Skip to content
Conference

Explainable AI and Machine Learning Framework for Cyber Threat Detection and Adaptive Defense Systems

Jul 2026 · 2026 7th International Conference on Smart Systems and Inventive Technology (ICSSIT) · pp. 706-712 · 0 citations · 20 references

Abstract

Advanced persistent threats, zero-day exploits, encrypted command-and-control traffic, and botnet campaigns continue to reduce the reliability of conventional intrusion detection systems because static detectors provide limited transparency and weak adaptation under traffic drift. This paper presents an explainable and adaptive machine learning framework that integrates a LightGBM threat detector, SHAP-based decision explanations, density-aware concept drift detection, active incremental updating, and a contextual bandit defense policy. LightGBM is adopted because its leaf-wise gradient boosting structure provides high discrimination for heterogeneous flow features while maintaining low inference latency and native feature-importance support. The framework is evaluated on CIC-IDS2017, UNSW-NB15, and ToN_IoT using stratified train-validation-test splits, leakage prevention, five-run validation, and a 48-hour Kafka-based streaming simulation. The proposed model achieved 99.1% accuracy, 98.7% F1-score, 98.4% recall, and a 0.007 false alarm rate. During streaming evaluation, 14 adaptive model updates reduced mean detection latency from 27.4 s to 11.2 s, while SHAP explanations based on DNS entropy, JA3 rarity, packet interval, and flow-duration evidence reduced analyst triage time by 23%. Comparative results show that the proposed explainable adaptive pipeline improves detection reliability, reduces false alarms, and supports auditable mitigation decisions better than static and black-box IDS baselines.

View source

Similar papers

Open access Aug 2026

Interpretable and Adaptive Intrusion Detection Using SHAP-Enhanced Ensemble Learning and Feature Attribution for Next-Generation Cybersecurity

The speed of cyberattack evolution and the growing sophistication of new attacks have revealed critical limitations of traditional IDS, specifically in terms of adaptability and interpretability. Although modern machine learning models are highly accurate at detection, their black-box nature makes them opaque, reducing analysts' trust and limiting their practical deployment in security-critical environments. To address this issue, this study proposes an interpretable and adaptive intrusion detection framework that achieves high detection performance and explainable decision-making. The proposed framework is built on a SHAP-enhanced ensemble learning architecture that incorporates heterogeneous classifiers, including tree-based and deep neural network models, to effectively capture complex and diverse attack behaviors. SHAP provide global and instance-level feature attributions, allowing security analysts to understand, validate, and trust model predictions. In addition, adaptive learning mechanisms are introduced to address concept drift in streaming network traffic, making it more robust under changing threat conditions. The framework is tested on benchmark intrusion detection datasets, such as NSL-KDD and CICIDS, with realistic multi-class attack scenarios. Experimental results show that the proposed approach achieves over 98% detection accuracy, an F1-score of more than 0.97, and approximately a 20% reduction in the false positive rate compared with state-of-the-art methods. Overall, the study validates the use of combining ensemble learning with SHAP-based explainability to achieve highly accurate, transparent and adaptive IDS that can be used in next-generation cybersecurity environments.

Alycia Sebastian, S. Priscila, B. M. Praveen · 0 citations
Open access Jul 2026

Adaptive intrusion detection system for cloud security using deep learning

The findings confirm that the proposed IDSaaS framework provides an efficient, scalable, and adaptive solution for real-time cloud intrusion detection and significantly enhances the reliability and resilience of modern cloud and industrial cybersecurity infrastructures.

Unik B. Lokhande, Kavita Sonawane · 0 citations
Open access Aug 2026

Network Attack Detection Using Machine Learning, Deep Learning, and Autonomous Defense Agents

This paper presents a data-driven analysis of network attack detection and reduction using machine learning, deep learning, and an Autonomous Defense Agent (ADA) for real-time threat detection and response, and provides an ADA design to validate real benchmark datasets.

Marwah Yaseen · 0 citations
Open access Jul 2026

Beyond the Signature: Machine Learning for Adaptive Cyber Threat Intelligence

Modern cyberattacks are increasingly dynamic, multi-stage, and difficult to recognize with static signatures alone. Machine learning (ML) provides a complementary approach by learning patterns from large volumes of security telemetry and identifying behavior that may indicate compromise. This paper presents an integrated framework for applying ML across the cyber threat intelligence lifecycle, from data ingestion and preprocessing to model training, deployment, continuous monitoring, and response. It discusses supervised classification and anomaly detection, together with specialized security functions such as web filtering, dynamic sandboxing, behavioral analysis, deceptive-domain detection, and email protection. The paper also emphasizes a human-in-the-loop model in which automated systems prioritize evidence while analysts validate important decisions. Finally, it considers data drift, concept drift, adversarial manipulation, privacy, and retraining. The proposed approach treats ML as one layer of a broader defense system, combining automated pattern recognition with threat context and human expertise to improve detection speed, reduce alert fatigue, and support adaptive cyber defense.

Mitra Bhargeshbhai Patel, Bindi Bhatt, Dharvi Soni et al. · 0 citations
Aug 2026

AI-Based Cybersecurity Threat Detection Using Machine Learning

A multi-layered intelligent detection system that unites supervised learning, unsupervised anomaly analysis, and ensemble decision strategies to identify network intrusions, malicious software activity, and stealthy advanced persistent threats in near real time is introduced.

Ameen Pasha.A · 0 citations
Open access Jul 2026

Explainable AI for Intrusion Detection: A SHAP-Guided Machine Learning Framework for Actionable Cybersecurity Insights

An explainable machine learning framework for network intrusion detection using the CICIDS2017 dataset is proposed, which improves detection accuracy, reduces false positives, and supports informed decision-making, thereby enhancing the transparency, trustworthiness, and practical applicability of intrusion detection systems.

Moa’ath Sa’ad Al-A’athal, Q. A. Al-Haija · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.