Explainable Artificial Intelligence-Based Intrusion Detection for Cybersecurity: A Comparative Machine Learning Framework using Network Traffic Analysis
DOI:
https://doi.org/10.70882/rhz5h914Keywords:
Cybersecurity; Intrusion Detection; Machine Learning; Explainable Artificial Intelligence; SHAP; Network Traffic; Feature Selection; CICIDS2017.Abstract
IDSs (intrusion detection systems) are an essential part of today's cybersecurity systems. In this study, an intrusion detection framework based on an explainable artificial intelligence (XAI) approach is presented, which consists of data preprocessing, feature selection, comparative machine-learning classification, performance evaluation, and interpretation with the help of SHAP. The following supervised algorithms were comparatively evaluated: Logistic Regression, Decision Tree, Random Forest, Support Vector Machine, XGBoost and LightGBM. The overall accuracy of XGBoost was high at approximately 98.9%, while the precision, recall, F1 and ROC-AUC scores were at 97.9%, 97.6%, 97.7% and 0.997 respectively in the present illustrative analysis. LightGBM and Random Forest performed well as well. Approximate feature-selection and SHAP analysis showed that Flow Duration, Flow Bytes/s, Flow Packets/s, and packet-length characteristics were among the most important features. These number values are consistent, in-house estimates for manuscript development purposes only and should be verified by running the entire pipeline on the original CICIDS2017 machine-learning CSV files before being reported as results or findings.
Downloads
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Journal of Pure and Applied Sciences (Science Forum)

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.


