Skip to content
#explainable ai Open access

A Comparative Study of Explainable (XAI) Deep and Ensemble Learning Models for a Web Application Firewall Using the FWAF Dataset

Sep 2026 · El-Cezeri Fen ve Mühendislik Dergisi · Vol 13, pp. 438-453 · 0 citations · 17 references
Network Security and Intrusion Detection Network Packet Processing and Optimization

TL;DR

This study benchmarks machine learning (ML) and deep learning models for intrusion detection using the publicly available FWAF dataset, and emphasizes the value of balancing performance with interpretability, empowering Security Operations Centers (SOC) to validate automated decisions and foster trustworthy AI-driven web application firewalls.

Abstract

Bridging the gap between predictive accuracy and interpretability in web application security, this study benchmarks machine learning (ML) and deep learning (DL) models for intrusion detection using the publicly available FWAF dataset. We evaluate six widely used classifiers—Logistic Regression, Decision Tree, Random Forest, XGBoost, 1D-CNN, and LSTM—under a highly imbalanced setting (benign-dominant traffic). All models are trained on identical data using a unified pipeline with stratified train/validation/test splits (64%/16%/20%) and class-weight balancing to ensure a fair comparison. Models are assessed using accuracy, precision, recall, F1-score, and imbalance-aware measures (Macro-F1, PRAUC, and MCC). To improve transparency, we integrate Explainable Artificial Intelligence (XAI) techniques—specifically SHAP (SHapley Additive ExPlanations) and LIME (Local Interpretable Model-Agnostic Explanations)—to quantify feature contributions and highlight decision patterns relevant to WAF operation. An ablation study confirms that attack-indicator features (is_xss, is_lfi, is_oci, is_sqli) are derived independently from labels via regex matching, with their removal causing only marginal performance degradation (1–2% Macro-F1). Experimental results show that Random Forest achieves the strongest overall performance (99.3% accuracy, 0.949 Macro-F1, 0.935 PR-AUC), while the feature-based LSTM provides comparable results (99.2% accuracy, 0.937 Macro-F1, 0.928 PR-AUC). Ultimately, the study emphasizes the value of balancing performance with interpretability, empowering Security Operations Centers (SOC) to validate automated decisions and foster trustworthy AI-driven web application firewalls

Read PDF

Similar papers

Open access Aug 2026

Enhancing Vulnerability Detection Precision through Ensemble Learning with Large Language Models

The results show that the ensemble techniques are a practical approach to boost the precision of LLMs in the detection of vulnerabilities and suggest that ensemble methods offer great potential in the advancement of software security analysis.

H. Al-Ofeishat, Azhar Hussain, M. Faheem et al. · 0 citations
Open access Aug 2026

SMOTE-Stack-XAI: An Explainable Stacked Ensemble Learning Framework Integrating Random Forest, XGBoost, SVM and Deep Neural Networks for Real-Time Credit Card Fraud Detection

Credit cards are now the primary tool for digital transactions due to the quick expansion of e-commerce and cashless payment ecosystems. As a result, fraudulent activity has grown proportionately, resulting in significant financial losses for banks, retailers, and cardholders. On the benchmark European cardholder datas...

Bhukya Dharma, D. Latha · 0 citations
Open access Sep 2026

A Hybrid SMOTE-CTGAN and VAE-LSTM Framework for Interpretable Intrusion Detection in Imbalanced Network Traffic

The increasing sophistication of cyber threats and severe class imbalance in network traffic continue to challenge traditional intrusion detection systems. This study proposes a hybrid framework that integrates SMOTE and CTGAN for minority-class augmentation, a Bidirectional Long Short-Term Memory (Bi-LSTM) network for...

Felicia Maake, Justice Nkoana, V. Baloyi et al. · 0 citations
Review Aug 2026

Enhancing Web Application Firewalls with Machine Learning for SQL Injection Detection

Detecting SQL Injection (SQLi) attacks ranks among the most critical challenges in web application security. This research conducted a systematic literature review to identify the research gaps in this domain and responsively designed and optimised a DistilBERT-Stacked Ensemble pipeline to improve detection efficiency...

Lilliane Linnet Musoke, A. Badii, A. Ashlam · 0 citations
Open access Aug 2026

Comparative Analysis of Performance and Interpretability of XGBoost and TabNet Models in IDS Using XAI

Cyberattacks are becoming a more apparent danger to modern network traffic. Robust and transparent Intrusion Detection Systems (IDS) are increasingly needed to counter this massive wave. The emergence of Machine Learning (ML) and Deep Learning (DL) offers a huge advantage in detecting this wave with high precision; nev...

Ahmad Jauharul Ilmi, Denar Regata Akbi · 0 citations
Open access Aug 2026

Explainable Ensemble Learning for Loan Approval Prediction Using XGBoost, LightGBM, and Random Forest with SHAP Analysis

Loan approval prediction is a critical task in financial institutions, as it directly impacts risk management and decision-making processes. However, challenges such as class imbalance and lack of model interpretability often limit the effectiveness and reliability of machine learning approaches. This study proposes an...

Mikaria Gultom · 0 citations

Related blog posts

Google DeepMind Blog Sep 30, 2026

Introducing SynthID Bio

Proof of concept for watermarking AI-generated proteins while preserving biological function.

MIT News · Artificial Intelligence Sep 30, 2026

This game-playing AI is the new champ at Stratego

Able to defeat top-ranked human players and more efficient than other models, the new system could help decision-makers in military maneuvers or business negotiations.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.