Skip to content
Open access

Beyond Black Boxes: Permutation Feature Importance for Explainable Intrusion Detection and Model Optimization

Sep 2026 · International Journal of Computer Science and Mathematical Theory · 0 citations

Abstract

Deep learning models for network intrusion detection have demonstrated remarkable accuracy, yet their black-box nature limits trust and adoption in security-critical environments. This paper addresses the interpretability gap by applying permutation feature importance analysis to identify the most influential features in intrusion detection. Using our previously established hard voting ensemble of DNN, LSTM, and CNN models (Godspower et al., 2026), we compute permutation importance scores to quantify each feature's contribution to model performance. Experiments on the UNSW-NB15 dataset reveal that only ten features— particularly label, sbytes, smean, sttl, dmean, proto_udp, service_http, synack, id, and sload—account for the majority of predictive power. Retraining the ensemble on these top ten features yields improved computational efficiency while maintaining accuracy (84.98% vs. 85.01%). Feature importance scores also provide actionable insights for network security analysts, enabling focused monitoring of critical traffic attributes. This work demonstrates that permutation importance not only opens the black box of deep learning intrusion detection but also enables model optimization without sacrificing detection accuracy. The findings establish feature importance analysis as an essential tool for deploying trustworthy and efficient intrusion detection systems in operational environments.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.