2026· International Journal of Scientific and Management Research· Vol 09, pp. 24-30· 0 citations· 7 references
TL;DR
The SHAP analysis identifies the transformed network attributes that contribute most strongly to attack predictions and illustrates how individual records can be explained, which adds an interpretability layer to conventional network-traffic classification and can support analystoriented investigation of suspicious events.
Abstract
Machine-learning-based intrusion detection can identify suspicious network traffic with high
predictive performance, but security analysts also need to understand why a traffic record is
classified as an attack. This paper presents an explainable machine-learning framework for
binary suspicious-traffic detection using the UNSW-NB15 dataset. The study uses a
reproducible stratified sample of 20,000 training records and 10,000 testing records, with
identifier and attack-category fields excluded from the binary model input. Numerical
attributes are median-imputed and standardized, while categorical attributes are imputed and
one-hot encoded. Random Forest is used as the principal predictive model because it provided
the best overall balance in the earlier classifier-comparison study. SHAP (SHapley Additive
exPlanations) is then applied to the trained tree ensemble to provide global feature-importance
explanations and local explanations for individual network records. On the uploaded UNSWNB15 files and the stated sampling/configuration, the rerun achieved 86.95% accuracy, 81.52%
precision, 98.66% recall, 89.28% F1-score and 97.73% ROC-AUC. The SHAP analysis
identifies the transformed network attributes that contribute most strongly to attack predictions
and illustrates how individual records can be explained. The resulting framework adds an
interpretability layer to conventional network-traffic classification and can support analystoriented investigation of suspicious events.
Machine-learning intrusion detection is challenged by attacks resembling legitimate traffic and by class imbalance. This study evaluates Random Forest detection on the UNSW-NB15 dataset for five binary attack-versus-normal tasks: DoS, Exploit, Backdoor, Analysis, and Reconnaissance. Categorical attributes were label-en...
J. Pospíchal, A. Augustín, L. Huraj et al.· Information· 0 citations
Machine-learning intrusion detection systems can provide strong predictive performance while offering limited evidence for why an individual network-flow record was classified as suspicious. This study examines the integration of SHapley Additive exPlanations (SHAP) with a LightGBM-based network intrusion detector trai...
K. Chibueze, Okika Stephen Sunday, Onyeabo Uzoamaka Agatha et al.· World Journal of Advanced En...· 0 citations
The increasing frequency and sophistication of cyber threats have highlighted the need for effective Intrusion Detection Systems (IDS) capable of accurately identifying malicious network traffic. Traditional rule-based frameworks often face limitations in detecting previously unseen attacks and handling high-dimensiona...
Jennifer Adelia Putri, A. Taqwa, A. Handayani· bit-Tech· 0 citations
Class imbalance in Internet of Things (IoT) Intrusion Detection System (IDS) datasets is a major challenge that degrades the detection performance on minority attacks and complicates model interpretability. This study investigates the performance of an IoT IDS based on Random Forest (RF) combined with the Synthetic Min...
Julfikar Mawansyah, Anik Nur Handayani, A. Wibawa et al.· Jurnal Elektronika dan Telek...· 0 citations
Network intrusion-detection models are commonly evaluated with a fixed training and testing
configuration. Such an evaluation does not fully show how a classifier behaves when feature
values or class distributions change. This paper evaluates the robustness of a Random Forest
model using the UNSW-NB15 dataset. The expe...
D. P., H. S· International Journal of Sci...· 0 citations
Machine-learning intrusion detectors often report near-perfect performance on familiar benchmarks, yet their generalization and decision transparency remain uncertain. This study evaluates a reproducible and explainable binary network-intrusion-detection workflow using the NSL-KDD KDDTrain+_20Percent file (25,192 recor...
Dawlat Mustafa Sulaiman· Dasinya Journal for Engineer...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.