Jul 2026· 2026 7th International Conference on Smart Systems and Inventive Technology (ICSSIT)· pp. 706-712· 0 citations· 20 references
Abstract
Advanced persistent threats, zero-day exploits, encrypted command-and-control traffic, and botnet campaigns continue to reduce the reliability of conventional intrusion detection systems because static detectors provide limited transparency and weak adaptation under traffic drift. This paper presents an explainable and adaptive machine learning framework that integrates a LightGBM threat detector, SHAP-based decision explanations, density-aware concept drift detection, active incremental updating, and a contextual bandit defense policy. LightGBM is adopted because its leaf-wise gradient boosting structure provides high discrimination for heterogeneous flow features while maintaining low inference latency and native feature-importance support. The framework is evaluated on CIC-IDS2017, UNSW-NB15, and ToN_IoT using stratified train-validation-test splits, leakage prevention, five-run validation, and a 48-hour Kafka-based streaming simulation. The proposed model achieved 99.1% accuracy, 98.7% F1-score, 98.4% recall, and a 0.007 false alarm rate. During streaming evaluation, 14 adaptive model updates reduced mean detection latency from 27.4 s to 11.2 s, while SHAP explanations based on DNS entropy, JA3 rarity, packet interval, and flow-duration evidence reduced analyst triage time by 23%. Comparative results show that the proposed explainable adaptive pipeline improves detection reliability, reduces false alarms, and supports auditable mitigation decisions better than static and black-box IDS baselines.
The speed of cyberattack evolution and the growing sophistication of new attacks have revealed critical limitations of traditional IDS, specifically in terms of adaptability and interpretability. Although modern machine learning models are highly accurate at detection, their black-box nature makes them opaque, reducing analysts' trust and limiting their practical deployment in security-critical environments. To address this issue, this study proposes an interpretable and adaptive intrusion detection framework that achieves high detection performance and explainable decision-making. The proposed framework is built on a SHAP-enhanced ensemble learning architecture that incorporates heterogeneous classifiers, including tree-based and deep neural network models, to effectively capture complex and diverse attack behaviors. SHAP provide global and instance-level feature attributions, allowing security analysts to understand, validate, and trust model predictions. In addition, adaptive learning mechanisms are introduced to address concept drift in streaming network traffic, making it more robust under changing threat conditions. The framework is tested on benchmark intrusion detection datasets, such as NSL-KDD and CICIDS, with realistic multi-class attack scenarios. Experimental results show that the proposed approach achieves over 98% detection accuracy, an F1-score of more than 0.97, and approximately a 20% reduction in the false positive rate compared with state-of-the-art methods. Overall, the study validates the use of combining ensemble learning with SHAP-based explainability to achieve highly accurate, transparent and adaptive IDS that can be used in next-generation cybersecurity environments.
Alycia Sebastian, S. Priscila, B. M. Praveen· FMDB Transactions on Sustain...· 0 citations
The findings confirm that the proposed IDSaaS framework provides an efficient, scalable, and adaptive solution for real-time cloud intrusion detection and significantly enhances the reliability and resilience of modern cloud and industrial cybersecurity infrastructures.
Unik B. Lokhande, Kavita Sonawane· Journal of Cloud Computing· 0 citations
This paper presents a data-driven analysis of network attack detection and reduction using machine learning, deep learning, and an Autonomous Defense Agent (ADA) for real-time threat detection and response, and provides an ADA design to validate real benchmark datasets.
Marwah Yaseen· Al-Noor Journal of Engineeri...· 0 citations
Modern cyberattacks are increasingly dynamic, multi-stage, and difficult to recognize with static signatures alone. Machine learning (ML) provides a complementary approach by learning patterns from large volumes of security telemetry and identifying behavior that may indicate compromise. This paper presents an integrated framework for applying ML across the cyber threat intelligence lifecycle, from data ingestion and preprocessing to model training, deployment, continuous monitoring, and response. It discusses supervised classification and anomaly detection, together with specialized security functions such as web filtering, dynamic sandboxing, behavioral analysis, deceptive-domain detection, and email protection. The paper also emphasizes a human-in-the-loop model in which automated systems prioritize evidence while analysts validate important decisions. Finally, it considers data drift, concept drift, adversarial manipulation, privacy, and retraining. The proposed approach treats ML as one layer of a broader defense system, combining automated pattern recognition with threat context and human expertise to improve detection speed, reduce alert fatigue, and support adaptive cyber defense.
Mitra Bhargeshbhai Patel, Bindi Bhatt, Dharvi Soni et al.· International Journal of Sci...· 0 citations
A multi-layered intelligent detection system that unites supervised learning, unsupervised anomaly analysis, and ensemble decision strategies to identify network intrusions, malicious software activity, and stealthy advanced persistent threats in near real time is introduced.
Ameen Pasha.A· International Scientific Jou...· 0 citations
An explainable machine learning framework for network intrusion detection using the CICIDS2017 dataset is proposed, which improves detection accuracy, reduces false positives, and supports informed decision-making, thereby enhancing the transparency, trustworthiness, and practical applicability of intrusion detection systems.
Moa’ath Sa’ad Al-A’athal, Q. A. Al-Haija· Recent Progress in Science a...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.