Skip to content
Open access

Explainable Machine Learning for Suspicious Network Traffic Detection Using the UNSW-NB15 Dataset

2026 · International Journal of Scientific and Management Research · Vol 09, pp. 24-30 · 0 citations · 7 references

TL;DR

The SHAP analysis identifies the transformed network attributes that contribute most strongly to attack predictions and illustrates how individual records can be explained, which adds an interpretability layer to conventional network-traffic classification and can support analystoriented investigation of suspicious events.

Abstract

Machine-learning-based intrusion detection can identify suspicious network traffic with high predictive performance, but security analysts also need to understand why a traffic record is classified as an attack. This paper presents an explainable machine-learning framework for binary suspicious-traffic detection using the UNSW-NB15 dataset. The study uses a reproducible stratified sample of 20,000 training records and 10,000 testing records, with identifier and attack-category fields excluded from the binary model input. Numerical attributes are median-imputed and standardized, while categorical attributes are imputed and one-hot encoded. Random Forest is used as the principal predictive model because it provided the best overall balance in the earlier classifier-comparison study. SHAP (SHapley Additive exPlanations) is then applied to the trained tree ensemble to provide global feature-importance explanations and local explanations for individual network records. On the uploaded UNSWNB15 files and the stated sampling/configuration, the rerun achieved 86.95% accuracy, 81.52% precision, 98.66% recall, 89.28% F1-score and 97.73% ROC-AUC. The SHAP analysis identifies the transformed network attributes that contribute most strongly to attack predictions and illustrates how individual records can be explained. The resulting framework adds an interpretability layer to conventional network-traffic classification and can support analystoriented investigation of suspicious events.

Read PDF

Similar papers

Open access Aug 2026

Random Forest-Based Network Intrusion Detection with Feature Selection and Class Balancing on UNSW-NB15 Traffic

Machine-learning intrusion detection is challenged by attacks resembling legitimate traffic and by class imbalance. This study evaluates Random Forest detection on the UNSW-NB15 dataset for five binary attack-versus-normal tasks: DoS, Exploit, Backdoor, Analysis, and Reconnaissance. Categorical attributes were label-en...

J. Pospíchal, A. Augustín, L. Huraj et al. · 0 citations
Open access Sep 2026

EXPLAINABLE MACHINE LEARNING FOR NETWORK INTRUSION DETECTION USING LIGHTGBM AND SHAP: AN IMPLEMENTATION STUDY ON HIKARI-2021

Machine-learning intrusion detection systems can provide strong predictive performance while offering limited evidence for why an individual network-flow record was classified as suspicious. This study examines the integration of SHapley Additive exPlanations (SHAP) with a LightGBM-based network intrusion detector trai...

K. Chibueze, Okika Stephen Sunday, Onyeabo Uzoamaka Agatha et al. · 0 citations
Open access Aug 2026

Network Attack Classification Using Random Forest and XGBoost Algorithms on UNSW-NB15 Dataset

The increasing frequency and sophistication of cyber threats have highlighted the need for effective Intrusion Detection Systems (IDS) capable of accurately identifying malicious network traffic. Traditional rule-based frameworks often face limitations in detecting previously unseen attacks and handling high-dimensiona...

Jennifer Adelia Putri, A. Taqwa, A. Handayani · 0 citations
Open access Aug 2026

Explainable IoT Intrusion Detection Using Random Forest, SMOTE, and SHAP

Class imbalance in Internet of Things (IoT) Intrusion Detection System (IDS) datasets is a major challenge that degrades the detection performance on minority attacks and complicates model interpretability. This study investigates the performance of an IoT IDS based on Random Forest (RF) combined with the Synthetic Min...

Julfikar Mawansyah, Anik Nur Handayani, A. Wibawa et al. · 0 citations
Open access 2025

Robustness-Aware Machine Learning for Network Intrusion Detection under Feature and Distribution Variations Using UNSW-NB15

Network intrusion-detection models are commonly evaluated with a fixed training and testing configuration. Such an evaluation does not fully show how a classifier behaves when feature values or class distributions change. This paper evaluates the robustness of a Random Forest model using the UNSW-NB15 dataset. The expe...

D. P., H. S · 0 citations
Open access Aug 2026

AI Transparency in Network Intrusion Detection

Machine-learning intrusion detectors often report near-perfect performance on familiar benchmarks, yet their generalization and decision transparency remain uncertain. This study evaluates a reproducible and explainable binary network-intrusion-detection workflow using the NSL-KDD KDDTrain+_20Percent file (25,192 recor...

Dawlat Mustafa Sulaiman · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.