Related Experiment Videos
A domain-agnostic explainable framework for network attack detection across diverse traffic datasets
1Department of Computer Science, College of Computer Engineering and Sciences, Prince Sattam bin Abdulaziz University, Al-Kharj, 11942, Saudi Arabia. ad.alanazi@psau.edu.sa.
Scientific Reports
|July 16, 2026
Summary
This study introduces an explainable deep learning framework for robust cyber threat detection across diverse network data. The model achieves high accuracy and provides interpretable insights for improved network security.
Area of Science:
- Cybersecurity
- Artificial Intelligence
- Network Intrusion Detection
Background:
- Modern network security faces challenges from complex, diverse cyber threats.
- Existing intrusion detection systems lack generalizability across datasets and interpretability.
Purpose of the Study:
- To develop and evaluate an explainable deep learning framework for detecting cyber threats in heterogeneous network environments.
- To ensure consistent performance and provide interpretable insights for critical systems.
Main Methods:
- A consistent preprocessing pipeline (normalization, encoding, label alignment) was applied.
- A multi-layer perceptron (MLP) classifier with dropout regularization was trained.
- Explainability was achieved using SHAP and LIME techniques.
Main Results:
- The framework achieved high accuracy: 96.0% (Kitsune), 99.99% (Server-Based), and 99.58% (Malware).
- ROC-AUC values approached 1.00, indicating strong classification performance.
- The model provided both global and instance-level explanations for its predictions.
Conclusions:
- The proposed framework effectively handles heterogeneous network traffic for intrusion detection.
- The explainable nature of the model enhances trust and applicability in critical network security scenarios.