbolic-update load by up to 88% relative to a global-rewrite ablation evaluated on the same trace. For comparative positioning, these figures are contrasted with values reported in the literature for established IoT/DT IDS baselines (Kitsune, deep-learning zero-day detectors, NeSy-IDS and the (H-DIR)2 predecessor); under the conditions reported in those works, Ψ-Risk-DT exhibits an order-of-magnitude latency gain[C] and a 20–40% FPR reduction[C] relative to deep-learning baselines, presented as a positional comparison rather than as a coevaluated measurement. Broader empirical replication on out-of-distribution (OOD) variants of community benchmarks (Kitsune, WiseML 2024, Sec4ML 2023), on multi-vector Routing Protocol for Low-Power and Lossy Networks (RPL) attack scenarios, and on heterogeneous edge hardware is identified as ongoing future work. Overall, Ψ-Risk-DT provides explainable, entropy-gated, semantically adaptive protection for DT ecosystems and contributes to FSOFT topics on resilient digital transformation, trustworthy cyber-physical software, IoT security, adaptive threat detection and explainable neurosymbolic Artificial Intelligence (AI).