Machine Learning and Explainable Artificial Intelligence for Network Intrusion Detection
Ibidun Christiana Obagbuwa et al.
What the paper says
The growing sophistication of cyber threats demands adaptive security mechanisms beyond traditional Intrusion Detection Systems (IDS). This paper explores integrating Machine Learning (ML) and Explainable Artificial Intelligence (XAI) to enhance Network Intrusion Detection Systems (NIDS). Using the CICIDS2017 dataset, the authors evaluate ML models including Convolutional Neural Networks (CNN), Random Forest, and XGBoost, balancing detection performance with interpretability. Results show XGBoost achieves the highest accuracy with minimal misclassifications, underscoring its robustness for intrusion detection. To address the black-box challenge of deep learning, SHapley Additive exPlanations (SHAP) is applied to interpret predictions. Key features such as Destination Port, Flow Duration, and Packet Length emerged as critical, improving trust, reducing false positives, and aiding investigation. The authors highlight the necessity of coupling high-performing ML with XAI frameworks for transparency. Finally, challenges in scalability, robustness, and dataset generalizability are discussed.
Evidence weight
Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40
| F · citation impact | 0.50 × 0.4 = 0.20 |
| M · momentum | 0.50 × 0.15 = 0.07 |
| V · venue signal | 0.50 × 0.05 = 0.03 |
| R · text relevance † | 0.50 × 0.4 = 0.20 |
† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.