International Journal of Computer Networks & Communications (IJCNC)

AIRCC PUBLISHING CORPORATION

IJCNC 07

SHAP-GUIDED XGBOOST FOR EXPLAINABLE
NETWORK INTRUSION DETECTION SYSTEM

Areeba Asif Siddiquee1 , Lamia Alhazmi2 and Asif Irshad Khan3

1Department of Computer Science, Aligarh Muslim University, Aligarh, India
2Department of Management Information System, College of Business Administration,
Taif University, P.O. Box 11099, Taif, 21944, Saudi Arabia
3Department of Computer Science, Aligarh Muslim University, Aligarh, India

ABSTRACT

As the internet and networked systems are increasingly growing, cyberattacks have become a more common occurrence. Therefore, the demand for a highly accurate and efficient Intrusion Detection Systems (IDS) has become very important in recent years. Machine learning models have been used to achieve a high rate of accuracy in intrusion detection, but most are “black boxes,” whereby the decisions they make are difficult to understand and explain. This paper introduces an explainable intrusion detection approach that integrates explainable artificial intelligence with a large language model interpretation and machine learning. The NSL-KDD dataset is used to train and test various classification algorithms, such as Random Forest, Support Vector Machine, Logistic Regression, and XGBoost. The model is the best obtained using grid search CV hyperparameter tuning. Our experimental results showed that using classification XGBoost gave the highest outcome of all succession models. SHAP is used to compute feature importance and explain the model’s predictions for better interpretability. In addition, the framework implements a Large Language Model in order to translate SHAP-level feature-based explanations into a text description understandable to security analysts for making sense of detected attacks. The proposed approach helps to enhance the detection performance and also explains the rationale behind the intrusion detection engine of the Network Intrusion Detection System (NIDS), detecting the specific intrusion, thus enhancing the interpretability of the detection results.

KEYWORDS

Intrusion Detection System (IDS), XGBoost, SHAP, Explainable Artificial Intelligence (XAI), Large Language Model (LLM’s)

Leave a comment

Information

This entry was posted on August 19, 2026 by .

Navigation