Skip to content
Conference Open access

A Calibrated and Explainable Bimodal Machine Learning Framework for Hybrid Intrusion Detection

May 2026 · International Conference on Machine Learning Technologies · pp. 773-777 · 0 citations · 15 references
Computer Science

Abstract

Modern communication systems face critical gaps in detecting unknown attacks and rare threat classes due to extreme data imbalance and black-box decision logic. We propose a bimodal framework of calibrated and explainable machine learning (ML) for network security, unifying known-class precision with open-set generalization without the complexity of deep learning. Our framework introduces security-oriented feature extraction to enhance signal-to-noise ratio, hybrid resampling (ADASYN + manual boosting) to reduce class imbalance, isotonic calibration and adaptive thresholding $(\tau=0.30 \text{for XSS})$ to recover recall for rare attacks, and SHAP-based explainability to validate domain-aligned decision logic. Evaluated on the CIC-IDS2017 dataset and compared with prior ML models and studies, our framework achieves significant accuracy on known attacks (Macro $\mathrm{F}1 = 0.8626$) and detects unknown classes at 1% FPR with TPR up to 90.17% (DoS slowloris), and 77.04% (Web-XSS). The SHAP analysis confirms decisions are driven by security-relevant features, not model artifacts. Our work bridges the gap between theoretical models and operational IDS by delivering calibrated, explainable, and open-set-capable attack detection and prevention in a single, reproducible framework.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.