Skip to content
Open access

Explainable Machine Learning for Suspicious Network Traffic Detection Using the UNSW-NB15 Dataset

2026 · International Journal of Scientific and Management Research · 0 citations · 7 references

Abstract

Machine-learning-based intrusion detection can identify suspicious network traffic with high predictive performance, but security analysts also need to understand why a traffic record is classified as an attack. This paper presents an explainable machine-learning framework for binary suspicious-traffic detection using the UNSW-NB15 dataset. The study uses a reproducible stratified sample of 20,000 training records and 10,000 testing records, with identifier and attack-category fields excluded from the binary model input. Numerical attributes are median-imputed and standardized, while categorical attributes are imputed and one-hot encoded. Random Forest is used as the principal predictive model because it provided the best overall balance in the earlier classifier-comparison study. SHAP (SHapley Additive exPlanations) is then applied to the trained tree ensemble to provide global feature-importance explanations and local explanations for individual network records. On the uploaded UNSWNB15 files and the stated sampling/configuration, the rerun achieved 86.95% accuracy, 81.52% precision, 98.66% recall, 89.28% F1-score and 97.73% ROC-AUC. The SHAP analysis identifies the transformed network attributes that contribute most strongly to attack predictions and illustrates how individual records can be explained. The resulting framework adds an interpretability layer to conventional network-traffic classification and can support analystoriented investigation of suspicious events.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.