Explainable Deep Learning for Network Attack Detection and Classification: A SHAP-Based Interpretation Framework

Authors

  • Anupama Mishra Swami Rama Himalayan University image/svg+xml
  • Pramod Kumar
  • Vinay Rishiwal

Keywords:

CNN, LSTM, SHAP, , Distributed Denial of Service Attacks, DDoS, Network Security, Machine learning, Deep Learning, Web Security

Abstract

There are many attacks on network such as DNS, LDAP, MSSQL, NTP, NetBIOS, PortMap, SNMP, and DDoS. Among all Distributed Denial-of-Service (DDoS) attacks are major security threats in networks. These attacks affect the availability and performance of network services. Traditional intrusion detection methods often face difficulties in identifying different types of attacks accurately. In our research paper, a framework based on an explainable deep learning is proposed to detect and predict multi-classification DDoS attacks. Here, we used the CIC-DDoS2019 dataset for experimentation. Initially, data preprocessing and feature selection are carried out using the Random Forest technique to identify important network traffic features. The selected features are then provided to a hybrid model mix of Convolutional Neural Network (CNN) and Long Short-Term Memory (LSTM) model for classification. The results we achieve as accuracy of 75.39% and a weighted F1-score of 72%. SHAP analysis is applied to explain the prediction results. The tool is used to enhance the interpretability of the model. The analysis shows that Flow Bytes/s, Flow IAT Std, and Fwd Packets Length Total are the most important features for attack detection. The proposed approach provides effective classification along with better understanding of model decisions.

Downloads

Download data is not yet available.

References

[1] Mishra, A., Gupta, N., Gupta, B. B., Bhatia, K., & Aswal, M. S. (2024). Prediction of variants of DDoS attacks based on statistical analysis and machine learning algorithms. International Journal of Innovative Computing and Applications, 15(1), 14-25.

[2] Abdulganiyu, O. H., Ait Tchakoucht, T., & Saheed, Y. K. (2023). A systematic literature review for network intrusion detection system (IDS). International journal of information security, 22(5), 1125.

[3] Mohammadpour, L., Ling, T. C., Liew, C. S., & Aryanfar, A. (2022). A survey of CNN-based network intrusion detection. Applied Sciences, 12(16), 8162.

[4] Imrana, Y., Xiang, Y., Ali, L., & Abdul-Rauf, Z. (2021). A bidirectional LSTM deep learning approach for intrusion detection. Expert Systems with Applications, 185, 115524.

[5] Dwivedi, R., Dave, D., Naik, H., Singhal, S., Omer, R., Patel, P., ... & Ranjan, R. (2023). Explainable AI (XAI): Core ideas, techniques, and solutions. ACM computing surveys, 55(9), 1-33.

[6] Mosca, E., Szigeti, F., Tragianni, S., Gallagher, D., & Groh, G. (2022, October). SHAP-based explanation methods: a review for NLP interpretability. In Proceedings of the 29th international conference on computational linguistics (pp. 4593-4603).

[7] https://www.kaggle.com/datasets/dhoogla/cicddos2019

[8] Ahmed, U., Nazir, M., Sarwar, A., Ali, T., Aggoune, E. H. M., Shahzad, T., & Khan, M. A. (2025). Signature-based intrusion detection using machine learning and deep learning approaches empowered with fuzzy clustering. Scientific Reports, 15(1), 1726.

[9] Varma, M. A. D., Vaasist, G. S., Reddy, B. C., Reddy, M. P., & Nair, R. (2025, April). Intrusion Detection System using Signature and Anomaly based Algorithm. In 2025 International Conference on Inventive Computation Technologies (ICICT) (pp. 838-842). IEEE.

[10] Nguyen, S. K., & Harper, J. P. (2026). Hybrid Signature and Anomaly-Based Detection for API-Centric Microservices.

[11] Blessing, A. I., Chole, A., & Themmah, Y. (2023). Signature-Based vs. Anomaly-Based Detection.

[12] He, Q., Zhang, Y., Xu, A., Ye, Z., Zhou, W., Lin, Q., & Zhang, T. (2026). LSTM-1DResNet: An intrusion detection model for connected and autonomous vehicles based on deep learning. IEEE Transactions on Vehicular Technology.

[13] Kaur, S., Bajaj, R., Bansal, S., & Liu, H. (2026, April). Learning Spatio-Temporal Patterns for Network Intrusion Detection Using a Hybrid CNN-GRU Model. In 2026 13th International Conference on Computing for Sustainable Global Development (INDIACom) (pp. 1-6). IEEE.

[14] Alsarray, Z. A. (2026). GRU-based Federated Learning for Privacy-Preserving Intrusion Detection in SDN-Enabled IoT Networks. Journal Port Science Research, 9(2), 405-413.

[15] Gupta, S., Kaveri, P. R., Gupta, K. K., Awasthi, P., & Shaik, M. (2026, May). Performance comparison of GRU, LSTM, and RNN models for detecting DDoS attacks in cloud infrastructure. In AIP Conference Proceedings (Vol. 3410, No. 1, p. 020069). AIP Publishing LLC.

[16] Gupta, S., & Singh, B. (2026). Lightweight ensemble learning based intrusion detection framework with explainable artificial intelligence. Engineering Applications of Artificial Intelligence, 163, 112936.

[17] Kumar, P. V. P., Swetha, M., Kumari, P. M., Akshitha, P., Sreeja, R., & Harshitha, R. (2026, April). Explainable AI for Cyber Security: Interpretable Threat Analysis Using SHAP and LIME. In 2026 13th International Conference on Computing for Sustainable Global Development (INDIACom) (pp. 1-6). IEEE.

[18] Ghosh, S., Goyal, R. K., & Chowdhury, K. (2026). Explainable AI-Driven Intrusion Detection System for DoS Attack Classification Using Deep Learning and Optimization Techniques. IEEE Access, 14, 5618-5642.

Downloads

Published

2026-01-31