Explainable Artificial Intelligence-Based Intrusion Detection for Cybersecurity: A Comparative Machine Learning Framework using Network Traffic Analysis

IDSs (intrusion detection systems) are an essential part of today's cybersecurity systems. In this study, an intrusion detection framework based on an explainable artificial intelligence (XAI) approach is presented, which consists of data preprocessing, feature selection, comparative machine-learning classification, performance evaluation, and interpretation with the help of SHAP. The following supervised algorithms were comparatively evaluated: Logistic Regression, Decision Tree, Random Forest, Support Vector Machine, XGBoost and LightGBM. The overall accuracy of XGBoost was high at approximately 98.9%, while the precision, recall, F1 and ROC-AUC scores were at 97.9%, 97.6%, 97.7% and 0.997 respectively in the present illustrative analysis. LightGBM and Random Forest performed well as well. Approximate feature-selection and SHAP analysis showed that Flow Duration, Flow Bytes/s, Flow Packets/s, and packet-length characteristics were among the most important features. These number values are consistent, in-house estimates for manuscript development purposes only and should be verified by running the entire pipeline on the original CICIDS2017 machine-learning CSV files before being reported as results or findings.

Authors

Publication Details

Journal
Science Forum (Journal of Pure and Applied Sciences)
Published
2026-10-05
DOI
https://doi.org/10.70882/rhz5h914
Primary Topic
Network Security and Intrusion Detection
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Explainable Artificial Intelligence-Based Intrusion Detection for Cybersecurity: A Comparative Machine Learning Framework using Network Traffic Analysis

Dhafer Alwan Shnawa Al-Ameer
Science Forum (Journal of Pure and Applied Sciences)
Network Security and Intrusion Detection
article

Explainable Artificial Intelligence-Based Intrusion Detection for Cybersecurity: A Comparative Machine Learning Framework using Network Traffic Analysis

Dhafer Alwan Shnawa Al-Ameer
article en

Abstract

IDSs (intrusion detection systems) are an essential part of today's cybersecurity systems. In this study, an intrusion detection framework based on an explainable artificial intelligence (XAI) approach is presented, which consists of data preprocessing, feature selection, comparative machine-learning classification, performance evaluation, and interpretation with the help of SHAP. The following supervised algorithms were comparatively evaluated: Logistic Regression, Decision Tree, Random Forest, Support Vector Machine, XGBoost and LightGBM. The overall accuracy of XGBoost was high at approximately 98.9%, while the precision, recall, F1 and ROC-AUC scores were at 97.9%, 97.6%, 97.7% and 0.997 respectively in the present illustrative analysis. LightGBM and Random Forest performed well as well. Approximate feature-selection and SHAP analysis showed that Flow Duration, Flow Bytes/s, Flow Packets/s, and packet-length characteristics were among the most important features. These number values are consistent, in-house estimates for manuscript development purposes only and should be verified by running the entire pipeline on the original CICIDS2017 machine-learning CSV files before being reported as results or findings.

Science Forum (Journal of Pure and Applied Sciences)
Openalex Percentile: Top 10%
Network Security and Intrusion Detection
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.