EXPLAINABLE MACHINE LEARNING FOR NETWORK INTRUSION DETECTION USING LIGHTGBM AND SHAP: AN IMPLEMENTATION STUDY ON HIKARI-2021
Abstract
Machine-learning intrusion detection systems can provide strong predictive performance while offering limited evidence for why an individual network-flow record was classified as suspicious. This study examines the integration of SHapley Additive exPlanations (SHAP) with a LightGBM-based network intrusion detector trained on HIKARI-2021. The work is extracted from an implemented intelligent hybrid intrusion detection system (IDS), but this paper isolates the explainability contribution rather than treating the complete hybrid architecture as its subject. HIKARI-2021 contains 555,278 records and 83 original columns in the project dataset; after preprocessing, 81 features were retained. LightGBM was configured with 250 estimators, a learning rate of 0.05, 48 leaves, class weighting, and a tuned decision threshold of 0.7987. On the held-out test set, the classifier achieved 90.60% accuracy, 94.63% weighted precision, 90.60% weighted recall, 92.01% weighted F1-score, and an ROC AUC of 0.9522. Suspicious-class precision was 40.50% and recall was 81.89%. SHAP was integrated into the suspicious-prediction pathway to attribute predictions to input features, while a fallback textual explanation was implemented when SHAP output was unavailable. The source experiment did not include a formal quantitative evaluation of explanation fidelity, stability, completeness, or analyst usefulness. Accordingly, this paper reports SHAP as an implemented explainability mechanism and does not claim that SHAP itself improves predictive accuracy or reduces false positives.