Skip to content
Review Open access

Interpretable Detection of Evolving Network Intrusions: A Review of Explainable Machine Learning and Operational Gaps

Oct 2026 · International Journal of Scientific Research in Artificial Intelligence and Machine Learning · 0 citations · 15 references

Abstract

In this review, the shift from traditional intrusion detection systems (IDSs) to machine-learning based network intrusion detection and explicit explainability is explored. The source material is assembled with recent literature and the field is structured around five recurring concerns: detection capability, data quality and imbalance, feature relevance, cross-dataset generalization and explanation quality. Low-cost deployment is still the reason for using classical supervised/ unsuper-vised approaches, while deep learning and attention-based architectures offer bet-ter representation learning at the cost of higher requirements for computational ef-fort and interpretability. Additional recent reviews and representative studies also reveal that explainability is no longer considered as a visualization add-on, but ra-ther as an operational necessity, especially in the case where the model output has to be cross-checked with security analysts. A number of studies reported, how-ever, the performance is not easy to compare due to different datasets, prepro-cessing techniques, class distributions, train-test splits and metrics used. Useful benchmarks are still CIC-IDS2017 and UNSW-NB15, but the benchmark-only evaluations offer little evidence of robustness when the network conditions change, the attack variants are unseen, or the attacks drift over time. Although there exist complementary types of interpretabilities such as SHAP, LIME, fea-ture-importance analysis, and attention mechanisms, the fidelity of explanations, stability of explanations, computational cost of explanations, and exposure to ad-versarial examples remain underrepresented. From the re-viewed evidence, re-search directions for the future of IDS include cross-dataset and time-aware vali-dation, cost-sensitive evaluation, lightweight explainability, drift-aware learning, and human-centered incident response.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.