An Explainable Machine Learning for Network Intrusion Detection: A Random Forest and SHAP-based Implementation

No Thumbnail Available
Date
2026
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
In this work, we propose an explainable artificial intelligence (XAI)-based approach for network intrusion detection using the CICIDS2017 dataset. The main objective is to develop an interpretable model capable of detecting multiple types of network attacks while providing clear and transparent explanations for its predictions. A Random Forest classifier is used for multi-class classification. The dataset is preprocessed and analyzed to handle issues such as data imbalance and feature representation. The performance of the model is evaluated using standard metrics including accuracy, precision, recall, and F1-score. In addition to performance evaluation, explainability is introduced using SHAP (SHapley Additive exPlanations). This allows a better understanding of the model’s decisions by identifying the most important features influencing the predictions. The results show that the proposed model achieves high classification performance while providing meaningful insights into its behavior, making it more reliable for real-world intrusion detection applications.
Description
Keywords
Citation
Collections