Explainable Machine Learning for Suspicious Network Traffic Detection Using the UNSW-NB15 Dataset
Abstract
Machine-learning-based intrusion detection can identify suspicious network traffic with high predictive performance, but security analysts also need to understand why a traffic record is classified as an attack. This paper presents an explainable machine-learning framework for binary suspicious-traffic detection using the UNSW-NB15 dataset. The study uses a reproducible stratified sample of 20,000 training records and 10,000 testing records, with identifier and attack-category fields excluded from the binary model input. Numerical attributes are median-imputed and standardized, while categorical attributes are imputed and one-hot encoded. Random Forest is used as the principal predictive model because it provided the best overall balance in the earlier classifier-comparison study. SHAP (SHapley Additive exPlanations) is then applied to the trained tree ensemble to provide global feature-importance explanations and local explanations for individual network records. On the uploaded UNSWNB15 files and the stated sampling/configuration, the rerun achieved 86.95% accuracy, 81.52% precision, 98.66% recall, 89.28% F1-score and 97.73% ROC-AUC. The SHAP analysis identifies the transformed network attributes that contribute most strongly to attack predictions and illustrates how individual records can be explained. The resulting framework adds an interpretability layer to conventional network-traffic classification and can support analystoriented investigation of suspicious events.