Explainable and Trustworthy Machine Learning for Network Intrusion Detection

  • Unique Paper ID: 203399
  • Volume: 12
  • Issue: 12
  • PageNo: 12427-12436
  • Abstract:
  • Modern network environments face increasingly sophisticated cyber threats, requiring intrusion detection systems that are both accurate and interpretable. This study proposes a leakage-aware and explainable machine learning framework for network intrusion detection using the UNSW-NB15 dataset. The framework integrates a Random Forest classifier with SHapley Additive exPlanations (SHAP) to achieve high predictive performance and transparent decision-making. A structured preprocessing pipeline involving duplicate removal, missing-value handling, leakage-prone feature elimination, categorical encod-ing, and feature alignment was employed to ensure experimental reliability and reproducibility. A comparative evaluation was conducted using Logistic Re-gression, Decision Tree, K-Nearest Neighbors, Random For-est, and XGBoost classifiers. Experimental results show that ensemble-based models outperform conventional approaches in intrusion detection tasks. The proposed Random Forest model achieved 97.60% accuracy, a 0.9781 F1-score, and a ROC-AUC score of 0.9970, while also demonstrating strong generalization on unseen testing data. SHAP-based analysis identified influ-ential network traffic features contributing to malicious traffic detection, improving model transparency and analyst trust. The findings demonstrate that combining ensemble learning with explainable AI provides reliable and interpretable intrusion detection for modern cybersecurity systems.

Copyright & License

Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.

BibTeX

@article{203399,
        author = {KUMARAN .V and Mrs. Radhika. S and V JAI KRISHNA and S. selvaboopathi and S.Muhilan},
        title = {Explainable and Trustworthy Machine Learning for Network Intrusion Detection},
        journal = {International Journal of Innovative Research in Technology},
        year = {2026},
        volume = {12},
        number = {12},
        pages = {12427-12436},
        issn = {2349-6002},
        url = {https://ijirt.org/article?manuscript=203399},
        abstract = {Modern network environments face increasingly sophisticated cyber threats, requiring intrusion detection systems that are both accurate and interpretable. This study proposes a leakage-aware and explainable machine learning framework for network intrusion detection using the UNSW-NB15 dataset. The framework integrates a Random Forest classifier with SHapley Additive exPlanations (SHAP) to achieve high predictive performance and transparent decision-making. A structured preprocessing pipeline involving duplicate removal, missing-value handling, leakage-prone feature elimination, categorical encod-ing, and feature alignment was employed to ensure experimental reliability and reproducibility.
A comparative evaluation was conducted using Logistic Re-gression, Decision Tree, K-Nearest Neighbors, Random For-est, and XGBoost classifiers. Experimental results show that ensemble-based models outperform conventional approaches in intrusion detection tasks. The proposed Random Forest model achieved 97.60% accuracy, a 0.9781 F1-score, and a ROC-AUC score of 0.9970, while also demonstrating strong generalization on unseen testing data. SHAP-based analysis identified influ-ential network traffic features contributing to malicious traffic detection, improving model transparency and analyst trust. The findings demonstrate that combining ensemble learning with explainable AI provides reliable and interpretable intrusion detection for modern cybersecurity systems.},
        keywords = {Network Intrusion Detection System (NIDS), Explainable Artificial Intelligence (XAI), Random Forest, SHAP, UNSW-NB15, Cybersecurity Analytics, Machine Learn-ing, Leakage-Aware Preprocessing},
        month = {May},
        }

Cite This Article

.V, K., & S, M. R., & KRISHNA, V. J., & selvaboopathi, S., & S.Muhilan, (2026). Explainable and Trustworthy Machine Learning for Network Intrusion Detection. International Journal of Innovative Research in Technology (IJIRT), 12(12), 12427–12436.

Related Articles