An Improved Explainable Hybrid CNN–LSTM Framework with Leakage-Aware Evaluation for Network Traffic Intrusion Detection
Abstract
This paper proposes an explainable hybrid Convolutional Neural Network–Long Short-Term Memory (CNN–LSTM) model for binary intrusion detection in network traffic using flow-based data. The research problem addressed in this study is the need for a reliable intrusion detection model that preserves temporal traffic behavior, minimizes data leakage during evaluation, handles class imbalance, and generalizes across different network traffic datasets. Experiments were conducted on UNSW-NB15, CSE-CIC-IDS2018, and a merged hybrid dataset, using a hash-based 70/10/20 split with 25 time steps and 30 numerical features. The implementation was developed in Python using TensorFlow/Keras, Scikit-learn, and SHapley Additive exPlanations (SHAP), and was executed on a workstation with an Intel Core i7-12650H CPU, 16 GB RAM, and an NVIDIA RTX 4060 GPU. The proposed model reached 85.76% accuracy and 62.29% attack recall on UNSW-NB15, 98.57% accuracy and 93.53% attack recall on CSE-CIC-IDS2018, and 97.18% accuracy with 88.15% attack recall on the combined dataset. SHAP analysis was used to explain the model’s predictions and identify the most influential traffic features. The main finding is that integrating spatial feature extraction, temporal modeling, leakage-aware evaluation, and explainability improves the reliability, robustness, and interpretability of intrusion detection systems.