CORTEXA
← Browse
openalexZenodo (CERN European Organization for Nuclear Research)2026-07-25Cited by 0

How Stable Are SHAP Explanations for Network Intrusion Detection? A Perturbation-Based Faithfulness Study

Musa Khan

Explainable AI (XAI) methods such as SHAP are increasingly presented to security operations center (SOC) analysts as a way to justify machine-learning-based network intrusion detection system (NIDS) alerts, on the premise that a stated explanation increases trust and speeds triage. However, an explanation is only useful if it is stable: small, operationally realistic changes to a flow’s measured features should not produce a substantially different explanation for the same underlying event. In this work we quantify SHAP explanation stability for a gradient-boosted NIDS classifier trained on the UNSW-NB15 benchmark (82,332 training / 175,341 testing flows, 9 attack categories). Our classifier achieves 90.07% test accuracy and 0.986 ROC-AUC sing the dataset’s official, distribution-shifted train/test split. On a stratified 500-flow subsample, we apply a small (3% of feature standard deviation) Gaussian perturbation to continuous flow features — well within the range of ordinary measurement jitter — and find that 22.0% of predictions flip label entirely, and that the top-5 SHAP-attributed features overlap with the pre-perturbation explanation only 54.5% of the time on average (Jaccard index). Explanation stability is markedly higher for confidently and correctly classified flows (0.60 mean overlap) than for misclassified flows (0.46) or near-decision-boundary flows (0.44), and specific continuous byte-count and service features are disproportionately responsible for explanation churn. These results indicate that post-hoc explanations for tree-based NIDS models should be treated as confidence-dependent artifacts rather than fixed ground truth, with direct implications for how such explanations are surfaced to SOC analysts.

View free PDFSource page

Related papers

openalexZenodo (CERN European Organization for Nuclear Research)2026-07-26

Detection Depth and Distributed Trust in AI-Based IoT Intrusion Detection: A Systematic Analysis

Gilbert Aimufua, Hashim Abdul Isah

Blockchain-integrated deep learning intrusion detection systems for the Internet of Things have attracted growing research attention, yet the relationship between detection depth and blockchain trust scope in these architectures has not been examined systematically. This analysis…

View free PDFSource page
openalexZenodo (CERN European Organization for Nuclear Research)

Data and Code to reproduce results in paper "A Systematic Literature Review on Graph-Based Models in Credit Risk Assessment"

Lennart John Baals, Yiting Liu, Joerg Osterrieder, Branka Hadji Misheva

Data and Code to reproduce results in paper "A Systematic Literature Review on Graph-Based Models in Credit Risk Assessment" This repository contains the necessary codes to reproduce results in the paper: Baals, L. J., Liu, Y., Osterrieder, J., & Hadji-Misheva, B. (2025). A Syste…

Also available via: European Organization for Nuclear Research

View free PDFSource page
openalexZenodo (CERN European Organization for Nuclear Research)2026-07-26

AI-Driven Intrusion Detection for the Internet of Things: A Scoping Review of Federated Learning, Privacy-Preserving Architectures, and Edge Deployability

Gilbert Aimufua, Godwin Agbonkhese

Federated learning has emerged as the dominant architectural response to the privacy and communication constraints of centralised intrusion detection in Internet of Things environments, yet the field lacks a synthesis that maps the concurrent state of architecture diversity, priv…

View free PDFSource page
openalexZenodo (CERN European Organization for Nuclear Research)2026-07-23

kvsambasivarao/Dataset-repository: Multi-Class Severity-Annotated Controller Area Network (CAN) Dataset for Intrusion Detection

Kambhampati Venkata Sambasiva Rao

Version 1.0 Multi-Class Severity-Annotated Controller Area Network (CAN) Dataset for Intrusion Detection Dataset Availability and Description To facilitate reproducible research in automotive cybersecurity, the dataset developed in this study has been made publicly available thro…

View free PDFSource page
openalexZenodo (CERN European Organization for Nuclear Research)2026-07-23

A Deep Convolutional Neural Network Based Architecture for Accurate Detection of Brain Diseases Using Medical Imaging

Pedireddi Yaswanth Saipavan, Laxmi Math

Brain tumors are among the most life-threatening neurological disorders, and their early, accurate diagnosis through Magnetic Resonance Imaging (MRI) is critical for effective treatment planning. Manual interpretation of MRI scans is time-consuming, subjective, and prone to inter…

View free PDFSource page
openalexZenodo (CERN European Organization for Nuclear Research)2026-07-24

YOLO vs. Diffusion Networks for Underground Pipe Detection: A Case Study Using Ground Penetrating Radar Data

Doaa Senousy, Omar Saad, Shereen Ebrahim, Abbas Abbas, Amr Gody

This repository contains the official open-source code for [YOLO vs. Diffusion Networks for Underground PipeDetection: A Case Study Using Ground PenetratingRadar Data]. ### OverviewThis software provides an end-to-end implementation of deep Learning for Pipeline Detection Using G…

View free PDFSource page